Original URL: http://www.theregister.co.uk/2010/09/06/virtual_security/

Virtual security: Even better than the real thing?

The jury's still out

By Dan Olds, Gabriel Consulting

Posted in Virtualization, 6th September 2010 10:24 GMT

VMworld VMware is taking some big steps in the security and network management arena with its vShield product set. I sat in on a deepish dive into the somewhat new security products being offered by VMware to deliver on the ‘secure’ part of their “Secure Hybrid Cloud” initiative.

The speakers went through each of the three offerings, along with outlining VMware’s security philosophy, at a very brisk pace. (VMware hasn’t yet provided the slide sets from the presentations, so I’m left with my cryptic and sometimes indecipherable notes.)

In terms of messages around VMware’s security offerings, I took away the following broad points:

1. Security is too complicated, and takes too many separate devices to configure/control.

2. Security now belongs in the hypervisor layer.

3. Workloads in VMs are more secure than workloads on physical systems.

4. Customers using vShield can cut security costs by 5x compared to today’s current state-of-the-art, while improving overall security.

Do I buy all of this? Let me put a firm stake in the sand by saying I’m sure that security is too complicated. It’s definitely too complicated for me. But all the rest of it? Color me undecided.

Putting security into the hypervisor layer makes conceptual sense from a simplification standpoint, and it would certainly cut down the number of things that need to be configured and managed. But does combining security with the hypervisor make things too simple? Is there enough configurability in the products to handle the unique needs of the enterprise?

I also have some questions about how this will impact overall VM and system performance. Under the vShield, separate hardware to handle security tasks is a thing of the past – security moves to the hypervisor layer and protects the guest VMs from intrusions, spam, and other nasty stuff. For example, as I understand it, you would have only one firewall per physical host that would protect all of the VMs running inside that host.

When asked, the VMware speakers did admit that this will add a significant processing load to the host systems, but said that the demands shouldn’t cause much impact on existing workloads since CPUs are still generally underutilized, even on highly virtualized systems.

They also made the point that eliminating security appliances would cut down on a lot of redundant processing due to the elimination of a myriad of individual appliances and potentially cut a lot of costs as well. Fair points all, but I’d like to see how it works in the real world and hear how it’s working with customers to see if the trade-offs are a net benefit.

The three new and/or improved vShield products that received the most attention at the show were vShield Edge, vShield App, and vShield Endpoint.

The edge product is a network gateway that provides firewalling, DHCP, VPN, load balancing, and other typical functions that you’d find in a hardware-based gateway appliance. vShield App protects individual applications hosted in VMs by monitoring network traffic between virtual machines to maintain separation and enforce isolation policies. It’s sort of a virtual ‘air gap’ that takes the place of physically isolating systems. The endpoint package is an antivirus solution that uses a secure VM to handle inspection chores for the entire host.

In my casting around looking for perspective on vShield and VMware’s security strategy, I found these blog posts by Chris Hoff. He’s a renaissance geek with 20 years of IT security experience and, as he puts it, “a passion for virtualization and all things cloud.” He had me at “My life? It’s like Blade Runner meets Beautiful Mind w/some Patrick Swayze Roadhouse violence mixed in.”

He’s currently the director of cloud/virtualization security stuff at Cisco, but that doesn’t seem to color his opinions or much of anything else in his blog. Here are his first and second takes on VMware’s vShield offerings.

It’s going to be interesting to see the uptake of vShield. While I have questions, I think that this move by VMware is important – and a pretty good strategy. Many of the questions that customers have about cloud (both internal and external) revolve around security, and these offerings show that VMware sees security as a crucial part of its product set.

It also gives VMware significant differentiation from Microsoft, Xen, and KVM offerings. Of course, it puts it at odds with others in the industry, including anyone who makes a gateway or security appliance. It also moves it into the enterprise systems management space, where the lineup of rivals includes Tivoli, CA, HP, and a host of other players. ®