Virtualization Security
Submitted by smsharif on Wed, 04/29/2009 - 12:56.
A lot of virtualization has happened in organizations without any regard for security. Security professional can continue to warn businesses about some of the impending security issues with virtualization, don't expect them to secure their environments unless and until a system(s) is compromised.
Although all the attacks are possibilities, none of them have actaully happened. Some of the possibilities are:
- Timing attacks against another guest OS
- Network attacks which could render the hypervisor to crash
- Guest hopping attacks
- VM migration attacks
Mitigating risks against virtual machines:
- Restrict access to VM consoles
- Use OOB (Out of Band) network for VM Management
- Use OOB network for SANS used for VM environments
- Implement security controls on how VM backups are handled
- Implement security controls on how VM snapshots are handled
- Have standard images of OS for virtual environments, and ensure those images are protected against un-authorized modification
- Install all applications on the Guest OS as if it was running on bare metal
Posted in Submitted by smsharif on Wed, 04/29/2009 - 12:56.
- smsharif's blog
- Add new comment
- 133 reads

