Sunday | 21 March, 2010
CSO
Chris Hoff on Virtualization and Cloud Computing
Bill Brenner 20/11/2008 10:55:00

Chris Hoff, chief security architect for the systems and technology division at Unisys and an advisor on the Skybox Security customer advisory board, is one of the biggest critics of virtualization security out there. Not because it isn't important - but rather because it is vital and needs to mature rapidly.

Here, Hoff explains how a lack of real understanding of virtualization makes it very difficult to secure the technology.

Where do you see the biggest virtualization security holes going into 2009?

Unfortunately, it remains a cloudy issue. When you look at how people think of virtualization and what it means, the definition of virtualization is either very narrow -- that it's about server consolidation, virtualizing your applications and operating systems and consolidating everything down to fewer physical boxes. Or, it's about any number of other elements -- client-side desktops, storage, networks, security. Depending on who you are and where you are, the definition of what's coming in the virtualization world means a lot of different things to a lot of different people. Then you add to the confusion with the concept of cloud computing, which is being pushed by Microsoft and a number of smaller, emerging companies. You're left scratching your head wondering what this means to you as a company. How does it impact your infrastructure? It's very confusing.

And this confusion feeds into the larger security dangers?

Sure. You really have to frame the virtualization discussion around three elements: The first is to talk about securing virtualization. Once you have multiple virtualization platforms, you have to look at what it does to your architecture, your people processes, and how to make sure it's all secure. Next, the discussion has to be about virtualizing security. The first was securing virtualization, the second is virtualizing security -- understanding the impact on people, process and architecture. How do I take what I already have today and use what works and what makes sense, and then understand what the security landscape looks like among the vendors I have and those I'm looking at. The third thing is ultimately security through virtualization, using virtualization to actually achieve better security. If you break the discussion into those three parts, you're better off. All the discussions need to be conducted through the concept of what the business is and where the highest risks are found. Unless you understand all these things, it's just a giant hamster wheel of pain.

How are the IT vendors doing at offering guidance on this issue?

They're doing a very poor job. The first opportunity from a marketing and sales perspective is that it's about creating buzzwords and selling new technology. Until the security technology is more integrated as opposed to bolt-on, the vendors are just doing the best they can with what they have, to suggest they are relevant. From a leadership perspective, you see virtualization vendors at one end of the extreme or the other, you should trust this platform, it's the most secure, etc. In a way they have to be simplistic because it's complex and it's difficult to put holistic guidelines around it. The solution involves far more than bolt-on technology.

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Enter the fully qualified URL, eg. http://www.example.com/
Users posting comments agree to the CSO Online comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Syndicate content Syndicate content Syndicate content
 
Whitepaper

Making the move to Ethernet | A DECISION GUIDE

While enterprises today need higher bandwidth, there is increasing demand for solutions that can provide scalability, performance, simplicity and control at lower costs. Get the best of both worlds - read about Ethernet adoption today.

Sponsored Links