SlideShare a Scribd company logo
1 of 11
VDISecurity.org Intro
ABOUT IT
Agenda
 WhoAmI?
 Why VDI?
 Overview of VDI with
 Citrix and VMware Component Layout
 Securing VDI Basics
 Questions
WhoAmI?
 Noob, Patrick Coble, 2x Father, Nerd, Hacker, Trainer, Speaker, Meme User,
PowerPoint Clicker and Citrix CTA.
 I have been working with computers since 1988 and started hacking in the
early AOL days. I started working in the IT industry in 1997 and joined the
Marine Corps where I was Intel working on computers. Upon finishing his
time in the Marine Corps, I worked in the security industry, specifically
within Healthcare, and later joined a reseller before starting his own
company in 2016.
 Patrick Founded his own security consulting company in 2016 to close the
gap in local and personal security along with IT consulting for Small
Businesses and Individuals. I still do EUCVDI Consulting for large
companies.
VDISecurity.org
Who cares about VDI?
90% of Fortune 1000 Companies
have a VDI Deployment.
A HACKERS SUMMARY
Company Info & Major Versions
Horizon
 VMware Founded, 1998
 VMware 2016, 5.62 Billion
 First Version 2.0, January 2008
 Major Release Family
 3.0, 4.0, 5.0
 6.0
 7.0-7.2
XenDesktop
 Citrix Founded, 1989
 Citrix 2016, 3.42 Billion
 First Version 2.0, October 2007
 Major Release Family
 2.0, 3.0, 4.0
 5.0, 5.6
 7.0-7.15
VDI Basic Components
Endpoint
Front End Web
Services
Broker
Virtual Desktop
App Server
Imaging
Method
Agent
Citrix VDI Basic Components
Endpoint StoreFront
Delivery
Controller
Virtual Desktop
App Server
Provisioning Server
MCS (Linked Clone)
Agent
NetScaler
Gateway
VMware VDI Basic Components
Endpoint
Security Servers
Connectinon
Server
Virtual Desktop
App Server
Linked Clone (Composer)
Instant Clone
Agent
F5 Load
Balancer
or APM
Access Point
Unified Access
Gateway
VDISecurity.Org
 I founded this site in honor of people like Sean Metcalf
with ADSecurity.org and many others who were experts
in a product set and work to improve security for it.
 At this Site you will see things from two perspectives
 VDI Admin, How to Secure It
 Security Nerds, How to do Recon, Get In and Pivot
 I have a couple blog posts ready to roll out but just have to
wrap up a couple things. I have been slacking.
VDI – Securing It - Basic
 Securing the Policies to make sure data cannot leave the session in a
way you don’t want it to. DLP for VDI.
 Keeping it Patched is the biggest battle, it only takes one box.
 Optimize the image to turn off unused features. (Makes it more secure)
 Run some form of AV (For years when the devices were provisioned
and or Non-Persistent it was recommended not to install it, due to its
overhead and problems within VDI)
 Use AppLocker or other AV Systems to Whitelist applications to ensure
other applications cannot be launched.
 Windows Firewall, IPsec, Microsegmentation
 Replace Default SSL Certificates and use SSL Certificates Everywhere.
Questions

More Related Content

What's hot

Cw13 securing your journey to the cloud by rami naccache-trend micro
Cw13 securing your journey to the cloud by rami naccache-trend microCw13 securing your journey to the cloud by rami naccache-trend micro
Cw13 securing your journey to the cloud by rami naccache-trend micro
TheInevitableCloud
 

What's hot (20)

SYN308: How XenMobile integrates with NetScaler, XenDesktop and XenApp for co...
SYN308: How XenMobile integrates with NetScaler, XenDesktop and XenApp for co...SYN308: How XenMobile integrates with NetScaler, XenDesktop and XenApp for co...
SYN308: How XenMobile integrates with NetScaler, XenDesktop and XenApp for co...
 
EUC State of the Union 2021
EUC State of the Union 2021EUC State of the Union 2021
EUC State of the Union 2021
 
SYN310: Deep dive into ShareFile Enterprise functionality
SYN310: Deep dive into ShareFile Enterprise functionalitySYN310: Deep dive into ShareFile Enterprise functionality
SYN310: Deep dive into ShareFile Enterprise functionality
 
VMware vRealize Network Insight 3.4 whats new
VMware vRealize Network Insight 3.4 whats newVMware vRealize Network Insight 3.4 whats new
VMware vRealize Network Insight 3.4 whats new
 
Cw13 securing your journey to the cloud by rami naccache-trend micro
Cw13 securing your journey to the cloud by rami naccache-trend microCw13 securing your journey to the cloud by rami naccache-trend micro
Cw13 securing your journey to the cloud by rami naccache-trend micro
 
VMware vRealize Network Insight 3.5 - Whats New
VMware vRealize Network Insight 3.5 - Whats NewVMware vRealize Network Insight 3.5 - Whats New
VMware vRealize Network Insight 3.5 - Whats New
 
Microsoft Solves BYOD Using Microsoft System Center Configuration Manager and...
Microsoft Solves BYOD Using Microsoft System Center Configuration Manager and...Microsoft Solves BYOD Using Microsoft System Center Configuration Manager and...
Microsoft Solves BYOD Using Microsoft System Center Configuration Manager and...
 
