<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: montego]]></title>
    <link>http://securityratty.com/tag/montego</link>
    <description></description>
    <pubDate>Tue, 22 Apr 2008 14:07:24 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</link>
      <guid>http://securityratty.com/article/03c1f11d6787944e11b9ab1baec0352e</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor and Alert when VM’s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">•</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/350982407/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Security Through Visibility - Montego, Lancope and NetFlow]]></title>
      <link>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</link>
      <guid>http://securityratty.com/article/5b6ed1101dc183f8ebcfa1e481566982</guid>
      <description><![CDATA[We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments. This is because it is extremely challenging to see...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>We've probably all heard that you can't secure what you can't see and that statement is even more profound when it comes to virtual environments.&nbsp; This is because it is extremely challenging to see what is going on at a micro vs. macro level within a virtual environments network.&nbsp; The virtualization vendors such as VMWare and Citrix have provided embedded tools into their management consoles that show a macro level of visibility but its not enough to identify security events in the environment.&nbsp; Take a look at the attached picture.&nbsp; It simply shows VMWare's ability to monitor virtual network performance statistics from a bits per second perspective.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/performancescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Performancescreen" title="Performancescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/performancescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
<br />&lt;-Click To Enlarge</p>

<p>With only this level of detail how can one determine which network applications are causing spikes.&nbsp; Is it FTP traffic that is occuring at a high volume at an unuseal time of day?&nbsp; If that were occuring, could that be indicative of either a breach or some sort of problem? What if FTP isn't even an authorized service in the virtual environment but there is a high volume of it?&nbsp; Did someone install a rouge FTP service so they could steal information from the server at will? </p>

<p>These types of questions can't really be answered without a micro level of detail into the packets flowing in, out and within the virtual environment.&nbsp; Now, what I am highlighting is not security in the traditional sense of prevention but using visibility as a means to first identify, then pin point the source of an issue so that it can properly be mitigated.&nbsp; Having constant visibility can also ensure that other security products in the environment are performing as expected.&nbsp; What if a Montego HyperSwitch with firewalling enabled is configured with many policies but someone forgot to create an FTP block policy.&nbsp; One could think they are protected from rouge FTP services transmiting data out of the network, but without constant visibility monitoring, can you be certain?</p>

<p>Some vendors, namely Reflex Security will get you to believe that their IPS / IDS solution that is inline and running in the virtual environment is the right and only approach.&nbsp; Or they will tell you to hang a virtual IDS off a span port in the virtual environment and you will at least have visibility into the attacks that are taking place.&nbsp; Well, sure... You now have attack visibility but at the performance cost of your virtual environment.&nbsp; Signature matching technologies are great, I'm a huge believer; however they don't scale very well in shared computing environments such as virtual ones.&nbsp; IDS systems also don't typically track protocol and network service (FTP, HTTP, etc.) utilizations; which is another important part of visibility.</p>

<p>So, what do we do to gain visibility without the performance headache?&nbsp; Well, for starters its probably best to put your IDS/IPS solutions in the physical environment where performance will be less of a concern.&nbsp; In fact, you can span a virtual switch's traffic out to a physical NIC as easy as you can to a virtual one.&nbsp; So why do it virtual and have to pay a 60% CPU utilization tax?&nbsp; Another solution is to IDS inspect only the things you care about.&nbsp; Why IDS inspect SSL traffic if you know your solution can't unencrypt SSL.&nbsp; Its just a waste of compute cycles isnt it?&nbsp; Policy based switching helps you with directing only the things you care about to an IDS (attack visualization product).&nbsp; Montego's HyperSwitch also can help you with the traffic redirection of only the things you care about. </p>

<p>Another method of visibility which I tend to be a fan of is one of packet analysis (aka NetFlow).&nbsp; NetFlow was invented by Cisco some time ago and has gained popularity in the physical world and definately has a use in the virtual world.&nbsp; NetFlow is lightweight.&nbsp; Let me say that again, its light weight!&nbsp; It only sends a summation of packet detail to an analytical engine which can do some number crunching, packet comparison, etc. etc. to make some sense out of whats going on.&nbsp; <a href="http://www.lancope.com">Lancope</a>, an Atlanta based visibility company that provides Network Visibility, Security Visibility and User Visibility has this tool on their website that is a Netflow Bandwidth calculator.&nbsp; You'll see from playing with this ( <a href="http://www.lancope.com/netflowcalculator.aspx">http://www.lancope.com/netflowcalculator.aspx</a> ) calculator that it doesn't consume a lot of network bandwidth to transmit these network accounting records.&nbsp; It also doesn't cause a lot of CPU overhead to send these records to an analytical engine sitting somewhere in the network.</p>

<p>Lancope's analytical engines have the ability to do the following for you within your virtual environment:</p><meta http-equiv="Content-Type" content="text/html; charset=utf-8" /><meta name="ProgId" content="PowerPoint.Slide" /><meta name="Generator" content="Microsoft PowerPoint 11" /><title><p>&lt;p&gt;Slide 3&lt;/p&gt;</p></title><meta name="Description" content="7/30/2008" /><style>
.O
	{color:black;
	font-size:149%;}
a:link
	{color:#CC9900 !important;}
a:active
	{color:#9B2D1F !important;}
a:visited
	{color:#96A9A9 !important;}
</style><style media="print">
&amp;lt;!--.sld
	{left:0px !important;
	width:6.0in !important;
	height:4.5in !important;
	font-size:103% !important;}
--&amp;gt;
</style><o:shapelayout v:ext="edit"></o:shapelayout><o:idmap v:ext="edit" data="1"></o:idmap><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9">&nbsp;</p:colorscheme><p:colorscheme colors="#ffffff,#000000,#e9e5dc,#696464,#d34817,#9b2d1f,#cc9900,#96a9a9"><div v:shape="_x0000_s1026" class="O">

<ol><li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert network behavior of VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Track Vmotion movement of VMs accross physical servers</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert on communication between VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify users accessing VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify unauthorized or rouge VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor and Alert when VM???s go online or offline
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Identify network services running on VMs
</span></li>

<li><span style="font-size: 56%;"><span style="position: absolute; left: -0.85%;">???</span></span><span style="font-size: 10pt;">Monitor Network / Application performance of VMs<br />Display active hosts accessing VMs</span></li></ol>















<div></div>

</div>

</p:colorscheme><p>...and probably a slew of other things I'm not aware of.&nbsp; A screen shot of their product is bellow:</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/07/30/lancopescreen.jpg" onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="187" width="300" border="0" alt="Lancopescreen" title="Lancopescreen" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/07/30/lancopescreen.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a> &lt;- Click to enlarge</p>

<p>You'll notice from the screenshot that you are able to visualize who is talking to who, how much traffic they have sent and received and something called a concern index (not seen on this screenshot).</p>

