NSA on the hidden dangers of virtualization

news
Mar 13, 20081 min

The U.S. NSA realized that alongside the benefits, security and otherwise, virtualization introduces potential threats and hidden dangers.

For instance, “graphics cards and network cards today are really miniature computers that see everything in all the VMs,” Don Simard, the agency’s commercial solutions director.

As such they could be used as spies across all the VMs, letting a single PC spy on multiple networks, executive editor Galen Gruman writes in Virtualization’s secret security threats. “Although [Simard is] not aware of any such spyware today, it’s not a problem the NSA wants to experience or see happen in other intelligence agencies.”

The NSA now sees virtualization working to protect systems in a new layering approach, “so even if an OS has security flaws, a separate layer that the OS can’t compromise handles security threats such as viruses and worms or implements firewalls.”