Virtualization is the darling of industry analysts. In fact it’s been in Gartner’s list of
top 10 strategic technologies for a number of years. And there are good reasons for the hype around virtualization. The benefits of using it include:
- Helps maximize infrastructure and shrinks the number of servers needed
- Reduces administrative costs
- Fewer physical machines to upgrade, monitor and maintain
- Provides high accessibility of applications and data
But despite these benefits, based on new information, Gartner is warning companies to review their security practices used with virtualized servers. In fact they’ve found that as many as 60 percent of virtualized servers are less secure than traditional non-virtualized servers. The problem isn’t a flaw in the virtualization technology, it is a problem with education and lack of sophisticated administration tools for the new systems.
“Virtualisation is not inherently insecure,” said Neil MacDonald, vice president and Gartner Research fellow. “However, most virtualised workloads are being deployed insecurely. The latter is a result of the immaturity of tools and processes and the limited training of staff, resellers and consultants.”
Gartner does not expect the security problem to improve much over the next two years, which isn’t good. Today only about 18 percent of operations that potentially can be virtualized are run in a VM, but by the end of 2012,
Gartner is predicting that half of virtualizable operations will be in VMs. Not until 2015 do they expect the 60 percent difference between security on virtualized and non-virtualized servers to drop to 30 percent.
The Gartner report
identified the following five reasons for why security in virtualized environments is often lacking.
- 40 percent of the time IT security people are not involved in the architecture and setup of virtualized environment.
- In virtualized environments, application density is higher. Compromising the virtualization layer can lead to the compromise of all applications in the virtual environment.
- VM-to-VM communication happens frequently, but it is specialized and abuse typically can not be detected by standard network intrusion detection software or devices.
- Applications with very different trust levels are often combined and running side by side on the same virtual machine without sufficient separation.
- Central administration in VM environments can be reached by many different paths, complicating the securing of administration.