<p>Now, a concern index is a number that increases as Lancopes analytical engines monitor suspicious activity on a session.&nbsp; A high counter can be indicative of a security problem.&nbsp; Its another way of identifying (visualizing) compromised hosts (virtual machines) without having to do signature matching like a heavy weight IPS engine.&nbsp; Example:&nbsp; Lets say you have a VM that has a BOT on it and is &quot;owned&quot;.&nbsp; The Lancope product is monitoring this long life session.&nbsp; Let's say that session is established for several hours or maybe even days or months.&nbsp; Lets also say that the conversation appears to be mostly unidirectional from a public ip address not belonging to your enterprise.&nbsp; Lancope would increase a the concern index on this since this server hasn't typically had this type of behavior.&nbsp; Once the concern index reached a certain level it could then fire off an email, send you a text message or something saying:&nbsp; <strong>Warning, Warning, Danger, Danger Will Robinson!!! You're virtual server may be infected with a BOT, please investigate immediately!!!</strong></p>

<p>This example is VISIBILITY which helps you with SECURITY.&nbsp; There are a number of other things you can do with NetFlow and Lancope products that have less to do with security and more to do with operational efficiencies.&nbsp; Things like, helping you answer questions of:&nbsp; How do I know what network applications are taking up the most bandwidth?&nbsp; When should I move those applications over to a server with more horsepower?&nbsp; When did these VM's vmotion over here and was there a traffic condition / CPU condition that caused that to occur?&nbsp; I could go on and on but thats a topic for another blog entry.</p>

<p>So, my suggestion is to take a look at what NetFlow has to offer.&nbsp; Montego Networks supports NetFlow transmission and Lancope supports NetFlow analytics and with both you can regain what was lost visibility.</p>

<p>I hope this was helpful to you all!</p>

<p>-John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 30 Jul 2008 17:57:06 +0000</pubDate>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/network visibility">network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/environments">environments</category>
      <category domain="http://securityratty.com/tag/virtual environments network">virtual environments network</category>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/network bandwidth">network bandwidth</category>
      <category domain="http://securityratty.com/tag/bandwidth">bandwidth</category>
      <category domain="http://securityratty.com/tag/virtual">virtual</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/07/security-throug.html">Security Through Visibility - Montego, Lancope and NetFlow</source>
    </item>
    <item>
      <title><![CDATA[Security Between Virtual Machines?]]></title>
      <link>http://securityratty.com/article/69916a03ef5251f62e6e3deefe8910ec</link>
      <guid>http://securityratty.com/article/69916a03ef5251f62e6e3deefe8910ec</guid>
      <description><![CDATA[Is there security needed between virtual machines? Some say no, some say yes. I've been out talking to a number of virtualization users and non users on this topic and I'm finding that some say no and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Is there security needed between virtual machines?&nbsp; Some say no, some say yes.&nbsp; I've been out talking to a number of virtualization users and non users on this topic and I'm finding that some say no and some say yes.&nbsp; The users of virtualization technology tend to say yes while others looking at virtualization from the outside tend to say no.&nbsp; Why is this?</p>

<p>Well, I thought I'd blog on my thoughts on this!</p>

<p>You see, in the physical datacenter there is no firewalling between servers plugged into the same switch and because of this some people think, well if its not done in the physical world why should it be done in the virtual world.&nbsp; I believe that its not done in the physical world today because there are no solutions today that embed security into datacenter switches.&nbsp; Should it be done in the physical world?&nbsp; I think so!&nbsp; It never hurts to get security as close as possible to the things you are trying to protect and what better place than the switch port in which the critical asset are connected to.&nbsp; This is why people have HOST BASED FW/IPS ON SERVERS!&nbsp; To get security as close as possible!&nbsp; Is that needed?&nbsp; </p>

<p>So my first response to those that say, security between virtual machines is not needed because its not done in the physical world is:&nbsp; Well, just because people have done things one way for many years doesn't mean there isn't a better way.</p>

<p>Would environments be more secure if there was security between servers?&nbsp; I tend to think so.&nbsp; You see, many of the attacks that are taking place these days are not attacks for fame but attacks for fortune and gone are the days where people just hacked to spread nasty viruses.&nbsp; Its all about the data these days (ie. credit cards, social security numbers, etc).&nbsp; We've all heard about the TJ Max security breach where customer data was compromised and many others like banks that have had credit cards compromised.&nbsp; </p>

<p>How and the heck do you think most of these things happened?&nbsp; Attackers are targeting the datacenter these days.&nbsp; Physical or Virtual.&nbsp; Their gateway into these environments are the Web Front End Servers.&nbsp; Let me say that again.&nbsp; The Web Front End Servers!&nbsp; Hackers get to the data from the web front end server that talks to the database backend server.&nbsp; This useually occurs by something called &quot;Cross-Site Scripting&quot; or &quot;SQL Injection&quot; breaches.&nbsp; </p>

<p>Here is a trival way of how this happens:</p>

<p>A hacker finds a vulnerable web site.&nbsp; He sometimes does this by something called Google Hacking.&nbsp; He uses Google to search for sites that has vulnerabilities on it.&nbsp; Say a web site has some content on one of the pages that says &quot;Powered by Drupal 4.1&quot;.&nbsp; If a hacker knows that Drupal 4.1 software has a vulnerability in it, he can now target all the search results related to this.&nbsp; <a href="http://en.wikipedia.org/wiki/Google_hacking">Click Here for more detail</a>.</p>

<p>Now lets say Drupal 4.1 on a web site has a SQL-Injection vulnerability because the developer of the Drupal software didn't do Form Field Validation properly.&nbsp; A Form field is something you fill out on a web page like a form that asks for the user name and password.&nbsp; User names and passwords to log into the web site are stored on whats called a Database Server.&nbsp; Hmmm... So this means the web server needs to talk to the database server right?&nbsp; Yes!&nbsp; Keep this in the back of our head for now.&nbsp; The hacker enters in &quot;Admin&quot; for the user ID and &quot;password doesn't matter <strong>'or 1=1--</strong>&quot; for the password.&nbsp; And presto!&nbsp; He is logged in to the server as Admin.</p>

<p>The reason he was able to log in is because the web site sends a SQL Database command to the Database server and because the developer of the Drupal software didn't do &quot;Form Field Validation&quot; properly (method of checking for invalid characters like the ' (single quote)&nbsp; symbol), the user was able to bypass the password.&nbsp; Notice the 'OR 1=1 command appended to the password.&nbsp; One does equal one so therefore it will return a TRUE result to the password checker and the OR says use the password typed in (password doesnt matter) OR check to see if one is equal to one.&nbsp; If its true then the password is valid for this user which is Admin.</p>

<p>Now that the user is on the web server, he probably has the ability to connect to the database server or other servers in the network.&nbsp; Why?&nbsp; Because there is connectivity from the web front end to all of the backend servers.&nbsp; He essently can backdoor his way throughout the network. </p>

