Advertisement
Promo

Security threats Toolkit

McAfee to support VMsafe

Tom Espiner ZDNet.co.uk

Published: 03 Mar 2008 17:05 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Security vendor McAfee has announced an agreement to use VMsafe virtualisation APIs to build VMware-compatible security products.

The VMsafe APIs, announced on Wednesday, will allow security vendors to build and sell VMware compatible security products.

McAfee products will include host-based intrusion prevention "to prevent tampering with VMware processes", according to McAfee chief technology officer Christopher Bolin.

The McAfee intrusion prevention product that supports VMsafe APIs will be available next quarter. The as-yet unnamed product will enable IT managers to monitor VMware images of virtual machines to gauge whether they have been compromised.

McAfee has yet to see an attack against VMware infrastructure, Bolin said. As VMware has not provided third-party access to its hypervisor through software development kits (SDKs), which may introduce vulnerabilities, VMware has so far escaped the security issues which have plagued other companies that encourage third-party software development, according to Bolin.

"The more you expose [software], the more vulnerable you are," said Bolin.

VMware has not opened up its core hypervisor, said Reza Malekzadeh, VMware senior director of products and marketing.

"VMware has announced a secure API which will allow virtual machines running third-party security software to access other virtual machines running within the same infrastructure," said Malekzadeh. "All code running from third parties will be running within a virtual machine, which by its very nature is isolated or 'sandboxed'."

Read this

Comment
Comment: The right application of virtualisation

Server virtualisation has its benefits but it's at the application level where the technology can really make a real difference, says DataSynapse's Peter Lee

Read more +

Malekzadeh said VMsafe works on a trust model: customers have to select which virtual machines they want VMsafe-enabled security applications to access.

As third-party products would require digital certificates to run, VMware applications would be secure, McAfee added. Bolin said McAfee would have to develop virtualisation products that mitigated the possible compromise of digital certification.

"We will become a third party, but cusotmers can be very selective about what is run," said Bolin. "VMware will be a [digital certificate] signature authority; a malware attacker would have to go through the signing process."

However, digital certification was by no means a security failsafe, said Bolin.

"As any application or platform realises broad use, it becomes subject to attack," he said. "It's absolutely incumbent on all VMware partners to ensure there are no vulnerabilities where code is signed."

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters