BeyondTrust

Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Insider Threats Exist in Virtualized Environments Too!

Posted September 13, 2011    Peter McCalister

Disgruntled Dave is at it again! What happens when a disgruntled IT administrator deletes the contents of 15 virtual hosts (roughly equivalent to 88 different computer servers)? According to a recent eWeek article highlighting the incident – quite a bit! For the Japanese pharmaceutical company, the attack was so damaging that it froze operations for “a number of days, leaving employees unable to ship products, to cut checks or even communicate via email,” according to court documents. Estimated damages cost the company $800,000. For the disgruntled employee, he’s looking at the possibility of serving 10 years in prison when he is sentenced in November.

While this incident highlights the perils of disgruntled employees it also clearly illustrates the vulnerabilities around virtualization and cloud computing infrastructures. The prolific use of virtualization and cloud models characterized by multi-hybrid architectures are providing organizations with notable cost benefits, but are also introducing added complexity when it comes to privileged access. According to Neil MacDonald, vice president and Gartner fellow, “Most virtualized workloads are being deployed insecurely, introducing significant organizational risk. Installation of x86 virtualization platforms should be treated as one of the most critical software layers in data centers, but tools and processes are relatively immature and staff, resellers and consultants are still learning. Because of the critical support the hypervisor/VMM layer provides, administrative access to this layer must be tightly controlled.”

In many cases measures are already in place to protect companies from abuse of root-level access on physical servers, but awareness and understanding of how that translates onto their virtual counterparts is low. The answer to this vulnerability is a privilege identity management solution like PowerBroker Virtualization.

Leave a Reply

Additional articles

expert-russellsmith

Best Practices for Managing Domain Admin Accounts

Posted August 3, 2015    Russell Smith

The risks of using privileged domain accounts on devices that are not secured to the same level as DCs increases the chances that domain administrator credentials could be exposed. Windows caches credentials by default to authenticate users when a domain controller can’t be reached, including those of domain administrator accounts that have previously logged in to a device. As such, a compromised workstation or member server can also lead to stolen domain administrator credentials.

Tags:
, ,
powerbroker-for-mac-diagram-small

PowerBroker for Mac: A Least-Privileged Apple a Day…

Posted July 27, 2015    Jason Silva

BeyondTrust PowerBroker for Mac reduces the risk of privilege misuse by enabling standard users on Mac OS X to perform administrative tasks successfully without entering elevated credentials.

Tags:
, ,
PrivilegedAccountManagement

On Demand Webinar – Now is the time for Privileged Account Management

Posted July 24, 2015    BeyondTrust Software

In this webinar, SANS Instructor and Founder of Voodoo Security, Dave Shackleford, will revisit several hacking and breach scenarios that involved privileged accounts, and use these as examples while discussing tools and tactics to get this problem under control once and for all.

Tags:
, ,