Skip to content

CyberSecurity Institute

Security News Curated from across the world

Menu
Menu

Category: Trends

Boom times ahead for IT security profession

Posted on November 9, 2004December 30, 2021 by admini

Approximately 680,000 of this expanded workforce will work in Europe.

IDC analysed responses from 5,371 full-time information security professionals in 80 countries worldwide, with nearly half employed by organisations with $1bn or more in annual revenue. The web-based study is described as the first major study of the global information security profession ever undertaken.

On average survey respondents had 13 years work experience in IT and seven years specialised security experience. This wealth of skill is often well rewarded.

Around 10 per cent of the survey participants in both the US earned more than $125,000 per annum; 22 per cent of US residents who took part in the survey earned between $100,000-$120,000 a year (Europe 16 per cent).

At the other end of the scale, five per cent of security pros in the states and nine per cent in Europe earn less than $50,000.

In Asia, 60 per cent of security professionals earn less than $50,000.

Managers hiring security professionals (93 per cent) said certification was important in choosing potential recruits; but commercial awareness is also becoming increasingly important.

“The study shows a shift in the information security profession, indicating that business acumen is now often required along with technology proficiency,” said Allan Carey, the IDC analyst who led the study. “This widening responsibility means information security professionals not only have to receive a constant refresh of the best security knowledge but also must acquire a solid understanding of business processes and risk management to be successful in their roles.”

“With competing demands on industry and government to expand access to services and information, the highly trained and experienced information security professional must now be an active participant to fulfil stringent regulatory requirements and provide proactive solutions to circumvent emerging risks,” he added.

http://www.theregister.co.uk/2004/11/09/isc2_security_job_survey/

Read more

Trends in Web Application Security

Posted on October 27, 2004December 30, 2021 by admini

This article highlights both technical and business trends in web application security.

Traditionally, vulnerability analysis (and its management) has been focused at the network or operating system level. Trends are leaning towards merging the ability to scan for network vulnerabilities and application-level vulnerabilities together. The goal in this merging of network and application vulnerability analysis is the ability to use data found from one level and drive a more focused approach for the other level.

Another key area where we will see more integration is in the area of network management consoles. Currently, most consoles are geared towards soliciting network device information (e.g. firewalls). On the network side, consoles can be set up to attach patch management solutions to notifications of problem detection. However, many web applications are proprietary and thus unique to a particular customer or department within a large corporation.

Mercury Interactive, a major player in automated testing tools, recently announced partnerships with some leading application security testing companies that provide an integrated solution between Mercury’s testing products and the vendors’ application vulnerability detection tools. Some vendors have created development tools for enhancing code security, but to date, sales of these tools have been relatively poor. In addition, most of these code scanning tools are unable to provide complete application awareness and can only focus on a specific module of code.

This has started to prompt some awareness in the developer community. However, it is still too early for application tools to incorporate sophisticated integration, as web application security analysis still lies primarily in the hands of security professionals such as penetration testers, QA engineers, and auditors.

While no formal direction has yet been established, industry trade groups, such as the Information Technology Association of America (ITAA), are anticipated to start providing guidelines for web application security for offshore code.

With the rise of cross-site scripting (XSS) attacks, tools are still only focused on inline detection (the ability to attack and detect success in the same process). Complexities yet to be tackled include performance (as large amounts of data from the web application and user input need to be stored and referenced with each new interaction) and accuracy (by reducing false positives). For example, some large financial organizations have recently had issues with cross-frame scripting (XFS), a particular type of phishing attack that poisons a single frame in a page. While web services has been very slow in mass adoption, some users have sites and online applications that depend on web services, and therefore have an urgent need to test for web services vulnerabilities.

For the most part, vendors in this space have focused on simple detection techniques such as XML (malformed) schema based attacks and applying known web application vulnerabilities in non-XML applications to XML applications. This generally involves the ability to write scripts to address new and cutting-edge vulnerabilities. Vendors have been using scripts that use languages ranging from ones that look like Visual Basic to JavaScript and Nessus’ NASL language.

For the immediate future, most well-defined tools will choose multiple script languages to incorporate open source tools as well as proprietary methods.

Another area poised for substantial increases in effectiveness is the ability to handle testing of client-side technology for web applications.

Some of the more prominent standards include the Application Vulnerability Description Language (AVDL) and Web Application Security (WAS), which are both XML-based standards.

http://www.securityfocus.com/infocus/1809

Read more

A Snapshot of Security Project Plans, the Security Market and Vendor Mindshare

Posted on October 27, 2004December 30, 2021 by admini

From the perspective of corporate security projects:
– The fastest growing project space is Authentication, Encryption and Intrusion;
– Security management is still just the leader but the trends show it deminishing over time;
– Wireless security is growing slowly as a priority item.

For entreprise software:
1. Directory Services with 30% percent of respondents consistenly stating that this has been their number 1 priority for the past 12 months.
2. ERP, which has taken over from CRM.
3. CRM
4. Groupware
5. Vertical industries
6. Document Management

For Web Technologies:
1. Web Service, showing very strong upward trending over the past 12 months.
2. Other
3. Site Development
4. Portals
5. E-Commerce
6. Content Management

Other charts showing the top ten security vendors and the October 2004 priorities.

Research comes from IDC and ZDNET.

http://news.zdnet.com/2100-9596_22-5429425.html?part=rss&tag=feed&subj=zdnet

Read more

Mind those IMs–your cubicle’s walls have eyes

Posted on October 25, 2004December 30, 2021 by admini

But now employers are going further than ever, thanks to technology that can capture e-mail and instant messaging conversations, or record a worker’s every keystroke. Websense, a maker of Internet monitoring tools, has seen its stock price nearly double in the last year, though it saw some gains erased late last week. Other top players in the market include SurfControl and Secure Computing.

“I think all these companies are seeing great demand,” said Katherine Egbert, an analyst with Jefferies & Co. “Lately, regulatory compliance issues, and deadlines for meeting those regulations, have been driving sales.” The regulatory factors include financial reporting rules under the Sarbanes-Oxley Act and health care privacy mandates set forth in the Health Insurance Portability and Accountability Act, also known as HIPAA. Liability concerns regarding employee e-mails and IMs are also on the rise, as lawyers increasingly turn to computer records as evidence in sexual harassment suits and other legal actions involving the workplace.

Even tech luminaries, such as Microsoft Chairman Bill Gates, have used corporate networks to send e-mail that proved embarrassing in court.

“Productivity is a concern; loss of confidential information is still a concern; security breaches are a concern. Employers are afraid of being sued,” said Nancy Flynn, executive director of the ePolicy Institute, which, together with the American Management Association (AMA), recently published a survey on e-mail and IM surveillance in the workplace. “In almost every workplace lawsuit being filed today, e-mail is being subpoenaed as evidence,” Flynn said.

“IM will soon be subpoenaed on a regular basis as well.”

Aiming at IM According to the ePolicy-AMA survey, 60 percent of U.S. companies now use software to monitor incoming and outgoing external e-mail, while 27 percent of employers use software to track internal e-mail between employees. By contrast, employers have been relatively slow to monitor instant messaging, with just 10 percent of companies surveyed indicating they have taken steps to listen in on desktop chat. “Employers think IM is an emerging technology and they don’t have to monitor it yet,” Flynn said. “But if they have employees in their 20s, chances are (those employees) probably have been using IM since high school and view it as old technology.

And if a company doesn’t provide enterprise IM, (workers will) probably go out on the Internet and download a free version.”

IM giants America Online and Yahoo launched plans two years ago to offer corporate versions of their IM products, promising better security, along with regulatory compliance features not found in their free versions. Both have since scaled back those plans, but other companies have stepped in to fill the void, including industry titans such as Sun Microsystems and IBM, which are embedding their own IM products into their existing applications, and smaller companies such as IMLogic, FaceTime Communications and Akonix.

“Industry estimates say that by the end of 2005, IM in the workplace will surpass e-mail in the workplace,” Flynn said. “IM is coming on fast, and given that, employers need to take the necessary steps now with their policies and monitoring software.”

Monitoring software downloads is a top issue as well, industry observers and legal experts say.

In 2002, an Arizona company paid $1 million to settle a lawsuit with the recording industry that charged copyright violations involving MP3s stored on the company’s computer systems.

