- Nokia's new N97 vs. the iPhone
- Talk-powered cell phones?
- FBI: Copper thieves jeopardize U.S. infrastructure
- 10 Microsoft research projects
- Smartphone smackdown: Storm vs. iPhone
Have you read your security policy today? Does it take virtualization into account?
In a previous blog I mentioned that the Defense Information Security Agency (DISA)'s Security Technical Implementation Guide (STIG) had an interesting reason for not running antivirus on the Service Console of ESX. The reason was that the Unix-based antivirus tool recommended in the STIG won't install properly on ESX. There are performance issues and the potential for false positives as well.
Many security policies require that some form of antivirus be run on any system attached to the network unless that system happens to be an appliance.
That presents an interesting picture of its own for VMware infrastructure administrators. VMware ESXi is considered to be an appliance, but VMware ESX is not.
However, I happen to believe that they are both hybrid devices that combine network, storage, and compute resources into one system; sort of a combination of appliance and operating system.
This causes interesting issues with the written security policies that often dictate no multi-homed machines unless it is a switch, router, etc. Well since VMware ESX and ESXi both contain a switch rather than a bridge, do both fall under that rule?
By the same token, it is a compute resource and many security policies dictate that these must contain some form of antivirus, antispyware, and other protection tools.
Because of the differentiation over what is or is not an appliance, ESXi and ESX are treated differently. I think they should be treated the same. (As the management console for VMware ESXi should be secured using many of the same techniques for VMware ESX.)
In either case, running antivirus tools from the management appliances for ESX and ESXi is frowned upon by the virtualization experts for several reasons:
* Antivirus full disk scans will affect performance.
* VMware ESX/ESXi management appliances provide special use environments where users would not store files, documents, etc.
* Scanning virtual disk files will produce false positives.
* The VMware Hypervisor throttles all disk accesses from the management appliances so that reads and writes are very, very
slow.
* There is no current antivirus software for VMware ESXi.
Security policies will need to be updated to account for VMware ESX or ESXi if this has not already happened.
Partner Content
Brilliantly simple security and control solutions for email, web and endpoint
www.sophos.com
Stopping data leakage
Learn how to exploit your current security investment to control the information that flows into, through and out of your network.
Download the white paper.
Why detection rates aren't enough
Evaluating endpoint security products is a time-consuming and daunting task. Learn the six critical questions you need to ask prospective vendors to get the right endpoint solution.
Download the white paper.
Applications: taking back control
Employees installing unauthorized applications is a growing threat to business security and productivity. Cost-effectively reduce this threat by integrating control into your malware protection.
Learn more today.
Comment