| By Karl MacMillan | Article Rating: |
|
| November 25, 2008 10:00 AM EST | Reads: |
2,489 |
Server virtualization has moved well beyond the arena of early adopters and is an accepted solution to many of the challenges faced by IT organizations. However, desktop virtualization has not made the same inroads. Certainly, there have been some key uses for desktop virtualization, such as development and test, but there has not been broad penetration into the non-technical desktop market. There are signs that this trend is about to change.
The major virtualization vendors, including Citrix, VMware, and Microsoft, have recently released new or updated desktop
virtualization products that aim to make virtualization as common on the desktop as in the data center. The value proposition is largely the same as on the server: rapid deployment, better hardware utilization, easier management, and increased separation of workloads.
At the same time, security and compliance concerns are pushing IT organizations to bring the same level of application and data separation common in the data center to the desktop. Just as it's now unimaginable to host Internet-facing applications on the same server as key internal applications, security and privacy concerns may make using a single desktop operating system for each user similarly unthinkable.
Given these trends, it would seem natural for organizations with high-risk environments, which have long recognized the need for strong separation on the desktop, to flock to desktop virtualization. These environments, traditionally found in government, utility, health care, and financial organizations, are driven by security concerns to utilize two or more physically separate desktop systems per user to protect internal systems and prevent confidential data from leaking. Consolidating these desktop systems using virtualization can dramatically reduce space, power, hardware, and management costs. However, despite these apparent advantages, security often remains a barrier to entry to adopting desktop virtualization solutions in these environments. These security concerns go beyond the separation and security features provided by typical desktop virtualization products.
To illustrate the security concerns of these high-risk environments, consider the recent high-profile emergency shutdown of the Hatch nuclear power plant near Baxley, Georgia, that was caused when a single computer system was updated. The computer system, which was connected to both the corporate network and the network dedicated to controlling the nuclear power plant, was updated by an administrator unaware of the two network connections. When the administrator rebooted the system, it caused the plant's safety systems to erroneously conclude that there was a drop in the water reservoirs used to cool the reactor, causing an emergency shutdown of the reactor. Thankfully, the shutdown proceeded smoothly and no one was in danger; however, it probably cost millions of dollars and required a full investigation by the Nuclear Regulatory Commission.
It was not simply a procedural problem that led an administrator to make updates to a system without fully understanding its function. The system was incorrectly connected to both networks, a mistake the plants technicians were aware of but hadn't corrected. While it's not clear from public information why this inappropriate connection was made, it underscores the importance of strict separation and isolation in these environments. Even a single lapse in network separation caused significant safety concerns in this environment. It also demonstrates why these organizations can't lightly adopt desktop virtualization in high-risk environments. As desktop virtualization solutions would be relied on to maintain this crucial network separation, it's critical that the solutions be carefully architected and engineered to provide the required level of security.
Published November 25, 2008 Reads 2,489
Copyright © 2008 SYS-CON Media, Inc. — All Rights Reserved.
Syndicated stories and blog feeds, all rights reserved by the author.
More Stories By Karl MacMillan
Karl MacMillan is Tresys Technology's Director of the Linux Security Practice, author of "SELinux by Example: Using Security Enhanced Linux," and frequent speaker at virtualization, security and open source events nationwide. With experience spanning dozens of successful strong security implementations, delivering security products and services for some of the most sensitive security missions around the world, including those at defense and intelligence agencies globally, and through partnerships with IBM, General Dynamics, Red Hat and Cisco, Karl is an established security thought leader.
- Cloud CEOs, CTOs & SVPs to Speak at 4th International Cloud Computing Expo
- Kindle 2 vs Nook
- Why IBM’s Server Chief Got Busted
- The Difference Between Web Hosting and Cloud Computing
- Cloud Computing Journal Opens "Readers' Choice Awards" Nominations
- Cloud Computing Expo: Exclusive Q&A with Yahoo! SVP Cloud Computing
- Industry Experts Discuss the State of Cloud Computing
- Ajax in RichFaces 3.3, JSF 2 and RichFaces 4
- It's the Java vs. C++ Shootout Revisited!
- The End of IT 1.0 As We Know It Has Begun
- An Introduction to Abbot
- Java Kicks Ruby on Rails in the Butt
- Interviewing Java Developers With Tears in My Eyes
- Cloud CEOs, CTOs & SVPs to Speak at 4th International Cloud Computing Expo
- 1st Annual Government IT Expo: Call for Papers Deadline July 15
- How to Diagnose Java Resource Starvation
- REA Is Where RIA Becomes the Norm
- Kindle 2 vs Nook
- Anatomy of a Java Finalizer
- Why IBM’s Server Chief Got Busted
- A Cup of AJAX? Nay, Just Regular Java Please
- Java Developer's Journal Exclusive: 2006 "JDJ Editors' Choice" Awards
- The i-Technology Right Stuff
- JavaServer Faces (JSF) vs Struts
- Rich Internet Applications with Adobe Flex 2 and Java
- Java vs C++ "Shootout" Revisited
- Bean-Managed Persistence Using a Proxy List
- Reporting Made Easy with JasperReports and Hibernate
- Creating a Pet Store Application with JavaServer Faces, Spring, and Hibernate
- What's New in Eclipse?