<p>Another method is for him to append some SQL statement to another SQL statement.&nbsp; Lets say their is a FORM FIELD on the website that collects some information from the database to display it to web site users.&nbsp; It could be entering in the Zip code to find store locations in your area.&nbsp; Instead of putting in the zip code you could put in &quot;95123 'UNION SELECT * FROM credit_card_table--&quot;.&nbsp; The hacker is injecting via the UNION command (which means join one SQL statement with another one) a command that says grab all (via the asterisk) information out the credit card table.</p>

<p>Lastly, the hacker can use the UNION command to write text of his desire to a text file on the database server.&nbsp; He may write some nasty code, tell the database to write the code to a file and then tell the server to execute that file.&nbsp; The code could be used to do a denial of service attack to the other virtual machines or whatever.&nbsp; The possibilities are endless!!</p>

<p>Anyway, these are high level examples.&nbsp; I think you get the point.</p>

<p>The Web Front End Virtual Machine has a need to talk to the Web Back End Virtual Machine and security such as Firewalling, Intrusion Prevention definately needs to be in place to have a higher level of security.</p>

<p>Another reason to have security between virtual machines is because servers are now mobile in the virtual world.&nbsp; They move between trust domains to take advantage of computing resources that may be available on a given piece of hardware.&nbsp; Lets say one PHYSICAL server was hosting database VM's and another PHYSICAL server was hosting file server VM's.&nbsp; The file server VM could VMOTION to the same environment as the database VM's.&nbsp; &nbsp;Now where is your isolation between trust domains or unlike resources?</p>

<p>People should think about this problem in greater detail.&nbsp; I'd love to hear everyones comments as to whether or not they think security between VM's is needed.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/06/22/creditcardhacker_2.jpg" onclick="window.open(this.href, '_blank', 'width=640,height=400,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="312" border="0" width="500" alt="Creditcardhacker_2" title="Creditcardhacker_2" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/06/22/creditcardhacker_2.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
 </p><br /><br /><br /><br /><p>John Peterson<br />Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Sun, 22 Jun 2008 11:30:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web page">web page</category>
      <category domain="http://securityratty.com/tag/web site sends">web site sends</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/file server">file server</category>
      <category domain="http://securityratty.com/tag/database backend server">database backend server</category>
      <category domain="http://securityratty.com/tag/web front">web front</category>
      <category domain="http://securityratty.com/tag/vulnerable web site">vulnerable web site</category>
      <category domain="http://securityratty.com/tag/database server">database server</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/317542130/security-betwee.html">Security Between Virtual Machines?</source>
    </item>
    <item>
      <title><![CDATA[Security Between Virtual Machines?]]></title>
      <link>http://securityratty.com/article/5e0193263d9b2c777748e80174926e2a</link>
      <guid>http://securityratty.com/article/5e0193263d9b2c777748e80174926e2a</guid>
      <description><![CDATA[Is there security needed between virtual machines? Some say no, some say yes. I've been out talking to a number of virtualization users and non users on this topic and I'm finding that some say no and...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Is there security needed between virtual machines?&nbsp; Some say no, some say yes.&nbsp; I've been out talking to a number of virtualization users and non users on this topic and I'm finding that some say no and some say yes.&nbsp; The users of virtualization technology tend to say yes while others looking at virtualization from the outside tend to say no.&nbsp; Why is this?</p>

<p>Well, I thought I'd blog on my thoughts on this!</p>

<p>You see, in the physical datacenter there is no firewalling between servers plugged into the same switch and because of this some people think, well if its not done in the physical world why should it be done in the virtual world.&nbsp; I believe that its not done in the physical world today because there are no solutions today that embed security into datacenter switches.&nbsp; Should it be done in the physical world?&nbsp; I think so!&nbsp; It never hurts to get security as close as possible to the things you are trying to protect and what better place than the switch port in which the critical asset are connected to.&nbsp; This is why people have HOST BASED FW/IPS ON SERVERS!&nbsp; To get security as close as possible!&nbsp; Is that needed?&nbsp; </p>

<p>So my first response to those that say, security between virtual machines is not needed because its not done in the physical world is:&nbsp; Well, just because people have done things one way for many years doesn't mean there isn't a better way.</p>

<p>Would environments be more secure if there was security between servers?&nbsp; I tend to think so.&nbsp; You see, many of the attacks that are taking place these days are not attacks for fame but attacks for fortune and gone are the days where people just hacked to spread nasty viruses.&nbsp; Its all about the data these days (ie. credit cards, social security numbers, etc).&nbsp; We've all heard about the TJ Max security breach where customer data was compromised and many others like banks that have had credit cards compromised.&nbsp; </p>

<p>How and the heck do you think most of these things happened?&nbsp; Attackers are targeting the datacenter these days.&nbsp; Physical or Virtual.&nbsp; Their gateway into these environments are the Web Front End Servers.&nbsp; Let me say that again.&nbsp; The Web Front End Servers!&nbsp; Hackers get to the data from the web front end server that talks to the database backend server.&nbsp; This useually occurs by something called &quot;Cross-Site Scripting&quot; or &quot;SQL Injection&quot; breaches.&nbsp; </p>

<p>Here is a trival way of how this happens:</p>

<p>A hacker finds a vulnerable web site.&nbsp; He sometimes does this by something called Google Hacking.&nbsp; He uses Google to search for sites that has vulnerabilities on it.&nbsp; Say a web site has some content on one of the pages that says &quot;Powered by Drupal 4.1&quot;.&nbsp; If a hacker knows that Drupal 4.1 software has a vulnerability in it, he can now target all the search results related to this.&nbsp; <a href="http://en.wikipedia.org/wiki/Google_hacking">Click Here for more detail</a>.</p>

<p>Now lets say Drupal 4.1 on a web site has a SQL-Injection vulnerability because the developer of the Drupal software didn't do Form Field Validation properly.&nbsp; A Form field is something you fill out on a web page like a form that asks for the user name and password.&nbsp; User names and passwords to log into the web site are stored on whats called a Database Server.&nbsp; Hmmm... So this means the web server needs to talk to the database server right?&nbsp; Yes!&nbsp; Keep this in the back of our head for now.&nbsp; The hacker enters in &quot;Admin&quot; for the user ID and &quot;password doesn't matter <strong>'or 1=1--</strong>&quot; for the password.&nbsp; And presto!&nbsp; He is logged in to the server as Admin.</p>

<p>The reason he was able to log in is because the web site sends a SQL Database command to the Database server and because the developer of the Drupal software didn't do &quot;Form Field Validation&quot; properly (method of checking for invalid characters like the ' (single quote)&nbsp; symbol), the user was able to bypass the password.&nbsp; Notice the 'OR 1=1 command appended to the password.&nbsp; One does equal one so therefore it will return a TRUE result to the password checker and the OR says use the password typed in (password doesnt matter) OR check to see if one is equal to one.&nbsp; If its true then the password is valid for this user which is Admin.</p>

<p>Now that the user is on the web server, he probably has the ability to connect to the database server or other servers in the network.&nbsp; Why?&nbsp; Because there is connectivity from the web front end to all of the backend servers.&nbsp; He essently can backdoor his way throughout the network. </p>

<p>Another method is for him to append some SQL statement to another SQL statement.&nbsp; Lets say their is a FORM FIELD on the website that collects some information from the database to display it to web site users.&nbsp; It could be entering in the Zip code to find store locations in your area.&nbsp; Instead of putting in the zip code you could put in &quot;95123 'UNION SELECT * FROM credit_card_table--&quot;.&nbsp; The hacker is injecting via the UNION command (which means join one SQL statement with another one) a command that says grab all (via the asterisk) information out the credit card table.</p>

<p>Lastly, the hacker can use the UNION command to write text of his desire to a text file on the database server.&nbsp; He may write some nasty code, tell the database to write the code to a file and then tell the server to execute that file.&nbsp; The code could be used to do a denial of service attack to the other virtual machines or whatever.&nbsp; The possibilities are endless!!</p>

<p>Anyway, these are high level examples.&nbsp; I think you get the point.</p>

<p>The Web Front End Virtual Machine has a need to talk to the Web Back End Virtual Machine and security such as Firewalling, Intrusion Prevention definately needs to be in place to have a higher level of security.</p>

<p>Another reason to have security between virtual machines is because servers are now mobile in the virtual world.&nbsp; They move between trust domains to take advantage of computing resources that may be available on a given piece of hardware.&nbsp; Lets say one PHYSICAL server was hosting database VM's and another PHYSICAL server was hosting file server VM's.&nbsp; The file server VM could VMOTION to the same environment as the database VM's.&nbsp; &nbsp;Now where is your isolation between trust domains or unlike resources?</p>

<p>People should think about this problem in greater detail.&nbsp; I'd love to hear everyones comments as to whether or not they think security between VM's is needed.</p>

<p><a href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/06/22/creditcardhacker_2.jpg" onclick="window.open(this.href, '_blank', 'width=640,height=400,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false"><img height="312" border="0" width="500" alt="Creditcardhacker_2" title="Creditcardhacker_2" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/06/22/creditcardhacker_2.jpg" style="margin: 0px 5px 5px 0px; float: left;" /></a>
 </p><br /><br /><br /><br /><p>John Peterson<br />Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Sun, 22 Jun 2008 11:30:57 +0000</pubDate>
      <category domain="http://securityratty.com/tag/web">web</category>
      <category domain="http://securityratty.com/tag/web page">web page</category>
      <category domain="http://securityratty.com/tag/web site sends">web site sends</category>
      <category domain="http://securityratty.com/tag/server">server</category>
      <category domain="http://securityratty.com/tag/file server">file server</category>
      <category domain="http://securityratty.com/tag/database backend server">database backend server</category>
      <category domain="http://securityratty.com/tag/web front">web front</category>
      <category domain="http://securityratty.com/tag/vulnerable web site">vulnerable web site</category>
      <category domain="http://securityratty.com/tag/database server">database server</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/06/security-betwee.html">Security Between Virtual Machines?</source>
    </item>
    <item>
      <title><![CDATA[Lancope and Montego Networks Does VM2VM Visibility with Netflow]]></title>
      <link>http://securityratty.com/article/fda4a6cc929c6d15a8cab0f92562d9b9</link>
      <guid>http://securityratty.com/article/fda4a6cc929c6d15a8cab0f92562d9b9</guid>
      <description><![CDATA[I've blogged on this topic of Netflow enabling visibility within virtual environments in the past but thought I'd discuss this topic once again as I feel visibility within virtual networks is VERY...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>I've blogged on this topic of Netflow enabling visibility within virtual environments in the past but thought I'd discuss this topic once again as I feel visibility within virtual networks is VERY important.</p>

<p>One of the big problems that comes along with virtualization is the inability to see &quot;hidden&quot; traffic flows within virtual networks created by VMWare, Citrix and others.&nbsp; There are a number of companies off building &quot;agents&quot; or visibility products that can drop inside VMWare to bring back that visibility that was once had in the physical network and I think this is great!&nbsp; But! These solutions although needed are yet another tool that needs to be purchased, managed and maintained.&nbsp; These new solutions also only work within the virtual environment.</p>

<p>Wouldn't it be great if you could leverage either existing tools that give you physical network visibility or being able to use a tool that could give you both physical and virtual visibility?&nbsp; It would be one less thing to manage right?&nbsp; It could also probably correlate information for your entire network vs. just a subset of it.</p>

<p>Well, look no further.&nbsp; With the enablement of a feature called Netflow within virtual switches from Montego Networks and an experimental version that exists in VMWare ESX 3.5 you can now export Netflow records to physical network monitoring solutions from the likes of Lancope, Plixer International, Mazu Networks, Arbor Networks and others.</p>

<p>What triggered my blog on this topic today was a webinar I listened in on this morning from CTO Adam Powers of Lancope.&nbsp; He did an excellent job explaining the how VM 2 VM communications are hidden and how you can bring back that visibility by leveraging Netflow and <a href="http://www.lancope.com">Lancope</a>.&nbsp; </p>

<p>I would suggest everyone interested in this topic <a href="http://www.lancope.com/news/webinars/">CLICK HERE</a> to register for the next Webinar by Lancope on this topic.&nbsp; It starts at 2:00 PM EST today May 21st 2008.&nbsp; </p>

<p>Bellow are a couple of screenshots from the webinar that was hosted earlier today.</p>

<p>CLICK IMAGES TO ENLARGE<br /><a onclick="window.open(this.href, '_blank', 'width=800,height=597,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_diagram_2.jpg"><img width="200" height="149" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/netflow_diagram_2.jpg" title="Netflow_diagram_2" alt="Netflow_diagram_2" style="margin: 0px 5px 5px 0px; float: left;" /></a> </p>

<p><a onclick="window.open(this.href, '_blank', 'width=800,height=597,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_diagram.jpg"></a><a onclick="window.open(this.href, '_blank', 'width=682,height=513,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_benefits.jpg"><img width="200" height="150" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/netflow_benefits.jpg" title="Netflow_benefits" alt="Netflow_benefits" style="margin: 0px 5px 5px 0px; float: left;" /></a>

</p><br /><br /><br /><br /><br /><br /><br />

<p>Also the picture bellow shows a nice graphic of how the Montego Networks HyperSwitch interacts with Netflow devices.</p>

<p><a onclick="window.open(this.href, '_blank', 'width=458,height=444,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/montego_netflow.jpg"><img width="200" height="193" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/montego_netflow.jpg" title="Montego_netflow" alt="Montego_netflow" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />

