Risk
3/26/2008
08:56 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Startup Flips On Its Virtual Switch

A growing number of security startups aim to bring visibility to the network traffic of virtual systems. Today, Montego Networks officially came out of stealth mode.

A growing number of security startups aim to bring visibility to the network traffic of virtual systems. Today, Montego Networks officially came out of stealth mode.There are definitely a number of security challenges associated with virtualization, including the predisposition of virtual machines to spawn like summertime dandelions. Not to mention the potential loss of visibility of network traffic traveling from VM to VM.

Montego says its new HyperSwitch integrates network policy enforcement and access control into this virtual switch.

The vendor boasts a number of capabilities in its release, from policy-based virtual network partitioning (this can be a big deal in regulated environments) to policy-based switching and load balancing.

Next month the vendor says it'll start offering a new Starter Edition of the HyperSwitch and will price its Enterprise Edition at $495. It supports VMware environments now, but will also support Citrix, Virtual Iron, and Microsoft (when it ships).

What's interesting about this announcement (other than that we seem to be virtualizing everything nowadays, from servers to storage to data) is that Montego's HyperSwitch can switch traffic, again based on policy, to other third-party virtual security vendors. Montego mentioned Blue Lane, Catbird, and StillSecure in its release.

If this app lives up to Montego's claims, it's another step toward solving one of virtualization's biggest security bugaboos: lack of VM-to-VM visibility.

If anyone has had a chance to kick around the beta version of this switch, I'd be interested in hearing about your experience.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-7876
Published: 2015-03-31
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27 and 4 before 2.03 and iLO Chassis Management (CM) firmware before 1.30 allows remote attackers to gain privileges, execute arbitrary code, or cause a denial of service via unknown vectors.

CVE-2015-0900
Published: 2015-03-31
Cross-site scripting (XSS) vulnerability in schedule.cgi in Nishishi Factory Fumy Teacher's Schedule Board 1.10 through 2.21 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2015-0901
Published: 2015-03-31
Cross-site scripting (XSS) vulnerability in the duwasai flashy theme 1.3 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

CVE-2015-2106
Published: 2015-03-31
Unspecified vulnerability in HP Integrated Lights-Out (iLO) firmware 2 before 2.27, 3 before 1.82, and 4 before 2.10 allows remote attackers to bypass intended access restrictions or cause a denial of service via unknown vectors.

CVE-2015-2108
Published: 2015-03-31
Unspecified vulnerability in Powershell Operations in HP Operations Orchestration 9.x and 10.x allows remote authenticated users to obtain sensitive information via unknown vectors.

Dark Reading Radio
Archived Dark Reading Radio
Good hackers--aka security researchers--are worried about the possible legal and professional ramifications of President Obama's new proposed crackdown on cyber criminals.