- +
Strategies for Dealing With IT Complexity 24/12/2007 10:30:47
Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.Every innovation, every business process improvement, comes with an IT complexity tax that must be paid by CIOs in time, money and sweat. Here are strategies to mitigate the increasing complexity of IT as it enables new business.
Researchers at the Carnegie Mellon University have developed a new antiphishing tool to address the growing problem of fraud.
The university says the Phoolproof Phishing Prevention system provides an additional layer of security at sensitive sites, such as banks, e-commerce and investment sites, by leveraging a mobile device, such as the user's mobile phone or PDA.
Phishing fraud typically occurs through fraudulent e-mails requesting sensitive information, such as passwords and credit card details, which may then be used to plunder financial accounts, make purchases, or apply for additional credit cards.
There were 28,571 unique cases of phishing fraud in June 2006, according to an Anti-Phishing Working Group report. This nearly doubles the number of reports from a similar period a year ago.
"While it is difficult to collect accurate data about the extent of phishing fraud, what data we do have suggests that phishing is a growing problem," said Carnegie Mellon researcher Bryan Parno. "Estimates suggest that millions of consumers have been affected by phishing attacks, while businesses have lost billions of dollars."
And it appears phishing is a problem for Web surfers of all levels. A separate study, conducted by researchers at Harvard University and the University of California Berkeley earlier this year, found that a well-designed fraudulent Web site fooled 90 percent of participants, Internet newbies and 'Web savvy'-types alike.
The prevention system eliminates the risk of a user being fooled, through the use of a secure electronic key that is stored on the user's mobile device. The device communicates with the Web browser, and will only reveal its authentication key to the appropriate Web site, researchers said.
"The Phoolproof Phishing Prevention system rests on the observation that users should not be authenticated based on information that they can readily reveal to others," Parno said. This way, phishers will not be able to access a user's accounts, even if they obtain information about the user.
The system also defends against keyloggers and other malicious software on the user's computer, the researchers said. And even if the mobile device is lost, the finder will still require the username and password to access accounts.
"An attack on the device itself will not produce enough information to allow an attacker to access the user's accounts," Parno said. "Beyond that, we expect mobile devices to adopt many of the defence techniques currently employed on desktops.
"In the long-term, mobile devices will include hardware support for enhanced security measures, and we can leverage these to enhance the security of our system."
Researchers do not expect there to be many additional costs in adopting the system. It was deliberately designed to be as simple as possible for both users and businesses to implement, Parno said.
The system uses the standard SSL protocol to minimize changes to a business' existing infrastructure. After being adopted, the system also allows legacy clients to authenticate as they normally would, which means that the system could be rolled out gradually without affecting too many customers.
Complicating the concern for more secure financial sites is a looming deadline for new security guidelines from the US Federal Financial Institutions Examination Council, a group of government agencies that sets standards for financial institutions. Last year, the council set a December 31 deadline for banks to add online security measures beyond just a user name and password. Failure to meet that deadline could result in fines, the council said.
Computerworld Member Login
Discover how SOA can create smarter outcomes for your business.
Attend and learn:
- How SOA is helping leading companies to become more agile
- Where you should be applying SOA processes in your company
- The top SOA implementation mistakes to avoid
Click here for more information.
- +
Computerworld Live Podcast #97: The Future of Enterprise Networking 25/07/2008 09:45:36
This week CW Live chats with Mark Thompson, global sales and marketing manager for HP ProCurve, on the future of the enterprise networking. Mark discusses the trends we can expect to see in the near future and how the right infrastructure can ensure your enterprise network is secure. - +
Computerworld Live Podcast #96: Security at the Edge 11/06/2008 09:22:22
CW Live speaks with Amol Mitra, HP ProCurve Director of Marketing for Asia Pacific and Japan. Today's topic: how enterprises are starting to shift away from simply controlling security via server logins, firewalls and moving to more adaptive security frameworks. - +
Data Management Edition #10: Multi-Petascale Systems 02/05/2008 09:12:33
This week we look at sustainability and the development of multicore technologies to build multi-petascale systems. - +
IT Security Edition #11: How to poison the Storm botnet 01/05/2008 08:51:55
This week CW Live presents a case study on how to poison the notorious Storm botnet . Plus we take a look at Cisco's plans for Ironport. - +
IT Security Edition #10: Cyber-battles fought and won 24/04/2008 11:09:47
Vendors bow to end user pressure to improve product security, and we take a look at the latest concepts shaping the cyber-battlefield of the future.
VeCommerce Launches Top Ten List of Personal Security Breaches In Lead Up to National ID Fraud Awareness Week 2008-10-07 15:10:00+10
Multimedia Technology signs exclusive National distribution agreement with Freecom 2008-10-07 14:30:00+10
Open Text: Upheaval in the Financial Markets Sharpens the Focus on Information Governance and Enterprise 2008-10-07 13:19:00+10
Symantec State of Spam Report - October 2008 2008-10-07 11:58:00+10
AIIA to Reward Sustainability and Green IT Champions at the 2009 iAwards 2008-10-07 11:56:00+10
Solve Exchange Storage Problems Once and For All: A New Approach without Stubs or Links
The management of Microsoft® Exchange storage growth is the most challenging problem facing Exchange administrators. Because of the popularity of email as a communication technology, and because users tend to keep email, maintaining adequate storage on the Exchange Server is a constant challenge. Learn how to maintain the space you need by reading on.











