Security Virtualization, Virtualization Security and Cloud Computing Issues 2009 Revisited

26-Jan-2010

Have you ever been Hyperjacked ? Recently found a Botnet in your Cloud?

Last year, LSEC organized a seminar on some of the Security aspects of Virtualization and Cloud Computing. During that seminar, an outline was presented on current threats, potential solutions and future evolutions. The current business drive on virtualization and cloud computing and the evolution of threats in the cloud, make this topic more than ever important for businesses, organisations and administrations working on or towards Virtualization.


Not yet aware about Hyperjacking, or you don’t know how to run Botnets in the Cloud? We plan to revisit some of the potential threats posed by the use of Hypervisors, Virtual Machines on multiple OS or even running a variety of Virtual Machines on a multitude of physical servers, Did you realize that physically moving a VM from one machine to another, is actually done in the clear?
How easy would it be within your organization to walk in with a USB-stick running a VM, copying all of the VM’s active and re-running their states somewhere else to find out your weaknesses?
How do you realize patch management in VM’s that have been online for a while, but could resurface with potential threats in them? How do you plan to control your ICT-environment, with this Virtual environment? What are your rights when a government enforcement groups hijacks your physical and virtual machines? The challenges are omnivalent and complex. Solutions are non-existent, or just barely surfacing.



Next to that, we also plan to investigate what opportunities Virtualization bring to the world of Security. In this case, as a means to an end. Using Virtual Security Appliances, but also Security solutions in your Virtual Machines, Hypervisors and ensuring their activities run secure - are topics that will be addressed.


Finally, we want to open the discussion on a local basis on the protection of activities in the cloud. What are your challenges in terms of Security? Business people can and will move company data outside of the company’s premises, but the controls can probably not always go along. There will be an increasing challenge to your security, with an increased need for security measures and control. But how can you ensure that no breaches have happened? What about concerns over data ownership, regulations and privacy concerns. Do you require stronger SLA’s? Will you be able to enforce those, if your data is residing abroad? The opportunity of Cloud Computing is there, but the discussion has only just begun.



Preliminary Program

13.00 : Welcome Coffee & Registration
13.30 : Introduction & Opening Notes by Ulrich Seldeslachts
13.40 : Overview of the current challenges on Cloud Computing and Security of Virtualization. Conclusions and ideas from the ENISA Working Group on Cloud Computing and Virtualization, by Phlippe Massonent, CETIC
14.30 : Update on Security Issues related to Virtualization and Cloud Computing, by Johan Celis, IBM Security Solutions Architect
15.20 : Coffee Break
15.40 : Security Challenges In Virtual Environments and how to address them, by Jeroen De Corel, Check Point Security Software, Security Engineer Belux
16.30 : Advantages and Security considerations when publishing applications on mobile devices from out of a cloud, by Gert Vanhaeght, Syscon
17.00 :  Legal Challenges in Cloud Computing, by Maarten Truyens, DLA Piper

About Maarten Truyens : Maarten Truyens is a qualified lawyer registered with the bar of Brussels (Belgium) and practices information technology law at DLA Piper Brussels. He specialises in the fields of e-commerce, IT contracting, data protection, telecom, consumer protection, outsourcing and new technologies. His practice includes clients in both the public and the private sector, in Belgium and abroad. In the domain of open source, he advises both startup companies and multinationals on issues such as dual licensing, open core licensing and the assessment of derivative works in the context of GPL software.

He is a contributing editor of the international Journal for Internet Law (Wolters Kluwer) and is also a regular speaker on seminars regarding ICT law, IT security (identity theft, internet crime), open source, privacy, electronic document management and corporate governance. He regularly participates in both national and international projects investigating the impact of new IT and telecommunications law. He was involved in a European study on the future of the legal framework for the information society (see http://www.euinternetlaw.eu) and another study on technology transfer (see http://www.eutechnologytransfer.eu), both for the European Commission.

Recent books and articles written or co-authored by Maarten Truyens include “Monitoring and analysis of technology transfer and intellectual property regimes and their use” (published in 2009); “Legal issues in technology transfer”, the European Association of Research Managers & Administrators, October 2009; “Standardisation in the European ICT sector: official procedures at the verge of being overhauled” (Shidler Journal of Law, Commerce & Technology, July 2009); “A balanced approach to open source” (IT Professional nr. 44, 9 April 2008); “Long awaited opinion on the use of search engines” (BNA International World Data Protection Report, April 2008); “The Swift Case” (Privacy Advisor, 2007); “The law and security” (Data News ICT Guide 2007) and “Rules for electronic commerce” (Informatie (NL), 2006).

Recent seminars include “Publishing vs patenting”, EIROforum Technology Transfer Conference organised by the European Commission, November 2009; “Legal developments in open source in the US and the EU”, iTechLaw conference for IT Lawyers, November 2009; “Open Source” (ADM, 2008); “How Liable Are You for Identity Theft?”, (RSA Security Conference 2007); “Legal aspects of electronic document management” (Kluwer, 2005-2007); “Legal aspects of IT systems” (University of Antwerp Management School, 2006) and “Instant Messaging: Legal aspects” (Microsoft, 2006).

Before joining DLA Piper Belgium in 2005, Maarten worked as an IT consultant, in areas such as transactional high-volume websites, database publishing, multimedia and business automation. This hands-on experience with e-commerce matters, from both a technical and managerial point of view, has rendered him invaluable technical information, which he now combines with his legal knowledge. His clients value his active technical knowledge of internet-related technologies and protocols, programming languages, databases and Web 2.0 programming frameworks. Having witnessed the internet revolution from the inside, he is acquainted with the benefits and pitfalls of e-commerce transactions and on-line business models.

17.50 : Some solutions in managing Security on Virtual Machines, by Peter van Eeckhout, McAfee IT Security and Compliance Solutions
18.40 : Reception and Close of Seminar

Other subjects to be discussed :
Security challenges of Hypervisors and Virtualization broken down.
Some solutions for better improving your Virtual Machines, your Virtualization environment and your Hypervisors.
Business and legal challenges posed by Cloud Computing.
The local debate on the future of Security and Control in the space of Virtualization and Cloud Computing.


Practical Details

LSEC Security Virtualization, Virtualization Security and Cloud Computing Issues 2009 Revisited

Leuven, Auditorium Kasteel Arenberg, KU Leuven, Kasteelpark Arenberg - 3001 Heverlee
Tuesday, January 26th, 2010 - from 13h - 18h seminar with exhibition and panel discussions.


Grotere kaart weergeven


Grotere kaart weergeven
Registration :
- You are welcome to register on this website if you haven’t done before and fill in your personal and company details.
- Afer registering on the website, or logging in on the homepage (scroll down to the fill in form) return to this page and push the subscribe button
- Too difficult? no problem, just send us email with your contact details to virtual2 at lsec.be

Attendance Fee :
- This seminar is part of LSEC’s awareness program and free to attend for anyone bringing along a colleague or a friend. Send us the email you’ve forwarded to your colleague or friend, and you and him (her) will be able to attend for free
- Alternatively you can support our activities by paying a small fee to support our catering and facilities of 150 € (excl VAT)
- We do have a cancellation policy that requires you to pay a fee of 150 € (excl VAT) if you have not cancelled at least 24 hours prior to the event.

The LSEC team is looking forward welcoming you January 26th.

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< January 2010 >>

S M T W T F S
27 28 29 30 31 1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30
31 1 2 3 4 5 6

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: Control & Process

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.