Site Sponsor:

mcafee_logo.gif
line

Now Available:

Featured Resource:

line

Newsletter

Email Address:


line

Ask the Expert

Have a question for our resident expert? Email your questions to Dan or post a comment to the blog.

« Automatic Patch-Based Exploits Demonstrate Weakness of Patching | Main | Ignorance Isn't Bliss When It Comes to Malware »

IBM's Work on Virtualization Security

IBM isn't the stiffed-shirt old school IT behemoth that it looked like when the dot com boom made selling pet food over the Web at a loss all the rage. It's dumped its hard drive and PC manufacturing units and focused attention on leading edge technologies. One those is virtualization security. IBM seems to be making a major effort in this area but isn't out too many details.

An IBM press release describes the initiative:

IBM's PHANTOM initiative aims to create virtualization security technology to efficiently monitor and disrupt malicious communications between virtual machines without being compromised. In addition, full visibility of virtual hardware resources would allow PHANTOM to monitor the execution state of virtual machines, protecting them against both known and unknown threats before they occur. It is also designed to increase the security posture of the hypervisor -- a critical point of vulnerability; because once an attacker gains control of the hypervisor, they gain control of all of the machines running on the virtualized platform. For the first time, the hypervisor -- the gateway to the virtualized world and all that lays above it -- can be locked down.

Ars Technica has been trying to get more info but details remain sketchy:


Plenty of important questions remain unanswered on the project, like whether it's software-only or has a hardware component. It's also not clear if PHANTOM is strictly for IBM's mainframes, or if it will be used in commodity (i.e., x86) servers as well.

What ever the breadth of the project, IBM's involvement will be welcome by customers. Securing virtualized servers, along with rolling out trusted computing platforms and combating evolving malware, is at the top of IT security's to do list.

TrackBack

TrackBack URL for this entry:
http://www.realtime-websecurity.com/type/mt-tb.cgi/718

Post a comment

(All comments are approved by site leader before appearing here. Thanks for commenting!)

line

Dan Sullivan's Bio:

Dan Sullivan is a systems architect with 20 years of IT experience that includes engagements in enterprise security, application design, and systems architecture. His experience includes a broad range of industries, including financial services, manufacturing, government, retail, gas and oil production, power generation, and education. Dan’s security-related project work has ranged from requirements analysis for enterprise information security to designing and implementing security for database applications and enterprise portals. Dan has written about information security and other enterprise information management topics for Business Security Advisor, DM Review, Intelligent Enterprise, and E-Business Advisor. You can contact Dan at: dan_sullivan@realtimepublishers.net