Security risks from mobile devices, cyberattacks, organized criminals

Opinion
Dec 6, 20043 mins

* Top 10 security issues for 2005, according to Unisys

As the year 2004 draws to a close, we’re spending the next few issues examining the top 10 security issues for 2005 as predicted by the prognosticators at Unisys. The full list can be found in last week’s newsletter (see link below). Today we want to look at No.s 3, 4 and 5.

No. 3 is “The mobile realm will continue to grow as a Petri dish for security incidents.”

What Unisys means is the explosive growth of wireless mobile devices (phones, PDAs and more) equipped with less-than-secure protocols such as Bluetooth. If you aren’t familiar with the ramifications of the Bluetooth protocol, listen to the tutorial (https://www.elusivefresh.com/bluetooth-noel.mp3) given by Microsoft’s Noel Anderson, especially the part about a “personal bomb” (and thanks to Microsoft’s Kim Cameron for making this available).

We sometimes lament that Microsoft ignored the business market in favor of the consumer market for far too long, but cell phone service providers and manufacturers are even worse at this – and their target market is pre-teens and teenagers. Not a security conscious group. I do fear that prediction No. 3 is right on the mark.

No. 4 is “Cyberattack styles will become virulent.” This predicts an order of magnitude increase in the maliciousness of worms, viruses and Trojan Horses. The past couple of years have seen the proliferation of what could be called the “hey, look at me” style of attack. They clogged the network, and boasted about their creators, but did no lasting damage. Unisys security honcho Sunil Misra thinks that’s going to change, and change soon as the malware creators do more malicious damage to get attention.

Attacks may also be targeted at the record, rather than the file, level causing disruption to your carefully crafted disaster recovery programs. By the time you find the records that have been altered or removed, it may be too late to re-create a true image of the data.

No. 5, “Organized attacks by Internet desperados will increase,” goes hand in hand with No. 4. As egomaniacal malware authors (and script kiddies) escalate their attacks, a real criminal element will seek to take advantage of the situation for material gain. The identity theft problem of the last couple of years may, in retrospect, seem “quaint” as organized criminals attempt to wreak havoc with the world’s finances. And oh, by the way, they’ll show no compunction at destroying your enterprise’s data should you not succumb to their extortionist demands. Unisys sees a worldwide cyber data “protection racket” being launched in the next year.

It’s certainly a group of “doom and gloom” predictions – and there are five  more to come. Well, the second five really predict the solutions organizations will adopt to fight the first five. We’ll examine those over the next couple of issues.