Home > Ask the Information Security Experts > Questions & Answers > What kinds of additional security protection do virtual machines offer?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

What kinds of additional security protection do virtual machines offer?

Ed Skoudis EXPERT RESPONSE FROM: Ed Skoudis

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 03 September 2007
Do virtual machines protect security technologies like antivirus tools and intrusion protection systems from attackers? How difficult is it for a malicious hacker to break through the defenses of a virtual machine?

>
EXPERT RESPONSE
At best, virtual machines make a guest system have the same security footprint as a real system. That is, virtualization doesn't add any additional protection to software running on a guest machine. If a given piece of software is exploitable in a real operating system, it will also be exploitable in a VM. That's because the goal of virtualization technologies is to make a virtual machine behave just like a real one. Thus, you have to harden and patch your guest machines just as you would a real operating system.

Now, virtualization can be used to try to achieve some isolation -- that is, to take a given piece of software and make it run on a guest machine to separate it out from other functions on the host or on a different guest. Proceed with caution though, as a clever attacker may be able to compromise the isolation that virtual machines provide. It's not trivial, but it is possible. If the attacker is able to get code to run on the host and on the guest, he or she can create virtual tunnels that plow through virtualization. My team has created a small tool called VMcat, which creates its own communications channel to tunnel data between guests and host. Now, VMcat requires that the attacker install and run something on both the guest and the host, so it is not a pure-play escape. A true escape would allow an attacker on a guest to start running software directly on the host, popping out of the isolation of the guest.

While no true escape software has been released publicly as of this writing, there has been some interesting movement in this arena recently. In July 2007, my team demonstrated how an unpatched VMware Workstation system can be undermined with an escape. In an unrelated development, in August 2007, Microsoft released MS07-049, a patch for a vulnerability in its Virtual Server and Virtual PC products that, according to Microsoft, "could allow a guest operating system user to run code on the host or another guest operating system." That's a textbook definition of virtual machine escape. Again, as of this writing, there is no public exploit for either the VMware or Microsoft issue.

What should you do about these concerns? Keep your virtualization products patched. VMware releases patches on a regular basis, as does Microsoft. Make sure you apply them. Also, harden both your guest and host machines to minimize the chance of an attacker compromising either side of the virtual divide. And, finally, carefully architect your virtual machine deployments to minimize the damage that an escape could cause. Separate weak machines -- those without important data -- from the strong ones that hold valuable information, and do so using different underlying hosts. Don't treat your virtual machine like a firewall. Use a real firewall instead.

More information

  • Will allowing virtual machines in the enterprise increase risk exposure? Ed Skoudis continues his virtualization explanation.
  • Be prepared for virtualization security unknowns.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Threat Management
    Network security basics: How to prevent common attacks
    Future security threats: Enterprise attacks of 2009
    Cybercrime reports: Security not broken, but breaking at the seams
    Data losses set to soar, KPMG predicts
    Screencast: How to gather host-level data with Network Miner
    Appliance provides network access protection on school campus
    Market Harborough Building Society finds way to monitor users' network traffic
    'Phlashing' attacks
    How to identify network attacks proactively
    Stopping spam brings additional security benefits for cable company

    Enterprise Data Storage
    Local council finds better way to track lost laptops
    Will the rise of SharePoint services lead to increased data loss?
    Scottish NHS trust ensures no repeat of USB data loss
    Finance sector poor at achieving outsourcing success
    Mobile technology may limit harm of laptop data loss
    HSBC loses customer data in the post
    How to lock down USB devices
    Another day, another embarrassing data loss
    How to achieve laptop data security
    Chemical giant says data leakage tools not up to snuff

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Centre for the Protection of National Infrastructure  (SearchSecurityUK.com)
    Serious Organized Crime Agency  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts