Skip Links

Network World

  • Social Web 
  • Email 
  • Close

(Comma separation for multiple addresses)
Your Message:

The year ahead: Juggling IT risks, opportunities

By Network World staff , Network World , 01/03/2007
  • Share/Email
  • Tweet This
  • Comment
  • Print

There's a four-letter word IT pros know all too well: risk.

In 2007, IT executives will need to clearly evaluate risk as they weigh sometimes opposing proposals to bolster security, increase wireless connectivity, extend more business processes over the Internet and address regulatory requirements.

In the end it's a balancing act. To help tip the scales in your favor, we've put together a preview of what the year ahead holds in key technology areas.

For starters, security will be no less challenging in 2007 than last year, when plagues of bots, spam and phishing attacks threatened corporate environs. This year, in addition to generic phishing, enterprises will have to contend with custom Trojans and spear-phishing, aimed at specific individuals or corporations.

"The year 2007 is going to be the year of the custom-Trojan attacks," says Richard Stiennon, chief marketing officer at Fortinet. "These Trojans, which will be targeted at the help desk at a bank, for instance, will avoid being detected by the signature base. Traditional antivirus signatures will be increasingly futile."

"Malicious code won't go away, but attackers will shift their attention to social-based engineering attacks," predicts Oliver Friedrichs, director of emerging technologies at Symantec's Security Response division. This means using every trick in the book to fool a victim into thinking an attacker is a trusted source.

If that's not enough, some say the adoption of VoIP technology, which is subject to denial-of-service and stolen capacity, may lead to disruptions in traditional circuit-switched telephony as well.

"More trouble is yet to come in VoIP, and hackers are going to gain complete control over your VoIP network," says Rohit Dhamankar, senior security manager at 3Com.

Trends for '07
For 2007, technologies such as standards-based IP PBX systems and Web-based applications are waxing, while others are waning.

What's hot What's not
Initiation Session Protocol-based standards for IP PBX systems Proprietary VoIP protocols
Telepresence Videoconferencing
Custom Trojan attacks Traditional antivirus defenses
Dual-mode cellular and WiFi devices Single-function devices
Software-as-a-service Monolithic application platforms
Enterprise service buses Enterprise application integration
Click to see:

Because VoIP servers "are interfacing with traditional ‘old phone' networks," he points out, hackers are likely to launch attacks through VoIP that will seriously affect the telecom infrastructure, such as Signaling System 7 for call setup. The result: downtime and criminal exploitation of the circuit-switched phone system through VoIP.

Other trends, says Friedrichs, can be traced to Web 2.0 technologies, such as AJAX, which support very flexible access to server resources behind the corporate firewall. This very flexibility appears likely to facilitate a new genre of exploits that will be difficult to detect and analyze, he notes.

Meanwhile, with Microsoft's Vista was expected to begin to gain a footprint in the enterprise and on consumer desktops in 2007, all eyes will be watching how well it holds up without patching. So far, some are at least optimistic. "Microsoft has made significant improvements in the core operating system," Friedrichs says.

  • Share/Email
  • Tweet This
  • Comment
  • Print

Partner Content

Blue Stripe Software

www.bluestripe.com/

Improving Application Performance Troubleshooting

Diagnosing why an application is slow is hard, at times taking days or weeks to isolate and resolve. This paper explains the challenges involved using current management tools, provides a 'wish list' for application management and analysis, and explains the need for an application system-wide approach that monitors entire applications, not components.

Download Whitepaper

Virtual Vigilance: Managing Application Performance in Virtual Environments

This paper highlights the impact of virtualization on application performance.  "Managing Application Performance in Virtual Environments" states: "Best-in-Class organizations are predominately taking actions around improving visibility across both physical and virtual systems, assessing the business impact of application performance and understanding interdependencies of applications in virtualized environments."

Download Whitepaper

Application Service Requests: The Missing Link for Pragmatic ITSM

Forrester Research analyst Glenn O'Donnell and BlueStripe co-founder Vic Nyman discuss a breakthrough approach to application problem management. Learn the new approach for ITSM problem management, which provides: Rapid isolation of application slow-downs to specific components for quick problem resolution, 24/7 monitoring for proactive notification of potential issues before end users are impacted and much more.

Register for Webcast

Comment
Login
Forgot your account info?
Add comment
Anonymous comments subject to approval. Register here for member benefits.
Have a NetworkWorld account? Log in here. Register now for a free account.

Videos

rssRss Feed