Secure Virtualization Seminar

13-Mar-2009

How to avoid the Virtual Desktop to become your Biggest Concern

On March 13, 2009 LSEC organized a Secure Virtualization Seminar in Brussels

Cloud Computing and Virtualized Desktops are being regarded as one of the most eminent threat vectors in 2009 and
beyond. With an increasing number of companies switching from fat client computing desktops to a virtualized
desktop and other virtualized applications, the risk concerns are obviously moving along.
Indeed, virtualization reduces a large proportion of the headaches of desktop clients and the personal users; but new
threats are coming up, sometimes creating major risks or even single points of failures.

During this seminar, the aim was to present an overview on how to improve security on such environments and
how to learn with evolving threats and risks involved. Some solutions are becoming apparent and risks are getting clearer.

We’ve selected some of the following topics of interest :
- Is creating a Virtual Desktop environment reducing my Enterprise Risk ?
- What threat vectors are still applicable for a Virtualized environment ?
- How to architect a comprehensive security for a Virtual Architecture?
- Are all of our security solutions sunk cost when we switch to a Virtual Environment ?
- Can a Virtualized Architecture serve as a Security solution?
- Virtualization : a risk management blessing or Single Point of Failure?
- …

The seminar has been directed to IT Professionals, Risk & Security managers and officers, CxO’s, project managers, program managers, system architects, system integrators, business and it consultants and security managers.

Program

9.30h : registration, welcome coffee

10.00h : Introduction, opening notes and agenda of the day
By Ulrich Seldeslachts, CEO LSEC


10.10 : Isn’t Virtsec just a way for the security people to jump on the Virtualization hype ? Isn’t Cloudsec just a way for the security people to jump on the Cloude hype? An example of OpenQRM.
By Kris Buytaert, Inuits

VirtSec, the new hot topic in virtualization town, but what it is.  Do we need it ?  Different opinions fly around on the internet and in the blogosphere. Some security experts claim there is nothing new under the sun and the VirtSec people are just trying to sell products based on the Virtualization Hype. Some see a genuine need to secure new elements in the infrastructure, where as others claim it is just a way for the Virtualization industry to get a piece from the security budget We’ll tackle the different VirtSec definitions while looking how the Open Source Virtualization crowd tackles the VirtSec story.

About : Kris Buytaert is a long time Linux and Open Source Consultant doing Linux and Open Source projects in Belgium and around the world. Kris is the Co-Author of Virtualization with Xen, used to be the maintainer of the openMosix HOWTO and author of different technical publications. He is a frequent speaker at different international conferences. He spends most of his time working on Linux Clustering (both High Availability, Scalability and HPC), Virtualisation and Large Infrastructure Management projects hence trying to build infrastructures that can survive the 10th floor test.



11.00h : issues related to Cloud computing and Virtualisation
By Philippe Massonet, CETIC


Cloud computing has emerged as a new approach to providing IT as a service. Cloud computing raises new issues regarding trust, security and privacy. These issues are important because they can have an impact on the successful adoption of the technology. Organisations are in general very reluctant to outsource critical applications or confidential data. Currently the kind of applications that could be safely deployed on clouds could be web based applications managing publicly available information, with no integration to internal company databases containing confidential information on customers for example.
However, much of the potential applications that could be moved to clouds are business-critical, and are tightly integrated with company business processes and confidential data. This paper provides an overview of cloud computing, then identifies some important security issues and proposes some solutions. The main security issues are related to secure virtual machine management, usage control of virtual resources and the perception of security by the user.

12.00h : Sandwich lunch & soft drinks offered by our sponsors

12.50h : Yes to virtualization . . . but not without protection
By Arno Brugman, Senior Principal Consultant, CA


Organizations are adopting virtualization technology to reduce total cost of ownership and improve quality of service of IT systems. This strategy provides the operational foundation to consolidate critical services and sensitive data that were once scattered amongst distributed system deployments.  From a security standpoint, not only are the security issues found on networked systems applicable to virtual machines, but the virtualization platform and guest virtual machine introduces a new breed of security threats.  This presentation covers the virtualization security gaps and how to close them.



