Skip Links

Network World

  • Social Web 
  • Email 
  • Close

Replicating virtual servers vulnerable to attack

Black Hat presentation details man-in-the-middle exploits can endanger data, availability of resources
By Tim Greene , Network World , 02/15/2008
  • Share/Email
  • Comment
  • Print

One of the most attractive features of virtualization -- the ability to replicate virtual servers on the fly to meet demand -- has a big security downside -- from data theft to denial of service -- according to a talk scheduled for the Black Hat DC 2008 conference next week in Washington, D.C.

When a virtual machine migrates from one physical server to another, it can be subject to a range of attacks primarily because authentication between machines is weak and the virtual-machine traffic between physical machines is unencrypted, says Jon Oberheide, a Ph.D. candidate at University of Michigan who will present the briefing.

Short term, the cure is installing hardware-based encryption on all the physical servers that might send or receive virtual machines, Oberheide says, but long term, virtual-machine software should incorporate strong authentication that minimizes the risk.

During his talk, he will describe a proof-of-concept tool he used in a lab to execute man-in-the-middle attacks against virtual machines as they migrated from one physical server to another. His research targeted open source Xen and VMware virtualization platforms.

Citrix, which sells a commercial version of Xen, says it gets around the problem with its management server acting as a third party to authenticate origination and destination servers to each other, says Simon Crosby, CTO of the virtualization and management division at Citrix. “We avoid that man-in-the-middle attack by being the man in the middle,” he says.

For its part, VMware recommends encryption of virtual machine migration, which it calls VMotion. "VMotion network activity is not encrypted, so as a best practice this traffic should occur on a dedicated VLAN or connection and kept secure from network sniffing, as the running memory state of a virtual machine traverses the VMotion network and will likely contain privileged information,” the company says on its Web site. “Hardware based SSL encryption is an option for securing VMotion networks in high security deployments."

Oberheide says he will not demonstrate his attacks, but he plans to show screenshots of how an attack would occur, and what his tool does to enable the attacks.

"It’s not very difficult at all as long as the [attacker and servers] are on the same network,” he says. “The prerequisite is man-in-the-middle capabilities, which can be achieved through a number of different methods, such as IP hijacking or ARP spoofing, which makes them send their migration traffic to you first and you can forward it on to the destination.”

  • Share/Email
  • Comment
  • Print
Partner Content

Explore the Ultrium Edge

The powerful tape technology can address data security with tape encryption as well as long term data protection.

Find out more

Disk and Tape Square Off

Discover what disk and tape really cost -- and which solution provides lower total cost of ownership and optimizes energy use for your organization

Download the White Paper

Don't Fall For The Myths

The Clipper Group explores the truth behind the myths of tape, digging into the misconceptions in the disk vs. tape debate.

Download the White Paper

Will You Add Tape Too?

Over two thirds of disk-only users look to add tape back into storage infrastructure according to recent survey.

Download Survey Information

Comments (1)
Login
Forgot your account info?

RE: Replicating virtual servers vulnerable to attackBy Kurt on February 20, 2008, 11:10 amHow is this different from protecting any sensitive data transmitted between hosts? Use IPSec, TLS, or some other transport encryption. It seems silly to expect...

Reply | Read entire comment

View all comments

Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed
Get instant email notification when white papers, webcasts, executive guides are added to our library. Stay informed and up-to-date with the latest on IT Technologies with Network World's Resource Alerts.
Network World,to go. Wherever you are. Breaking news delivered to your mobile device. Select the hottest topics in networking and start receiving Network World on your mobile device today.