Future Security in the Enterprise
February 27, 2012, Cloud Security Alliance Summit, San Francisco—Steve Harrod from VMware talked about the massive transformations due to virtualization, cloud, and mobile access. Security architectures need significant change to keep up with these transformations.
If you are a chief information officer, your career is over. Users are raising and changing their expectations on functions and user interfaces. In the past, the environment was a desktop machine in a fixed location and static permissions and network access. Now, SaaS, apps, and data services are increasing data sources and access points, and many of the use are browser driven. Enterprises need a common broker in the middle.
Companies need an enterprise level apps store that enables policies, permissions, and management on a per person basis. The mechanisms to secure this environment have to acknowledge that all apps and all data are available to everyone, so they have to give devices access. In areas like finance and health, all data moves into the data center.
One technology to consider is containerization of data. This can help to address the issue of drop boxes which are available to everyone without controls. Policies for access control and management must incorporate the fact that devices are net-based and may be BYOD.. Companies can download a level II hypervisor into these devices to create a virtual phone with the app and automatic VPN capabilities.
The enterprise has to develop containers and policies for both users and data that take into account transfers and other enabling technologies in the cloud. They must apply security to these functions in three ways. First, create a new app architecture that addresses the need for more services, complexity and dynamic functionality. Second, develop a hardware density at a cost and performance ratio at the server that is profitable. And finally move to more virtualization.
Currently, 60 percent of all server applications are virtual. By ’14, 80 million virtual machines will change the physical/virtual ratio, and virtual machines will be the primary machines and it will be security aware. Convergence in the hardware spaces will include I/O to address the increased traffic, x86 processors will have more functionality and more cores, and systems will have more integrated functions. One rack in this new environment will have 20,000 virtual machines in it, and all apps will run on a common infrastructure. The core infrastructure will move into the rack which will limit some management issues but increase security problems.
The security issues are related to increase density behind the switch, more ports to protect (but also fewer ports in total), and increased virtualization and mobility. Port security is a challenge because mobile represents an unknown port but still must map to an app per server.
Enterprises need to take a depth approach to move existing IP and tools into the cloud. First you must protect the virtual machines or risk a virus check storm. A separate virtual machine will allow apps and management functions to be isolated from each other. Second, develop cascading trees of firewalls which provides protection to the logical applications, but only protects outgoing ports. And finally, protect the logical data center. Virtual machines separate logical sections from each other and span the physical data center. Security and traffic management functions work at the edge of the logical data center.
Existing investments are still viable in a virtual machine environment. There is more app context which enables better security through context aware processing. This new environment is possible because it makes efficient use of existing and new resources. If you break apart functions to reduce the workload on the security appliances the result is a simplified yet integrated management system.
The world is changing very rapidly and we are stuck with the selection of choice versus control. We need a general broker to follow the user, but not the devices which creates challenges and requires changes in the hardware.


