sandra_gittlen
Contributing Writer

The biggest security challenges ahead

Feature
Mar 21, 20053 mins

Six researchers answer the question, “What are the most critical security issues facing IT?”

“A big challenge for IT managers will be cross-site scripting attacks. Hackers are able to corrupt SQL queries in Web forms and preempt what an application is intended to do. We don’t have tools to stop that and it requires an understanding of what the interface needs to do to block the attack.”

– Fred Schneider, director of the Information Assurance Institute at Cornell University, Ithaca, N.Y.

“Radio frequency ID tags are going to be very easily hacked. That has serious implications because use of these tags is being proposed in a lot of applications . . . . RFID technology should not be moved into high-security applications without attention to authentication protocols and repudiation methods.”

Mich Kabay, associate professor for information assurance at Norwich University, Northfield, Vt.

“The trustworthiness of an automated system is tied to the integrity and quality of the information that is shared between systems. This requires new trust models and identity constructs. In some instances, messages will be sent by entities that are unable to provide strong credentials in the form of digital certificates. Automated systems will need to be able to infer trust based on other types of indicators.”

– Bob Gleichauf, CTO, Cisco’s Security Technology Group

“Spam on wireless devices is going to be a significant challenge. CIOs are paying to download every megabyte of data across multiple channels. They don’t want to bear that cost. These devices are just not secure enough for the mass market yet.”

– Dave Steer, director of segment marketing, ARM

“The privacy issue is going to be more complicated because Big Brother can know who is doing what, where, how and when. Integration of biometrics in security is going to be much tighter. . . . And there are going to be more devices to secure and more systems that are going to require different types of access and control. I’d like to think that there’s going to be distributed systems where you can write policies to provide controls to these devices.”

– Sharon Besser, director of security solutions, Check Point

“The problem is that a majority of enterprise data is no longer on servers – it’s on the clients. The bad point of this is that a lot of security threats emanate from clients. I’d worry less about the man-in-the-middle sniffing and more about the endpoints and people walking off with laptops.”

– Charles Palmer, department manager for security, networking and privacy, IBM Research