<p>Again, I would suggest everyone interested in this topic <a href="http://www.lancope.com/news/webinars/">CLICK HERE</a> to register for the next Webinar by Lancope on this topic.&nbsp; It starts at 2:00 PM EST today May 21st 2008. </p>

<p>John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 21 May 2008 10:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/physical">physical</category>
      <category domain="http://securityratty.com/tag/physical network visibility">physical network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/netflow">netflow</category>
      <category domain="http://securityratty.com/tag/physical network">physical network</category>
      <category domain="http://securityratty.com/tag/virtual visibility">virtual visibility</category>
      <category domain="http://securityratty.com/tag/lancope">lancope</category>
      <category domain="http://securityratty.com/tag/topic">topic</category>
      <category domain="http://securityratty.com/tag/topic click">topic click</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/295162441/lancope-and-mon.html">Lancope and Montego Networks Does VM2VM Visibility with Netflow</source>
    </item>
    <item>
      <title><![CDATA[Lancope and Montego Networks Does VM2VM Visibility with Netflow]]></title>
      <link>http://securityratty.com/article/77d01228fe9045d6cd72c5b63b506a40</link>
      <guid>http://securityratty.com/article/77d01228fe9045d6cd72c5b63b506a40</guid>
      <description><![CDATA[I've blogged on this topic of Netflow enabling visibility within virtual environments in the past but thought I'd discuss this topic once again as I feel visibility within virtual networks is VERY...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>I've blogged on this topic of Netflow enabling visibility within virtual environments in the past but thought I'd discuss this topic once again as I feel visibility within virtual networks is VERY important.</p>

<p>One of the big problems that comes along with virtualization is the inability to see &quot;hidden&quot; traffic flows within virtual networks created by VMWare, Citrix and others.&nbsp; There are a number of companies off building &quot;agents&quot; or visibility products that can drop inside VMWare to bring back that visibility that was once had in the physical network and I think this is great!&nbsp; But! These solutions although needed are yet another tool that needs to be purchased, managed and maintained.&nbsp; These new solutions also only work within the virtual environment.</p>

<p>Wouldn't it be great if you could leverage either existing tools that give you physical network visibility or being able to use a tool that could give you both physical and virtual visibility?&nbsp; It would be one less thing to manage right?&nbsp; It could also probably correlate information for your entire network vs. just a subset of it.</p>

<p>Well, look no further.&nbsp; With the enablement of a feature called Netflow within virtual switches from Montego Networks and an experimental version that exists in VMWare ESX 3.5 you can now export Netflow records to physical network monitoring solutions from the likes of Lancope, Plixer International, Mazu Networks, Arbor Networks and others.</p>

<p>What triggered my blog on this topic today was a webinar I listened in on this morning from CTO Adam Powers of Lancope.&nbsp; He did an excellent job explaining the how VM 2 VM communications are hidden and how you can bring back that visibility by leveraging Netflow and <a href="http://www.lancope.com">Lancope</a>.&nbsp; </p>

<p>I would suggest everyone interested in this topic <a href="http://www.lancope.com/news/webinars/">CLICK HERE</a> to register for the next Webinar by Lancope on this topic.&nbsp; It starts at 2:00 PM EST today May 21st 2008.&nbsp; </p>

<p>Bellow are a couple of screenshots from the webinar that was hosted earlier today.</p>

<p>CLICK IMAGES TO ENLARGE<br /><a onclick="window.open(this.href, '_blank', 'width=800,height=597,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_diagram_2.jpg"><img width="200" height="149" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/netflow_diagram_2.jpg" title="Netflow_diagram_2" alt="Netflow_diagram_2" style="margin: 0px 5px 5px 0px; float: left;" /></a> </p>

<p><a onclick="window.open(this.href, '_blank', 'width=800,height=597,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_diagram.jpg"></a><a onclick="window.open(this.href, '_blank', 'width=682,height=513,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/netflow_benefits.jpg"><img width="200" height="150" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/netflow_benefits.jpg" title="Netflow_benefits" alt="Netflow_benefits" style="margin: 0px 5px 5px 0px; float: left;" /></a>

</p><br /><br /><br /><br /><br /><br /><br />

<p>Also the picture bellow shows a nice graphic of how the Montego Networks HyperSwitch interacts with Netflow devices.</p>

<p><a onclick="window.open(this.href, '_blank', 'width=458,height=444,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/21/montego_netflow.jpg"><img width="200" height="193" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/21/montego_netflow.jpg" title="Montego_netflow" alt="Montego_netflow" style="margin: 0px 5px 5px 0px; float: left;" /></a>
</p><br /><br /><br /><br /><br /><br /><br /><br /><br /><br />

<p>Again, I would suggest everyone interested in this topic <a href="http://www.lancope.com/news/webinars/">CLICK HERE</a> to register for the next Webinar by Lancope on this topic.&nbsp; It starts at 2:00 PM EST today May 21st 2008. </p>

<p>John Peterson</p></div>
]]></content:encoded>
      <pubDate>Wed, 21 May 2008 10:35:15 +0000</pubDate>
      <category domain="http://securityratty.com/tag/physical">physical</category>
      <category domain="http://securityratty.com/tag/physical network visibility">physical network visibility</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/netflow">netflow</category>
      <category domain="http://securityratty.com/tag/physical network">physical network</category>
      <category domain="http://securityratty.com/tag/virtual visibility">virtual visibility</category>
      <category domain="http://securityratty.com/tag/lancope">lancope</category>
      <category domain="http://securityratty.com/tag/topic">topic</category>
      <category domain="http://securityratty.com/tag/topic click">topic click</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/05/lancope-and-mon.html">Lancope and Montego Networks Does VM2VM Visibility with Netflow</source>
    </item>
    <item>
      <title><![CDATA[Virtualization Vendors Are Not In The Security Business?]]></title>
      <link>http://securityratty.com/article/306b180d27de5b1fbd7fbd6df4320857</link>
      <guid>http://securityratty.com/article/306b180d27de5b1fbd7fbd6df4320857</guid>
      <description><![CDATA[Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing. In an interview with searchsecurity.com he publicy...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing.&nbsp; In an interview with searchsecurity.com he publicy stated that virtualization vendors are not competent to try and secure virtual environments and therefore looks to 3rd party security companies to solve these concerns.&nbsp; </p>

<p><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1312793,00.html?track=sy160&amp;asrc=RSS_RSS-10_160">Listen to the podcast here</a></p>

<p>Who are these 3rd party security companies?&nbsp; Well, there are a number of startup companies such as <a href="http://www.montegonetworks.com">Montego Networks</a>, <a href="http://www.bluelane.com">Blue Lane</a>, <a href="http://www.catbird.com">Catbird</a>, <a href="http://www.altornetworks.com">Altor Networks</a> as well as some of the big guys that are working on helping the virtualization vendors with these security concerns.</p>

<p>I tend to agree with Simon that the virtualization vendors don't currently have the expertise to deliver appropriate security controls for virtual environments BUT should they?</p>

