The move from on-premises endpoints to hosted endpoints in the cloud is one many organizations are embracing. Why? Because it offers benefits like better availability, lower cost, and none of the hardware headaches. Cloud options like Amazon Web Services™, VMware® Cloud Air, Azure®, Rackspace® (to name a few) all provide IT with an ability to quickly create, manage, and remove virtual machines (VMs) as business needs change.
Once you move the endpoints into the cloud with a trusted vendor, you can’t (and shouldn’t) assume the endpoints are secure. The fact is, they’re not. The threat of malware is on the rise, and cloud-based systems are often seen as opportunistic, low-hanging fruit by cyber attackers. Employing a simple war dialer-type scan of a cloud infrastructure vendor’s IP addresses can highlight a number of potential unsecured targets for an attacker. According to the Verizon® Data Breach Investigations Report, most attacks involve some type of malware, so having some level of antivirus protection is a mandatory part of your layered defensive security strategy to safeguard your cloud-based endpoints from the latest viruses, malware, and spam.
In a word, absolutely.
Cloud-based antivirus, of course, has the same function as its on-premises counterpart. But the cloud adds one major design requirement to antivirus that on-premises is not as concerned with: performance. Given your cloud-based endpoints are likely virtual machines (VMs), there’s a big push to ensure the levels of disk and processor required are MUCH lighter in the cloud from that of on-premises antivirus—if not offloaded entirely. Traditional antivirus uses a number of operating system intercepts (memory, or file for example) to scan using various methods (such as signatures, heuristics, or sandboxing), which only kills a machine’s performance. Cloud-based antivirus is laser-focused on security and performance.
If you were to use that kind of solution within a cloud-based server hosting a number of VMs, you'd need to multiply the performance problem by the number of VMs—with each one slowing down the others (remember VMs are a shared resource system!).
Choosing the right antivirus for the cloud
The choice of a cloud-based antivirus solution comes down to three basic issues, all of which intersect:
If you choose a powerful, comprehensive antivirus solution, but it taxes the living daylights out of your most critical workloads, you’re in trouble. The same goes for an extremely light version of antivirus that leaves your endpoint’s resources relatively untouched. You need to find the perfect balance of powerful and light.
It’s important to look beyond marketing claims and focus on the technical capabilities of each solution. Depending on the vendor you select, you’ll want to make sure whatever antivirus you put in place has one or more of the following features:
Depending on the vendor, there are likely other features that add value, so the preceding list is by no means comprehensive. It does, however, provide a base level of functionality you should be looking for. Each vendor takes a slightly different approach, based on the way they see the problem and how it should be solved.
Regardless of which method is used, keep a watchful eye on the claims of what a vendor’s solution specifically addresses. Some will only scan downloaded files, others focus on scans of file system changes, while others schedule scans of an endpoint. Assuming you are taking a layered approach to your cloud security, you’ll need to identify the weaknesses in your strategy and select a cloud-based antivirus solution that fills in the gaps.
The right cloud-based antivirus solution will have more than one of these features, but not necessarily all of them. What’s important is: first, have something in place (don’t wait just because you can’t find the right feature set—cyber criminals aren’t going to give you the needed time before they attack); second, consider how the security features you implement will impact performance; and third, select a solution that fits in the context of your overall security strategy.
Nick Cavalancia has over 20 years of enterprise IT experience and is an accomplished executive, consultant, trainer, speaker, and columnist. He has authored, co-authored and contributed to over a dozen books on Windows®, Active Directory®, Exchange™ and other Microsoft® technologies. Nick has also held executive positions at ScriptLogic®, SpectorSoft® and Netwrix® and now focuses on the evangelism of technology solutions.
Follow Nick on Twitter® at @nickcavalancia
Click here to find out more about our Layered Security offering and how it can help you secure your clients’ business.
© 2017 SolarWinds MSP UK Ltd. All rights reserved.
Get the latest MSP tips, tricks, and ideas sent to your inbox each week.