Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

Security roundup for Oct. 28: Cloud security holes; Facebook vulnerable?; China hackers lambasted

In last week's news, Amazon Web Services vulnerabilities were found and fixed, but other cloud service providers are probably susceptible to similar problems discovered by a German research team at Ruhr University Bochum.

The research team used a variety of XML-based signature-wrapped attacks to gain administrative access of customer accounts, then created new instances of the customer's cloud. They also used cross-site scripting attacks against open source private-cloud framework Eucalyptus, and said the Amazon service was susceptible to cross-site scripting attacks, too. To its credit, Amazon is paying close attention to this research and has worked to correct problems.

MORE SECURITY: Got cyberinsurance?

Potential vulnerabilities in Facebook also got attention last week, with Symantec pointing to an attack technique called cross-site request forgery that allows the attacker to piggyback into an active session. Symantec said it's working with browser vendors on solutions to attacks of this style it's uncovered.

Separately, consultancy CDW posted a blog item about an alleged vulnerability in Facebook that would allow a hacker to send a potentially malicious file to anyone on Facebook. Facebook downplayed the risk.

Well, maybe all this interest in Facebook is due to the countdown to Nov. 5, the day celebrated as Guy Fawkes Day in England, which is the day on which the shadowy hacker group Anonymous last August said it would "destroy" Facebook. Yes, completely destroy. And that's next Saturday ...

Security-event management

Last week IBM officially completely its acquisition of Q1 Labs, and the IBM Security Systems Division is making it clear that the Q1 security information and event management (SIEM) technology will be the centerpiece for IBM security products going forward. The goal is to extend SIEM, which traditionally aggregated and correlated real-time data from security devices such as firewalls and intrusion-detection systems, in several ways, such as combining it with identity management data, as well as business intelligence analytics.

The evolving role of SIEM came up when discussing with the chief security officer at Zions Bancorporation how the multibillion-dollar bank-holding company is adopting the data security warehouse approach. In this arrangement, the SIEM becomes another feed into a massive repository for analytics that can also take in business intelligence. This is all fairly new, but it suggests SIEM, one of the more important technologies advanced over the past half-decade for security, is not standing still.

China in the news, again and again

Last Thursday, The New York Times, The Wall Street Journal and Bloomberg all ran articles highly critical of China on security and human rights grounds, and each article took up a different topic related to information technology.

There was everything from accusations about Chinese hackers trying to hack U.S. satellites, to China out to set up an "Internet management system" to strictly control social-networking and messaging, to Chinese firm Huawei Technologies setting up a surveillance-monitoring system for the Iranian government through the Iranian cellular-telephone system.

Two weeks ago, Chinese-based company Huawei was complaining about getting the cold shoulder for U.S. federal contracts related to an emergency response system.

There are a lot of political nuances that are coming to the fore and information technology, at least on the part of the U.S., is not seen as something that can necessarily be separated from geopolitical security and human rights.

Last week as well, Richard Clarke, former cybersecurity adviser and now CEO and consultant at Good Harbor Consulting, spoke plainly when he said in his discussion of cyberattacks, "Frankly, the government of China is involved in hacking into American companies and taking that information and giving it to Chinese companies. It means our intellectual property is going out the door in petabytes and terabytes."

Read more about wide area network in Network World's Wide Area Network section.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: Amazon, BlackBerry, Bloomberg, CDW, Facebook, Google, Huawei, IBM, IBM Australia, LAN, Security Systems, Symantec, Wall Street, Zions Bancorporation
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: Amazon Web Services, Facebook, IBM, security, symantec
Latest Blog Posts
Whitepapers
  • Removing BPM Silos to Unleash Process Power - 15 Best Practices for Enterprise BPM
    You are about to get a lot smarter about Enterprise Business Process Management (BPM ). T his article is the first in a series of our soon-to-be-published book, “The Intelligent Guide to Enterprise BPM .” So consider this first article your all-important primer.
    Learn more »
  • Teleworking made simple—and secure—with desktop virtualisation technology
    Businesses of all sizes are increasingly focused on creating flexible work environments and offering telework options for employees. By administering policies and providing the technical capability for employees to work remotely, these companies can improve job satisfaction and worker attraction and retention. This paper explores the implementation of teleworking based on a foundation of desktop and server virtualisation.
    Learn more »
  • Managing IBM License Complexity
    IBM provides thousands of products in its portfolio and uses a variety of license models, contract terms and conditions. These license models can be very complex, causing frequent confusion for organisations trying to grasp the concepts while maintaining license compliance. While at first IBM licensing may seem incomprehensible, some education on the license models and licensing scenarios will help minimise the confusion. In addition, a more automated approach to managing licenses enables organisations to gain control, reduce ongoing software costs and minimise license liability risks. Read on.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.
Recent comments