Web 2.0 Tops 'Emerging Cyber Threats'

The ever-nebulous "Web 2.0" is emerging as one of the five top security risks to watch for both consumers and the enterprise--this according to the inaugural edition of the "GTISC Emerging Cyber Threats Report for 2008" out of Georgia Tech's Information Security Center. The report, released at the GTISC Security Summit on Emerging Cyber Security Threats and Countermeasures, identifies the key data security threats that are likely to expand and evolve in the coming year.

According to the report, the chief motivator for all of the top emerging threats will continue to be financial gain, taking advantage of holes in continually advancing applications whose development has been, to date, outpacing the development of countermeasures.

Commenting on the report, GTISC Director Mustaque Ahamad said, “As newer and more powerful applications enabled by technologies like Web 2.0 continue to grow, and converged communications applications increasingly rely on IP-based platforms, new challenges will arise in safegaurding these applications and the services they rely on. The GTISC Emerging Cyber Threats Report for 2008 highlights those areas of greatest risk and concern, particularly as continued convergence of enterprise and consumer technologies is expected over the coming year."

The report listed five broad categories of data security risk, cited below:
  • Web 2.0 and client-side attacks on social networking technologies, aimed at "stealing private data, hijacking Web transactions, executing phishing scams, and perpetrating corporate espionage;"
  • Targeted messaging attacks, aimed at individual users, largely for the purpose of stealing authentications and private data;
  • Botnets expanding the scope of their activities to the theft of information and increasing abuse of DMS servers;
  • Mobile convergence threats, including "vishing," "smishing," and voice spam, plus denial of service attacks targeting voice infrastructure; and
  • RFID attacks, including automated exploitation tools for tracking users via RFID devices, cloning, RF blocking, and even a form of tunneling in which commands, such as SQL queries, might be submitted to an RFID reader.
The predictions, however, are not all dire. The GTISC suggests that in the coming year the gap between application development and security and countermeasure development will begin to narrow as coordination between the "security industry, carriers, Internet Service Providers, application developers, and the user community" increases.

More information, including the complete report, can be found at the links below.

Read More:

About the Author

David Nagel is the former editorial director of 1105 Media's Education Group and editor-in-chief of THE Journal, STEAM Universe, and Spaces4Learning. A 30-year publishing veteran, Nagel has led or contributed to dozens of technology, art, marketing, media, and business publications.

He can be reached at [email protected]. You can also connect with him on LinkedIn at https://www.linkedin.com/in/davidrnagel/ .


Featured

  • abstract illustration of artificial intelligence

    CSU Shares AI Learnings in Systemwide Survey

    In a systemwide survey of more than 94,000 faculty, staff, and students, California State University recently documented widespread AI use across its 22 campuses.

  • AI logo near computer equipment

    White House Releases National Policy Framework for AI

    The White House has released a four-page AI policy framework aimed at setting a national approach to AI, with priorities including child safety, intellectual property protections, truth and accuracy guardrails, and worker training for an AI-driven economy.

  • Dana Brunson facilitates a roundtable discussion with research and higher education IT leaders

    Internet2: Closing the Access Gap for Research Cyberinfrastructure

    Internet2's Research Engagement Team brings CIOs and other campus technology leadership together with research computing and data facilitators, forming a community that enables research cyberinfrastructure at institutions of all types and sizes.

  • Silhouettes of business professionals stand against a blurred futuristic city skyline at night, with a glowing digital network data connection

    It's Time for Higher Ed to Get Serious About AI Strategy

    Without a coordinated strategy that involves multiple academic and administrative units across the entire campus, colleges risk wasting resources, duplicating efforts, and ultimately failing to deliver on the promise of deploying technology to improve learning and operations.