There are several new products in the virtualization and cloud security spaces from PacketMotion, MicroSolved, and LynuxWorks. Each of these companies approach virtualization security from uniquely different ways. Unlike the current set we know and use, these tools could be considered adjuncts for general use, or perhaps specific use cases. All provide additions to the End-to-End virtualization security.
TVP Category Archives
TakeDownCon Dallas: Virtualization Security is NOT just about the Virtual Host
If there was any take-a-way from TakeDownCon related to virtualization, it was that the virtualization host is not the primary attack point but all the ancillary systems that touch it. These systems may not even be considered part of the virtual environment but they certainly can impact the security of the environment.
Tripwire Inc. Acquired
In around 2008 Tripwire started making itself known in the virtualization space with the release of two free tools, Tripwire’s ConfigCheck and OpsCheck. By the time 2009 came around, Tripwire was getting itself fully established in the virtual space for the release of its new product, Tripwire’s vWire. vWire was release in the summer of 2009 and then killed by the end of that year as Tripwire shifted its focus to an acquisition it made for log management to expand the capabilities of its flagship product , Tripwire Enterprise.
VMware Buys Shavlik
VMware has acquired one more company: Shavlik. This acquisition did not come as much of a surprise to me but is an interesting purchase for VMware. There are quite a few Security as a Service vendors that would make sense for VMware to purchase and Shavlik is one of them. The difference between the other vendors and Shavlik is that VMware has a existing track record with Shavlik as Shavlik is integral in two of VMware’s existing products: VMware Go and VMware Update Manager. Shavlik provides a very important patch management system for these existing products and is one line of defense in the security space. Are there other plans for Shavlik? Or this is a way to lock in one set of tools?
Cloud Applications are 3-5 years Out: Underlying Layers are Evolving
These announcements and ideas paint a better direction for cloud development and creation than there existed even one week ago. These announcements also concentrate on the data, not the computer engine(s) within the cloud. It has alwys been about the data.
Security of Performance and Management tools within the Virtual Environment
The problem is that not everything is as black and white as security folks desire. If we implement performance and other management tools, we often need to expose part of our all important virtualization management network to others. But how do we do this safely, securely, with minimal impact to usability? Why do we need to this is also another question. You just have to take one look at the Virtualization ASsessment TOolkit (Vasto) to realize the importance of this security requirement. But the question still exists, how do you implement other necessary tools within your virtual environment without impacting usability?