Security in a virtual world
By Throop Wilder
,
Network World
, 06/04/2009
This vendor-written tech primer has been edited by Network World to eliminate product promotion, but readers should note it will likely favor the submitter's approach.
- Share/Email
- Tweet This
- Print
Virtualization of the data center is provoking fundamental questions about the proper place for network security services. Will they simply
disappear into the One True Cloud, dutifully following applications as they vMotion about the computing ether? Will they remain
as a set of modular appliances physically separate from the server computing blob? Should everything be virtualized because
it can be?
Based on experience with large enterprises, we recommend that the network security infrastructure remain physically separate
from the virtualized server/app blob. This separation allows you to maintain strong "trust boundaries" and high performance/low
latency, without the loss of flexibility and adaptability of virtualized application infrastructures.
Large data centers have primarily safeguarded their servers with a well-protected perimeter and minimal internal protections.
As zonal protection schemes were introduced to mitigate the unfettered spread of worms and intrusions, the natural boundaries
became the divisions between the classic three tiers of Web infrastructures: Web, application and data layers.
More recently enterprises have further segmented these trust zones by service, business unit and other political criteria,
yet this infrastructure does not lend itself to change. As three-tier architectures become vastly more flexible due to virtualization
projects, the security infrastructure must develop its own flexibilty so it is never the bottleneck. Furthermore, it must
also maintain the real-time guarantees of high throughput, high connection per second rates and low latency.
The good news is that this is precisely what forward-thinking architects and operations teams are designing and building right
now. Best of all, some of these teams are discovering that, for once, security and performance optimization appear to benefit
from the same strategy. Here's how.
There are two core principles in new security architecture designs. The first principle is to virtualize within the three
layers, not across them, which forces inter-zone traffic to pass through physically separate security equipment.
The second principle is to use equipment that consolidates multiple security services that can be invoked in any combination
depending on the type of boundary crossing, while maintaining performance, latency and connection rates. You can refer to
this separate layer of security resources as the "second cloud."
The concept of virtualizing within layers (such as Web, application and database layers) vs. across layers can be depicted
as follows. For example, Web servers and application servers are considered to pose risks of different levels.
In Figure 1, VMs of different risk levels are on the same servers and boundary transitions between zones happen entirely inside
one or more servers. In Figure 2, all Web VMs run on one physical set of servers while the application VMs run on a separate
set. Boundary transitions in this model happen outside of each group of servers.
Partner Content
www.bmc.com
Gartner 2009 Magic Quadrant for Job Scheduling
Gartner has positioned BMC CONTROL-M in the Leaders Quadrant of their "2009 Magic Quadrant for Job Scheduling." The report assesses the ability to execute and completeness of vision of key vendors in the marketplace. Read a full copy today, courtesy of BMC Software.
Download whitepaper
Dell's SMART Approach to Workload Automation
Read a compelling case study by EMA, Inc. to learn how Dell uses BMC CONTROL-M to cut cost and increase productivity with workload automation.
Download whitepaper
Workload Automation Cost Savings 2 Minute Video
A major computer manufacturer uses BMC CONTROL-M and just four people to schedule and run over 85,000 jobs every month. By switching to BMC CONTROL-M, they more than quadrupled the workload without adding a single staff member. See how in this 2-minute video overview.
Go to video
Comment