Showing posts with label virtual desktops. Show all posts
Showing posts with label virtual desktops. Show all posts

Friday, August 20, 2010

MokaFive, AVG push the secure corporate perimeter to personal devices

Last week, we announced a joint solution with AVG to add one more layer of security to MokaFive which allows distributed virtual desktops to be quickly deployed to and safely run from any machine - corporate or personal. This solution extends MokaFive’s capability of running encrypted virtual desktop containers on the endpoint by further securing them from key-logging and screen-scraping attacks from the host machine with the AVG security scanning capability.

While there are a number of drivers for this integration, the key driver is securing the increasing number of personal devices that are constantly accessing sensitive corporate data. Whether organizations like it or not, they have to support ubiquitous access to stay relevant. Current solutions fall seriously short. Let’s start with VPN. Trying to secure access from personal devices using VPN is futile, since all it does is punch a hole from a dirty container into a clean datacenter. Next let’s look at server based desktops (VDI) and apps or terminal services. In each of these solutions, the data is sitting in a nicely protected container in the datacenter. For added security, let’s assume that there are military guards outside the datacenter. If all this secure data is ultimately being accessed by a browser from a dirty personal machine, then it can be screen scraped. Might as well toss out all the protection. The third approach is to distribute bootable USBs or CDs with a browser. This approach is secure, but cumbersome for the user, and more importantly, the image cannot be managed or updated.

As I have mentioned before, security cannot be talked about in absolutes. But if a company wants to enable access of corporate data from personal machines,; the best solution seems to be to have a secure, managed container provisioned to the personal machine. This is exactly what we are doing with the combined AVG – MokaFive solution. The corporate environment is captured and encapsulated in a virtual desktop (called LivePC in MokaFive parlance) which is then deployed to the personal endpoint. The encapsulation has built-in AV scanning that provides continuous protection from keyloggers and screenscrapers that might be present on the host machine. The scanning is running continuously during VM operation to ensure constant protection. All access to the corporate data is made available only through the VM container. Now, the user has the flexibility to use both corporate and personal environments on their machine, and the corporation has complete assurance that all the data is secured.

With this solution, enterprises can now finally extend the secure corporate perimeter to personal machines. Check out the press release.

Purnima Padmanabhan, VP of Products & Marketing

Tuesday, July 13, 2010

VDI Project? One question to make sure you ask.

We recently hosted a CIO summit that was attended by several CIOs, representing some of the largest organizations in the US. The topic was desktop virtualization, and we had a terrific discussion about ongoing initiatives at each company.

One CIO cited a statistic that was so surprising, shocking really, it really stuck out in our minds. At their organization—one of the premier universities in the world--they’d recently evaluated the use of VDI for university employees. In their analysis, they found the all-in cost of VDI to be nearly $12K per user per year! (sound of jaws hitting floor) When contemplating the necessary server, storage and network improvements, the costs were so prohibitive they dismissed VDI as being completely impractical.

His argument was so sincere and thoughtful that other attendees were heard making mental notes to ask their staffs for a business case on their VDI projects.

If you’re considering, planning, or even deploying VDI, one piece of advice: make sure you ask this question too. If you don’t have a staff, then ask yourself. Or ask your boss. Just don’t let the question go unasked and risk a rude $12K surprise.

Overheard, five years from now: "Tell me again, why did we spend so much on VDI?"

As the story goes, during the 1960s space race, NASA was faced with a major problem. The astronauts needed a pen that could write in the gravity-free environment of space. After a $1.5 million effort, they developed the Astronaut Pen which could write in a vacuum, write with no gravity, and write in extreme temperatures. It was brilliant!

The Russians, faced with the same problem, had a simpler approach: they used a pencil.

This apocryphal tale contains a valid lesson: sometimes we spend a great deal of time, effort and money to create a “high-tech” solution, when a perfectly elegant and low cost solution is right before our eyes. (Of course, one clear alternative to VDI springs to our minds. J)

Question: how many abandoned VDI projects are littering the streets?

The CIO’s comments resonated with many of us, as we’ve heard, particularly recently, of many organizations that have investigated, piloted and ultimately abandoned VDI because the costs were so prohibitive, and because better suited alternatives do exist.
So we ask the question to all of you: how many of you have gone through this experience and ultimately decided to go with status quo or an altogether different approach?

Burt Toma, Director of Products

Tuesday, June 15, 2010

Introducing MokaFive on BareMetal

We’re gearing up for BriForum this week, and for us, the highlight will be a sneak peak of an exciting new product that we have been working on: MokaFive BareMetal. Starting today, you can see for yourself what this solution is all about. Stop by our booth (#300) for the demo by MokaFive’s CTO, John Whaley.

The idea behind BareMetal is to provide a thin management layer that sits on the bare metal hardware. This is still in development so we don’t want to comment on the implementation details, but the benefits of BareMetal are clear: broad hardware support, extensive policy set, and the best management control in the industry.

If you’re familiar with MokaFive, you know we came out of the gate with support for VMware Player, and recently added another hypervisor to our arsenal – VirtualBox. Now, with MokaFive BareMetal, we’re going to eliminate the OS-middleman and enable users to run directly on the hardware itself.

So, why are we adding BareMetal? For one, it supports our commitment to be truly platform- and hypervisor- agnostic. Equally important, if not more, our customers have been asking for it. Those customers that are already running our Type-2 hypervisor based solution for their laptops and BYOC or employee owned devices are now looking to expand MokaFive management across all corporate desktops. With the BareMetal solution, customers will be able to use just a single Windows guest OS instead of licensing & paying for both the VM and the host OS. And the best part is that they can roll out the same virtual image, as well as policy controls, to both end users’ personal machines (using our Type-2 solution) as well as corporate-issued ones (using our BareMetal solution), with no additional management burden.

For the image, you can use the same image that you’re using for current deployments (BYOC). For installation of BareMetal, there will be a few different methods from which you can choose. Similar to other physical machines, you’ll be able to install it with installation ISOs, or over the network via a PXE server. I’m biased of course, but we have a solid solution here that dramatically simplifies management – of desktops and licenses – for customers.

If you’re at BriForum, be sure to come check out our BareMetal demo at booth #300. And while you’re there, Futurama fans should be sure to enter MokaFive’s drawing for a Bare Metal Bender.

Purnima Padmanabhan, VP of Products and Marketing

Wednesday, June 9, 2010

What is the right virtual desktop model for BYOC?

A recent blog post by Brian Madden compares the security differences between Type 1 and Type 2 hypervisors. Brian writes that Type 1 bare-metal hypervisors are “possibly more secure due to the smaller attack surface of the hypervisor.” But he’s quick to point out that neither Type 1 nor Type 2 hypervisors are a one-size-fits-all solution.

After reading Brian’s blog, I thought about MokaFive’s approach to security. The problem with security is that you can’t talk in absolutes: the discussion depends on both the use case and its associated risk profile. If you are completely intolerant of risk, then you have to ignore the benefits of most Internet-based computing and keep your computer offline, locked up in a dark room. But in the real world, you have to support mobile and offline workers so they can be productive, and with that comes some risk. This is true of any computing model, but it’s important to mitigate that risk by choosing the best technology for your needs.

Let’s specifically look at the BYOC model where organizations want to enable computing on employee-owned machines. While there are many models to deliver specific applications from the cloud using technologies such as terminal services or even app streaming, these don’t provide the full usability of the entire desktop environment. So, what are the options for BYOC? There is VDI, but it provides no offline access and contrary to popular belief is not completely secure, either. While the VDI desktop lives in the datacenter, IT has no way to control the endpoint machine accessing the VDI session. Those endpoints could have keyloggers or screenscrapers that can siphon data from the VDI session.

In contrast, with the client-side models, a fully encapsulated VM is delivered to the endpoint, either directly on baremetal (with Type 1 hypervisor), or on top of an existing OS (with Type 2 hypervisor). There is almost unanimous agreement that a Type 1-based model will not work for BYOC, since no user will allow IT to forklift their personal machine. Only when Type 1s are shipped with OEM machines will this model will become viable for BYOC.

Net-net, a Type 2-based client-side model, where a fully managed, encapsulated VM is delivered on top of the user’s existing OS, is ideally suited for BYOC. It provides users access to the corporate environment anytime, online or offline, without impinging on their personal machine environment.

MokaFive supports a Type 2 model today while allowing you to grow to a Type 1 approach in the future. We leverage the MokaFive player residing on the client to provide additional protection against risks associated with BYOC. I have outlined below our approach with seven layers of security that protect against your concerns:

1. Host checker
  • Checks for basic performance characteristics of the machine. It can also be extended to check for any other security characteristics of the host (such as configuration and execution status of anti-virus software) prior to the launch of the virtual desktop.
2. VM encapsulation
  • Encapsulates a full, locked down OS controlled by IT. This allows IT to completely control the patch level and GPO security settings.
3. VM encryption
  • Encrypts image with AES 256, including the base image and all user data. We also intercept all I/O that the hypervisor writes to disk or to memory, and this data is compressed and encrypted.
4. Tamper resistance of both code and policies, and copy protection
  • Attempts to alter the executable or configuration will disallow the Player from running. Also, by policy, IT can disallow users from moving images from one machine to another.
5. AD authentication / Two-factor authentication (RSA or PKI)
  • Integrates with Active Directory to enforce users’ authentication prior to virtual image access. Optionally, IT can configure RSA SecurID or PKI as a second authentication factor for additional security.
6. SSL
  • Communicates with the server over SSL. Clients validate the server’s SSL certificates against a Certificate Authority.
7. Policies
  • Enables administrators to have fine grained, centralized control of operational and security polices, such as peripheral access, and ability to drag and drop files from host to guest or vice versa.

Simply put, MokaFive is one of the few vendors that provides a secure, fully managed virtual desktop model for a BYOC model. Stay tuned: in an upcoming blog, we will talk about BYOC best practices.

Purnima Padmanabhan, VP of Products and Marketing