In mid May McAfee, announced a two-phases partnership with Citrix to deliver security solutions specifically tailored for virtual desktop infrastructures (VDI).
The first phase involved releasing a VDI-optimised antivirus, while the second is about introducing a single out-of-band security agent that control the whole virtual infrastructure through hypervisor’s APIs (something the industry usually calls introspection).
A few weeks ago McAfee completed the first step, announcing the availability of its new Management of Optimised Virtual Environments (MOVE) antivirus.
MOVE is based on a lightweight agent, that pseudo-randomizes some of its activities on the virtual desktops’ virtual hard drive, and that doesn’t carry on the scanning and removal engine.
The core activities are in fact executed out of band, in a remote, dedicated virtual appliance. What the optimised agents, which are centrally managed by McAfee ePolicy Orchestrator (ePO), really do is copying the suspicious files from the potentially infected virtual desktop to the security virtual appliance, over a secure channel..