Customers such as PepsiCo and Ford Motor use Websense software to track and report employee Internet usage, block access to some Web pages, and set temporary access windows that limit the times some sites are available. Many corporations have adopted policies banning file-swapping software in the office and installed network traffic management software to track down potential violators.

Despite hot prospects, the industry has not seen a flood of new players. Instead, it has seen a rise in consolidation, particularly this year, Jeffries analyst Egbert said. Among recent deals, Blue Coat purchased Cerberian, CyberGuard acquired Webwasher, and Internet Security Systems bought Cobion.

Courts have generally found that employers have the right to monitor equipment that they own on their premises, including telephones and computer systems. Nevertheless, laws surrounding the monitoring of employees’ electronic communications are not as cut-and-dried as they appear, legal experts say. The law, on the face of it, looks like it’s illegal. But the courts have ruled that viewing stored e-mail is not considered a violation of the wiretap laws,” said attorney Philip Gordon, chairman of the privacy practice group for law firm Littler Mendelson. In one U.S. Court of Appeals case, the court further detailed how it is only considered a violation of the Wiretap Act if an e-mail is intercepted while it is traveling through the network pipe and is between two points.

http://news.zdnet.com/2100-1040_22-5423220.html?part=rss&tag=feed&subj=zdnet

Read more

IT chiefs use scare tactics to tighten security

Posted on October 21, 2004December 30, 2021 by admini

The poll of IT network and security administrators in SMEs to determine how they persuade management to change security practice found that almost half of respondents admit to advocating the fear factor. Many respondents indicated that they have to present worst case scenarios involving confidentiality breaches, lost customers or liability charges to justify investments in information security technology.

The use of scare tactics may be prompted by the fact that, according to additional findings from the poll, more than one in four (29 per cent) network administrators claim that senior management rarely, or never, change standard practices in response to security recommendations alone.

However, an encouraging 30 per cent indicated that rational facts, including cost-based analysis, productivity statistics and industry articles, are sufficient to prompt a reaction.

Additionally, 51 per cent of respondents reported that senior management implement changes to security practices based on their recommendations most or all of the time.

“This survey shows that SMEs can vary greatly in their approach to security. Despite high profile attacks and regulatory pressure, a strong security-conscious culture is still not second nature to all organisations,” said Mark Stevens, chief strategy officer at WatchGuard. “While many organisations treat security as a priority from the top down, and are very proactive in their approach, others require more persuasion to implement and update secure practices. To protect against the threat of attack, executive sponsorship is critical. Organisations need to adopt an approach that incorporates not only technology solutions, but ongoing user education as well as development and enforcement of security policies.”

http://www.vnunet.com/news/1158895

Read more

ATMs in peril from computer worms?

Posted on October 20, 2004December 30, 2021 by admini

Trend Micro and Computer Associates have both identified this niche, but some rivals question the immediate need for content filtering on cash points.

The new generation of Automatic Teller Machines (ATMs) are migrating from the IBM OS/2 operating system to Microsoft Windows and IP networks. This saves costs and enhances customer services. But it also means that ATMs are now at risk from computer worms, according to Trend Micro. “Previously isolated cash machines can now be infected by self-launching network viruses via the banks’ IP networks. Infections have the potential to bring down ATM machines, incurring downtime, customer dissatisfaction and increased costs fixing infected machines,” it warns.

Last August, the Nachi (Welchia) worm contaminated the cash machines at two financial institutions. When the Slammer virus hit the back end systems of the Bank of America in January 2003, 13,000 US ATMs became unavailable.

But never fear, Trend Micro is on hand to offer assistance. The Japanese-based firm is launching hardware-based network worm filtering technology specially designed for ATMs at a conference later this month. As well as launching its Network VirusWall 300 hardware, Trend will also be exhibiting at the annual ATM security conference (ATM Sec 4) in London on 25 and 26 October. Raimund Genes, European president of Trend Micro, said that 70 per cent of ATMs are based on either XP or embedded XP. “That’s the way manufacturers are taking the ATM and ticketing machine market,” he said.

Computer Associates offers a software development kit that can be applied to systems based on embedded XP.

Genes argued that producing AV systems for embedded XP terminals is far from straightforward: using existing enterprise content filtering gateways to protect ATMs would be “overkill”. Hardware-based network worm filtering, such as Trend intends to launch offers a better approach, he argued.

But other security vendors question the need for the technology.

Nigel Hawthorn, of security appliance firm Blue Coat Systems, said that ATMs commonly operate on a separate physical network, which is closed. “Sasser hit the back-end systems of banks, not ATM machines,” he said. David Emm, senior technology consultant at anti-virus supplier Kaspersky, agrees. “The threat to ATMs is related to how closely they are integrated with the outside world. Normally ATMS are kept on separate systems. Online financial (ebanking) systems are far more at risk,” he said.

Trend’s Genes said the barriers between the network used by ATMs and the wider Internet are been lowered as banks switch from older telecoms technologies to IP-based networks. He acknowledged that widely deployed AV technology alone is failing to protect enterprises from fast-spreading worms. But Trend’s worm filtering tech would prove far more successful in keeping cashpoints up and running in the face of viral onslaught, he says.

http://www.theregister.co.uk/2004/10/20/atm_viral_peril/

Read more

Posts pagination

  • Previous
  • 1
  • …
  • 41
  • 42
  • 43
  • 44
  • 45
  • 46
  • 47
  • …
  • 56
  • Next

Recent Posts

  • Security Operations Weekly — July 19, 2026
  • Security Operations Weekly — July 19, 2026 — Interactive Topic Map
  • DevSecOps Weekly — July 19, 2026

Archives

  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • November 2025
  • April 2024
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2022
  • January 2022
  • December 2021
  • September 2020
  • October 2019
  • August 2019
  • July 2019
  • December 2018
  • April 2018
  • December 2016
  • September 2016
  • August 2016
  • July 2016
  • April 2015
  • March 2015
  • August 2014
  • March 2014
  • August 2013
  • July 2013
  • June 2013
  • May 2013
  • April 2013
  • March 2013
  • February 2013
  • January 2013
  • October 2012
  • September 2012
  • August 2012
  • February 2012
  • October 2011
  • August 2011
  • June 2011
  • May 2011
  • April 2011
  • February 2011
  • January 2011
  • December 2010
  • November 2010
  • October 2010
  • August 2010
  • July 2010
  • June 2010
  • May 2010
  • April 2010
  • March 2010
  • February 2010
  • January 2010
  • December 2009
  • November 2009
  • October 2009
  • September 2009
  • June 2009
  • May 2009
  • March 2009
  • February 2009
  • January 2009
  • December 2008
  • November 2008
  • October 2008
  • September 2008
  • August 2008
  • July 2008
  • June 2008
  • May 2008
  • April 2008
  • March 2008
  • February 2008
  • January 2008
  • December 2007
  • November 2007
  • October 2007
  • September 2007
  • August 2007
  • July 2007
  • June 2007
  • May 2007
  • April 2007
  • March 2007
  • February 2007
  • January 2007
  • December 2006
  • November 2006
  • October 2006
  • September 2006
  • August 2006
  • July 2006
  • June 2006
  • May 2006
  • April 2006
  • March 2006
  • February 2006
  • January 2006
  • December 2005
  • November 2005
  • October 2005
  • September 2005
  • August 2005
  • July 2005
  • June 2005
  • May 2005
  • April 2005
  • March 2005
  • February 2005
  • January 2005
  • December 2004
  • November 2004
  • October 2004
  • September 2004
  • August 2004
  • July 2004
  • June 2004
  • May 2004
  • April 2004
  • March 2004
  • February 2004
  • January 2004
  • December 2003
  • November 2003
  • October 2003
  • September 2003

Categories

  • AI-ML
  • AI-Ops
  • Augment / Virtual Reality
  • Blogging
  • Cloud
  • DR/Crisis Response/Crisis Management
  • Editorial
  • Financial
  • Make You Smile
  • Malware
  • Mobility
  • Motor Industry
  • News
  • OTT Video
  • Pending Review
  • Personal
  • Product
  • Regulations
  • Secure
  • Security Industry News
  • Security Operations
  • Statistics
  • Threat Intel
  • Trends
  • Uncategorized
  • Warnings
  • WebSite News
  • Zero Trust

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org
© 2026 CyberSecurity Institute | Powered by Superbs Personal Blog theme