Login, change your address, subscribe to new or manage current magazines or e-newsletter subscriptions
Computerworld Publication PageNetworkWorld Publication PageCIO Canada Publication PageITJobUniverse.ca
- The Information, Communication and Technology (ICT) Job Board
Advanced Search
Knowledge Centres
Content Types
Featured White Papers
Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network"Gartner Research Note "Boost SharePoint Performance with an Application Delivery Network" read more
From fear to value: CIO strategies for propelling business through the economic crisisFrom fear to value: CIO strategies for propelling business through the economic crisis read more
Reaping the rewards of your service-oriented architecture infrastructureReaping the rewards of your service-oriented architecture infrastructure read more
Yuk it Up
Featured White Paper
Ensuring that IT security is delivering true value to the organization requires approaching security through a business lens, with the ability to span operational silos and IT domains to secure your critical business processes across the organization. Read on to learn how to help mitigate enterprise security risks by leveraging IBM solutions to drive business innovation and success, while reducing complexity and costs along the way.
IT World Canada Blogs
Keep up with breaking news on worms, trojans, spam and other threats to your corporate network and hear about the best practices in risk management from some of Canada's leading experts.
Salary Calculator 2009
Check out Computerworld Canada's 2009 Salary Calculator. Access up-to-date information from our 2009 IT Salary Survey, including salaries, cash bonuses, and percentage increases over 2008.
Featured Spotlight
Keep up on who's hiring, who's downsizing and how the government is helping. News, job opportunities, recruiters and employment lawyers are all available.
Sign-Up for
Security
eNewsletter Delivered Weekly
Click here
Page 1 of 2

Digg it Twitter

eBay IT exec warns of application layer attacks

Speaking at this week’s Infosecurity Canada conference, the online auction site’s security director Dave Tyson singled out what he sees as the most significant threat to security at major organizations. Plus: A U.K. firm’s cautionary tale

TORONTO – The biggest security concern for your enterprise over the next year should be protecting against application layer attacks, according to a senior security director at eBay Inc.

More on ITWorldCanada.com

Hacker unleashes SQL injector update

During his keynote session at Thursday’s Infosecurity Canada 2008 conference in Toronto, Dave Tyson, the online auction giant’s senior director of information security operations and business continuity planning, said that companies which have strong interactions with customers over the Internet will be the most sought-after target for hackers.

“If you’re a product or services-based company and you want to interact with your customers with greater functionality, attacks at the application layer will be an emerging problem for you,” he said. “We’ve found that most companies are prepared at the network level, but they haven’t put the strategies and budget in place for these new threats.”

In an application layer attack, hackers could be looking to hijack user accounts to get passwords and other personal information, gain administrative privileges on client/server machines, gain root access to execute malicious commands, or install Trojans and Backdoors to wipe out or destroy applications.

“The thing that really keeps me up at night is the speed of sophistication of these attacks, where things we saw six months ago still haven’t been taken hold in the general community,” he said.

According to Tyson, application layer attacks can easily hinder the trust relationship your company has with its clients. He cited the example of last year’s Bayrob Trojan horse, which was capable of establishing a proxy server in a victim’s computer and using it to steal sensitive data.

“It was distributed by e-mail, so the user gets a link that looks like it’s coming from your company,” Tyson said. “The trouble is, when you click the link, it downloads Apache Web Server and puts up a copy of your Web site. So, the user thinks they’re conducting business with you, but they are actually working with the bad guys.”

The increasing sophistication of botnets, he said, is another major concern for application layer security.

“You might have 200,000 botnets looking for interactions between your customers,” Tyson said. “They’ll pick up your user IDs, then pound away to do logins with them. If you have a system that locks out users after a few tries, every customer you have could be locked out of your site. If you’re a bank, that’s a problem.”

To protect against the fast moving world of security attacks out there, he said security executives will need to bake security principles right into the infrastructure. Often times, Tyson said, enterprises fail to follow fundamental security principles, like enabling the encryption technology for their Cisco switches or properly coding their Web sites to limit security holes.

Page 1 of 2
Send to a Friend  Rate This Page  Print This PageAdd a new comment
Bookmark this article on:
del.icio.us| Digg it| Furl| Google| Technorati| StumbleIt| Yahoo!

Have something to say about this article? Add a new comment

If you find a comment inappropriate, You can notify the moderator by clicking the Report an innapropriate comment icon.
Web application security solutionReply to this commentReport an innapropriate comment
It seems like many businesses are just waking up to this threat now. There are web application security audit products and services that will find vulnerabilities and recommend fixes, like Devfense (Read more at http://www.boonbox.net/devfense.htm). These kinds of solutions ought to be standard for organizations already, but most seem to be behind the curve right now.
Written by: Jonathon, from Vancouver
ADD A COMMENT
Name:*Your email address will not appear online and will be used only in the event that the editor wishes to contact you personally for additional comment.
City:
Email:
Title:*
Comment:*
* required fields



Related Content
Articles

White Papers
Improving business through smart energy and environment policy
Businesses and public entities today face increasing pressure to develop policies that are both good for the planet and good for business. A framework developed by IBM offers businesses and other organizations a comprehensive approach to energy and environmental issues. The framework helps identify and prioritize environmental efforts by breaking down problems and opportunities into seven distinct business areas, which can then be segmented into manageable projects.