13.07.2015 Views

Download - Cloud Security Alliance

Download - Cloud Security Alliance

Download - Cloud Security Alliance

SHOW MORE
SHOW LESS
  • No tags were found...

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

CLOUD SECURITY ALLIANCE SecaaS Implementation Guidance, Category 6: Intrusion ManagementFigure 4: Hypervisor IntegrationThis type of integration allows inspection/blocking of guest events, offline VMs and “on-demand” and “onaccess”scanning of virtual disksAdvantages:Easy deploymentInterception of VM-to-VM communicationInterception of guest operationsAllows inspection of offline VMsUsage of additional configuration and status informationDisadvantages:A software instance cannot use hardware support (ASICs) like today’s dedicated IPS appliancesHigh load on the IPS modules will impact virtual machines or the host performanceIf the hypervisor is compromised, the IPS cannot be trusted4.1.4.2 Protecting the Virtualization LayerThe next level of protection is maintaining integrity of the hypervisor itself which is actually the foundation of alltrust in the previously described technologies.© Copyright 2012, <strong>Cloud</strong> <strong>Security</strong> <strong>Alliance</strong>. All rights reserved. 26

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!