Feeds

How many VMs are on your LAN – and how sure are you?

Server sprawl is virtually back

Combat fraud and increase customer satisfaction

Server virtualisation is taking companies back to the bad old days when they had no idea how many PCs and servers they had, because employees were buying them unchecked.

Now it is all too easy to run up a new virtual Windows server, without realising that under Microsoft's rules, each virtual machine (VM) needs its own software licence. As a result, company bosses risk being hit with large fines for running unlicensed systems, warns Walter Scott, the CEO of backup software developer Acronis.

"Right now people are bringing up machines without management knowing – in my company we had 12 added without my knowledge," he said. "We see a lot of customers trying to balance their VM count – they're losing control of it. It's like the server sprawl we saw 10 or 15 years ago.

"My concern is people will bring up unlicenced machines, and that's a big fine for wilful infringement."

He suggested this could even be one reason why Microsoft has sought to limit the number of times a Windows licence can be moved from server to server as part of a VM.

"I think software asset management is why Microsoft is changing its licensing," he said. "My understanding is that you're only allowed to move a VM so many times a year, they own't let you move it to and fro."

He pointed out that you can't find VMs with a physical asset check - you have to audit the network and hope they are online.

Even then, much network auditing software was written with physical servers in mind, and it can have problems detecting VMs, simply because it is not looking for the right things.

Craig Isaacs, president of Neon Software, said that while it is no problem for his LANsurveyor auditing tool to track VMs once they have been detected, it needed work to enable it to pick them up in the first place.

"We put special hooks into LANsurveyor for discovering and identifying VMs because people were having so many problems with understanding exactly what was running on their networks," he explained.

"In most cases it actually is no more difficult to discover the VMs and what's on them," agreed Francis Sullivan, CTO of Spiceworks, which is about to release a new version of its free IT management and discovery software.

"Of course, just like physical assets, people can configure them incorrectly making them undiscoverable or they can do that intentionally," he said. "The good news is that that's a small percent of the time."

Isaacs added that it's possible a VM won't be spotted on the first scan, particularly if attempts have been made to hide it, although a continuous network scan should pick it up later.

The irony in all this is that Walter Scott's company is at least partly responsible for the growing virtual sprawl and his resulting sleepless nights – as part of its backup mission, Acronis sells software that makes it easy to convert physical servers into virtual and vice versa. ®

3 Big data security analytics techniques

More from The Register

next story
This time it's 'Personal': new Office 365 sub covers just two devices
Redmond also brings Office into Google's back yard
Kingston DataTraveler MicroDuo: Turn your phone into a 72GB beast
USB-usiness in the front, micro-USB party in the back
AMD's 'Seattle' 64-bit ARM server chips now sampling, set to launch in late 2014
But they won't appear in SeaMicro Fabric Compute Systems anytime soon
Brit boffins use TARDIS to re-route data flows through time and space
'Traffic Assignment and Retiming Dynamics with Inherent Stability' algo can save ISPs big bucks
Microsoft's Nadella: SQL Server 2014 means we're all about data
Adds new big data tools in quest for 'ambient intelligence'
prev story

Whitepapers

Mobile application security study
Download this report to see the alarming realities regarding the sheer number of applications vulnerable to attack, as well as the most common and easily addressable vulnerability errors.
3 Big data security analytics techniques
Applying these Big Data security analytics techniques can help you make your business safer by detecting attacks early, before significant damage is done.
The benefits of software based PBX
Why you should break free from your proprietary PBX and how to leverage your existing server hardware.
Securing web applications made simple and scalable
In this whitepaper learn how automated security testing can provide a simple and scalable way to protect your web applications.
Combat fraud and increase customer satisfaction
Based on their experience using HP ArcSight Enterprise Security Manager for IT security operations, Finansbank moved to HP ArcSight ESM for fraud management.