• Follow us:
Don't miss out, sign up now: News Ezine Jobs Ezine
   
 
 
 
 
 

What kind of threats are lurking in today’s Web?

posted by cathal green on August 27, 2010

As a starting point it is worth reminding ourselves that the bad guys never went away, but they too have continued to evolve. As they look for new ways to exploit holes in technology, they have become increasingly financially motivated, as illustrated by cases in the press of identity theft and credit card fraud. Organised crime has picked up where the ‘hobbyist hacker’, doing it for kicks, left off.

Perhaps the most significant trend is towards more intelligent, targeted attacks on both individuals and businesses. Big companies have lived with this for a while, being hit by those extorting money or causing damage for some political motivation. But with smaller organisations and their employees being more visible on the Internet than they have ever been, through their company Web presence, social media, and so on, there is both more risk of becoming a target, and more information available to attackers to work out how best to hit you.

So, what kinds of threats are we talking about? We can consider:

Malware, viruses and spyware. • Recent events such as the Conficker worm suggest nobody should be binning their desktop antivirus nor their content filtering tools just yet. Email viruses and malicious code continue to be a potential problem, but more of a risk today is that of spyware downloaded from the Web, which a user can inadvertently install at the same time as a ‘freeware’ program or a Web site plug-in. Spyware can be used to track the activities of the user (including logging key strokes, watching for potential credit card numbers and extracting other personal and corporate data), to act as a host for sending out Spam emails or denial of service attacks on Web sites, or indeed to serve as a relay point to infect other vulnerable computers.

Web page drive-by infections.• Building on the malware theme above, note that malicious content does not have to be downloaded or installed, but can be picked up even from innocuous and legitimate sites, if these have in some way been hacked. In the US, popular sports sites have been infected with malicious code in the past, including major league baseball and hockey sites, and CNN Sports. Such code can then infect a desktop computer without any indication, just by visiting the site.

Social engineering and fraud.• In these attacks, a Web user is duped into doing something that will open them up to risks. Social networking has made this easier than ever, bringing many more people into potential conversations with Web-based strangers who may not be who they say they are. Recent examples include the use of truncated URLs (such as Tinyurl or Bit.ly) in combination with Twitter – the user is encouraged to click on what is claimed to be a video link, but which actually directs the user to a malicious site.

Misdirection and phishing.• This is where fake Web sites are set up to look just like the real thing, typically in an effort to extract confidential information from a user such as financial account information, social security info, credit card numbers, and so on. A user may be directed to a phishing site via email or from another site. Even more clever are the ingenious ‘man-in-the-middle’ attacks which forward the user, via a corrupt Web site, to a real Web site such that username and password information can be captured as it passes through the corrupt Web site.

Denial of service and botnets.• A denial of service attack may be launched on a corporate or governmental Web site, either for extortion, or simply because of a difference in beliefs: the goal is simply to shut the site down, at least for a period of time. Attacks can be launched from the attacker’s own computers, or by using so-called ‘bots’ or ‘zombies’ running on desktop computers that have been infected by certain spyware, as a ‘Distributed Denial of Service’ (DDOS) attack.

What to look for in a security solution

So, where can you start when it comes to responding to the threats? Unfortunately, the answer is not as simple as ‘buy a package’. There are a number of requirements on the information security architecture as a whole, which derive from the fact that security is more about managing a permeable membrane to the organisation, than trying to shore up the fortress walls.

It is important to implement protections that can evolve alongside any threats and changes in use, across all channels and wherever users might be connected. This may sound like a tall order, but what it implies is to provide an appropriate selection of protection mechanisms, deployed and managed in a co-ordinated manner.
The main options for Web security are not so much to do with what threats are addressed (the answer is ‘all of the above, in some way’), but how they address them. There are three key places that you can apply protection: notably on the desktop, at the edge of the organisation (e.g. using a firewall or running a gateway appliance), or within the Internet layer itself. This last option is becoming more prevalent given the increasing interest in so-called ‘software-as-a-service’ (SaaS) based security applications.

Below we consider what are the required characteristics of security solutions, and the relative benefits and costs of each approach. Please note however that we do not see this as a one-or-the-other decision as each approach will offer a better fit to different needs.

Confidentiality and data leakage.• Any information that is being transmitted over the Internet, must be considered at risk from being seen or in some way tampered with. This goes for corporate information as well as personal information: we know for example that Web mail accounts are a major conduit for confidential information leaving organisations. As we have already seen in the case of phishing attacks, hackers can be quite innovative in obtaining confidential data; adding social media into the mix creates additional information leakage challenges and raises concerns around Internet acceptable usage policies. For example, there is now a site which ‘follows’ the Twitter feeds of top executives. Should the head of business development be broadcasting about potential M&A activity, or indeed where they are going for lunch? Another recent example involved the spouse of a UK security service head, sharing personal information on Facebook.

Just how serious are these risks? There are a number of Web sites which monitor such things, and while there is no need to panic, the general advice is to be vigilant. In the past, individuals and organisations have set store in ‘security by obscurity’ – or otherwise phrased, “Why would anyone bother targeting me?”

The answer is twofold: first, the very mechanisms that have enabled the Web to grow so wide, have also given the bad guys broad scope when it comes to attacks (such as DDOS, for example) – everyone who is connected, is in some way vulnerable. Second, if there is money involved, then there is increasing likelihood of targeted attack. This is as true for corporations as for successful individuals. As technology continues to evolve – for example, in terms of virtualization, cloud computing, smart devices and so on – so do the innovative ways in which people can be exploited .



Find this useful? Sign up for our weekly Ezine and never miss out on what's happening in our Technology, Science & Innovation Community.






We understand that you need your IT infrastructure to work 24/7. We provide the services and support that makes sure it does.

Loughtec, based in Omagh, County Tyrone, provides IT infrastructure and computer support services to clients across the island of Ireland. We are also the sole reseller for the Ericom suite of remote access products in Ireland, as well as being a partner and reseller for Microsoft, HP and other leading brands. Our clients include the Foyle Food Group, LW Surphlis, Londonderry Port, the Irish Health Service Executive (HSE) and the Irish Department of Social Protection.

We differentiate ourselves from competitors through our approachability and our focus on technical expertise. We treat customers with respect and encourage clients to develop technical relationships with individuals in our team, contacting them through their individual email addresses and phone numbers. We spend a lot of time ensuring our staff are expert in the technologies we deploy. And we have also assembled a great suite of remote access, storage, networking and hardware products that provide outstanding performance at a competitive price. Our unique approach has lead to average annual growth of 50% per annum since we were founded in 2006.

