My Photo
Subscribe in a reader

Recent Comments

Categories


« Lancope and Montego Networks Does VM2VM Visibility with Netflow | Main | Virtual Security NIC - Concept »

June 22, 2008

TrackBack

TrackBack URL for this entry:
http://www.typepad.com/services/trackback/6a00e55005749e883300e55367c5788833

Listed below are links to weblogs that reference Security Between Virtual Machines?:

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Benjamin Wright

John: Although I agree security is important, sometimes the media make a bigger deal about break-ins (such as the one at TJX) than is warranted. --Ben http://hack-igations.blogspot.com/2008/04/more-on-tjx-data-breach-and-federal.html

John Peterson

Absolutely! The media does make things out to be bigger than they are. For this reason its even more important to safeguard your "virtual networks" in the way I am describing. Because a corporation not only runs the risk of lost revenue, customer dissatisfaction but runs the risk of public embarrassment and affects on reputation and brand. The media can be down right nasty. So, avoid all the drama I say and secure to the fullest.

This blog topic was in no way targeted at TJ Max however, it is a valid example of how hackers can penetrate your network if you are taking the stance of "well, it hasn't been done this way before..." and therefore not introducing something new to safeguard your networks.

-John Peterson

Christofer Hoff

John:

Your example, while defined as being high-level, assume that I'd mix web front-end, application and database servers running in VM's in the same host.

Secondly, it quietly assumes that these VM's are connected to the same vSwitch in the same VLAN as part of the same portgroup to allow for unobstructed traffic routing.

Obviously if these conditions are met, you're ripe for exploit, but really...

It all goes back to the point you brought up in the beginning; we don't do this today in the physical realm and if you do: (1) shame on you and (2) you're not introducing anything "different" simply by virtualizing.

Further, most people aren't virtualizing their databases and the notion of not using built-in clustering versus abandoning this strategy for Vmotion is not likely.

I'm not picking on you specifically, but these "reduction to the rediculous" corner case illustrations aren't practical or realistic.

NOW, I would say that virtualization is an opportunity to ADD additional security without having to forklift, but it should be framed this way and not by using FUD.

/Hoff

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment