McAfee to make PC virtualisation safe

Tom Espiner, ZDNet UK

04 March 2008 09:28 AM

Tags: mcafee, vmware, security, apis, sdk

Security vendor McAfee has announced an agreement to use VMsafe virtualisation APIs to build VMware-compatible security products.

The VMsafe APIs will allow security vendors to build and sell VMware compatible security products.

McAfee products will include host-based intrusion prevention "to prevent tampering with VMware processes", according to McAfee chief technology officer Christopher Bolin.

The McAfee intrusion prevention product that supports VMsafe APIs will be available next quarter. The as-yet unnamed product will enable IT managers to monitor VMware images of virtual machines to gauge whether they have been compromised.

McAfee has yet to see an attack against VMware infrastructure, Bolin said. As VMware has not provided third-party access to its hypervisor through software development kits (SDKs), which may introduce vulnerabilities, VMware has so far escaped the security issues which have plagued other companies that encourage third-party software development, according to Bolin.

"The more you expose [software], the more vulnerable you are," said Bolin.

Want to know more?

For all the latest news, analysis and opinion on security, click here

VMware has not opened up its core hypervisor, said Reza Malekzadeh, VMware senior director of products and marketing.

"VMware has announced a secure API which will allow virtual machines running third-party security software to access other virtual machines running within the same infrastructure," said Malekzadeh. "All code running from third parties will be running within a virtual machine, which by its very nature is isolated or 'sandboxed'."

Malekzadeh said VMsafe works on a trust model: customers have to select which virtual machines they want VMsafe-enabled security applications to access.

As third-party products would require digital certificates to run, VMware applications would be secure, McAfee added. Bolin said McAfee would have to develop virtualisation products that mitigated the possible compromise of digital certification.

"We will become a third party, but cusotmers can be very selective about what is run," said Bolin. "VMware will be a [digital certificate] signature authority; a malware attacker would have to go through the signing process."

However, digital certification was by no means a security failsafe, said Bolin.

"As any application or platform realises broad use, it becomes subject to attack," he said. "It's absolutely incumbent on all VMware partners to ensure there are no vulnerabilities where code is signed."

Advertisement

Talkback 0 comments


ZDNet's CIO Vision Series

Customs | Murray Harrison, CIO

Australian Customs CIO Murray Harrison dislikes SLAs and runs away if a vendor talks to him about innovation. In this interview, he also explains why getting excited about gadgets can be dangerous and talks about how Customs' outsourcing strategy has evolved.

Sponsored content

Power Centre - Content from our premier sponsors

Blogs

  • Munir Kotadia iPhone suckers test our patience
    So how many of you have bought a 3G iPhone? Do you feel like a sucker? If you don't, maybe you will once your first bill arrives.
  • Array Westpac bank: AVG's toughest competitor
    The next time you're buying antivirus software, don't go direct to Symantec or McAfee. Don't download free antivirus. And definitely don't see Harvey Norman. Ask your bank — they're quite literally giving the stuff away.
  • Array Will you manage in the exabyte era?
    Mammoth growth in storage volumes is a fact of life, but even so it's helpful to pause occasionally and try and work out whether our information strategies have fallen hopelessly out of step with the pace of technological growth and changes in costs.
  • More blogs »

Tags

Back to top

Featured