Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Virtualized security: the next frontier

Security: Risk and Reward By Andreas M. Antonopoulos , Network World , 03/11/2008
Andreas Antonopoulos

Companies are adopting virtualization technologies at a faster and faster rate. They are virtualizing servers, desktops, storage, networks. But one aspect of infrastructure has been lagging – very few companies address the growing demand for virtualized security.

Virtualized security is security technology that uses virtualization principles to create a flexible, logical security layer inside a virtualized data center. Because of the unique dynamic nature of a virtualized environment, traditional static security measures are often insufficient. Not only is it hard to manage static security devices next to a pool of dynamic virtual servers, but the security often gets in the way of the benefits of virtualization.

Encapsulation and portability of virtual machines free your virtual servers, allowing them to move from server to server. But if the security context can’t follow the servers, you’re forced to keep them stuck in place. Fortunately the virtualized security market is getting a lot more attention this year.

Up to this point, most virtual security offerings have been either virtual-appliance based or have deployed an agent inside a virtual machine. That gives them flexibility but also only limited access to virtual machine “internals.” A new solution from VMWare may change the table-stakes and inject momentum into the nascent virtual security industry. The recently announced VMSafe program will be a framework and API for virtual security services to interact with virtual machines and the hypervisor.

The API lets a virtual security tool inspect and filter all of a virtual machine’s memory, CPU, processes, storage and network traffic. That gives virtual security solutions the ability to act on a virtual machine while maintaining complete isolation from any nasty stuff running inside. Unlike agent-based solutions that run on the operating system and can be disabled or compromised by malware, virtual security solutions would lie beyond the reach of the operating system.

Virtual security technologies have two effects. In the short term, they allow companies to overcome the difficulties of securing a virtual environment. Security engineers can use virtual security to build solutions that support virtual servers without compromising on important virtualization features such as resource-pooling and live migration (VMotion, XenMotion etc.) of virtual machines. In the longer term, virtual security can use the principles of virtualization to take security to a whole new level.

Partner Content

Explore the Ultrium Edge

The powerful tape technology can address data security with tape encryption as well as long term data protection.

Find out more

Disk and Tape Square Off

Discover what disk and tape really cost -- and which solution provides lower total cost of ownership and optimizes energy use for your organization

Download the White Paper

Don't Fall For The Myths

The Clipper Group explores the truth behind the myths of tape, digging into the misconceptions in the disk vs. tape debate.

Download the White Paper

Will You Add Tape Too?

Over two thirds of disk-only users look to add tape back into storage infrastructure according to recent survey.

Download Survey Information

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.