Skip to navigation
   
Davey Winder's Blog

Black Hat risk to migrating VMs

By Davey Winder in Editorial

Posted in Data Protection, Blog, Security, Uncategorized on February 24, 2008 at 11:54 am

Permalink | Author Profile

I like the Black Hat conferences, not least because they always manage to produce a balanced measure of truly mind boggling security holes on the one hand and truly mind boggling self-serving smoke and mirrors on the other. I am not 100 percent sure where stories such as the RFID credit card hack fit into the balance, but there is little doubting the relevance of demonstrations such as the one which showed exactly how a determined attacker is able to hack into VMware and Xen virtualisation software while the VM is in transit between physical machines.

The security researcher in question is actually a PhD candidate from the University of Michigan, one Jon Oberheide who, if you say that quickly enough sounds like he belongs in the Star Wars movies somewhere along the line. But there is no air of science fiction about the proof-of-concept tool he demonstrated which shows how easy it is to hack into and control the VM hypervisor, as well as its applications, when a virtual machine is being migrated and use this to purloin data from those live VMs.

Oberheide reckons that his tool, Xensploit, reveals the lack of understanding when it comes to the risk involved with migrating live virtual machines. The main problem being, of course, that taking down a live system is not an option because that somewhat goes against the whole point of the dynamic availability of any VM deployment in the first place. But being aware of the risks means that measures can be taken to mitigate them, and in this case information is most definitely power.

Oberheide demonstrates that a man in the middle attack is possible while data moves in clear text during the VM migration, with Xensploit manipulating the SSHD authentication to provide the required administrative access. Route hijacking, ARP/DHCP spoofing and DNS poisoning can all play their part in such a compromise or, as Oberheide confides, even a simple passive password sniffing exercise.

And the solution? The usual to be honest, assess risks accordingly and take security seriously. Mutual authentication between hypervisors during migration, together with an encrypted data plane and a network isolated environment for the migrating VMs should do the trick…

12345
Rated: 100% (3 votes)
Loading ... Loading ...

Previous Post | Next Post

 
 
Comments
This article has no comments yet.

Make a comment

* required

* required

We stop spam using reCaptcha.
Type the words below and click Submit Comment.

   
Tag cloud

prison Microsoft Yahoo security green data protection hacker virtual world graphics HPC Texas Instruments avatar man-in-the-middle China remote Government web Death tech shopping betting Lotus adware payments Olympics broadband Video Noro sick open source black hat millions biometrics XP botnet carbon copy teleworking Business politics terrorism Finjan Blogging Bill Gates Web Development ASUS banking Programming exploit social networking Deal library Energy office chips BSI report Obama environment fool Twitter credit card fraud symantec economics Gartner Application work VM network NBC Rant survey outsourcing Supercomputer Eee christmas MessageLabs gaming ecommerce MiniBook Microchip books surveys ISPA IBM iPhone 3G linkedin The Federation CAPTCHA computer crime Space productivity Eee PC service Paris Hilton holidays staffing technology dumb Mobile Phone Battery BOFH policy virus worker Top 500 privacy IP Silverlight Project xmas Flash world of warcraft computing code Google workplace Mars students Research fun global hubdub Digg science Internet Facebook Linux Windows 7 email virtual machine ID Theft remote working second life SMS Trojan MSNBC Vista digitise transactional security Software AMD statistics Apple InfoSec mobile spam Health payment server Jesus Phone DNS IDC documentation news printing OS standards data hardware hacking fraud Hack patch management theft archiving Steve Jobs scam OCR FBI Funny copyright help stupid Russia Windows USA hypervisor Big Brother development storage MSN scareware Kill Switch stupidity migration SSL phishing Firefox size iPhone universe worm Adobe NASA scan Texting home compromise museum VPN web 2.0 debian rootkits Performance computing Zango malware Ballmer e-commerce trust banks money search Rumour
Advertisement
Advertisement
Advertisement