SHARE
Facebook X Pinterest WhatsApp

Are Virtual Servers Less Secure Than Physical Servers?

The rush to virtualization has yielded a major vulnerability. According to a study just released by Gartner, the majority of servers being virtualized are less secure than they were when they were separate, physical servers. Virtualization has been used as part of a consolidation strategy to put a multitude of underutilized servers on one physical […]

Mar 19, 2010
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

The rush to virtualization has yielded a major vulnerability. According to a study just released by Gartner, the majority of servers being virtualized are less secure than they were when they were separate, physical servers.

Virtualization has been used as part of a consolidation strategy to put a multitude of underutilized servers on one physical hardware unit. One modern server with lots of memory can house dozens or hundreds of virtual servers, thus saving floor space and electricity for power and cooling.

But as companies make the move, issues often crop up that weren’t anticipated. In its new report, Gartner found 60 percent of virtualized servers deployed between now and 2012 will be less secure than the physical ones they’ve replaced, thanks to bad practices by IT departments or a lack of proper tools to do the job.

“Most virtualized workloads are being deployed insecurely. The latter is a result of the immaturity of tools and processes and the limited training of staff, resellers and consultants,” said Neil MacDonald, vice president and Gartner fellow, in a statement.

Gartner based its findings on surveys taken at Gartner conferences in late 2009, some of which include shocking admissions by IT professionals. For example, about 40 percent of virtualization deployment projects did not involve the information security team in the initial architecture and planning stages.

Survey respondents said their operations teams argued that nothing really changed because it’s all the same hardware, workloads, and software. But Gartner noted that there is a hypervisor and virtual machine monitor (VMM) that is introduced when workloads are virtualized and it changes the basic operation of the server.

Gartner said the hypervisor is rather vulnerable to attack, and seems to hint that cybercriminals are already targeting the hypervisor, since it enjoys a privileged level of access to the system. The research firm advised IT that the hypervisor layer should be treated as the most critical part of the server platform even though many today pay it no mind at all.

It’s still early in the game as far as a broad virtualization. Gartner estimates that at the end of 2009, only 18 percent of enterprise datacenter workloads that could be virtualized had been virtualized. That will grow to 50 percent by 2012, and by 2015, Gartner thinks the percentage of unsecured servers will fall to 30 percent, which is still a large figure.

The company said that security needs to be brought in to the discussion of virtualization of workloads from the beginning. Gartner also recommends that at a minimum, organizations require the same type of monitoring for virtualized systems as physical systems. Administrative access to the hypervisor layer must be tightly controlled, given how important the hypervisor is.

The report, “Addressing the Most Common Security Risks in Data Center Virtualization Projects,” is available on the Gartner Web site for $95.

Andy Patrizio is a senior editor at InternetNews.com, the news service of Internet.com, the network for technology professionals.

AP

Andy Patrizio has nearly two decades experience as a technology journalist, covering everything from semiconductors to the business side of the industry, specializing in systems and datacenters, cloud computing and virtualization, HPC, and software development.

Recommended for you...

Wireless Network Security: WEP, WPA, WPA2 & WPA3 Explained
Maine Basan
Sep 15, 2025
From LinkedIn to Lies: What a Job Scam Looks Like Now
Aminu Abdullahi
May 21, 2025
Fake AI Video Tools Spreading New “Noodlophile” Malware, Targets Thousands on Facebook
Aminu Abdullahi
May 12, 2025
RSA Conference 2025: Top Announcements and Key Takeaways from the Cybersecurity World’s Biggest Stage
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.