Click here to receive your FREE subscription to Campus Technology
Home > Web 2.0 Tops 'Emerging Cyber Threats'
News
Web 2.0 Tops 'Emerging Cyber Threats'
10/9/2007
By David Nagel
The ever-nebulous "Web 2.0" is emerging as one of the five top security risks to watch for both consumers and the enterprise--this according to the inaugural edition of the "GTISC Emerging Cyber Threats Report for 2008" out of Georgia Tech's Information Security Center. The report, released at the GTISC Security Summit on Emerging Cyber Security Threats and Countermeasures, identifies the key data security threats that are likely to expand and evolve in the coming year.
According to the report, the chief motivator for all of the top emerging threats will continue to be financial gain, taking advantage of holes in continually advancing applications whose development has been, to date, outpacing the development of countermeasures.
Commenting on the report, GTISC Director Mustaque Ahamad said, “As newer and more powerful applications enabled by technologies like Web 2.0 continue to grow, and converged communications applications increasingly rely on IP-based platforms, new challenges will arise in safegaurding these applications and the services they rely on. The GTISC Emerging Cyber Threats Report for 2008 highlights those areas of greatest risk and concern, particularly as continued convergence of enterprise and consumer technologies is expected over the coming year."
The report listed five broad categories of data security risk, cited below:
- Web 2.0 and client-side attacks on social networking technologies, aimed at "stealing private data, hijacking Web transactions, executing phishing scams, and perpetrating corporate espionage;"
- Targeted messaging attacks, aimed at individual users, largely for the purpose of stealing authentications and private data;
- Botnets expanding the scope of their activities to the theft of information and increasing abuse of DMS servers;
- Mobile convergence threats, including "vishing," "smishing," and voice spam, plus denial of service attacks targeting voice infrastructure; and
- RFID attacks, including automated exploitation tools for tracking users via RFID devices, cloning, RF blocking, and even a form of tunneling in which commands, such as SQL queries, might be submitted to an RFID reader.
The predictions, however, are not all dire. The GTISC suggests that in the coming year the gap between application development and security and countermeasure development will begin to narrow as coordination between the "security industry, carriers, Internet Service Providers, application developers, and the user community" increases.
More information, including the complete report, can be found at the links below.
Read More:
About the author: Dave Nagel is the executive editor for 1105 Media's educational technology online publications and electronic newsletters. He can be reached at dnagel@1105media.com.
Have any additional questions? Want to share your story? Want to pass along a news tip? Contact Dave Nagel, executive editor, at dnagel@1105media.com.
Cite this Site
David Nagel, "Web 2.0 Tops 'Emerging Cyber Threats' ," Campus Technology, 10/9/2007, http://www.campustechnology.com/article.aspx?aid=51890
copy text (above) for proper citation
Recommended Reading
- California Community Colleges Partner with Waterfall Mobile on Statewide Emergency Notification Coverage
The Foundation for California Community Colleges (FCCC) has awarded a statewide emergency alert notification contract to Waterfall Mobile. The contract establishes Waterfall's AlertU as an approved technology through the official non-profit foundation for the California Community College (CCC) system office. Through this partnership, individual colleges may directly implement emergency communication services, eliminating lengthy technology evaluation and RFP processes.
- King's College and ASU Add e2Campus for Improved Emergency Notifications
King's College and Arizona State University have switched to Omnilert's e2Campus for emergency notification. Omnilert also has introduced a new program called the ENS Conversion Service that allows schools to bulk upload data from their previous emergency notification system into e2Campus at no charge.
- Saint Joseph Builds Out Wireless Network in Multi-year Upgrade
Saint Joseph's University has begun deploying a Meru Networks wireless local area network across its Philadelphia campus as part of a multi-year effort to bring wireless coverage to every building on campus.
- Vista Ramp Up Is Happening Now, Study Says
Organizations may have been slow to adopt Microsoft Windows Vista, but expect that to change by late 2008 to 2009, according to a Forrester Research report by Benjamin Gray et al., published last week.
- Talisma Launches New Version of CRM with Built-in Application Management
Talisma Corp. announced version 8.0 of its constituent relationship management (CRM) application for higher education. The new release includes application management, a revamped user interface, two-way text messaging, personalized Web portals, and an ADA-compliant Web client, among other enhancements.
- Bringing Composers into Classrooms Through Skype
Two Pennsylvania teaching colleagues with an interest in music and technology are bringing remote experts into classrooms at almost no cost, using Skype's free videoconferencing technology.