Subscribe to our e-mail newsletters
For more info on a specific newsletter, click the title. Details will be displayed in a new window.
Finance
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
More E-Mail Newsletters 
Computerworld 2007Subscribe to Computerworld
40 years of the most authoritative source of news and information for IT leaders.

Web services, Internet collaboration pose security challenges for 2002

Jaikumar Vijayan   Today’s Top Stories    or  Other Security Stories  
 

Sign up to receive Security Resource Alerts

January 03, 2002 (Computerworld) -- The increased use of videoconferencing and Internet-collaboration technologies, the rush toward Web services and an emerging class of malicious code that blends virus and wormlike capabilities represent some of the biggest security challenges for 2002, according to analysts.

As was the case last year, users can also expect to see a sharp increase in the number of macro and script viruses that emerge in 2002. But major antivirus software programs should be able to handle most malicious software relatively easily.

"The bottom line of malware prevention remains the same: filter, patch strategically and update your antivirus software," said Roger Thompson, an analyst at Herndon, Va.-based security firm TruSecure Corp. "Use common sense to protect your network's vulnerabilities."

The rush by corporations to set up videoconferencing and Web seminar capabilities after the Sept. 11 terrorist attacks on the U.S. presents a particularly serious security risk for companies that aren't careful, said John Pescatore, an analyst at Stamford, Conn.-based Gartner Inc.

Users can expect to see at least one widespread attack this year that tries to exploit openings in enterprise firewalls created by the frantic push to set up these capabilities, Pescatore said.

The accelerating efforts by corporations to link their internal applications with those belonging to external partners and suppliers using technologies such as XML and Simple Object Access Protocol are another source of concern, he said.

Increasingly, companies are opening new ports on their firewalls to let outside applications talk with inside applications, "even though the security aspects of doing so are totally unproven," Pescatore said.

"The rush toward Web services will result in glaring holes," he said. "2002 is not the year to jump on Web services."

Malicious code that blends virus and wormlike features and is designed to take advantage of multiple software vulnerabilities also poses a major threat, said Thompson.

One example of this emerging threat was last year's Nimda worm, which wreaked havoc on enterprise networks around the world (see story). Unlike previous-generation malware, Nimda spread via both the Internet and e-mail, taking advantage of multiple vulnerabilities.

Expect to see more sophisticated variants of Nimda this year, Thompson said. Dealing with them will require constant attention to patching and updating of antivirus suites, he said.

Wireless security will also emerge as a major concern this year, said David Lelievre, a project manager at Clinton Township, Mich.-based application service provider Tweddle Information Services Inc.

"The wireless Internet will emerge as the leading trend for the next three to five years," Lelievre said. "Security will have to be defined and established before the market hits full force."

People should also expect a lot of vendor consolidation this year, especially in the managed security services arena, said Eric Hemmendinger, an analyst at Boston-based Aberdeen Group Inc.

Corporations that are getting into first-time relationships with security vendors need to pay special attention to the financial stability of the company and its customer base, he warned.

"We are going to see some very public debacles in the security space this year," Hemmendinger said. "The caution here for users is you can't afford not to do due diligence" before choosing a security vendor, he said.

Related stories:




Print this Story Send Us Feedback E-mail this Story Digg! Digg this Story Slashdot this Story
"This company's infrastructure group is running a disaster recovery exercise with a reluctant participant: an IT manager who's notorious as..." Read more...
"It's IT Blogwatch: in which Mozilla's Firefox Web browser continues to gain market share, smashing records as it does so...." Read more...
Read more Security posts or See all Blogs
Microsoft promises four patches next week
Google gives away home-cooked Web application security scanner
Expect iPhone, Fourth of July scams, security firm says
More top stories...
Microsoft trumpets security additions in upcoming IE8
Apple cuts price of high-end SSD MacBook Air by $500
Ultrathin showdown: Apple MacBook Air vs. Lenovo ThinkPad X300 vs. Toshiba Portege R500
All it takes is a couple hours and about $125 to breathe new life into an old laptop. Here's how.
Is Microsoft's Golden Age over? What are Gates' most memorable quotes? Find out in Computerworld's complete coverage of the end of the Bill Gates era at Microsoft.
There are some things your CIO definitely doesn't want to hear. Also don't miss the flipside, Five things you should always tell your boss.
With its latest version, Mozilla's browser continues to raise the bar for what Web browsers should be.
Reviews, analyses, how-tos, visual tours, hot issues and predictions about Microsoft's new OS.
Four years from now, the IT field will be a vastly different place. Will you be ready?
All Zones
Application Performance Zone
Business Continuity Zone
Data Center Management Zone
Enterprise-Class Security Zone
The File Data Management Zone
Grid Computing on Windows Zone
Security Management Zone
ITIL Best Practices Zone
The SAS Zone
Storage Virtualization Zone
Business Intelligence and Analytics Zone

Ads by TechWords

See your link here
Why SaaS is Vital to Email and Web Security
Why SaaS is Vital to Email and Web Security
Download this webcast, free, compilments of Webroot Software
Go to the webcast 
Computerworld Executive Bulletin: Building a Robust Antivirus Defense
Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs.
(Source: MessageLabs) Antivirus software alone isn't enough to prevent today's speedy, sophisticated virus attacks. Security managers should consider multitiered approaches that include behavior scanning, appliances that check e-mail for worms, and restricting user access to dangerous Web sites. Download this Executive Bulletin (a $49.95 value) for free, compliments of MessageLabs, to learn more.
Download this executive briefing download
Eliminate SPAM, Gain Productivity
Get this white paper now!
(Source: MessageLabs) Learn all about the dangers and the costs of spam in all its forms - from stock-touting to spreadsheet. Also, understand the drawbacks of traditional hardware- and software-based defenses - and the unique benefits of MessageLabs multi-layered, managed Anti-Spam solution; as illustrated by a real-world case study where MessageLabs stopped spam cold.
Download this white paper go
White Papers
Read up on the latest ideas and technologies from companies that sell hardware, software and services.
Deploying Virtualized NetWare on Linux Whitepaper
Toward More Flexible, Next-Generation Collaboration Solutions
Driving Business Success Through Workgroup Choice and Flexibility
View more whitepapers