Virtualisation security problems will grow says panel

Nick Lowe, Check Point's regional director for Northern Europe, said that attacks on virtual servers and allied environments are likely in the near future and, because virtual environments are effectively a single entity, this actually increases the risk of attack.

James Pattinson, divisional director with DNS (Digital Network Services) Arrow, a value-added distributor in the security space, said that there is a need for education about the security risks of virtual environments, and that vendors can be helped by their specialist systems integrators and dealers in this regard.

"The task is a difficult one, but with education about the security risks - and the solutions - the challenge of virtualisation security can be met very effectively", he said.

Simon Perry, a principal analyst with Quocirca, meanwhile, said that virtualisation has changed the IT security ballgame, but the main problem is that the overall IT attack surface has increased due to the shift to a virtualised environment.

Most security exposures, he explained, actually come from the technology involved in virtualised environments, with the hypervisor - the virtual machine monitor that sits at the heart of the virtual system - posing a high security risk.

It is "choke points" like this, said Perry, that will engender the most potential attacks, since the hypervisor enables access to the physical server, which gives access to (for example) 30 virtual machines.

"So will we see attacks at the choke point? Yes. Will they be successful against the hyper visor? Yes they will", he said.

IT managers, he added, must decide on the level of complexity, as there are undoubtedly security flaws in the hypervisor environment and, as a result, it will become a target of security attacks.

As a result of this, Perry sees two main areas that attackers will go after in a virtual environment; the operating system that hosts the hypervisor platform and the system admin side of the server.

Fredrik Sjostedt, EMEA product marketing director with VMware - one of the main players in the virtual software environment - said that the evolution of security has become a never-ending process.

The problem facing users of virtualised environments, he said, is that the process of migration is not a simple switchover, but more a gradual process, so the issues of securing the environment become a lot more complex.

Chris Bidgland, EMEA global services director with RSA, concurred Sjostedt's view, adding that his clients are making the migration to a virtual environment a gradual process and, as a result, the IT security needs to be a lot tighter to cover all the possible issues.

"We are already talking to our clients about creating a high-level response team of professionals and advisers to help them respond as quickly and efficiently as possible if the worst does happen," he said.

"We are planning to make an announcement on this service at the upcoming RSA Europe event," he added.

What’s hot on Infosecurity Magazine?