Friday | 10 July, 2009
CSO
Security concerns cloud virtualization deployments
IT managers worry the intangible boundaries in virtual environments might not keep out the bad guys
Denise Dubie (Network World) 26/11/2007 07:19:36

4. The newness of hypervisor technology could be an invitation to hackers

Any new operating system is rife with flaws. So, does that mean hackers are champing at the bit to find virtual-operating-system vulnerabilities and launch security attacks?

Industry watchers advise security managers to remain a bit skeptical about virtual operating systems and their potential to introduce more holes and vulnerabilities than they can patch manually.

"Virtualization is essentially a new operating system, which is something that hasn't been done for a long time, and it enables an intimate interaction between underlying hardware and the environment," says Rich Ptak, founder and principal analyst at Ptak, Noel and Associates. "The potential for messing things up is significant."

The virtual hypervisor may not represent as much of a security threat on its own as people might think, however. Having learned from Microsoft's well-publicized problems patching Windows, companies such as VMware may have worked to limit the potential for security holes in the hypervisor technology.

"VMware has done a good job compared to Microsoft, and the vendor seems to be ahead of that type of issue," says Peter Christy, principal at Internet Research Group. "But a hypervisor is a small piece of code that represents a small and limited surface area, which is easier to make more secure than 80 million lines of code."

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Additional Resources
Newsletter Subscription
Sign up for our CSO Online newsletters!
RSS Feeds
Syndicate content
 
Whitepaper

The business justification for data security

In the information security world we face two major types of threats: "noisy" threats which directly interfere with our ability to do business and "quiet" threats which cause real damage, but don't necessarily prevent people from doing their jobs. Read on to discover how to combat both types of threats and to justify the use of data security within your business.

Sponsored Links