Advertisement
Promo

Security threats Toolkit

Security expert: Beware virtualisation in 2008

Tom Espiner ZDNet.co.uk

Published: 19 Nov 2007 16:57 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security company McAfee has predicted that virtualisation will be an area of security concern in 2008.

McAfee told ZDNet.co.uk that companies need to understand the risks, as well as the benefits, before implementing virtualisation technologies. The company has an interest in predicting virtualisation as an attack vector, as it sells a virtualisation security product.

"Virtualisation will radically change a lot of things," said David Marcus, security research manager for McAfee Avert Labs. "The ability to run inside a virtual layer gives you a God-like view of the shell and allows for certain detections, but it also allows for new attack vectors."

Marcus said that virtual layers can each be attacked, but that his real fear was seeing malware that could escape onto an operating system.

"A lot of malware has the ability to run in a virtual machine, work out it's in a virtual session, then completely shut down," said Marcus. "It's not a large jump to go from malware realising it's in a session to it jumping out."

Marcus also warned that VoIP, or internet telephony, would also be a target in 2008.

"We think we'll end up seeing theft-of-service attacks, like old-style phreaking," said Marcus. "People will steal calls, divert calls and impersonate others."

McAfee also has a VoIP protection product.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters