The Future Of Datacenter Security Charu Chaubal Senior Architect, Technical Marketing November 2008
Operating System Exchange Operating System Operating System VPN Operating System Operating System File/Print Operating System Operating System CRM Operating System Interconnect Pool CPU Pool Memory Pool Storage Pool Hypervisor Virtual Infrastructure Virtualization Virtualization Virtualization Virtualization Virtual Infrastructure
An OS for the Virtual Datacenter Virtual Infrastructure Interconnect Pool CPU Pool Memory Pool Storage Pool
Impact #1: Apps decoupled from Infrastructure VMotion VMware VMware VMware VMware
Application-independent Uptime Mechanisms Performance Planned Downtime Unplanned Downtime Virtual Machines Server Storage Interconnect Site Recovery Manager HA VCB NIC & HBA Teaming VMotion Storage VMotion Network Redundancy VM Failure Monitoring ESX Server App OS App OS App OS App OS App OS
Impact #2: Desktops Look Like Servers Thin or Stateless Clients Traditional Desktops
Centralized Management VirtualCenter VDM Clients  Virtual Desktop Manager  VMware Infrastructure  Physical Security attainable Can extend server security and management practices to the local PC Isolation contains faults and allows full user experience
Impact #3: Servers Act Like Files
Servers Can Be Managed Like Documents Publish or Retract Audit Usage Retain Dispose Document Lifecycle Management Request for VM Provisioning Delete VM Archive VM Virtual Machine Lifecycle Management Create Request Document Monitor & Adjust Resources Power-On or Suspend VM Route VM for Approval Deploy VM from Template Approve
File Replication, De-duplication, Check-in/out Master VM Linked Clone View Manager and View Composer Linked Clone Client Virtualization Check-In Check-Out Google Chrome Google Chrome Google Chrome Google Chrome App OS App OS App OS App OS
Centralized, Efficient File Processing VirtualCenter Clients  VMware Infrastructure  Offline Ops Patch Malware Scan Configuration Backup
Impact #4: Insight Through Hypervisor APIs VMsafe API and Partner Program Protect the VM by inspection of virtual components (CPU, Memory, Network and Storage) Run outside the VM Complete integration and awareness of VMotion, Storage VMotion, HA, etc. Fundamentally changes protection available for VMs running on VMware Infrastructure vs. physical machines Provides an unprecedented level of security – “Virtual is more secure than Real” http://vmware.com/go/vmsafe   ESX VMsafe ESX with VMsafe
Impact #5: Appliances Go Virtual Overcomes the limitations of physical topology Deploy anywhere Increases the granularity of security within the datacenter Deploy as many appliances as necessary
Auto-Configuration Of App Security Web tier App tier DB tier App App App App App App App Availability = 99.99% Security = High Performance = 500 msec SLA Definitions vApp Web OS App OS DB OS
Dynamic Capacity, Mobility Awareness Web tier App tier DB tier Availability = 99.99% Security = High Performance = 500 msec SLA Definitions vApp Web OS App OS DB OS App App App App App App App
“ No free lunch” rule applies to virtualization The Good The Bad Easy machine creation “ VM sprawl” Mobility Breaks static security Abstraction layer New layer to be secured Tremendous flexibility Potential for Misconfiguration
Summary Virtualization fundamentally transforms security Need to have a broader perspective about virtualization – utilize everything that’s different The “Next Generation” of datacenter is coming – and so are the security products
Where to Learn More Security Hardening Best Practices Implementation Guidelines http://vmware.com/go/security   Compliance Partner Solutions Advice and Recommendations http://vmware.com/go/compliance
End of Presentation Charu Chaubal [email_address]

Virutalization and the Future of Datacenter Security

  • 1.
    The Future OfDatacenter Security Charu Chaubal Senior Architect, Technical Marketing November 2008
  • 2.
    Operating System ExchangeOperating System Operating System VPN Operating System Operating System File/Print Operating System Operating System CRM Operating System Interconnect Pool CPU Pool Memory Pool Storage Pool Hypervisor Virtual Infrastructure Virtualization Virtualization Virtualization Virtualization Virtual Infrastructure
  • 3.
    An OS forthe Virtual Datacenter Virtual Infrastructure Interconnect Pool CPU Pool Memory Pool Storage Pool
  • 4.
    Impact #1: Appsdecoupled from Infrastructure VMotion VMware VMware VMware VMware
  • 5.
    Application-independent Uptime MechanismsPerformance Planned Downtime Unplanned Downtime Virtual Machines Server Storage Interconnect Site Recovery Manager HA VCB NIC & HBA Teaming VMotion Storage VMotion Network Redundancy VM Failure Monitoring ESX Server App OS App OS App OS App OS App OS
  • 6.
    Impact #2: DesktopsLook Like Servers Thin or Stateless Clients Traditional Desktops
  • 7.
    Centralized Management VirtualCenterVDM Clients Virtual Desktop Manager VMware Infrastructure Physical Security attainable Can extend server security and management practices to the local PC Isolation contains faults and allows full user experience
  • 8.
    Impact #3: ServersAct Like Files
  • 9.
    Servers Can BeManaged Like Documents Publish or Retract Audit Usage Retain Dispose Document Lifecycle Management Request for VM Provisioning Delete VM Archive VM Virtual Machine Lifecycle Management Create Request Document Monitor & Adjust Resources Power-On or Suspend VM Route VM for Approval Deploy VM from Template Approve
  • 10.
    File Replication, De-duplication,Check-in/out Master VM Linked Clone View Manager and View Composer Linked Clone Client Virtualization Check-In Check-Out Google Chrome Google Chrome Google Chrome Google Chrome App OS App OS App OS App OS
  • 11.
    Centralized, Efficient FileProcessing VirtualCenter Clients VMware Infrastructure Offline Ops Patch Malware Scan Configuration Backup
  • 12.
    Impact #4: InsightThrough Hypervisor APIs VMsafe API and Partner Program Protect the VM by inspection of virtual components (CPU, Memory, Network and Storage) Run outside the VM Complete integration and awareness of VMotion, Storage VMotion, HA, etc. Fundamentally changes protection available for VMs running on VMware Infrastructure vs. physical machines Provides an unprecedented level of security – “Virtual is more secure than Real” http://vmware.com/go/vmsafe ESX VMsafe ESX with VMsafe
  • 13.
    Impact #5: AppliancesGo Virtual Overcomes the limitations of physical topology Deploy anywhere Increases the granularity of security within the datacenter Deploy as many appliances as necessary
  • 14.
    Auto-Configuration Of AppSecurity Web tier App tier DB tier App App App App App App App Availability = 99.99% Security = High Performance = 500 msec SLA Definitions vApp Web OS App OS DB OS
  • 15.
    Dynamic Capacity, MobilityAwareness Web tier App tier DB tier Availability = 99.99% Security = High Performance = 500 msec SLA Definitions vApp Web OS App OS DB OS App App App App App App App
  • 16.
    “ No freelunch” rule applies to virtualization The Good The Bad Easy machine creation “ VM sprawl” Mobility Breaks static security Abstraction layer New layer to be secured Tremendous flexibility Potential for Misconfiguration
  • 17.
    Summary Virtualization fundamentallytransforms security Need to have a broader perspective about virtualization – utilize everything that’s different The “Next Generation” of datacenter is coming – and so are the security products
  • 18.
    Where to LearnMore Security Hardening Best Practices Implementation Guidelines http://vmware.com/go/security Compliance Partner Solutions Advice and Recommendations http://vmware.com/go/compliance
  • 19.
    End of PresentationCharu Chaubal [email_address]

Editor's Notes

  • #2 For a panel, list moderator in this slide and panelists on the following slide.