{"id":39334,"date":"2019-10-31T22:30:19","date_gmt":"2019-10-31T19:30:19","guid":{"rendered":"https:\/\/prohoster.info\/blog\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat\/"},"modified":"2019-10-31T22:30:19","modified_gmt":"2019-10-31T19:30:19","slug":"pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat","title":{"rendered":"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><b>More and more users are migrating their entire IT infrastructure to the public cloud. However, this leads to significant cyber risks when there is insufficient antivirus control in the customer's infrastructure. Practice shows that up to 80% of existing viruses thrive excellently in a virtual environment. In this post, we will discuss how to protect IT resources in the public cloud and why traditional antivirus solutions are not well-suited for these purposes. <\/b><\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/3bf1eca7c2e54cd95a310245b900c855.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nFirst, let us explain how we came to the conclusion that traditional antivirus protection tools are not suitable for the public cloud and that different approaches to resource protection are required. <noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><\/p>\n<p>Firstly, providers typically implement necessary measures to ensure high-level protection for their cloud platforms. For example, at #CloudMTS, we analyze all network traffic, monitor the security logs of our cloud, and regularly perform pentests. Segments of the cloud allocated to individual clients must also be reliably protected. <\/p>\n<p>Secondly, the classic approach to combating cyber risks involves installing antivirus software and managing it on each virtual machine. However, with a large number of virtual machines, this practice can be inefficient and require significant computational resources, thus further burdening the customer's infrastructure and lowering the overall cloud performance. This became a key reason for seeking new approaches to build effective antivirus protection for clients' virtual machines. <\/p>\n<p>Moreover, most antivirus solutions available on the market are not adapted to the tasks of protecting IT resources in a public cloud environment. Generally, they represent heavy EPP (Endpoint Protection Platform) solutions that also do not allow for necessary customization on the part of cloud provider clients. <\/p>\n<p>It becomes clear that traditional antivirus solutions are poorly suited for cloud environments, as they heavily burden the virtual infrastructure during updates and scans, and they also lack the necessary levels of role management and settings. Next, we will analyze in detail the reasons why the cloud requires new antivirus protection approaches. <\/p>\n<h2>What antivirus should be able to do in the public cloud <\/h2>\n<p>\nLet's focus on the specifics of working in a virtual environment: <\/p>\n<p><b>The effectiveness of conducting updates and mass checks on a schedule.<\/b> If a significant number of virtual machines using traditional antivirus initiate updates simultaneously, a so-called \"update storm\" will occur in the cloud. The resources of the ESXi host, which hosts several virtual machines, may not be sufficient to handle the influx of similar tasks initiated by default. From the cloud provider's perspective, this issue can lead to additional loads on a number of ESXi hosts, ultimately resulting in reduced performance of the cloud's virtual infrastructure. This can also affect the performance of virtual machines belonging to other cloud clients. A similar situation may arise during mass scanning: simultaneous processing of many identical requests from different users by the disk system will negatively impact the performance of the entire cloud. With a high probability, the performance drop of the storage system will affect all clients. Such abrupt loads are not favorable for either the provider or its customers, as they impact the \"neighbors\" in the cloud. From this perspective, traditional antivirus can pose a significant problem.<\/p>\n<p><b>Safe quarantine.<\/b> If a file or document potentially infected with a virus is detected in the system, it is sent to quarantine. Of course, the infected file can be deleted immediately, but this is often unacceptable for most companies. Corporate enterprise antivirus solutions that are not adapted for operation in the provider's cloud generally have a common quarantine area\u2014this is where all infected objects end up. For instance, those found on the computers of the company's users. Cloud provider clients 'live' in their own segments (or tenants). These segments are opaque and isolated: clients are unaware of each other and, of course, cannot see what others are storing in the cloud. It is evident that a document containing confidential information or trade secrets could potentially end up in the shared quarantine, which all users of the cloud antivirus will access. This is unacceptable for both the provider and its clients. Therefore, the solution must be a personal quarantine for each client within their segment, which is inaccessible to neither the provider nor other clients. <\/p>\n<p><b>Individual security policies. <\/b>Each client in the cloud is a separate company, whose IT department establishes its own security policies. For example, administrators set the scanning rules and schedule antivirus checks. Consequently, each organization should have its own management center for configuring antivirus policies. The defined settings must not affect other cloud clients, and the provider should be able to verify that, for instance, antivirus updates are proceeding normally for all of the client's virtual machines. <\/p>\n<p><b>Billing organization and licensing.