Risk
3/26/2008
08:56 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Startup Flips On Its Virtual Switch

A growing number of security startups aim to bring visibility to the network traffic of virtual systems. Today, Montego Networks officially came out of stealth mode.

A growing number of security startups aim to bring visibility to the network traffic of virtual systems. Today, Montego Networks officially came out of stealth mode.There are definitely a number of security challenges associated with virtualization, including the predisposition of virtual machines to spawn like summertime dandelions. Not to mention the potential loss of visibility of network traffic traveling from VM to VM.

Montego says its new HyperSwitch integrates network policy enforcement and access control into this virtual switch.

The vendor boasts a number of capabilities in its release, from policy-based virtual network partitioning (this can be a big deal in regulated environments) to policy-based switching and load balancing.

Next month the vendor says it'll start offering a new Starter Edition of the HyperSwitch and will price its Enterprise Edition at $495. It supports VMware environments now, but will also support Citrix, Virtual Iron, and Microsoft (when it ships).

What's interesting about this announcement (other than that we seem to be virtualizing everything nowadays, from servers to storage to data) is that Montego's HyperSwitch can switch traffic, again based on policy, to other third-party virtual security vendors. Montego mentioned Blue Lane, Catbird, and StillSecure in its release.

If this app lives up to Montego's claims, it's another step toward solving one of virtualization's biggest security bugaboos: lack of VM-to-VM visibility.

If anyone has had a chance to kick around the beta version of this switch, I'd be interested in hearing about your experience.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0235
Published: 2015-01-28
Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST."

CVE-2015-1375
Published: 2015-01-28
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.

CVE-2015-1376
Published: 2015-01-28
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host other than pixabay.com.

CVE-2015-1419
Published: 2015-01-28
Unspecified vulnerability in vsftp 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

CVE-2014-5211
Published: 2015-01-27
Stack-based buffer overflow in the Attachmate Reflection FTP Client before 14.1.433 allows remote FTP servers to execute arbitrary code via a large PWD response.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If youíre a security professional, youíve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.