Website: http://www.loughtec.com

More news related to Loughtec:
Jan 17
Clientless Browser-Based Access to Remote or Cloud-Hosted Applications and Desktops
Jan 03
Making a resolution to revamp your IT in the New Year?
Jan 03
BESx – a present from Loughtec
Dec 21
School Acquires a 30,000 User Licence of Ericom AccessNow for Browser-Based Access to VMware View
Dec 01
Want Access From Anywhere?
Nov 30
Video Interview with Sean McDermott, co-founder and director of Loughtec
Sep 26
Leading Insurance Provider Replaces Citrix with WebConnect
Aug 27
New Site Launched!
Jul 21
First Broker and Management Platform for VDI and Terminal Services
Jul 14
University Selects Ericom AccessNow™ for Browser-based Access to VMware View
Jul 01
A market-first offering!
Jun 08
Loughtec set sail with LPHC
May 26
AccessNow ready to go!
May 16
So you think WS08 R2 (RDS) will meet all of your organization’s needs?
May 04
BMW Group Financial Services UK Selects Blaze to Improve Terminal Server Performance and User Productivity
Apr 22
Loughtec and Ericom WebConnect RemoteView deliver workshifting!
Apr 20
Allianz Insurance Plc Selects Blaze to Improve Virtual Desktops
Apr 01
First Pure HTML5 Client for VMware View
Mar 30
WD-40 Lubricates Their Secure Remote Access With WebConnect
Mar 21
Doncaster Council turns to WebConnect for secure remote access
Mar 18
The Alternative to Citrix Just Got Better!
Feb 18
Centralising IT Resource
Feb 11
Terminal Services up to 25 Times Faster
Feb 09
Is Cloud The Best Way To Go?
Feb 02
WebConnect 5.7.1 Delivers Unprecedented Value-to-Cost Ratio of Application Access
Jan 12
Business Continuity Planning
Dec 10
Five Things to Consider Before Committing to an Infrastructure Cloud Deployment
Nov 26
Frustrated by Slow RDP sessions?
Nov 25
THE Alternative to Citrix
Nov 01
Loughtec tips for providing continuous access to IT resources
Oct 15
Loughtec hosts a successful WebConnect 5.7 Technology launch event in Omagh.
Oct 14
Seminary Leaps into Desktop Virtualisation (VDI) with Microsoft Hyper-V and WebConnect Technology
Oct 08
Irish Food Producer Reduces Costs and Improves Productivity by Replacing Citrix
Oct 01
New Virtualisation and Systems Technical Analyst to support Loughtec’s Company growth
Sep 28
Blaze + VMware View = Superior User Experience
Sep 24
WebConnect 5.7 Launch
Sep 20
Blaze - RDP Acceleration and Compression
Sep 14
Irrelevant emails overwhelm seven out of 10 employees
Sep 13
Protection Against Email Downtime
Sep 02
Centralised Virtual Desktops
Aug 31
ESET releases Mobile Security
Aug 23
All the features you need - minus the complexity and overhead
Aug 20
10 Anti-Spam Questions
Jul 27
Virtual Desktop Deployments
Jul 26
Tips for providing continuous access to IT resources
Jul 06
Any Time, Any Where, Any Device!
Jul 05
How would you feel if your company couldn’t access its data for a day?

