Securing the Virtual Environment and over one million other books are available for Amazon Kindle. Learn more



or
Sign in to turn on 1-Click ordering
More Buying Choices
Have one to sell? Sell yours here
Start reading Securing the Virtual Environment on your Kindle in under a minute.

Don't have a Kindle? Get your Kindle here, or download a FREE Kindle Reading App.
Sorry, this item is not available in
Image not available for
Color:
Image not available

To view this video download Flash Player

 

Securing the Virtual Environment, Included DVD: How to Defend the Enterprise Against Attack [Paperback]

Davi Ottenheimer , Matthew Wallace
4.5 out of 5 stars  See all reviews (2 customer reviews)

List Price: $49.99
Price: $32.03 & FREE Shipping. Details
You Save: $17.96 (36%)
o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o o
Only 4 left in stock (more on the way).
Ships from and sold by Amazon.com. Gift-wrap available.
Want it Friday, June 21? Choose One-Day Shipping at checkout. Details
Free Two-Day Shipping for College Students with Amazon Student

Formats

Amazon Price New from Used from
Kindle Edition $28.49  
Paperback $32.03  
Rent Your Textbooks
Save up to 70% when you rent your textbooks on Amazon. Keep your textbook rentals for a semester and rental return shipping is free.

Book Description

May 8, 2012 1118155483 978-1118155486 1
A step-by-step guide to identifying and defending against attacks on the virtual environment

As more and more data is moved into virtual environments the need to secure them becomes increasingly important. Useful for service providers as well as enterprise and small business IT professionals the book offers a broad look across virtualization used in various industries as well as a narrow view of vulnerabilities unique to virtual environments. A companion DVD is included with recipes and testing scripts.

  • Examines the difference in a virtual model versus traditional computing models and the appropriate technology and procedures to defend it from attack
  • Dissects and exposes attacks targeted at the virtual environment and the steps necessary for defense
  • Covers information security in virtual environments: building a virtual attack lab, finding leaks, getting a side-channel, denying or compromising services, abusing the hypervisor, forcing an interception, and spreading infestations
  • Accompanying DVD includes hands-on examples and code

This how-to guide arms IT managers, vendors, and architects of virtual environments with the tools they need to protect against common threats.


Frequently Bought Together

Securing the Virtual Environment, Included DVD: How to Defend the Enterprise Against Attack + Virtualization Security: Protecting Virtualized Environments
Price for both: $66.21

Buy the selected items together


Editorial Reviews

Review

'Anyone who is serious about virtualization security should certainly make sure that Securing the Virtual Environment: How to Defend the Enterprise Against Attack is on their reading list, and that of every security administrator in their company.' (RSA Conference, 7th May)

From the Back Cover

Defend your virtual environment from attacks

Your virtual environment might be a prime target for hackers and attackers who want to steal data or exploit your resources. This book arms you with the knowledge and tools to safeguard your virtual and cloud environments against external and internal threats. You'll gain insight into how to avoid denial of service, log and audit activity, protect virtual networks from eavesdroppers, and harden virtual servers. If your job involves protecting assets in virtual and cloud environments, this book will be invaluable to you.

  • Perform vulnerability assessments of your virtual environment to uncover security weaknesses

  • Learn how attacks in a virtual model differ from traditional computing models and how to best use technology and processes to defend yourself

  • Learn how attackers use and abuse APIs to manipulate and gain entry to virtual environments

  • Understand the risks of Software as a Service and how to get the protection you must have

  • Be ready for audits by ensuring that your virtual and cloud environments comply with standards and regulations such as PCI DSS and ISO 27001

  • Build your own low-budget virtualized test lab for hands-on evaluation of attacks and to practice prevention and response

ON THE DVD

Use the files on the DVD to follow along with the hands-on examples, or use them as the basis for your own code. Using the code and the book, you can

  • Conduct a "hypervisor escape", breaking out of a virtual machine into the host system

  • Load the included, ready-made penetration testing virtual machine—which is preloaded with tools such as nmap, ettercap, the Open VAS vulnerability scanner, and more—directly into your virtual environment

  • Test the security posture of your Xen or VMware environment using automated scripts that peek at virtual disks and copy or modify virtual machines

  • See the code used for hands-on exercises in the book that audit or attack virtual environments


Product Details

  • Paperback: 456 pages
  • Publisher: Wiley; 1 edition (May 8, 2012)
  • Language: English
  • ISBN-10: 1118155483
  • ISBN-13: 978-1118155486
  • Product Dimensions: 7.3 x 1 x 9.2 inches
  • Shipping Weight: 1.6 pounds (View shipping rates and policies)
  • Average Customer Review: 4.5 out of 5 stars  See all reviews (2 customer reviews)
  • Amazon Best Sellers Rank: #712,182 in Books (See Top 100 in Books)

More About the Authors

Discover books, learn about writers, read author blogs, and more.

Customer Reviews

4.5 out of 5 stars
(2)
4.5 out of 5 stars
Share your thoughts with other customers
Most Helpful Customer Reviews
5 of 5 people found the following review helpful
4.0 out of 5 stars Excellent guide to virtualization security May 7, 2012
Format:Paperback
One of the selling points around virtualization is about its perceived added level of security. But virtualization, like any other piece of software can be implemented incorrectly, and itself have flaws.

Last year, NIST came out with SP 800-125, Guide to Security for Full Virtualization Technologies. The guide is intended for system administrators, security program managers, security engineers and anyone else involved in designing, deploying or maintaining full virtualization technologies.

NIST SP 800-125 recommends organizations do the following:
* secure all elements of a full virtualization solution and maintain their security
* restrict and protect administrator access to the virtualization solution
* ensure that the hypervisor, the central program that runs the virtual environment, is properly secured
* carefully plan the security for a full virtualization solution before installing, configuring and deploying it

All good items to do; but at 25 pages, SP 800-125 is clearly inadequate to cover all of the details around how to securely use virtualization. With that, Securing the Virtual Environment: How to Defend the Enterprise Against Attack, by Davi Ottenheimer and Matthew Wallace is a great new book that that provides a comprehensive overview on how to secure systems and defend against attacks on virtualized environments.

The book takes a very strong approach that in order to secure virtualization effectively, one needs to understand how adversaries will attack a virtualized environment. The authors provide numerous details on how to precisely do that.

The book is a highly technical guide meant for those designing, deploying and administering virtualized systems.
... Read more ›
Was this review helpful to you?
3 of 3 people found the following review helpful
5.0 out of 5 stars Excellent and Detailed Work on VirtSec July 1, 2012
Format:Paperback
I have been meaning to get to this review for a while, as I have had the book since it came out. In a nutshell, Davi and Matthew have done a fantastic job outlining general premises of virtsec, as well as detailed attack methods and examples for all aspects of a typical virtual environment. My general notes on each chapter are as follows:

1. "Virtualized Environment Attacks" - this chapter lays out a lot of terminology and general theory on virtualization and why it's vulnerable technology. This book is really geared towards a security audience, so I found a lot of the infosec basics in this chapter unnecessary, but I see why they're there.

2. "Attacking from the Outside" - this chapter breaks down the differences between outside and internal attacks, and show why and how roles and privileges play a big role in the security ecosystem, especially around virtualization. Great discussion and examples on some basic technology issues, like reliance on certificates and automated patching.

3. "Making the Complex Simple" - Really cool chapter on enumeration of virt and cloud systems and applications. How to time attacks, how to "read between the lines" on scanner output when looking at cloud infrastructure, etc.

4. "Denial of Service" - Those of us in the virtsec space know how DoS attacks can be executed differently in virtual environments, but the authors do a nice job of breaking these attacks down. Covers all manner of DoS attacks, including authentication DoS, remote packet-based DoS, resource over-consumption DoS, and more.

5. "Abusing the Hypervisor" - One of my two favorite chapters in the book. The authors explain how hypervisors are constructed, and how kernel attacks are possible and subtly different when done in virtual environments.
... Read more ›
Comment | 
Was this review helpful to you?
Search Customer Reviews
Only search this product's reviews


Forums

There are no discussions about this product yet.
Be the first to discuss this product with the community.
Start a new discussion
Topic:
First post:
Prompts for sign-in
 



So You'd Like to...


Create a guide


Look for Similar Items by Category