Category: Top » Computers » Information-technology »


Author: Sciencelogic | Total views: 132 Comments: 0
Word Count: 885 Date: Fri, 20 Mar 2009 11:07 PM

FOSE 2009 - The Virtual Reality: Securely Embracing Virtualization

It's become common knowledge that virtualization has plenty of benefits but plenty of drawbacks as well. Virtual machines can contribute to the "greening" of data centers and lower costs on space, power, cooling and provisioning. As virtualization adoption begins to pick up at the agency level, all potential security risks must be scrutinized to ensure the required level of security.

One of FOSE's afternoon sessions today, "The Virtual Reality: Securely Embracing Virtualization," explored the threats that exist when agencies turn to virtualization, and included personal experiences and best practices the panelists. The panel consisted of:
* Bill Bockoven, (moderator), VP- Public Sector, APC by Schneider Electric
* Josh Corman, Principal Security Strategist, IBM Corporation
* Brent Conran, Director of Information, Security, U.S. House of Representatives
* Jack Nichols, Director, Enterprise Operations, U.S. House of Representatives

Bill and Josh started off by discussing how agencies can securely adopt virtualization and what existing threats must be considered prior to any virtualization implementation. They suggest that it is important to cut your teeth on virtualizing a low-risk asset, since the first attempt quite often fails, simply due to unforeseen migration or integration issues. Clustering servers to keep information with similar levels of sensitivity together as well as using provisioning to prevent sprawl are two additional policies to pay attention to during migration.

Josh outlined some common mistakes:
* Elective risk - beware of Type 2 server virtualization for production
* Failure to establish policy - need to create guidelines and organize processes
* Failure to consider compliance - regulation has not caught up to virtualization yet; will you still be PCI compliant?
* Failure to involve security - make sure to build in security at all levels
* Failure to control live migration - can create a domino effect of failures
* Failure to have performance/capacity plan - virtualization is not devoid of bottlenecks, agencies must properly plan for expected capacity
* 'Silver bullet' virtual appliances - Can lead to a false sense of security

Best practices:
* Install security in each guest VM
* Apply defense-in-depth
* Lock-down management
* Segment networks with VLANs
* Use stand-alone security appliances

Limitations:
* New VMs need security provisioning
* Redundant security = more resources
* Management nightmare

And what to expect to see from providers in the next 12-18 months:
* Apply defense-in-depth
* Shrink the management stack
* Install security VM on each machine
* Integrate security VM with VMM

Jack and Brent presented a case study along with first hand accounts of the House of Representatives' move to virtual storage. The primary reason for The House's move was lack of juice, as the House's IT deparment functions out of an older government building and was hitting the ceiling when it came to power - there just wasn't enough. Each office had their own file server kept behind a locked door, for security reasons, creating a highly-distributed storage environment. To further complicate matters, each office was in charge of its own IT tools.

As a solution, Jack and Brent looked to consolidate servers and bring them into a proper data center environment using virtual blade servers, storage area networks, back-up solutions, redundant sites and encryption to solve the power problem, all while maintaining required security levels. This undertaking was also inline with the Green Capital Initiative, a movement to encourage political leaders to find ways to make the capital more environmentally friendly, with a virtualized data center being a prime example of a green IT solution.

Their first attempt to virtualize some of their most mission-critical assets failed miserably. They failed not because of technology, however, but because all levels of employees were not educated on virtualization and how it affected their operations. Senior management needed to be retrained because all processes had changed and what they had done before didn't exist anymore; there was also no longer a system of checks and balances.

After going through the implementation, some security challenges they discovered were:
* Traditional threats are still there (like poorly thought-out patches, IT changes, etc.) but with additional complexity
* Virtual sprawl - what should be virtualized? Microsoft Exchange, firewalls and payroll are bad ideas
* Inter VM server traffic - traffic patterns change so existing security measures don't work correctly anymore
* Access Control - server administrator will have access to everything in the environment creating a potential security threat
* Segregation of data - Plan what you are going to virtualize and how
* Organizational ownership - Who owns what now?

Jack and Brent suggest using third-party tools to monitor and enforce provisioning. This can be a double-edged sword, as it is very important to choose the right tools for what you are monitoring or it can create a sense of false security. Different monitoring tools can watch data that exists in different types of environments (mixed and static), so it is important to understand your needs before implementation.

Overall, they assert that while virtualizing IT operations does add complexity and introduces operational risks, it has plenty of benefits too. It increases time to market, lowers IT's impact on the environment, saves money and centralizes information.

About the Author

David Link is president and CEO of ScienceLogic. He and his partners built a thriving company from the ground up by focusing on delivering "products that just work" to the underserved virtualization management and monitoring solutions marketplace. He has held senior management and corporate officer positions at large public companies.




Rate, comment or bookmark this article

Seed Newsvine

Rating: Not yet rated

Bookmark this article in your preferred program
AddThis Social Bookmark Button

Comments RSS

No comments posted.

Add Comment

Your Name:


Your Email:


Comment

Enter the code shown

Visual CAPTCHA



Popular Articles in this cathegory

1: How facebook proxy work or proxies bloked to unblock?
Facebook proxy bypass servers are necessary if you have some reason to hide the IP address either of your internet connection, or of the site to which you are trying to connect. You can use proxies blocked to unblock any site. Why should anybody want to do this, and how do Facebook proxy providers work?

2: Amazing Technological Advancements Of 2008
As a global people, technology is moving ahead so quickly that we are beginning to get a sense that just about anything is possible, and nothing is impossible. However, some technological advancements continue to surprise us - information technology consulting and network performance management have created some of 2008's amazing technological advancements, which we examine here.

3: Information Technology in Hospitality Industry
Most hotels are familiar with booking rooms and reservations over the phone, but information technology has expanded well beyond that. Information technology in the hospitality industry is still going forward.

4: Tips to Increase the Speed of Your Windows XP PC
Windows XP is definitely the most popular OS as on date. But people complain it getting slower as time progresses. Following great tips will considerably improve the spees of your Windows XP PC.

5: Importance of IT Systems Management Service
Information Systems is the heart of any business. Factors such as globalization and outsourcing have led to increased demand for an effectual IT environment. A good server system is key to handle an enterprise's business activities smoothly and effectively.


Creative Commons License
This article is licensed under a Creative Commons Attribution-Noncommercial-No Derivative Works 3.0 License.
Spanish taslation