Thermblow to Spring Forward after Graduating from NISP CONNECT Springboard Programme
Feb 03
Online Reputation Management and the Risk of Fakery
Feb 03
Are Entrepreneurs Happier People : Nicholas O' Shiel
Feb 03
Local IT specialist targets cloud services market with support from Invest NI
Feb 03
Foster announces new deal in the Netherlands for TotalMobile
Feb 02
Queens Medical Students urged to 'Follow the Leader'
Feb 02
Leading Entrepreneur Inspires At Ulster!
Feb 02
Discoverireland.ie wins Global Site of the Year 2011
Feb 02
Information security and the small business
Feb 02
LMS wins Gold Brandon Hall Excellence in Technology Award
Feb 02
Successful Work Placement at Magee Campus to encourage future Computing students
Feb 01
University of Ulster Researcher Reaches World Finals
Feb 01
Ulster provincial winners of Ulster Bank Business Achievers Awards revealed
Feb 01
Need to get fracking issue right - Attwood
Feb 01
Foster encourages innovative thinking from business
Feb 01
Google Analytics Qualified? Yes we are!
Feb 01
Mformation Delivers Solution Developer Kit (SDK) To Simplify Enterprise Mobility Adoption
Feb 01
Almac Announce Launch of Next Generation Sequencing (NGS) Data Analysis Services
Feb 01
Mformation CTO and Founder To Speak At MSPAlliance MSPWorld on Enterprise Mobile Device Management
Jan 31
Follow up: £6m NIACE Research Centre Opens
Jan 31
Browse by Company:
3PAR (8)
8over8 (2)
Advantage (2)
Aepona (28)
Aerona Software Systems (1)
Aetopia (4)
AirPOS (4)
Allstate Northern Ireland (2)
Anaeko (2)
Andor Technology (30)
Arcatech (2)
Asidua (25)
ATG (1)
Atlas Communications (4)
Aurion Learning (25)
Autonomy Meridio (1)
Aventure Hosting (2)
Awakin (1)
Axis Three (8)
Barclay Communications (11)
BiancaMed (1)
Bitbuzz (8)
Blue Apricot (2)
Blue Tree Services (5)
BluePrint Specialist Appointments (3)
Bohill Consulting (1)
Brightwater Recruitment Consultancy (1)
BroadSoft (5)
BrowseAloud (11)
BT (22)
BTI Photonic Systems (1)
Bubble (NI) Ltd (14)
Byte Mobile (6)
C-TRIC (1)
Causeway Data Communications (1)
Causeway Design (1)
CEM Systems (2)
ChainReactionCycles.com (1)
Cisero (2)
Citi (3)
Computacenter (1)
Consilium Technologies (1)
Cora Systems (3)
Core Systems (4)
Cornerstone Automation Systems (1)
CSR (20)
Cúnamh ICT (2)
CyberSource (6)
Dark Water Studios (5)
Datactics (9)
Datasentiment (2)
David Henderson Design (1)
Digimumsni (1)
Digital Robot Software (1)
DiskShred (4)
Donor2Deed (3)
DTS (2)
Ecom Software Ltd (1)
EG Consulting (2)
Eircom NI (2)
Empowerment Quality Engineering (1)
EOS Systems (1)
Equiniti ICS (8)
Exiseco (1)
EyeSpyFX (3)
Farmvet Systems (1)
FarmWizard (1)
Fidessa (5)
Fimtrip (3)
First Derivatives (9)
FlowJob.com (1)
Fluent Technology (1)
Forde Campbell LLP (1)
Foyle Technologies (1)
FRONT (2)
FSL Electronics (2)
Fujitsu Services (5)
G-Care (1)
GCD Technologies (1)
Green Beans Media (1)
H2O Ireland (1)
HeartSine (1)
i-Path Diagnostics (3)
i3 (formerly biznet IIS) (6)
ICONI Software (1)
iGuidez.com (1)
Infurious Comics (2)
inphoActive (1)
InstaGiv (1)
Intelesens (1)
Intune Networks (2)
InVision Software (1)
iON (7)
Jolt Online Gaming (1)
JPR (5)
JSR Technology (1)
K-Point Internet Solutions (1)
Kainos (25)
Karacha (1)
Kelsius (3)
Lagan, a Division of KANA (6)
Latens (17)
Leaf Consultancy (4)
Learning Pool (13)
Lee Munroe (1)
Liberty IT (21)
Lighthouse Communications (2)
Lookaly.com (4)
Lorien Resourcing (1)
Loughtec (31)
Magdalene (2)
Maildistiller (2)
MakeMeTop (1)
MatchMedia.TV (3)
Media Lightbox (8)
Metacompliance (1)
Mformation Technologies (5)
Microsoft Ireland (2)
MindMill (2)
MITIE (2)
Momentum NI (1)
Movidius (1)
NaviNet (1)
Nifty Nosh (1)
NiSoft (1)
Nortel (5)
Northgate Managed Services (26)
Novosco (22)
NWE Wireless (1)
NYSE Technologies (8)
OMIINO (1)
Openwave (1)
Optaros (1)
Origin Partners (12)
PadStand (1)
Paper Bag (2)
Parity Solutions (1)
PatentNav (2)
Philips Healthcare Informatics (2)
Pinnacle Computing Ltd (2)
Platinum Appointments (1)
Polaris Software Lab Ltd (3)
Propertynews.com (2)
PropertyPal.com (2)
Q1 Labs (2)
Quadriga Consulting (1)
Qwizdom (1)
Rantec Research (1)
Raytheon (4)
Redstone (1)
Reflex Stock (6)
Rehab Studio (14)
Replify (25)
SA Screen Media (1)
Sagnard Associates Ltd (2)
SAP (1)
Schrader Electronics (1)
Seagate (11)
Sembarc (1)
Sensei Learning and Performance (2)
Shhmooze (1)
Shred-it Ireland (1)
Singularity (26)
SLA (10)
Softedge Systems (1)
Sophia (2)
SpeechStorm (15)
Spiral Hosting Limited (3)
SQS (4)
Statzpack (4)
Steria (1)
Stiona Software Ltd (1)
StreamOn.net Ltd. (4)
Swarmteams (5)
Switch New Media (3)
Sysco (1)
TaxiZapp (2)
Team Solutionz (1)
TeleTech (2)
Ten Alps Vision (4)
Texthelp Systems (5)
Thales Air Defence Limited (3)
The Design Zoo (2)
theOneSwitch (1)
Tibus (3)
Total Mobile (2)
Trace First (2)
Tyco International (1)
Unblanked (2)
UTV Media plc (3)
VanRath IT (1)
Voz Media (1)
Wee Man Studios (9)
WFS (4)
Xperience (4)
Yelo (1)
Browse by date:
February 2012 (18)
January 2012 (126)
December 2011 (94)
November 2011 (91)
October 2011 (64)
September 2011 (94)
August 2011 (64)
July 2011 (65)
June 2011 (55)
May 2011 (100)
April 2011 (94)
March 2011 (186)
February 2011 (169)
January 2011 (170)
December 2010 (164)
November 2010 (182)
October 2010 (227)
September 2010 (259)
August 2010 (211)
July 2010 (148)
June 2010 (147)
May 2010 (98)
April 2010 (88)
March 2010 (132)
February 2010 (112)
January 2010 (81)
December 2009 (60)
November 2009 (36)
October 2009 (54)
September 2009 (28)
August 2009 (20)
July 2009 (17)
June 2009 (55)
May 2009 (49)
April 2009 (67)
March 2009 (93)
February 2009 (56)
January 2009 (77)
December 2008 (14)
November 2008 (8)

Technical Support Engineer - SQL, UNIX, CRM, (German Speaking)
Feb 03

Senior MS SharePoint Developer - MOSS 2007, 2010, SP (WSS) 3.0
Feb 03

Senior Application Support Manager - MySQL, Sybase, Powerbuilder - C551
Feb 03

Unix System Administrator
Feb 03

Super .NET Role - Small Company But Big Plans
Feb 03

Senior Support Engineer - Linux
Feb 03

JAVA - Software Engineer
Feb 03

Web Developer / Applications Developer – Java, Linux
Feb 03

Senior Business Analyst
Feb 03

Technical Support Engineer
Feb 03

Wintel Support Engineer - Londonderry / Derry
Feb 03

Junior Oracle Developer
Feb 02

Web Developer - Java / PHP / MySQL Belfast - Z1001
Feb 01

Developer - Ruby, PHP, Java, OO - i555
Feb 01

PHP Developer - D 52145
Feb 01

Software Engineer (Embedded C++/DSP)
Feb 01

Java Web Application Developer – Belfast
Feb 01

Principal / Senior Java Software Developer - Belfast
Feb 01

Hardware, Networking Support Consultant, Belfast - Ref: PC/HS0112
Feb 01

PHP/MySQL Web Developer - £22,000 to £30,000
Feb 01

Analyst Programmer (3)


Application Support Analyst (2)


Application Support Engineer (2)


Architect (2)


BI Reporting Analyst (1)


Build and Release Engineer (1)


Business Analyst (5)


Business Analyst : Technical (1)


Business Development Manager (2)


Business Intelligence Analyst (1)


Consultant (7)


Consultant : Oracle (2)


Consultant : Senior (1)


Control Systems Engineer (1)


Customer Support (1)


Database Administrator (DBA) (2)


Database Developer (4)


Database Developer : SQL (1)


Developer : .NET (22)


Developer : ASP.NET (2)


Developer : C (3)


Developer : C# (6)


Developer : C++ (8)


Developer : Flash (1)


Developer : iPhone (2)


Developer : Java (32)


Developer : Mobile (1)


Developer : PHP (9)


Developer : Web (3)


Developer/Team Leader (3)


Development Manager (1)


Electronic Design Engineer (1)


Embedded Engineer (3)


Engineer : Senior (9)


Engineering Manager (1)


Firmware Engineer (3)


Graduate (6)


IP Cisco Engineer (1)


IT Manager (1)


Marketing (1)


MOSS Technical Specialist (1)


Network Administrator (1)


Network Engineer (4)


New Media (1)


Programme Manager (2)


Project Manager (6)


Quality (2)


Recruitment / HR (1)


Sales : Business To Business (2)


Sales : IT (4)


Sales : Software (4)


Sales : Web (1)


Senior Developer / Manager (2)


Software Developer (12)


Software Engineer (18)


Software Quality Officer (2)


Solution Architect (2)


Support (4)


Support : Analyst (3)


Support : Manager (2)


Support : Team Leader (1)


Support : Unix (1)


Systems Adminstrator (4)


Systems Adminstrator : Unix (3)


Systems Analyst (4)


Systems Architect (1)


Systems Engineer (3)


Team Leader (1)


Technical Architect (4)


Technical Director (1)


Technical Project Manager (2)


Technical Support (10)


Technical Writer (1)


Test / QA : Analyst (2)


Test / QA : Lead (1)


Test / QA : Senior Engineer (4)


Tester / QA Engineer (9)


Trainer (2)


User Interface : Developer (1)


Web Designer (1)


Web Developer (8)


.net     ajax     antrim     asp.net     banking     belfast     c     c#     c++     career     css     developer     down     finance     graduate     html     it     j2ee     java     java developer     javascript     job     linux     mysql     northern ireland job     opportunity     oracle     perl     php     qa     role     software developer     software engineer     sql     sql server     tester     unix     vacancy     vb.net     xml    
  1. Senior Software Engineer - Belfast
  2. Senior Embedded Engineer
  3. Java Developer
  4. Software Test Engineer
  5. Software Consultant
  6. Senior Java Developer
  7. Software Tester X 3 - Manual
  8. Program Manager – EMEA / APAC
  9. Software Engineer Manager
  10. Technical Consultant
  11. Business development - Web
  12. Senior SQL Database Administrator
  13. Customer Support Engineer (Software)
  14. Technical Lead, Belfast
  15. SAP Basis Support
  16. Senior Systems Administrator - Belfast
  17. Senior Developer, Belfast
  18. Java Web Application Developer – Belfast
  19. Applications Architect
  20. Network Support Engineer
  21. IT Support Manager
  22. IT Sales (Internal) OTE c. £40k
  23. Senior .Net Developer
  24. Support Engineer
  25. Software Developer - ASP/VB.Net
  26. Firmware Engineer
  27. Technical Project Manager – OpenIN – EMEA / APAC
  28. Technical Business Analyst, Belfast
  29. Senior Network Analyst
  30. Oracle Developer / Data Modelling - L&T INFOTECH BELFAST N. IRELAND 16724S
  31. Software Developer - Belfast
  32. Java Developer - Belfast
  33. PHP Developer
  34. Senior Software Quality Engineer
  35. Quality Assurance Engineer x 2
  36. Firmware Engineer
  37. Wintel Support Engineer - Londonderry / Derry
  38. Solutions / Professional Services Manager (C++ or Java or .NET) 17020S
  39. Infrastructure Consultant - South Belfast - Contract to Perm
  40. SCM Tools Engineer
  41. Software Sales / Business Development Executives - Belfast or Derry or London based 17013S
  42. .NET Technical Team Lead - Agile 16996S
  43. Front End Web Developer
  44. Web Designer - Contract
  45. Helpdesk Support Engineer - Antrim
  46. Software QA Engineer 12.42
  47. Software Engineer 12.40
  48. Senior Citrix Administrator
  49. Developer, Belfast
  50. Principal / Senior Java Software Developer - Belfast

Sign up for our weekly email newsletter to receive the latest news, jobs, events and more...

Email:

Suffering from information overload online?

No problem! Take time out & catch up with our free quarterly magazine.

Subscribe Now
We maintain two twitter accounts:
@SyncNI
For tech news and events in Northern Ireland
@SyncNI_Jobs
Specifically for job opportunities in Northern Ireland
We have two RSS feeds:
News
For Technology, Science & Innovation news in Northern Ireland
Jobs
Specifically for job opportunities in Northern Ireland

 
Shortlisted Best Technology Website in the Irish Web Awards 2009, 2010 & 2011