Security holes are everywhere even in secure virtualization systems, says Green Hills Software CEO

By Joseph Normandin

Posted by John McHale
If the Wikileaks scandal shows anything it proves that no system is secure as people may think it is -- especially software virtualization systems, said Dan O'Dowd, chief executive officer of Green Hills Software during the company’s Software Elite Users Technology Summit. "Virtualization adds nothing to security," he added.

O'Dowd pointed out that virtualization systems have less code, "but that just means they are less bad, not more secure. Running bug-ridden operating systems in virtual machines does not solve the security issue unless the virtualization system itself is secure."

He then made a point that I think resonates well beyond virtualization systems. "The security claims of popular virtualization systems are just marketing fluff to exploit the desperate need of all computer users for security," O'Dowd says. These systems have only been evaluated to the National Security Agency's (NSA's) Common Criteria EAL4+.

According to the Common criteria EAL4+ "makes them appropriate for protecting against 'inadvertent or casual attempts to breach system security,'" O’Dowd said. It's as if they have five doors to their house but only locked four, he added.

O'Dowd was working up to making the case for his company's EAL6+ secure virtualization software, but, I think he's also right on that this is not just a virtualization security phenomenon.

People are lazy when it comes to securing their computers. They all want their systems to be secure, but typically buy into the marketing fluff of certain technology because they like the convenience it provides. However, in the long run they are setting themselves up for security breaches.

It reminded me of something an export compliance officer at a major aerospace company once told me that he tells his employees who travel overseas. He says they need to assume that their emails are being read and their phone conversations are being listened to. It doesn't make you paranoid, it makes you vigilant, he said.

Speaking of vigilance, let's get back to the secure virtualization discussion.

During their work in this area O'Dowd's engineers found security vulnerabilities in standard device drivers in virtual machines. He said they attempted to use I/O memory management units (MMUs) to improve the security of virtual machines, but found that "it doesn't work.

"We weren't looking for vulnerabilities, we were just trying to make the device drivers work," O'Dowd said. "Modern I/O devices often contain huge software control programs consisting of hundreds of thousands lines of code and they have just as many security vulnerabilities as traditional operating systems."

He made the case that if users want to be vigilant with their virtualization systems they need to use an EAL6+ secure system like that offered by Green Hills. Makes sense but with that vigilance also comes cost.

Systems like Green Hills do not come cheap, so it becomes a matter of managing risk. Military and avionics systems cannot take that chance, but companies in less mission/life critical applications may be able to get away with it.

What's more expensive paying for the security ahead of time or not paying and hoping nothing happens? I guess it depends on whether or not you think you, your company, or your technology is actually a target.

Previous Blog Posts

The haunting bugle call Taps is 150 years old this summer

The Navy's solid-state laser weapon

High-performance embedded computing (HPEC) gaining market traction, but its definition remains elusive

Did I say $114 million mistake? I meant $351 million.

Continuing the conversation

Lockheed Martin experimental stealth surface vessel to be scrapped after yielding valuable technology

Air Force competes in National Collegiate Cyber Defense competition

Will Intel 3rd Generation Intel Core processor make a big splash in embedded computing applications?

The $114 million mistake

Iran under attack once again

High-performance computing for rugged mobile military applications is becoming a hot design issue

Is the U.S. getting ready for conflict?

Historic obsession about the Titanic sinking 100 years ago wipes Bread and Roses strike from popular memory

The future of UAV technology aims high

Conference combo

We can thank a self-absorbed Congress for hurting national defense if deep automatic defense cuts happen

Securing the military network

FAA's impending rule on small UAVs may usher in a new era of civil aerial warfare

Boeing and Airbus both claim victory in WTO Appeal? That can't be right...

The defense industry may be adjusting to a new age of financial austerity

What's up with all the anti-tamper technology?

Effects of 2013 DOD budget cuts already being felt with program cancellations

Top ten technologies the U.S. Army's Rapid Equipping Force is looking for

The Aerospace & Defense Bloggers

Ernesto Burden is the publisher of PennWell’s Aerospace & Defense Media Group, including Military & Aerospace Electronics, Avionics Intelligence and Avionics Europe.  He’s a father of four, a runner, and an avid digital media enthusiast with a deep background in the intersection of media publishing, digital technology, and social media. He can be reached at ernestob@pennwell.com and on Twitter @aero_ernesto.

John Keller is editor-in-chief of Military & Aerospace Electronics magazine, which provides extensive coverage and analysis of enabling electronic and optoelectronic technologies in military, space, and commercial aviation applications. A member of the Military & Aerospace Electronics staff since the magazine's founding in 1989, Mr. Keller took over as chief editor in 1995.

Skyler Frink is an Assistant Editor of Military & Aerospace Electronics and Avionics Intelligence. Skyler graduated Cum Laude from the University of New Hampshire with a BA in Journalism and a Minor in Information Technology in 2011. He has contributed to many different publications both online and in print throughout his career as a Journalist. Skyler can be reached skylerf@pennwell.com.

Courtney E. Howard, as executive editor, enjoys writing about all things electronics and avionics in PennWell’s burgeoning Aerospace and Defense Group, which encompasses Military & Aerospace Electronics, Avionics Intelligence, the Avionics Europe conference, and much more. She’s also a self-proclaimed social-media maven, mil-aero nerd, and avid avionics geek. Connect with Courtney at Courtney@Pennwell.com, @coho on Twitter, and on LinkedIn.

Mil & Aero Magazine

May 2012
Volume 23, Issue 5