State of the EUC - 2020 What's new in End-User Computing
State of the EUC - 2020 What's new in End-User ComputingState of the EUC - 2020 What's new in End-User Computing
State of the EUC - 2020 What's new in End-User Computing
 
Cisco Security portfolio update
Cisco Security portfolio updateCisco Security portfolio update
Cisco Security portfolio update
 
Azure security
Azure  securityAzure  security
Azure security
 
ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?
ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?
ECMDay2015 - Nico Sienaert – Enterprise Mobility Suite – What it’s all about?
 
Maximize your Investment in Microsoft Office 365 with Citrix Workspace
Maximize your Investment in Microsoft Office 365 with Citrix Workspace Maximize your Investment in Microsoft Office 365 with Citrix Workspace
Maximize your Investment in Microsoft Office 365 with Citrix Workspace
 
Citrix Synergy 2017: Technology Keynote Sketch Notes
Citrix Synergy 2017: Technology Keynote Sketch NotesCitrix Synergy 2017: Technology Keynote Sketch Notes
Citrix Synergy 2017: Technology Keynote Sketch Notes
 
F5 Programmability & Orchestration
F5 Programmability & OrchestrationF5 Programmability & Orchestration
F5 Programmability & Orchestration
 
The Process of Migrating to Cloud Services - Leveraging Fast IT - All the coo...
The Process of Migrating to Cloud Services - Leveraging Fast IT - All the coo...The Process of Migrating to Cloud Services - Leveraging Fast IT - All the coo...
The Process of Migrating to Cloud Services - Leveraging Fast IT - All the coo...
 
RSA For Vblock
RSA For VblockRSA For Vblock
RSA For Vblock
 
Azure for beginners series session 4
Azure for beginners series session 4Azure for beginners series session 4
Azure for beginners series session 4
 
Citrix solutions - How on earth, as in heaven
Citrix solutions - How on earth, as in heavenCitrix solutions - How on earth, as in heaven
Citrix solutions - How on earth, as in heaven
 
Azure security and Compliance
Azure security and ComplianceAzure security and Compliance
Azure security and Compliance
 
Trust No-One Architecture For Services And Data
Trust No-One Architecture For Services And DataTrust No-One Architecture For Services And Data
Trust No-One Architecture For Services And Data
 

Similar to VDISecurity.org Overview

Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
Sameer Mohammed
 
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
michaelbasoah
 
Presentation security build for v mware
Presentation   security build for v mwarePresentation   security build for v mware
Presentation security build for v mware
solarisyourep
 
A Dash of SPiCE_The Power of VDI
A Dash of SPiCE_The Power of VDIA Dash of SPiCE_The Power of VDI
A Dash of SPiCE_The Power of VDI
Erlyn911
 
Vdi, rds, med v, app-v - right decisions
Vdi, rds, med v, app-v - right decisionsVdi, rds, med v, app-v - right decisions
Vdi, rds, med v, app-v - right decisions
Concentrated Technology
 
VTI Learning Series Beyond the Convergence of Physical & Cyber Security
VTI Learning Series Beyond the Convergence of Physical & Cyber SecurityVTI Learning Series Beyond the Convergence of Physical & Cyber Security
VTI Learning Series Beyond the Convergence of Physical & Cyber Security
Shane Glenn
 
About The Cloud Virtualization Vendor Wyse And Its...
About The Cloud Virtualization Vendor Wyse And Its...About The Cloud Virtualization Vendor Wyse And Its...
About The Cloud Virtualization Vendor Wyse And Its...
Jennifer Campbell
 

Similar to VDISecurity.org Overview (20)

VMUG 6 Program
VMUG 6 ProgramVMUG 6 Program
VMUG 6 Program
 
Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
Sameer's (Vmware & Wintel Systems Engineer)Resume-04-2016
 
Innovation and Architecture
Innovation and ArchitectureInnovation and Architecture
Innovation and Architecture
 
Enhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for PartnersEnhancing SaaS Performance: A Hands-on Workshop for Partners
Enhancing SaaS Performance: A Hands-on Workshop for Partners
 
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
Are Your Appliance Security Solutions Ready For 2048-bit SSL Certificates ?
 
Virtuize
VirtuizeVirtuize
Virtuize
 
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
PROACT SYNC 2013 - Breakout - VSPEX en vBlock Converged Infrastructure bouwbl...
 
