Home > Virtual Desktop Tips > Virtual desktop management tips > Top tools for securing a virtual desktop infrastructure
Virtual Desktop Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

VIRTUAL DESKTOP MANAGEMENT TIPS

Top tools for securing a virtual desktop infrastructure


Eric Schultze, Contributor
10.28.2009
Rating: --- (out of 5)


Enterprise IT tips and expert advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Most of the virtual desktop infrastructure technologies available are rooted in security products built for traditional desktops -- albeit with a few twists.

Here's a look at tools for patch management, application control, and antivirus and firewall protection in virtualized environments.

Patch management
VMware offers Update Manager to help administrators assess patches and deploy them to virtual guest images. While this product can be used to patch the master virtual desktop infrastructure (VDI) image, it can also be used to scan and patch offline images, or those that aren't currently turned on. This may be a valuable tool for administrators that have a lot of master images -- not all of which may be currently turned on.

Microsoft says its Offline Virtual Machine Servicing Tool can be used to patch offline images. Instead of scanning and patching offline images, as the name suggests, it moves the images to a private network, boots them up and lets them do their Windows Server Update Services patch process. The tool then shuts them down, saves them and moves them back to the production library.

Shavlik Technologies sells a product for VMware images that doesn't require Update Manager. Shavlik NetChk Protect includes the ability to scan ESX and VI Servers and assess and deploy patches to images found on those servers, whether online or offline at the time of the scan.

Application Control
TriCerat offers an application control system that can help you lock down the VDI desktop, including the applications that are allowed to execute. Its software is available for Microsoft, VMware and Citrix VDI implementations...


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



RELATED CONTENT
Virtual desktop management
Citrix CEO: Transition to on-demand services won't be pretty
What's new with virtual desktop infrastructure?
How to protect virtual desktops on a corporate network
Symantec and Quest's desktop virtualization suites hit the big leagues
Moving from Presentation Server 4.5 to XenApp 5.0 Feature Pack 2
The top 5 ways that VDI can help improve your enterprise's security
Will Windows 7 fuel desktop virtualization adoption?
Rejoice! Citrix modifies its XenDesktop license plans
Manage Remote Desktop Services with Windows PowerShell
How to back up PCs in a virtual desktop infrastructure

Tools and Technologies
Installing VMware View components
How to configure Wyse terminals without console interaction
Dazzle brightens Citrix flexibility story
VMware vs. Citrix virtual desktops -- what's the better deal?
VMware View 4: An improvement to View 3, but still a ways to go
VMware revs up performance on virtual desktops
Symantec and Quest's desktop virtualization suites hit the big leagues
Moving from Presentation Server 4.5 to XenApp 5.0 Feature Pack 2
Rejoice! Citrix modifies its XenDesktop license plans
Manage Remote Desktop Services with Windows PowerShell

Virtual desktop management tips
How to configure Wyse terminals without console interaction
How to protect virtual desktops on a corporate network
Moving from Presentation Server 4.5 to XenApp 5.0 Feature Pack 2
The top 5 ways that VDI can help improve your enterprise's security
Capacity planning for Windows Terminal Services
Taking a fresh look at Terminal Services security
Manage Remote Desktop Services with Windows PowerShell
How to back up PCs in a virtual desktop infrastructure
The first step toward a virtual desktop infrastructure: The assessment
How to set up Remote Desktop Services on Windows 2008 R2

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Remote Desktop Protocol (RDP)  (SearchEnterpriseDesktop.com)
saved state  (SearchEnterpriseDesktop.com)
virtual machine snapshot  (SearchEnterpriseDesktop.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


.

Antivirus and firewall
Many security vendors have announced support for VMware's VMsafe program. The VMsafe application programming interfaces enable security vendors to build products that live on one Windows virtual machine (VM) and monitor CPU, disk, network and memory on other VM images on the same server. This provides centralized antivirus and firewall support for VDI images without requiring any agent on the guest image. Administrators who still want protection on the desktop should consider a free lightweight cloud-based antivirus service like Immunet Protect().

Catbird is a VMsafe vendor that has focused on security products for the virtual world. Catbird's virtual appliance provides intrusion detection and prevention; firewall services; and policy, compliance and vulnerability scanning. This is comprehensive set of security services for VDI implementations that don't require security software to be installed or managed on each user's desktop.

Lastly, don't forget to secure your hypervisor servers themselves. For VMware implementations, check out the free host security assessment solutions from Tripwire and EMC. These tools perform assessments and provide remediation suggestions as per VMware's recommended best practices for ESX Server security configuration. For Microsoft Hyper-V, review the Hyper-V Security Guide Solution Accelerator. By securing the hypervisor, you can ensure that your VDI images remain intact.

ABOUT THE AUTHOR:   

[IMAGE]Eric Schultze
Eric Schultze is an independent security consultant who most recently designed Microsoft patch management solutions at Shavlik Technologies. Prior to Shavlik, Schultze worked at Microsoft, where he helped manage the security bulletin and patch-release process. Schultze likes to forget that he used to work as an internal auditor on Wall Street.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseDesktop.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Enterprise Desktop Security - Virus Protection, Malware Protection, Intrusion Detection
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts