Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.


IBM's 'Phantom' to Study Virtual Security

Research project will help identify, fix vulnerabilities in virtualized environments

SAN FRANCISCO -- RSA Conference 2008 -- IBM has begun a new research project designed to find and fix security vulnerabilities in virtual computing environments.

The project, a joint initiative between IBM's X-Force security research team and IBM Research, is code named Phantom. It will help identify potential vulnerabilities in virtualized environments and use network and host intrusion prevention technology to guard them.

"There's a lot of momentum behind virtualization out there, but not everyone has thought through the security implications," says Joe Anthony of IBM's Tivoli unit. "Phantom is taking a deeper look at those."

Under Phantom, IBM will develop technology to monitor and disrupt malicious communications between virtual machines. Phantom will also seek out ways to monitor the security state of virtual machines to protect them against known and unknown threats before they occur. "We'll analyze behavioral patterns, not just signatures," Anthony says.

IBM is also looking for ways to secure the hypervisor, which is a central point of control for all machines running on a virtualized platform. "We'll be looking not only at our own platform, but at different hypervisors from different vendors," Anthony says.

Anthony could not say how long the research would take or when IBM might be able to deliver a product from the Phantom research. He did say that the company will likely offer both a stand-alone product and a security service.

— Tim Wilson, Site Editor, Dark Reading

  • IBM Tivoli

    Tim Wilson is Editor in Chief and co-founder of Dark Reading.com, UBM Tech's online community for information security professionals. He is responsible for managing the site, assigning and editing content, and writing breaking news stories. Wilson has been recognized as one ... View Full Bio

    Comment  | 
    Print  | 
    More Insights
  • Comments
    Oldest First  |  Newest First  |  Threaded View
    Cyberattacks Are Tailored to Employees ... Why Isn't Security Training?
    Tim Sadler, CEO and co-founder of Tessian,  6/17/2021
    7 Powerful Cybersecurity Skills the Energy Sector Needs Most
    Pam Baker, Contributing Writer,  6/22/2021
    Microsoft Disrupts Large-Scale BEC Campaign Across Web Services
    Kelly Sheridan, Staff Editor, Dark Reading,  6/15/2021
    Register for Dark Reading Newsletters
    White Papers
    Current Issue
    The State of Cybersecurity Incident Response
    In this report learn how enterprises are building their incident response teams and processes, how they research potential compromises, how they respond to new breaches, and what tools and processes they use to remediate problems and improve their cyber defenses for the future.
    Flash Poll
    How Enterprises are Developing Secure Applications
    How Enterprises are Developing Secure Applications
    Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
    Twitter Feed
    Dark Reading - Bug Report
    Bug Report
    Enterprise Vulnerabilities
    From DHS/US-CERT's National Vulnerability Database
    PUBLISHED: 2021-06-22
    Huawei LTE USB Dongle products have an improper permission assignment vulnerability. An attacker can locally access and log in to a PC to induce a user to install a specially crafted application. After successfully exploiting this vulnerability, the attacker can perform unauthenticated operations. A...
    PUBLISHED: 2021-06-22
    There is an out-of-bounds read vulnerability in eCNS280_TD V100R005C10 and eSE620X vESS V100R001C10SPC200, V100R001C20SPC200, V200R001C00SPC300. The vulnerability is due to a message-handling function that contains an out-of-bounds read vulnerability. An attacker can exploit this vulnerability by se...
    PUBLISHED: 2021-06-22
    There is an information leak vulnerability in Huawei products. A module does not deal with specific input sufficiently. High privilege attackers can exploit this vulnerability by performing some operations. This can lead to information leak. Affected product versions include: IPS Module versions V50...
    PUBLISHED: 2021-06-22
    There is a resource management error vulnerability in eCNS280_TD V100R005C10SPC650. An attacker needs to perform specific operations to exploit the vulnerability on the affected device. Due to improper resource management of the function, the vulnerability can be exploited to cause service abnormal ...
    PUBLISHED: 2021-06-22
    There is a command injection vulnerability in S12700 V200R019C00SPC500, S2700 V200R019C00SPC500, S5700 V200R019C00SPC500, S6700 V200R019C00SPC500 and S7700 V200R019C00SPC500. A module does not verify specific input sufficiently. Attackers can exploit this vulnerability by sending malicious parameter...