<\/b> The cloud model is characterized by flexibility and entails payment only for the IT resources that have been used by the customer. If necessary, for example, due to seasonal factors, the volume of resources can be quickly increased or decreased\u2014all based on the current needs for computing power. Traditional antivirus solutions are not as flexible\u2014typically, the client purchases a license for a year for a predetermined quantity. <a class=\"wpil_keyword_link\" href=\"https:\/\/prohoster.info\/en\/server\/\"   title=\"servers\" data-wpil-keyword-link=\"linked\"  data-wpil-monitor-id=\"1274\">servers<\/a> or workstations. Cloud users regularly disconnect and connect additional virtual machines based on their current needs \u2014 accordingly, antivirus licenses must support the same model. <\/p>\n<p>The second question concerns what exactly the license will cover. Traditional antivirus is licensed based on the number of servers or workstations. Licenses based on the number of protected virtual machines are not entirely suitable within the cloud model. A client can create any convenient number of virtual machines from the available resources, for example, five or ten machines. This number is not constant for most clients, and tracking its change is not feasible for us as a provider. Licensing by CPU is not technically possible: clients receive virtual CPUs (vCPU), which is what licensing should be based on. Thus, the new model of antivirus protection should allow the customer to determine the necessary number of vCPUs for which they will receive antivirus licenses. <\/p>\n<p><b>Compliance with legislation.<\/b> An important point, as the solutions used must ensure compliance with the regulator's requirements. For example, cloud 'inhabitants' often work with personal data. In this case, the provider must have a separate certified segment of the cloud that fully meets the requirements of the law on 'Personal Data'. Then companies do not need to 'build' the entire system for handling personal data themselves: acquiring certified equipment, connecting it, and configuring it, and undergoing certification. For cyber protection of personal data processing systems, such clients' antivirus must also comply with the requirements of Russian legislation and have an FSTEC certificate.<\/p>\n<p>We have reviewed the mandatory criteria that antivirus protection must meet in a public cloud. Next, we will share our own experience in adapting an antivirus solution for use in the provider's cloud. <\/p>\n<h2>How to integrate antivirus with the cloud.<\/h2>\n<p>\nBased on our experience, selecting a solution based on descriptions and documentation is one thing, but implementing it in a live cloud environment is quite another challenge in terms of complexity. We will share what we did in practice and how we adapted the antivirus for operation in the provider's public cloud. The vendor for the antivirus solution was Kaspersky, which offers antivirus protection solutions for cloud environments. We settled on 'Kaspersky Security for Virtual Environments' (Light Agent). <\/p>\n<p>It includes a unified Kaspersky Security Center console, a Light Agent, Security Virtual Machines (SVM), and a KSC integration server. <\/p>\n<p>After studying the architecture of the Kaspersky solution and conducting initial tests together with the vendor's engineers, the question of integrating the service into the cloud arose. The first deployment was carried out jointly at the Moscow cloud site. Here\u2019s what we understood. <\/p>\n<p>To minimize network traffic, we decided to place an SVM on each ESXi host and 'bind' the SVMs to the ESXi hosts. In this way, the light agents of the protected virtual machines communicate with the SVM of the ESXi host on which they are running. A separate administrative tenant was chosen for the main KSC. Consequently, the subordinate KSCs are located in the tenants of each individual client and connect to the upper-level KSC, located in the management segment. This scheme allows for quick resolution of issues that arise in the clients' tenants. <\/p>\n<p>In addition to the challenges of setting up the components of the antivirus solution itself, we faced the task of organizing network interaction through the creation of additional VxLANs. Although the solution was initially intended for enterprise clients with private clouds, through engineering ingenuity and the technological flexibility of NSX Edge, we were able to address all issues related to tenant separation and licensing. <\/p>\n<p>We collaborated closely with Kaspersky engineers. During the analysis of the solution's architecture regarding network interaction between the system components, it was established that, in addition to access from lightweight agents to the SVM, feedback from the SVM to lightweight agents is also required. This network connectivity is impossible in a multitenant environment due to the possibility of identical network configurations of virtual machines existing in different tenants of the cloud. Therefore, at our request, the vendor's colleagues reworked the network interaction mechanism between the lightweight agent and the SVM to eliminate the need for network connectivity from the SVM to the lightweight agents.<\/p>\n<p>After the solution was deployed and tested at the Moscow cloud site, we replicated it to other sites, including the certified segment of the cloud. The service is now available in all regions of the country. <\/p>\n<h2>Architecture of the Information Security solution within the new approach<\/h2>\n<p>\nThe overall scheme of the antivirus solution in a public cloud environment is as follows:<\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/ce43f6ad32fc287cc593f11fea3c4b6c.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>The operational scheme of the antivirus solution in a public cloud environment #CloudMTS<\/i><\/p>\n<p>Let's describe the features of the operation of individual elements of the solution in the cloud: <\/p>\n<p>\u2022 A unified console that allows clients to centrally manage the protection system: run checks, monitor updates, and observe quarantine zones. There is an option to configure individual security policies within their segment. <\/p>\n<p>It should be noted that while we are a service provider, we do not interfere with the settings established by our clients. The only thing we can do is reset security policies to their defaults if reconfiguration is necessary. For instance, this may be needed if a client accidentally tightened them or significantly loosened them. Companies can always obtain a management center with default policies that can then be configured independently. The downside of Kaspersky Security Center is that currently, the platform is available only for the Microsoft operating system. However, lightweight agents can work with both Windows and Linux machines. However, Kaspersky Lab promises that KSC will be operational under Linux OS soon. One important feature of KSC is the ability to manage quarantine. Each client company in our cloud has its own personalized quarantine. This approach eliminates situations where a virus-infected document accidentally becomes visible to everyone, as might happen with a traditional corporate antivirus with a shared quarantine.<\/p>\n<p>\u2022 Lightweight agents. In the new model, a lightweight Kaspersky Security agent is installed on each virtual machine. This eliminates the need to store the antivirus database on every VM, reducing disk space usage. The service is integrated with the cloud infrastructure and operates via SVM, enhancing the density of virtual machines on the ESXi host and the performance of the entire cloud system. The lightweight agent creates a task queue for each virtual machine: to check the file system, memory, etc. However, SVM is responsible for executing these operations, which we will discuss next. Additionally, the agent performs firewall functions, controls security policies, sends infected files to quarantine, and monitors the overall \u201chealth\u201d of the operating system on which it is installed. All of this can be managed through the aforementioned unified console. <\/p>\n<p>\u2022 Security Virtual Machine. All resource-intensive tasks (updating antivirus databases, scheduled checks) are handled by a separate Security Virtual Machine (SVM). It is responsible for the operation of a full-fledged antivirus engine and its databases. The company's IT infrastructure may include several SVMs. This approach increases system reliability \u2013 if any machine fails and doesn't respond for thirty seconds, agents automatically begin searching for another. <\/p>\n<p>\u2022 KSC Integration Server. One of the components of the main KSC, which assigns its SVMs to lightweight agents according to the algorithm set in its configuration, and also monitors the availability of SVMs. Thus, this software module ensures load balancing across all SVMs in the cloud infrastructure. <\/p>\n<h2>Cloud operation algorithm: reducing the load on the infrastructure. <\/h2>\n<p>\nOverall, the antivirus operation algorithm can be represented as follows. The agent accesses a file on the virtual machine and checks it. The result of the check is stored in a common centralized verdict database of the SVM (called Shared Cache), where each entry identifies a unique file specimen. This approach helps ensure that the same file is not checked repeatedly (for example, if it is opened on different virtual machines). A file is rescanned only if it has been modified or if the check was initiated manually.<\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/d1741e0176af0cadafd7e286259eab32.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Implementation of the antivirus solution in the provider's cloud.<\/i><\/p>\n<p>The image shows a general scheme of the solution implemented in the cloud. The main Kaspersky Security Center is deployed in the management zone of the cloud, and on each ESXi host, an individual SVM is deployed using the KSC integration server (each ESXi host has its own SVM tied to special settings on VMware vCenter Server). Clients operate in their cloud segments, where virtual machines with agents are located. They are managed through individual KSC servers subordinate to the main KSC. If protection for a small number of virtual machines (up to 5) is needed, the client may be provided access to the virtual console of a dedicated KSC server. Network interaction between client KSCs and the main KSC, as well as lightweight agents and SVM, is facilitated through NAT via client virtual routers EdgeGW.<\/p>\n<p>According to our estimates and the results of vendor testing, the Lightweight agent reduces the load on clients' virtual infrastructure by about 25% (compared to a system using traditional antivirus software). Specifically, the standard Kaspersky Endpoint Security (KES) for physical environments consumes almost twice as much server CPU time (2.95%) compared to the virtualization solution based on lightweight agents (1.67%).<\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/376e66b285c716718f271adf0516723b.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>CPU Load Comparison Chart<br \/>\n<\/i><br \/>\nA similar situation is observed with the disk write access frequency: for the classic antivirus, it is 1011 IOPS, while for the cloud antivirus, it is 671 IOPS.<\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/52acb9423ca10f2b532f5b79ccb61818.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<i>Disk Access Frequency Comparison Chart<br \/>\n<\/i><br \/>\nThe performance gain allows for maintaining infrastructure stability and more efficient utilization of computing power. Due to its adaptation for operation in a public cloud environment, the solution does not decrease cloud performance: it performs centralized file scanning and updates distribution of load. This means that, on one hand, current threats relevant to the cloud infrastructure will not be missed, and on the other hand, resource requirements for virtual machines will be reduced by an average of 25% compared to traditional antivirus.<\/p>\n<p>Both solutions are very similar in functionality: the comparative table is provided below. However, as the testing results above show, it's still more optimal to use a solution for virtual environments in the cloud. <\/p>\n<p><img decoding=\"async\" alt=\"Why Traditional Antivirus Solutions Are Unsuitable for Public Clouds, and What to Do About It?\" src=\"\/wp-content\/uploads\/2019\/10\/e46787ae67d4f1cf6d237a06da150d39.jpg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\n<b>About the billing in the new approach.<\/b> We decided to utilize a model that allows licenses to be acquired based on the number of vCPUs. This means that the number of licenses will equal the number of vCPUs. The antivirus can be tested by submitting a request. <noindex><a rel=\"nofollow\" href=\"https:\/\/cloud.mts.ru\/?utm_source=SiteMTS&amp;utm_medium=cpc&amp;utm_campaign=habr1\">on the website<\/a><\/noindex>. <\/p>\n<p>In the next piece on cloud topics, we will discuss the evolution of cloud WAF and what is better to choose: hardware, software, or cloud. <\/p>\n<p><i>The text was prepared by the staff of cloud provider #CloudMTS: Denis Myagkov, Lead Architect, and Alexey Afanasev, Product Development Manager for Information Security. <\/i><\/p>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/ru_mts\/blog\/472892\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0412\u0441\u0435 \u0431\u043e\u043b\u044c\u0448\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432\u044b\u0432\u043e\u0434\u044f\u0442 \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u0435 \u043e\u0431\u043b\u0430\u043a\u043e \u0432\u0441\u044e \u0441\u0432\u043e\u044e \u0418\u0422-\u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443. \u041e\u0434\u043d\u0430\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0432 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0435 \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u044e\u0442 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043a\u0438\u0431\u0435\u0440-\u0440\u0438\u0441\u043a\u0438. \u041f\u0440\u0430\u043a\u0442\u0438\u043a\u0430 \u043f\u043e\u043a\u0430\u0437\u044b\u0432\u0430\u0435\u0442, \u0447\u0442\u043e \u0434\u043e 80% \u0441\u0443\u0449\u0435\u0441\u0442\u0432\u0443\u044e\u0449\u0438\u0445 \u0432\u0438\u0440\u0443\u0441\u043e\u0432 \u043e\u0442\u043b\u0438\u0447\u043d\u043e \u0436\u0438\u0432\u0443\u0442 \u0432 \u0432\u0438\u0440\u0442\u0443\u0430\u043b\u044c\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435. \u0412 \u044d\u0442\u043e\u043c \u043f\u043e\u0441\u0442\u0435 \u0440\u0430\u0441\u0441\u043a\u0430\u0436\u0435\u043c \u043e \u0442\u043e\u043c, \u043a\u0430\u043a \u0437\u0430\u0449\u0438\u0442\u0438\u0442\u044c \u0418\u0422-\u0440\u0435\u0441\u0443\u0440\u0441\u044b \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u043c \u043e\u0431\u043b\u0430\u043a\u0435 \u0438 \u043f\u043e\u0447\u0435\u043c\u0443 \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u044b \u043d\u0435 \u0441\u043e\u0432\u0441\u0435\u043c \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0442 \u0434\u043b\u044f \u044d\u0442\u0438\u0445 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":39335,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[688],"tags":[],"class_list":["post-39334","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-administrirovanie"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0412\u0441\u0435 \u0431\u043e\u043b\u044c\u0448\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432\u044b\u0432\u043e\u0434\u044f\u0442 \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u0435 \u043e\u0431\u043b\u0430\u043a\u043e \u0432\u0441\u044e \u0441\u0432\u043e\u044e \u0418\u0422-\u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443. \u041e\u0434\u043d\u0430\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0432 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0435 \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u044e\u0442 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043a\u0438\u0431\u0435\u0440-\u0440\u0438\u0441\u043a\u0438.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u041f\u043e\u0447\u0435\u043c\u0443 \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u044b \u043d\u0435 \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0442 \u0434\u043b\u044f \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0445 \u043e\u0431\u043b\u0430\u043a\u043e\u0432. \u0418 \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0442\u044c? | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0412\u0441\u0435 \u0431\u043e\u043b\u044c\u0448\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432\u044b\u0432\u043e\u0434\u044f\u0442 \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u0435 \u043e\u0431\u043b\u0430\u043a\u043e \u0432\u0441\u044e \u0441\u0432\u043e\u044e \u0418\u0422-\u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443. \u041e\u0434\u043d\u0430\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0432 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0435 \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u044e\u0442 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043a\u0438\u0431\u0435\u0440-\u0440\u0438\u0441\u043a\u0438.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T19:30:19+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T19:30:19+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Why traditional antivirus solutions are unsuitable for public clouds. And what to do? | ProHoster","description":"More and more users are moving their entire IT infrastructure to the public cloud. However, in cases of inadequate antivirus protection within the client's infrastructure, serious cyber risks arise.","canonical_url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u041f\u043e\u0447\u0435\u043c\u0443 \u0442\u0440\u0430\u0434\u0438\u0446\u0438\u043e\u043d\u043d\u044b\u0435 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u044b \u043d\u0435 \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0442 \u0434\u043b\u044f \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u044b\u0445 \u043e\u0431\u043b\u0430\u043a\u043e\u0432. \u0418 \u0447\u0442\u043e \u0434\u0435\u043b\u0430\u0442\u044c? | ProHoster","og:description":"\u0412\u0441\u0435 \u0431\u043e\u043b\u044c\u0448\u0435 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439 \u0432\u044b\u0432\u043e\u0434\u044f\u0442 \u0432 \u043f\u0443\u0431\u043b\u0438\u0447\u043d\u043e\u0435 \u043e\u0431\u043b\u0430\u043a\u043e \u0432\u0441\u044e \u0441\u0432\u043e\u044e \u0418\u0422-\u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0443. \u041e\u0434\u043d\u0430\u043a\u043e \u0432 \u0441\u043b\u0443\u0447\u0430\u0435 \u043d\u0435\u0434\u043e\u0441\u0442\u0430\u0442\u043e\u0447\u043d\u043e\u0441\u0442\u0438 \u0430\u043d\u0442\u0438\u0432\u0438\u0440\u0443\u0441\u043d\u043e\u0433\u043e \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u044f \u0432 \u0438\u043d\u0444\u0440\u0430\u0441\u0442\u0440\u0443\u043a\u0442\u0443\u0440\u0435 \u0437\u0430\u043a\u0430\u0437\u0447\u0438\u043a\u0430 \u0432\u043e\u0437\u043d\u0438\u043a\u0430\u044e\u0442 \u0441\u0435\u0440\u044c\u0435\u0437\u043d\u044b\u0435 \u043a\u0438\u0431\u0435\u0440-\u0440\u0438\u0441\u043a\u0438.","og:url":"https:\/\/prohoster.info\/en\/blog\/administrirovanie\/pochemu-traditsionnye-antivirusy-ne-podhodyat-dlya-publichnyh-oblakov-i-chto-delat","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T19:30:19+00:00","article:modified_time":"2019-10-31T19:30:19+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"39334","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-02-09 18:02:23","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 00:51:28","updated":"2026-02-09 18:02:23","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/39334","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=39334"}],"version-history":[{"count":1,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/39334\/revisions"}],"predecessor-version":[{"id":158518,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/39334\/revisions\/158518"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/39335"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=39334"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=39334"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=39334"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}