Presentation security build for v mware
Presentation   security build for v mwarePresentation   security build for v mware
Presentation security build for v mware
 
A Dash of SPiCE_The Power of VDI
A Dash of SPiCE_The Power of VDIA Dash of SPiCE_The Power of VDI
A Dash of SPiCE_The Power of VDI
 
ISTC Keynote Smart Authoring For A Smarter Planet
ISTC Keynote   Smart Authoring For A Smarter PlanetISTC Keynote   Smart Authoring For A Smarter Planet
ISTC Keynote Smart Authoring For A Smarter Planet
 
Cloud Switch 318
Cloud Switch 318Cloud Switch 318
Cloud Switch 318
 
Vdi, rds, med v, app-v - right decisions
Vdi, rds, med v, app-v - right decisionsVdi, rds, med v, app-v - right decisions
Vdi, rds, med v, app-v - right decisions
 
SYN 321: Securing the Published Browser
SYN 321: Securing the Published BrowserSYN 321: Securing the Published Browser
SYN 321: Securing the Published Browser
 
Brand Commerce - We all know the shiny stuff at the front. But what magic is ...
Brand Commerce - We all know the shiny stuff at the front. But what magic is ...Brand Commerce - We all know the shiny stuff at the front. But what magic is ...
Brand Commerce - We all know the shiny stuff at the front. But what magic is ...
 
ppt_rs.jpg
ppt_rs.jpgppt_rs.jpg
ppt_rs.jpg
 
Virtualization 2011 v1
Virtualization 2011 v1Virtualization 2011 v1
Virtualization 2011 v1
 
VTI Learning Series Beyond the Convergence of Physical & Cyber Security
VTI Learning Series Beyond the Convergence of Physical & Cyber SecurityVTI Learning Series Beyond the Convergence of Physical & Cyber Security
VTI Learning Series Beyond the Convergence of Physical & Cyber Security
 
About The Cloud Virtualization Vendor Wyse And Its...
About The Cloud Virtualization Vendor Wyse And Its...About The Cloud Virtualization Vendor Wyse And Its...
About The Cloud Virtualization Vendor Wyse And Its...
 
October VMware Cloud Forum
October VMware Cloud ForumOctober VMware Cloud Forum
October VMware Cloud Forum
 
vDesk.works Secure Cloud Desktop Solution.pptx
vDesk.works Secure Cloud Desktop Solution.pptxvDesk.works Secure Cloud Desktop Solution.pptx
vDesk.works Secure Cloud Desktop Solution.pptx
 

Recently uploaded

Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
Joaquim Jorge
 

Recently uploaded (20)

TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law DevelopmentsTrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
TrustArc Webinar - Stay Ahead of US State Data Privacy Law Developments
 
Automating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps ScriptAutomating Google Workspace (GWS) & more with Apps Script
Automating Google Workspace (GWS) & more with Apps Script
 
Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024Axa Assurance Maroc - Insurer Innovation Award 2024
Axa Assurance Maroc - Insurer Innovation Award 2024
 
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
Bajaj Allianz Life Insurance Company - Insurer Innovation Award 2024
 
Boost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdfBoost Fertility New Invention Ups Success Rates.pdf
Boost Fertility New Invention Ups Success Rates.pdf
 
Boost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivityBoost PC performance: How more available memory can improve productivity
Boost PC performance: How more available memory can improve productivity
 
How to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected WorkerHow to Troubleshoot Apps for the Modern Connected Worker
How to Troubleshoot Apps for the Modern Connected Worker
 
AWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of TerraformAWS Community Day CPH - Three problems of Terraform
AWS Community Day CPH - Three problems of Terraform
 
A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)A Domino Admins Adventures (Engage 2024)
A Domino Admins Adventures (Engage 2024)
 
Artificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and MythsArtificial Intelligence: Facts and Myths
Artificial Intelligence: Facts and Myths
 
A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?A Year of the Servo Reboot: Where Are We Now?
A Year of the Servo Reboot: Where Are We Now?
 
Tech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdfTech Trends Report 2024 Future Today Institute.pdf
Tech Trends Report 2024 Future Today Institute.pdf
 
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
Mastering MySQL Database Architecture: Deep Dive into MySQL Shell and MySQL R...
 
GenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdfGenAI Risks & Security Meetup 01052024.pdf
GenAI Risks & Security Meetup 01052024.pdf
 
Strategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a FresherStrategies for Landing an Oracle DBA Job as a Fresher
Strategies for Landing an Oracle DBA Job as a Fresher
 
Data Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt RobisonData Cloud, More than a CDP by Matt Robison
Data Cloud, More than a CDP by Matt Robison
 
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time AutomationFrom Event to Action: Accelerate Your Decision Making with Real-Time Automation
From Event to Action: Accelerate Your Decision Making with Real-Time Automation
 
🐬 The future of MySQL is Postgres 🐘
🐬  The future of MySQL is Postgres   🐘🐬  The future of MySQL is Postgres   🐘
🐬 The future of MySQL is Postgres 🐘
 
GenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day PresentationGenCyber Cyber Security Day Presentation
GenCyber Cyber Security Day Presentation
 
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemkeProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
ProductAnonymous-April2024-WinProductDiscovery-MelissaKlemke
 

VDISecurity.org Overview

  • 2. Agenda  WhoAmI?  Why VDI?  Overview of VDI with  Citrix and VMware Component Layout  Securing VDI Basics  Questions
  • 3. WhoAmI?  Noob, Patrick Coble, 2x Father, Nerd, Hacker, Trainer, Speaker, Meme User, PowerPoint Clicker and Citrix CTA.  I have been working with computers since 1988 and started hacking in the early AOL days. I started working in the IT industry in 1997 and joined the Marine Corps where I was Intel working on computers. Upon finishing his time in the Marine Corps, I worked in the security industry, specifically within Healthcare, and later joined a reseller before starting his own company in 2016.  Patrick Founded his own security consulting company in 2016 to close the gap in local and personal security along with IT consulting for Small Businesses and Individuals. I still do EUCVDI Consulting for large companies. VDISecurity.org
  • 4. Who cares about VDI? 90% of Fortune 1000 Companies have a VDI Deployment. A HACKERS SUMMARY
  • 5. Company Info & Major Versions Horizon  VMware Founded, 1998  VMware 2016, 5.62 Billion  First Version 2.0, January 2008  Major Release Family  3.0, 4.0, 5.0  6.0  7.0-7.2 XenDesktop  Citrix Founded, 1989  Citrix 2016, 3.42 Billion  First Version 2.0, October 2007  Major Release Family  2.0, 3.0, 4.0  5.0, 5.6  7.0-7.15
  • 6. VDI Basic Components Endpoint Front End Web Services Broker Virtual Desktop App Server Imaging Method Agent
  • 7. Citrix VDI Basic Components Endpoint StoreFront Delivery Controller Virtual Desktop App Server Provisioning Server MCS (Linked Clone) Agent NetScaler Gateway
  • 8. VMware VDI Basic Components Endpoint Security Servers Connectinon Server Virtual Desktop App Server Linked Clone (Composer) Instant Clone Agent F5 Load Balancer or APM Access Point Unified Access Gateway
  • 9. VDISecurity.Org  I founded this site in honor of people like Sean Metcalf with ADSecurity.org and many others who were experts in a product set and work to improve security for it.  At this Site you will see things from two perspectives  VDI Admin, How to Secure It  Security Nerds, How to do Recon, Get In and Pivot  I have a couple blog posts ready to roll out but just have to wrap up a couple things. I have been slacking.
  • 10. VDI – Securing It - Basic  Securing the Policies to make sure data cannot leave the session in a way you don’t want it to. DLP for VDI.  Keeping it Patched is the biggest battle, it only takes one box.  Optimize the image to turn off unused features. (Makes it more secure)  Run some form of AV (For years when the devices were provisioned and or Non-Persistent it was recommended not to install it, due to its overhead and problems within VDI)  Use AppLocker or other AV Systems to Whitelist applications to ensure other applications cannot be launched.  Windows Firewall, IPsec, Microsegmentation  Replace Default SSL Certificates and use SSL Certificates Everywhere.

Editor's Notes

  1. VMware View 3.1.3 (May 5, 2010) VMware View 4 (November 9, 2009) VMware View 4.0.2 (September 15, 2010) VMware View 4.5 (September 9, 2010) VMware View 4.6 (February 24, 2011) VMware View 4.6.1 (March 15, 2012) VMware View 4.6.2 (December 11, 2012) VMware View 4.6.3 (March 7, 2013) VMware View 5.0 (September 8, 2011) VMware View 5.0.1 (March 15, 2012) VMware View 5.1 (May 16, 2012) VMware View 5.1.1 (August 16, 2012) VMware View 5.1.2 (December 13, 2012) VMware View 5.1.3 (March 14, 2013) VMware View 5.2 (October 4, 2012) VMware View 5.3 (November 21, 2013) VMware View 5.3.1 (March 11, 2014) VMware View 5.3.2 (June 24, 2014) VMware View 5.3.3 (November 25, 2014) VMware View 5.3.4 (March 17, 2015) VMware Horizon 6.0 (June 19, 2014) VMware Horizon 6.0.1 (September 9, 2014) VMware Horizon 6.0.2 (December 9, 2014) VMware Horizon 6.1 (March 12, 2015) VMware Horizon 6.1.1 (June 4, 2015) VMware Horizon 6.2 (September 3, 2015)