Feeds

Fake servers even less secure than real ones

But not necessarily so

Choosing a cloud hosting partner with confidence

The prognosticators at Gartner are at it again, and this time they are guessing that IT shops are not going to be as diligent in securing their virtual servers as they need to be for many years to come.

The company has released a new report, with the catchy title Addressing the Most Common Security Risks in Data Center Virtualization Projects, that makes predictions based on surveys of IT shops doing server virtualization projects in 2009. (You can shell out some cash for the report here.)

According to Gartner's surveys, only about 18 per cent of the workloads running on servers that could be virtualized have been virtualized as of the end of last year. By the end of 2012, three long IT years later, Gartner is projecting that about 50 percent of the applications that are suited to be run atop hypervisors will be lifted one level up above their physical boxes.

This is all well and good, but virtual machines and their software stacks are mobile, thanks to live migration, which allows VMs to be teleported from one physical server to another (provided their hypervisors are compatible). Applications running on a single virtual server will have differing levels of trust and security, too, and the virtual networks inside of hypervisors do not generally plug into intrusion detection systems and other security appliances on existing physical networks, so this virtual traffic is largely invisible in terms of security.

"Virtualization is not inherently insecure," explains Neil MacDonald, the vice president at Gartner who wrote the report. "However, most virtualized workloads are being deployed insecurely. The latter is a result of the immaturity of tools and processes and the limited training of staff, resellers, and consultants."

Oddly enough, in many cases, security seems to not even be an afterthought, much less a forethought. Gartner's surveys show that 40 per cent of server virtualization projects were done without bringing the company security experts in from the get-go as the virtualized infrastructure was planned.

While companies do have processes in place to secure hardware, operating systems, and networks, they do not always have processes to lock down access to the hypervisor and its virtual machine monitoring (VMM) tools.

Gartner recommends that companies have to get tools to check the hypervisors and tools at boot time to make sure they are not compromised and that they never rely on host-based tools running inside a virtual environment to assess the security of hypervisors and VMMs. And Gartner adds that IT shops should brace themselves for this hypervisor layer to become the plump, juicy target that it is for hackers to try to crack. Administrative access to the hypervisor has to be controlled tightly and monitored continually.

But, not everyone will do the things they need to do, just as is the case with physical servers, thanks to laziness or ignorance. And therefore Gartner is projecting that through 2012, when virtualization is firmly established in the data center, some 60 per cent of virtualized servers will be less secure than the physical servers they replace. And by 2015, Gartner projects, some 30 per cent of virtual servers will still be less secure than if their workloads had been running in bare-metal mode on physical boxes. ®

Remote control for virtualized desktops

More from The Register

next story
Just don't blame Bono! Apple iTunes music sales PLUMMET
Cupertino revenue hit by cheapo downloads, says report
The DRUGSTORES DON'T WORK, CVS makes IT WORSE ... for Apple Pay
Goog Wallet apparently also spurned in NFC lockdown
IBM, backing away from hardware? NEVER!
Don't be so sure, so-surers
Hey - who wants 4.8 TERABYTES almost AS FAST AS MEMORY?
China's Memblaze says they've got it in PCIe. Yow
Microsoft brings the CLOUD that GOES ON FOREVER
Sky's the limit with unrestricted space in the cloud
This time it's SO REAL: Overcoming the open-source orgasm myth with TODO
If the web giants need it to work, hey, maybe it'll work
'ANYTHING BUT STABLE' Netflix suffers BIG Europe-wide outage
Friday night LIVE? Nope. The only thing streaming are tears down my face
Google roolz! Nest buys Revolv, KILLS new sales of home hub
Take my temperature, I'm feeling a little bit dizzy
Storage array giants can use Azure to evacuate their back ends
Site Recovery can help to move snapshots around
prev story

Whitepapers

Cloud and hybrid-cloud data protection for VMware
Learn how quick and easy it is to configure backups and perform restores for VMware environments.
Forging a new future with identity relationship management
Learn about ForgeRock's next generation IRM platform and how it is designed to empower CEOS's and enterprises to engage with consumers.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Intelligent flash storage arrays
Tegile Intelligent Storage Arrays with IntelliFlash helps IT boost storage utilization and effciency while delivering unmatched storage savings and performance.
Website security in corporate America
Find out how you rank among other IT managers testing your website's vulnerabilities.