April 9, 2014 By Vikash Abraham 2 min read

Optimum Cloud Security: Traffic Flowing between vSwitches Requires Monitoring

The cloud has been a major talking point for a couple of years now, and cloud security has become interesting material for gossip. We don’t need to dwell on the advantages of a cloud because we are all adept at the topic; however, the security aspect still remains something of a mystery.

It is often effective to deploy traditional security philosophies to new environments, and one of the “good” words we want more of in security is “visibility.” Whether by utilizing satellites to review national borders or installing video cameras in ATM kiosks, the idea is to have an “eye” watching over it all — with intelligence — to identify threats and mitigate them in time. A hacker focuses on finding the blind spots of the eye or disabling the eye itself.

The Blind Spot

Virtualization is one of the main components of the cloud. A virtual environment provides flexibility, allows optimization of the workloads running in the cloud and provides an essential benefit by detaching this workload from the underlying hardware. Virtualization can also be viewed as having invisible, miniature data centers that include virtual switches (vSwitches) and traffic that flows between these vSwitches. Being invisible to the physical eye, virtualization is a frequently ignored area within the cloud. Physical networks are monitored and have network protection solutions inspecting traffic; however, the traffic between vSwitches goes invisible, making it a sweet spot for hackers.

Why Is It a Risk?

In cloud environments, workloads and virtual machines (VMs) are working continuously to achieve optimal utilization or performance. This also means that infected workloads or VMs could be circulating. Therefore, logical network segmentation and security setting become imperative for cloud security. If one infected VM is communicating with another VM over the virtual layer, physical network protection solutions are not monitoring these communications and are consequently unable to disrupt the threats embedded within them. With the advanced persistent threat approach, attackers watch and wait for such opportunities.

How Do You Address It?

The answer is straightforward: Deploy that much-required visibility to monitor inter-vSwitch traffic as you would with other network traffic. There are different approaches to achieve this, one being to route inter-VM traffic through the physical network protection appliance already available on your network. This could be a tedious process, however, and could lead to a few performance concerns. A much more effective way of managing this would be to use a virtual appliance that sits on the virtual layer and is able to monitor and prevent threats within inter-vSwitch traffic and to provide logical network segmentation security settings.

More from Cloud Security

2024 Cloud Threat Landscape Report: How does cloud security fail?

4 min read - Organizations often set up security rules to help reduce cybersecurity vulnerabilities and risks. The 2024 Cost of a Data Breach Report discovered that 40% of all data breaches involved data distributed across multiple environments, meaning that these best-laid plans often fail in the cloud environment.Not surprisingly, many organizations find keeping a robust security posture in the cloud to be exceptionally challenging, especially with the need to enforce security policies consistently across dynamic and expansive cloud infrastructures. The recently released X-Force…

Cloud threat report: Why have SaaS platforms on dark web marketplaces decreased?

3 min read - IBM’s X-Force team recently released the latest edition of the Cloud Threat Landscape Report for 2024, providing a comprehensive outlook on the rise of cloud infrastructure adoption and its associated risks.One of the key takeaways of this year’s report was focused on the gradual decrease in Software-as-a-Service (SaaS) platforms being mentioned across dark web marketplaces. While this trend potentially points to more cloud platforms increasing their defensive posture and limiting the number of exploits or compromised credentials that are surfacing,…

Cloud Threat Landscape Report: AI-generated attacks low for the cloud

2 min read - For the last couple of years, a lot of attention has been placed on the evolutionary state of artificial intelligence (AI) technology and its impact on cybersecurity. In many industries, the risks associated with AI-generated attacks are still present and concerning, especially with the global average of data breach costs increasing by 10% from last year.However, according to the most recent Cloud Threat Landscape Report released by IBM’s X-Force team, the near-term threat of an AI-generated attack targeting cloud computing…

Topic updates

Get email updates and stay ahead of the latest threats to the security landscape, thought leadership and research.
Subscribe today