<p>Well, Chris Hoff who blogs on the topic of virtualization security a lot seems to think that they should deliver security tools and and by not delivering solutions to secure the environment they are doing their customers a disservice.</p>

<p>&quot;Further, I don't expect that the hypervisor should be the place in
which all security functionality is delivered, but simply transferring
the lack of design and architecture forethought from the hypervisor
provider to the consumer by expecting someone else to clean up the mess
is just, well, typical.&quot;&nbsp; Said Chris Hoff in <a href="http://rationalsecurity.typepad.com/blog/2008/05/citrixs-crosby.html">his blog on this topic</a></p>

<p>I've spoken with a number of research analysts, venture capitalists and customers on this topic over the last several months and whenever I tell them what Montego Networks is off building they ALL seem to ask the same questions.&nbsp; One of those questions is:&nbsp; Why isn't VMWare or Citrix/Xensource doing this?&nbsp; My response has always been that &quot;they have publicly stated they do not want to and plan on leveraging an eco-system of security vendors to provide this&quot;.&nbsp; </p>

<p>Well, Simon's public statement is right in line with what I've been saying all along.&nbsp; The other question I get when I describe how Montego has security built into a virtual switch we've created is; shouldn't this technology be in the VMWare Virtual Switch?&nbsp; And my response is &quot;absolutely!&nbsp; But it isn't!&nbsp; so, someones got to do it.&quot;</p>

<p>So, I agree with Chris Hoff and I also agree with Simon Crosby.&nbsp; The virtualization vendors don't have the expertise BUT I feel they should provide SOME security tools to ensure the environment is safe.&nbsp; </p>

<p>There are some virtualization vendors that I have spoken with that are planning on using security as a differentiator and its my prediction that one of them will acquire security technology to do this.&nbsp; &nbsp;Its often easier to acquire vs. try and built it yourself given you don't currently have the expertise.</p>

<p>So who's problem is it to solve??&nbsp; Virtualization Vendors or Security Vendors??</p>

<p>I see the finger pointing game starting!</p>

<p><a onclick="window.open(this.href, '_blank', 'width=400,height=295,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/09/fingerpointing.png"><img width="200" height="147" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/09/fingerpointing.png" title="Fingerpointing" alt="Fingerpointing" style="margin: 0px 5px 5px 0px; float: left;" /></a> </p><br /><br /><br />

<p>-John Peterson</p>

<p>CTO / Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Fri, 09 May 2008 11:44:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security tools">security tools</category>
      <category domain="http://securityratty.com/tag/deliver security tools">deliver security tools</category>
      <category domain="http://securityratty.com/tag/virtualization vendors">virtualization vendors</category>
      <category domain="http://securityratty.com/tag/acquire">acquire</category>
      <category domain="http://securityratty.com/tag/acquire security technology">acquire security technology</category>
      <category domain="http://securityratty.com/tag/security functionality">security functionality</category>
      <category domain="http://securityratty.com/tag/security controls">security controls</category>
      <category domain="http://securityratty.com/tag/security concerns">security concerns</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/286984713/virtualization.html">Virtualization Vendors Are Not In The Security Business?</source>
    </item>
    <item>
      <title><![CDATA[Virtualization Vendors Are Not In The Security Business?]]></title>
      <link>http://securityratty.com/article/e0fbd22fd6947f84d93553636bc8e67c</link>
      <guid>http://securityratty.com/article/e0fbd22fd6947f84d93553636bc8e67c</guid>
      <description><![CDATA[Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing. In an interview with searchsecurity.com he publicy...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p>Simon Crosby, CTO of Citrix/XenSource made a pretty bold statement yesterday that has some people agreeing with his position and others disagreeing.&nbsp; In an interview with searchsecurity.com he publicy stated that virtualization vendors are not competent to try and secure virtual environments and therefore looks to 3rd party security companies to solve these concerns.&nbsp; </p>

<p><a href="http://searchsecurity.techtarget.com/news/article/0,289142,sid14_gci1312793,00.html?track=sy160&amp;asrc=RSS_RSS-10_160">Listen to the podcast here</a></p>

<p>Who are these 3rd party security companies?&nbsp; Well, there are a number of startup companies such as <a href="http://www.montegonetworks.com">Montego Networks</a>, <a href="http://www.bluelane.com">Blue Lane</a>, <a href="http://www.catbird.com">Catbird</a>, <a href="http://www.altornetworks.com">Altor Networks</a> as well as some of the big guys that are working on helping the virtualization vendors with these security concerns.</p>

<p>I tend to agree with Simon that the virtualization vendors don't currently have the expertise to deliver appropriate security controls for virtual environments BUT should they?</p>

<p>Well, Chris Hoff who blogs on the topic of virtualization security a lot seems to think that they should deliver security tools and and by not delivering solutions to secure the environment they are doing their customers a disservice.</p>

<p>&quot;Further, I don't expect that the hypervisor should be the place in
which all security functionality is delivered, but simply transferring
the lack of design and architecture forethought from the hypervisor
provider to the consumer by expecting someone else to clean up the mess
is just, well, typical.&quot;&nbsp; Said Chris Hoff in <a href="http://rationalsecurity.typepad.com/blog/2008/05/citrixs-crosby.html">his blog on this topic</a></p>

<p>I've spoken with a number of research analysts, venture capitalists and customers on this topic over the last several months and whenever I tell them what Montego Networks is off building they ALL seem to ask the same questions.&nbsp; One of those questions is:&nbsp; Why isn't VMWare or Citrix/Xensource doing this?&nbsp; My response has always been that &quot;they have publicly stated they do not want to and plan on leveraging an eco-system of security vendors to provide this&quot;.&nbsp; </p>

<p>Well, Simon's public statement is right in line with what I've been saying all along.&nbsp; The other question I get when I describe how Montego has security built into a virtual switch we've created is; shouldn't this technology be in the VMWare Virtual Switch?&nbsp; And my response is &quot;absolutely!&nbsp; But it isn't!&nbsp; so, someones got to do it.&quot;</p>

<p>So, I agree with Chris Hoff and I also agree with Simon Crosby.&nbsp; The virtualization vendors don't have the expertise BUT I feel they should provide SOME security tools to ensure the environment is safe.&nbsp; </p>

<p>There are some virtualization vendors that I have spoken with that are planning on using security as a differentiator and its my prediction that one of them will acquire security technology to do this.&nbsp; &nbsp;Its often easier to acquire vs. try and built it yourself given you don't currently have the expertise.</p>

<p>So who's problem is it to solve??&nbsp; Virtualization Vendors or Security Vendors??</p>

<p>I see the finger pointing game starting!</p>

<p><a onclick="window.open(this.href, '_blank', 'width=400,height=295,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/05/09/fingerpointing.png"><img width="200" height="147" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/05/09/fingerpointing.png" title="Fingerpointing" alt="Fingerpointing" style="margin: 0px 5px 5px 0px; float: left;" /></a> </p><br /><br /><br />

