Steps to Safer Virtual Servers

At last week's Black Hat conference, virtualization security was one of the hottest topics and sources of debate. If you're trying to get a grip on how your enterprise's virtualization security stacks up, consider this advice from Chris Whitener, chief security strategist, HP Secure Advantage.

By Chris Whitener, CIO.com,

At last week's Black Hat conference, virtualization security was one of the hottest topics and sources of debate. If you're trying to get a grip on how your enterprise's virtualization security stacks up, consider this advice from Chris Whitener, chief security strategist, HP Secure Advantage.

1. Protect your host operating system by using server hardening tools and methodologies.

Additional OS features such as isolation capabilities and strong security between OS partitions makes it easier for you to decrease the "attack surface" of a host OS.

MORE ON VIRTUALIZATION SECURITY VMware's Free ESXi Will Cost You if it's Not Secured Properly How to Find and Fix 10 Real Security Threats on Your Virtual Servers Future Threats to Virtualization Security: Fact vs. Fiction

2. Ensure that your host OS is as secure as the guest operating system.

A virtual machine inherits all vulnerabilities of a host OS. Select a virtualization technology which provides strong security isolation (enforces distrust) between guest OS instances if needed. If organizations are concerned about malicious software in one guest OS attacking another OS, or don't have mutual trust among administrators of the different guest OSes, then the virtualization layer must be designed to enforce the idea of distrust.

3. Security policies in the host OS should reflect requirements of individual virtual machines.

Using the host OS to implement compliance requirements further enhances your assurance of compliance. It can be relied upon independently of trust in the administration of the guest OS.

4. Manage virtual processes more like you already manage your physical resources.

The host OS security lifecycle and virtual machine security lifecycle(s) must both be managed efficiently thought the data center. Ideally, the virtual infrastructure would be managed in the same way as physical resources. This includes software configuration, updates and patches, auditing and performance monitoring.

5. Stay vigilant about securely managing the physical infrastructure.

Deploying workloads on virtualized platforms make them more mobile, and provides flexibility and agility; this does not mean that the physical infrastructure can be ignored. The physical infrastructure has a critical role in supporting the good execution of those workloads, and the security of the virtualized infrastructure depends on the physical resource configuration and access control being managed securely across the data center.

For more advice on improving the security of your virtual infrastructure, see CIO.com's in-depth feature article How to Find and Fix 10 Real Security Threats on Your Virtual Servers. Also see CIO.com's virtualization security expert Edward L. Haletky's blogs for continuing virtual security coverage.

Copyright © 2008 IDG. All rights reserved.

Related Articles
- Bolt-On Security for Virtual Servers
Virtualization security planning done at every step of design and implementation will help you handle key issues including data co-mingling, network attack prevention, forensics, auditing, disaster recovery, and business continuity.
- Virtual Servers Within the DMZ Networks
- OpenVZ / Virtuozzo
- Choosing the Correct Web Hosting Service
- Credit Cards For Online Shopping
- Auditing and Improving Virtual Server Security
- Tips for Increasing Virtual Machines
- Hosting Types
- Web Servers And Firewall Zones
- Virtual Machines May Pose New Threats
Regional Articles
- Steps to Safer Virtual Servers Alabama
- Steps to Safer Virtual Servers Alaska
- Steps to Safer Virtual Servers Arizona
- Steps to Safer Virtual Servers Arkansas
- Steps to Safer Virtual Servers California
- Steps to Safer Virtual Servers Colorado
- Steps to Safer Virtual Servers Connecticut
- Steps to Safer Virtual Servers DC
- Steps to Safer Virtual Servers Delaware
- Steps to Safer Virtual Servers Florida
- Steps to Safer Virtual Servers Georgia
- Steps to Safer Virtual Servers Hawaii
- Steps to Safer Virtual Servers Idaho
- Steps to Safer Virtual Servers Illinois
- Steps to Safer Virtual Servers Indiana
- Steps to Safer Virtual Servers Iowa
- Steps to Safer Virtual Servers Kansas
- Steps to Safer Virtual Servers Kentucky
- Steps to Safer Virtual Servers Louisiana
- Steps to Safer Virtual Servers Maine
- Steps to Safer Virtual Servers Maryland
- Steps to Safer Virtual Servers Massachusetts
- Steps to Safer Virtual Servers Michigan
- Steps to Safer Virtual Servers Minnesota
- Steps to Safer Virtual Servers Mississippi
- Steps to Safer Virtual Servers Missouri
- Steps to Safer Virtual Servers Montana
- Steps to Safer Virtual Servers Nebraska
- Steps to Safer Virtual Servers Nevada
- Steps to Safer Virtual Servers New Hampshire
- Steps to Safer Virtual Servers New Jersey
- Steps to Safer Virtual Servers New Mexico
- Steps to Safer Virtual Servers New York
- Steps to Safer Virtual Servers North Carolina
- Steps to Safer Virtual Servers North Dakota
- Steps to Safer Virtual Servers Ohio
- Steps to Safer Virtual Servers Oklahoma
- Steps to Safer Virtual Servers Oregon
- Steps to Safer Virtual Servers Pennsylvania
- Steps to Safer Virtual Servers Rhode Island
- Steps to Safer Virtual Servers South Carolina
- Steps to Safer Virtual Servers South Dakota
- Steps to Safer Virtual Servers Tennessee
- Steps to Safer Virtual Servers Texas
- Steps to Safer Virtual Servers Utah
- Steps to Safer Virtual Servers Vermont
- Steps to Safer Virtual Servers Virginia
- Steps to Safer Virtual Servers Washington
- Steps to Safer Virtual Servers West Virginia
- Steps to Safer Virtual Servers Wisconsin
- Steps to Safer Virtual Servers Wyoming
Related Articles
- Bolt-On Security for Virtual Servers
Virtualization security planning done at every step of design and implementation will help you handle key issues including data co-mingling, network attack prevention, forensics, auditing, disaster recovery, and business continuity.
- Virtual Servers Within the DMZ Networks
- OpenVZ / Virtuozzo
- Choosing the Correct Web Hosting Service
- Credit Cards For Online Shopping
- Auditing and Improving Virtual Server Security
- Tips for Increasing Virtual Machines
- Hosting Types
- Web Servers And Firewall Zones
- Virtual Machines May Pose New Threats

Rss   Delicious   Digg   Add To My Yahoo   Add To My Google   Bookmark   Search Plugin

Topics:
Advertising Family Home Services Real Estate Resources
Business Services Fashion Industrial Goods & Services Retail & Consumer Services
Career Financial Services Insurance Software
Cars Food & Beverage Internet Technology
Computer Hardware Franchise Legal Telecommunications
Construction Health Miscellaneous Trade Shows
Education Holidays Nightlife Travel
Entertainment Home Appliances Online Database Weddings
Environmental Home Electronics Pets World History