13.45h : From virtualization hype to day to day use, the reality of security of virtualization and a strategy for the future of a secure datacenter
By Jan Tiri, VMWare


Real business requirements are requiring operations and systems for which traditional technologies are no longer sufficient. However already there for many years, virtualization technologies recently have become an answer to quite a number of business challenges, and with significant benefits. A view on the reality of today.
Virtualization technologies are also driving major changes in the datacenter. The have a major impact on security policy, management, products and technologies. This presentation will outline a vision for how security can be implemented in the next-generation datacenter.


15.15h : Coffee Break & Networking


15.45h : Securing the Virtual Environment
By Johan Celis, Security Solutions Architect, IBM ISS EMEA

The cost reduction benefits for virtualization are enormous and as more servers and networks get virtualized, security is too often neglected.

In a project code named Phantom, IBM researchers are developing new security technologies to protect the hypervisor and monitor communications between virtual environments. At Phantom’s core is industry-leading network and host intrusion protection used to guard the virtual environment and the machines from the inside out. The new technology sits in a secure, isolated partition and integrates with the hypervisor, the layer of management software that coordinates calls between operating systems and computer hardware. This session will cover security issues related to the virtual environment. Some are identical to those encountered with physical servers and networks, but some are unique to this environment and this calls for new solutions and strategies.

About : Johan Celis has over 15 years of ICT experience of which over 8 years in security. He currently works for IBM Internet Security Systems as a Security Solutions Architect for the EMEA region. In this role he manages the EMEA lab environment and ISS EBC briefings. Prior to joining IBM ISS, he worked for Symantec as a Principal Security Consultant for Western Europe. He started his career by launching one of the first ISP’s. He later joined cable operator business for UPC and its subsidiary Chello


16.35h : Keynote : Virtualization and security: what does it mean for me?
Kai Axford (CISSP, MCSE-Security) is a Senior Security Strategist in Microsoft’s Trustworthy Computing Group.


Virtualization is the Next Big Thing™, and certainly you’ve at least examined it, and probably are using several virtualized servers already. How are you handling the security of your images? How are you securing the guest and host operating systems, and the applications you’re running? Virtualization raises certain unique security requirements, and provides some interesting security capabilities, too. Join Steve Riley as he explores the interesting aspects of virtualization and security.



About : A ten-year Microsoft veteran, Kai is responsible for discussing and recommending security solutions for both private and public sector organizations. In addition, he conducts Chief Security Officer councils worldwide, taking executive feedback and affecting change within Microsoft’s security products and processes. Kai started with Microsoft in 1999 as a Server Support Engineer and then moved on to become an IT Pro Evangelist, focusing on his peers through the Microsoft TechNet Events program. Kai has delivered more than 300 security presentations on a variety of topics, including digital forensics, security management, incident response, and computer espionage. He is a frequent speaker at security conferences, executive meetings, and business seminars around the world.
Prior to Microsoft, Kai served as a leader in several real-world operations with the U.S. Army’s elite 75th Ranger Regiment.


17.50h : Panel discussion


18.20h : Closing notes
By Ulrich Seldeslachts, CEO LSEC


18.30h : Reception, Drinks & Snacks offered by LSEC and its partners. Networking


19.30h : Close of Event

A whitepaper of this event is being published. Send a note to virtualizationsecurity @ lsec.be if you wish to recieve a copy of it.

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< January 2012 >>

S M T W T F S
1 2 3 4 5 6 7
8 9 10 11 12 13 14
15 16 17 18 19 20 21
22 23 24 25 26 27 28
29 30 31 1 2 3 4

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: TNO

TNO Research and Innovation

Expert: Control & Process

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.