VirtSec

Workshop: VirtSec - Compliance to (audit) secure operatiing in virtualized environments

Target audience: Security Officers and Auditors

Duration: 2 days (1 day course & 1 day workshop)

VirtSec

After introducing the basic elements of virtualization architecture, the most important attacks, their threats and vulnerabilities will be presented. We will also explain design questions, security-relevant processes and typical policy elements.
Afterwards specific problems of VMware ESX will be examined. Hardening directives, (Audit) checklists, configuration aspects of the vSwitch and the management access iwill be focused on. Finally (commercial) add-on tools will be presented, their use discussed.

Content:
Day 1 (course)- Basic concepts and Terminology
- Typical elements and essential solutions
- Attacks overview (guest-> guest, guest-> Host, attacks on Mgmt)
- Backdoor / VMEscape
- Attacks tools, fuzzing
- The "Rogue VMs" problem
- Realization of an exemplary risk assessment
- Typical policy elements when using
- Security processes (patching, change management etc.)


Day 2 (Workshop) VMware ESX

Hardening steps & (audits) listen, security aspects of the vSwitch and the management interfaces, commercial add-on tools: classification, presentation, Demo/exercise (Blue Lane, Montego, RSA Reflex]
Technology forecast (Flash based Hypervisor, vSafe-Initiative)

Dates
22. - 23.07.2010
02. - 03.09.2010
25. - 26.10.2010
06. - 07.12.2010


TROOPERS11 takes place from 14-18. March 2011 at Heidelberg. Mark your calendars now and sign up for the official TROOPERS newsletter to stay up-to-date. [More]
Testing IT security is one of the core competences of ERNW. Many of our customers get their IT infrastructure and (Web) applications checked on a regular basis. This may either be done on a very technical level in terms of penetration testing or in a more formal way in terms of general security audits, during which we verify the IT Security Compliance of your company compared to best practices according to ISO17799/ISO27001 ... [More]
Research is the foundation of our Know-How leadership. The objections of this work is to unveil security flaws and vulnerabilities in protocols, technologies and products. Some findings derive from design-flaws, some from poor implementation on a technical level.... [More]