VMware虚拟化技术详解.ppt

  1. 1、本文档共82页,可阅读全部内容。
  2. 2、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。
  3. 3、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载
  4. 4、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
VMware虚拟化技术详解

* 虚拟化 VMSafe announced earlier in 2008, is a set of APIs that enable protection of VMs by a protection engine that : Works with the hypervisor to inspect a VM’s mem, cpu and storage from a higher privilege point Is isolated from the malware Covers all aspects of security – not limited to network or host. 虚拟化 VMSafe based products from our security partner ecosystem will work with 虚拟化 vSphere? editions to provide higher levels of security than even physical systems. A number of partners have demo-ed prototypes of products that use VMSAfe to protect their environments. MORE DETAIL Security solutions have an inherent problem. Protection engines are running in the same context as the malware they are protecting against and as a result, malware is able to subvert these engines by simply using the same hooks into the system as the protection engine. Worse, with Longhorn and Vista, Microsoft has enabled Patchguard, effectively eliminating the kernel hooks available to both the security solutions and the malware. While this helps, it doesn’t change the fact that malware and rootkits still exist and can run in those environments. The context that these security solutions need to protect against is also not limited to one set of interactions (e.g. attacks from the network and from spyware and from rootkits). Even those solutions that are in a safe context (outside the OS), they can’t see information from other contexts (e.g. network protection has no host visibility). Security API’s built into the hypervisor allow for 2 key advantages: Better Context – Provide protection from outside the OS, from a trusted context New Capabilities – now they can view all interactions and contexts Now, new security solutions can be developed and integrated within the 虚拟化 virtual infrastructure and we can protect the VM by inspection of virtual components (CPU, Memory, Network and Storage). Provides complete integration with VMotion, Storage VMotion, HA, etc. for any new security solution

文档评论(0)

shuwkb + 关注
实名认证
内容提供者

该用户很懒,什么也没介绍

1亿VIP精品文档

相关文档