« Not one cloud fits all | Main | Measuring Security Performance, Part II »

August 19, 2009

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00d8341e76b553ef0120a505736d970b

Listed below are links to weblogs that reference Pesky Virtual Environments:

Comments

Todd Ignasiak

You raise some good issues here. But I think most of these are solvable problems. Of course, I'm biased.. I work at Altor Networks and we make a virtual firewall that addresses virtualization security concerns.

We use VMsafe to integrate into the hypervisor. Being embedded into the platform allows us to wrap each VM in a firewall policy to address the intra-VM communications within the hypervisors. You get the per-machine policy of a host firewall, without all the disadvantages (OS support limits, exposure to malware in the machines, lack of separation between security & sysadmin, etc.)

As for the 'policy on the move' issues, in our model the policy and session state table follow the VM as it migrates. Typically the firewall is deployed on all the hypervisors in the cluster that a VM can migrate to -- with an automated installer that simplifies this process. But, if there were some misconfiguration and a VM migrates to a non-firewalled hypervisor, the administrator has chosen whether this results in blocking traffic to ensure security or allowing connections to maintain availability.

There are certainly challenges in securing a virtual infrastructure. But, being able to embed into the hypervisor, hook into the management layer, and automate security deployment gives some huge advantages over what can be done in physical network security.

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

  • Burton Group Free Resources Stay Connected Stay Connected Stay Connected Stay Connected


Blog powered by TypePad