80 likes | 192 Views
This white paper by Rapid7, published in August 2012, underscores the critical need for real-time vulnerability management and risk assessment within virtualized environments. Highlighting the unique challenges posed by virtualization, it advocates for automated solutions capable of discovering and scanning virtual machines as they are created or migrated. With insights from Forester Research, the paper explores the dynamic nature of security risks in virtualization and emphasizes the integration of Rapid7's Nexpose and Metasploit for comprehensive vulnerability management.
E N D
The Dynamic Nature of Virtualization Security The need for real-time vulnerability management and risk assessment A white paper by Rapid7 August 2012
Contents • Forester Research Inc. • Vulnerability Management of Virtualization Security • Challenges • Solutions • Risk Intelligence • Conclusion
Forester Research INC, Jan 2012 • Virtualization New Norm • Deploying Physical Server Exception • 85% Organizations x86 Server Virtualization • 2014 • 75% All Servers Virtualized
Vulnerability Management Solution • Deployable as a virtual machine (VM) • Discover and scan VM’s as they spin up and down for vulnerabilities and misconfigurations • Detect snapshot rollbacks and scan after restores • Track asset migrations and proactively monitor their security postures
Challenges: • ON or OFF? • Snapshot Rollbacks • Virtual Machine Migration
Solutions: • Automated Discovery and Scanning • configure VMS to automatically scan critical resources when activated & send report • Rollback Detection and Automated Scanning • Automated Scanning to track migrations • Do you see a theme?
Rapid7 Security Risk Intelligence • Rapid7 Security Risk Intelligence is a data-driven approach to risk assessment and vulnerability management that weighs the value of data sets when measuring risk. Rapid7 offers a powerful combination of innovative vulnerability management and penetration testing solutions along with deep security expertise to identify and prioritize the dynamic security risks of virtualized environments. • Rapid7 Nexpose is the industry’s first vulnerability management solution with capabilities, such as Continuous Discovery, designed specifically for virtualized environments. Working closely with VMware, Rapid7 continues to add virtualization-specific capabilities into Nexpose, its vulnerability management and risk-assessment solution. Nexpose is the only third party vulnerability management solution included in the VMware security reference architecture. • Additionally, Rapid7 Metasploit can be used in conjunction with Nexpose to validate risk in IT environments based on actual exploitability of vulnerabilities, both in physical and in virtual environments.
Conclusion • Be wary of white papers, after all they are ONLY the opinions of the author. • Be more selective in my search for white papers.