<?xml version="1.0" encoding="UTF-8"?>
<?xml-stylesheet type="text/css" href="/stylesheets/rss.css"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/">
  <channel>
    <title>ClearNet Security: When virtual servers play havoc </title>
    <link>http://blog.clearnetsec.com/articles/2008/04/14/when-virtual-servers-play-havoc</link>
    <language>en-us</language>
    <ttl>40</ttl>
    <description></description>
    <item>
      <title>When virtual servers play havoc </title>
      <description>&lt;p&gt;
I recorded a tidbit which came from a comment spoken at one of this year's RSA panel tracks.  I hadn't thought of this issue on a big scale.  It was a comment on how disruptive an environment which frequently &lt;i&gt;"resets"&lt;/i&gt; virtual servers as part of normal business is to security.
&lt;/p&gt;
&lt;p&gt;
It's obvious such an environment can have a significant impact on security tools, especially those which strive to learn patterns or look at history or both.  
&lt;/p&gt;
&lt;p&gt;
I was just imagining if I was a security admin responsible for a large block of EC2 virtual servers.  As part of that, maybe the use of these blocks of servers is similar to a class lab whereby students get to install and do anything they want on the servers.  When they're done, the instructor runs around and resets all the servers.  Extrapolate this and it can lead to a hard problem, security speaking, for general cases.  
&lt;/p&gt;
&lt;p&gt;
I haven't meditated on this issue, but I'm guessing it'll become more visible in short time.  
&lt;/p&gt;

</description>
      <pubDate>Mon, 14 Apr 2008 15:19:00 -0600</pubDate>
      <guid isPermaLink="false">urn:uuid:df455eaa-c476-4bdc-a7da-17e8764b7ce9</guid>
      <author>tate@ClearNetSec.com (Tate Hansen)</author>
      <link>http://blog.clearnetsec.com/articles/2008/04/14/when-virtual-servers-play-havoc</link>
      <category>security</category>
      <category>ClearNet</category>
      <category>ClearNet Security</category>
      <category>Tate Hansen</category>
      <category>virtual servers</category>
      <category>virtualization</category>
    </item>
  </channel>
</rss>