<p>-John Peterson</p>

<p>CTO / Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Fri, 09 May 2008 11:44:33 +0000</pubDate>
      <category domain="http://securityratty.com/tag/security">security</category>
      <category domain="http://securityratty.com/tag/security tools">security tools</category>
      <category domain="http://securityratty.com/tag/deliver security tools">deliver security tools</category>
      <category domain="http://securityratty.com/tag/virtualization vendors">virtualization vendors</category>
      <category domain="http://securityratty.com/tag/acquire">acquire</category>
      <category domain="http://securityratty.com/tag/acquire security technology">acquire security technology</category>
      <category domain="http://securityratty.com/tag/security functionality">security functionality</category>
      <category domain="http://securityratty.com/tag/security controls">security controls</category>
      <category domain="http://securityratty.com/tag/security concerns">security concerns</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/05/virtualization.html">Virtualization Vendors Are Not In The Security Business?</source>
    </item>
    <item>
      <title><![CDATA[Netflow visibility inside Virtual Environments]]></title>
      <link>http://securityratty.com/article/9e6ab076e0d0fc2b37896b0a3105275f</link>
      <guid>http://securityratty.com/article/9e6ab076e0d0fc2b37896b0a3105275f</guid>
      <description><![CDATA[I blogged on this topic a few weeks ago but given the huge interest in this topic Ive decided to blog on it again. One of the major concerns in virtualized environments is the lack of visibility of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p class="MsoNormal">I blogged on this topic a few weeks ago but given the huge
interest in this topic I’ve decided to blog on it again. One of the major concerns in virtualized
environments is the lack of visibility of the communication between virtual
machines. With this lack of visibility a
number of challenges start to appear such as security, monitoring and capacity planning.&nbsp; It’s hard to secure what you can’t see or don’t
know about and it’s hard to determine when you need to add more resources when
you don’t have a clear picture into what applications are consuming them.</p>

<p class="MsoNormal">This problem is widely known and as a result there are a few
companies that are starting to pop up that are building Virtual Network
Visibility tools. But should you buy yet
another tool to gain visibility into your Virtual Network communication when
you may already have a tool for your physical network? Should you have to have separate tools for
your physical network and virtual network?</p>

<p class="MsoNormal">One common method of gaining visibility into network
communication is through a technology called Netflow. Netflow was originally developed by Cisco
Systems but has since become a defacto standard for Network Monitoring and
Network Behavioral Analysis. Companies
such as <a href="http://www.lancope.com">Lancope</a>, <a href="http://www.mazunetworks.com">Mazu Networks</a>, <a href="http://www.plixer.com">Plixer International</a> and Arbor Networks all
have products that enable network visibility, monitoring and analysis. These tools typicaly take Netflow feeds from a switch of some sort.&nbsp; Knowing that some of these tools may
have already been deployed in physical environments, IT staff will now need to
consider&nbsp; whether or not to buy new
visibility tools to give them visibility into their virtual environment
communication or try and leverage existing solutions already deployed in their
physical environments.</p>

<p class="MsoNormal">Up until recently there has been no elegant way to export
Netflow records from virtual environments such as VMWare and as a result
companies have had consider purchasing new visibility tools that would often
antiquate their existing physical solutions. This is due to their migration from physical environments to virtual environments. </p>

<p class="MsoNormal">Montego Networks now has Netflow capability in its
HyperSwitch product which runs inside VMWare and enables security, visibility and control for the virtual environment by leveraging existing tools. Through its API’s and standards based methods
Montego can enable customers to leverage existing infrastructure purchases to
gain visibility and control within the virtual environment. </p>

<p class="MsoNormal">So, enough of the commercial and lets get on
to the technical meat of this new Netflow enablement within the virtual
environment.</p>

<p class="MsoNormal">Let’s say that you have a virtual machine that is infected
with a BOT and it is communicating to a Command and Control Site of a BOT-Army. How would you know this? Well, you could have a NetFlow tap at a
network switch close to your internet connection. But what if you have some sort of
communication between VM’s on a non standard port that you are not aware
of? Maybe a machine got infected and is
sending data from the database virtual machine to a web server virtual machine
and then feeding that info from the web server virtual machine to the internet. Your Netflow tap on the internet facing
switch would see traffic coming from the web server virtual machine to the
internet but wouldn’t see that data was being taken from the database, put on
the web server and then fed out to the internet. Kinda tricky to hunt this problem down isn’t it?</p>

<p class="MsoNormal">So, whats needed is Netflow all the way into the virtual
environment so that it can be fed to the same tools in your physical
environment for easy correlation. </p>

<p class="MsoNormal">Take a look at the attached screen shot which shows Lancope
and Montego Networks in action.</p>

<p class="MsoNormal"><a onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/22/lancopeandmontego.jpg"><img width="200" height="125" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/22/lancopeandmontego.jpg" title="Lancopeandmontego" alt="Lancopeandmontego" style="margin: 0px 5px 5px 0px; float: left;" /></a>
&lt;---Click to Enlarge</p>

<p>With this level of visibility now you can see who is talking to who, when are they communicating and how much traffic is being consumed by which applications and which virtual machines.&nbsp; This can now all be done by leveraging existing Netflow analytics tools.</p>

<p>This screen shot is showing flow data of Virtual Machines talking either to the Internet or to other virtual machines within the same environment.&nbsp; You will notice from the flow data that one of the Virtual Machines has iTunes running on it.&nbsp; An IT Administrator may have not sanctioned this or even know about it.&nbsp; But with Flow records you can now see!&nbsp; Like a new pair of glasses for your virtual environment.&nbsp; With this visibility you can now go in to the Montego HyperSwitch and enable a firewall policy to block that iTunes traffic as an example.<br />&nbsp; </p>

<p>Lancope is just one example here and its important to note that, because Netflow is a defacto standard for this type of visibility, other tools such as those from Mazu Networks, Plixer International and others can be used as well.&nbsp; They all have their unique advantages and disadvantages but the point here is that dependent upon your prior network purchases in this area you will now be able to leverage existing tools vs. having to purchase new ones in many cases.</p>

<p>Check out Montego Networks at Networld Interop 2008 in the Lancope booth to see the solution in action!</p>

<p>John Peterson<br />CTO Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 14:07:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtual network communication">virtual network communication</category>
      <category domain="http://securityratty.com/tag/communication">communication</category>
      <category domain="http://securityratty.com/tag/virtual network">virtual network</category>
      <category domain="http://securityratty.com/tag/virtual environment communication">virtual environment communication</category>
      <category domain="http://securityratty.com/tag/netflow">netflow</category>
      <category domain="http://securityratty.com/tag/network communication">network communication</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/enable network visibility">enable network visibility</category>
      <source url="http://feeds.feedburner.com/~r/SecurityInTheVirtualWorld/~3/275637947/netflow-visibil.html">Netflow visibility inside Virtual Environments</source>
    </item>
    <item>
      <title><![CDATA[Netflow visibility inside Virtual Environments]]></title>
      <link>http://securityratty.com/article/b28249b4ffa373666ae945f1822f0cf1</link>
      <guid>http://securityratty.com/article/b28249b4ffa373666ae945f1822f0cf1</guid>
      <description><![CDATA[I blogged on this topic a few weeks ago but given the huge interest in this topic I???ve decided to blog on it again. One of the major concerns in virtualized environments is the lack of visibility of...]]></description>
      <content:encoded><![CDATA[
<div xmlns="http://www.w3.org/1999/xhtml"><p class="MsoNormal">I blogged on this topic a few weeks ago but given the huge
interest in this topic I???ve decided to blog on it again. One of the major concerns in virtualized
environments is the lack of visibility of the communication between virtual
machines. With this lack of visibility a
number of challenges start to appear such as security, monitoring and capacity planning.&nbsp; It???s hard to secure what you can???t see or don???t
know about and it???s hard to determine when you need to add more resources when
you don???t have a clear picture into what applications are consuming them.</p>

<p class="MsoNormal">This problem is widely known and as a result there are a few
companies that are starting to pop up that are building Virtual Network
Visibility tools. But should you buy yet
another tool to gain visibility into your Virtual Network communication when
you may already have a tool for your physical network? Should you have to have separate tools for
your physical network and virtual network?</p>

<p class="MsoNormal">One common method of gaining visibility into network
communication is through a technology called Netflow. Netflow was originally developed by Cisco
Systems but has since become a defacto standard for Network Monitoring and
Network Behavioral Analysis. Companies
such as <a href="http://www.lancope.com">Lancope</a>, <a href="http://www.mazunetworks.com">Mazu Networks</a>, <a href="http://www.plixer.com">Plixer International</a> and Arbor Networks all
have products that enable network visibility, monitoring and analysis. These tools typicaly take Netflow feeds from a switch of some sort.&nbsp; Knowing that some of these tools may
have already been deployed in physical environments, IT staff will now need to
consider&nbsp; whether or not to buy new
visibility tools to give them visibility into their virtual environment
communication or try and leverage existing solutions already deployed in their
physical environments.</p>

<p class="MsoNormal">Up until recently there has been no elegant way to export
Netflow records from virtual environments such as VMWare and as a result
companies have had consider purchasing new visibility tools that would often
antiquate their existing physical solutions. This is due to their migration from physical environments to virtual environments. </p>

<p class="MsoNormal">Montego Networks now has Netflow capability in its
HyperSwitch product which runs inside VMWare and enables security, visibility and control for the virtual environment by leveraging existing tools. Through its API???s and standards based methods
Montego can enable customers to leverage existing infrastructure purchases to
gain visibility and control within the virtual environment. </p>

<p class="MsoNormal">So, enough of the commercial and lets get on
to the technical meat of this new Netflow enablement within the virtual
environment.</p>

<p class="MsoNormal">Let???s say that you have a virtual machine that is infected
with a BOT and it is communicating to a Command and Control Site of a BOT-Army. How would you know this? Well, you could have a NetFlow tap at a
network switch close to your internet connection. But what if you have some sort of
communication between VM???s on a non standard port that you are not aware
of? Maybe a machine got infected and is
sending data from the database virtual machine to a web server virtual machine
and then feeding that info from the web server virtual machine to the internet. Your Netflow tap on the internet facing
switch would see traffic coming from the web server virtual machine to the
internet but wouldn???t see that data was being taken from the database, put on
the web server and then fed out to the internet. Kinda tricky to hunt this problem down isn???t it?</p>

<p class="MsoNormal">So, whats needed is Netflow all the way into the virtual
environment so that it can be fed to the same tools in your physical
environment for easy correlation. </p>

<p class="MsoNormal">Take a look at the attached screen shot which shows Lancope
and Montego Networks in action.</p>

<p class="MsoNormal"><a onclick="window.open(this.href, '_blank', 'width=800,height=500,scrollbars=no,resizable=no,toolbar=no,directories=no,location=no,menubar=no,status=no,left=0,top=0'); return false" href="http://vmwaresecurity.typepad.com/.shared/image.html?/photos/uncategorized/2008/04/22/lancopeandmontego.jpg"><img width="200" height="125" border="0" src="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/images/2008/04/22/lancopeandmontego.jpg" title="Lancopeandmontego" alt="Lancopeandmontego" style="margin: 0px 5px 5px 0px; float: left;" /></a>
&lt;---Click to Enlarge</p>

<p>With this level of visibility now you can see who is talking to who, when are they communicating and how much traffic is being consumed by which applications and which virtual machines.&nbsp; This can now all be done by leveraging existing Netflow analytics tools.</p>

<p>This screen shot is showing flow data of Virtual Machines talking either to the Internet or to other virtual machines within the same environment.&nbsp; You will notice from the flow data that one of the Virtual Machines has iTunes running on it.&nbsp; An IT Administrator may have not sanctioned this or even know about it.&nbsp; But with Flow records you can now see!&nbsp; Like a new pair of glasses for your virtual environment.&nbsp; With this visibility you can now go in to the Montego HyperSwitch and enable a firewall policy to block that iTunes traffic as an example.<br />&nbsp; </p>

<p>Lancope is just one example here and its important to note that, because Netflow is a defacto standard for this type of visibility, other tools such as those from Mazu Networks, Plixer International and others can be used as well.&nbsp; They all have their unique advantages and disadvantages but the point here is that dependent upon your prior network purchases in this area you will now be able to leverage existing tools vs. having to purchase new ones in many cases.</p>

<p>Check out Montego Networks at Networld Interop 2008 in the Lancope booth to see the solution in action!</p>

<p>John Peterson<br />CTO Montego Networks</p></div>
]]></content:encoded>
      <pubDate>Tue, 22 Apr 2008 14:07:24 +0000</pubDate>
      <category domain="http://securityratty.com/tag/virtual network communication">virtual network communication</category>
      <category domain="http://securityratty.com/tag/communication">communication</category>
      <category domain="http://securityratty.com/tag/virtual network">virtual network</category>
      <category domain="http://securityratty.com/tag/virtual environment communication">virtual environment communication</category>
      <category domain="http://securityratty.com/tag/netflow">netflow</category>
      <category domain="http://securityratty.com/tag/network communication">network communication</category>
      <category domain="http://securityratty.com/tag/visibility">visibility</category>
      <category domain="http://securityratty.com/tag/network">network</category>
      <category domain="http://securityratty.com/tag/enable network visibility">enable network visibility</category>
      <source url="http://vmwaresecurity.typepad.com/security_in_the_virtual_w/2008/04/netflow-visibil.html">Netflow visibility inside Virtual Environments</source>
    </item>
  </channel>
</rss>
