All Access


Security holes are everywhere even in secure virtualization systems, says Green Hills Software CEO

By Joseph Normandin

Posted by John McHale
If the Wikileaks scandal shows anything it proves that no system is secure as people may think it is -- especially software virtualization systems, said Dan O'Dowd, chief executive officer of Green Hills Software during the company’s Software Elite Users Technology Summit. "Virtualization adds nothing to security," he added.

O'Dowd pointed out that virtualization systems have less code, "but that just means they are less bad, not more secure. Running bug-ridden operating systems in virtual machines does not solve the security issue unless the virtualization system itself is secure."

He then made a point that I think resonates well beyond virtualization systems. "The security claims of popular virtualization systems are just marketing fluff to exploit the desperate need of all computer users for security," O'Dowd says. These systems have only been evaluated to the National Security Agency's (NSA's) Common Criteria EAL4+.

According to the Common criteria EAL4+ "makes them appropriate for protecting against 'inadvertent or casual attempts to breach system security,'" O’Dowd said. It's as if they have five doors to their house but only locked four, he added.

O'Dowd was working up to making the case for his company's EAL6+ secure virtualization software, but, I think he's also right on that this is not just a virtualization security phenomenon.

People are lazy when it comes to securing their computers. They all want their systems to be secure, but typically buy into the marketing fluff of certain technology because they like the convenience it provides. However, in the long run they are setting themselves up for security breaches.

It reminded me of something an export compliance officer at a major aerospace company once told me that he tells his employees who travel overseas. He says they need to assume that their emails are being read and their phone conversations are being listened to. It doesn't make you paranoid, it makes you vigilant, he said.

Speaking of vigilance, let's get back to the secure virtualization discussion.

During their work in this area O'Dowd's engineers found security vulnerabilities in standard device drivers in virtual machines. He said they attempted to use I/O memory management units (MMUs) to improve the security of virtual machines, but found that "it doesn't work.

"We weren't looking for vulnerabilities, we were just trying to make the device drivers work," O'Dowd said. "Modern I/O devices often contain huge software control programs consisting of hundreds of thousands lines of code and they have just as many security vulnerabilities as traditional operating systems."

He made the case that if users want to be vigilant with their virtualization systems they need to use an EAL6+ secure system like that offered by Green Hills. Makes sense but with that vigilance also comes cost.

Systems like Green Hills do not come cheap, so it becomes a matter of managing risk. Military and avionics systems cannot take that chance, but companies in less mission/life critical applications may be able to get away with it.

What's more expensive paying for the security ahead of time or not paying and hoping nothing happens? I guess it depends on whether or not you think you, your company, or your technology is actually a target.

Easily post a comment below using your Linkedin, Twitter, Google or Facebook account.

Previous Blog Posts

SWAPped: how size, weight, and power are transforming the military electronics industry

Tue May 21 11:46:00 CDT 2013

China continues to improve capabilities in carrier-based military aviation

Tue May 14 10:23:00 CDT 2013

Small is more: SWAP for soldier systems and unmanned vehicles dominates today's technology

Tue May 07 10:44:00 CDT 2013

The defense budget is here: time to get to work

Mon Apr 29 11:57:00 CDT 2013

Ron Mastro: an unforgettable figure in the aerospace and defense electronics industry

Tue Apr 23 07:45:00 CDT 2013

Mil & Aero Publisher Ernesto Burden unhurt after bombs hit today's Boston Marathon

Mon Apr 15 15:04:00 CDT 2013

After all those sleepless nights of worry, now we find the Pentagon's budget is actually UP?

Wed Apr 10 11:54:00 CDT 2013

Confederate surrender at Appomattox ended the American Civil War 148 years ago this month

Tue Apr 09 10:22:00 CDT 2013

Dear God, what more can the U.S. military ask from the poor letter C?

Fri Apr 05 10:23:00 CDT 2013

Saber rattling in North Korea: how dangerous are these threats?

Tue Apr 02 10:26:00 CDT 2013

At last, some good news; is our industry really ready for this?

Tue Mar 26 09:24:00 CDT 2013

Teledyne Technologies becoming major player in unmanned underwater vehicle (UUV) sensors

Tue Mar 19 09:46:00 CDT 2013

Is sequestration killing aerospace and defense trade shows?

Thu Mar 14 11:27:00 CDT 2013

Nuclear ballistic missile technology remains a post-Cold-War defense priority

Tue Mar 12 09:22:00 CDT 2013

The sequester hits! Is everyone okay?

Tue Mar 05 09:46:00 CST 2013

The continuing drone war of low-tech vs. high-tech

Tue Feb 26 12:30:00 CST 2013

Prospects for high-performance embedded computing (HPEC) look brighter than ever before

Tue Feb 19 10:09:00 CST 2013

Self-sealing suction cups show promise for future robots

Mon Feb 11 11:32:00 CST 2013

Air Force moving forward with potential upgrades to PAVE PAWS, BMEWS, and PARCS missile-defense radar

Thu Feb 07 13:32:00 CST 2013

Cyberattacks carried out against media outlets

Mon Feb 04 15:49:00 CST 2013

Quest for the humvee-mounted mobile data center for the battlefield edge

Wed Jan 30 11:40:00 CST 2013

Dempsey worries about cyberattack, DoD makes plans to hire additional cybersecurity workers

Mon Jan 28 14:16:00 CST 2013

Defense industry will emerge from these hard times stronger than ever

Thu Jan 24 11:07:00 CST 2013

More on our favorite quadruped robot, the LS3

Mon Jan 21 14:09:00 CST 2013

Wave of aerospace and defense company acquisitions may be indication of things to come

Thu Jan 17 10:05:00 CST 2013

The Aerospace & Defense Bloggers

John Keller is editor-in-chief of Military & Aerospace Electronics magazine, which provides extensive coverage and analysis of enabling electronic and optoelectronic technologies in military, space, and commercial aviation applications. A member of the Military & Aerospace Electronics staff since the magazine's founding in 1989, Mr. Keller took over as chief editor in 1995.

Ernesto Burden is the publisher of PennWell’s Aerospace & Defense Media Group, including Military & Aerospace Electronics, Avionics Intelligence and Avionics Europe.  He’s a father of four, a runner, and an avid digital media enthusiast with a deep background in the intersection of media publishing, digital technology, and social media. He can be reached at ernestob@pennwell.com and on Twitter @aero_ernesto.

Courtney E. Howard, as executive editor, enjoys writing about all things electronics and avionics in PennWell’s burgeoning Aerospace and Defense Group, which encompasses Military & Aerospace Electronics, Avionics Intelligence, the Avionics Europe conference, and much more. She’s also a self-proclaimed social-media maven, mil-aero nerd, and avid avionics geek. Connect with Courtney at Courtney@Pennwell.com, @coho on Twitter, and on LinkedIn.

Mil & Aero Magazine

May 2013
Volume 24, Issue 5
file

Download Our Free Apps



iPhone

iPad

Android

Follow Us On...