Firms headed for cloud security 'wake-up' call

 

Summary

Lesson may come in form of hacker targeting cloud infrastructures when adoption goes mainstream within two to three years, warns security analyst.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

SINGAPORE--Like it or not, businesses are headed for a cloud security "wake-up" call, which can happen within the next two to three years, according to a security analyst.

Magnus Kalkuhl, senior virus analyst at Kaspersky Lab, noted in an interview that cloud computing is still at a very early stage and aspects such as standards or even security experiences that would otherwise help companies be more judicious in their cloud implementations, are "missing".

Speaking to ZDNet Asia during a stopover in Singapore, Kalkuhl cited the example of the LoveLetter worm that plagued companies and individuals in 2000. Also know as the I Love You virus, the worm appeared as an attachment and when executed, deleted multimedia files as well as attempted to infect machines of other users listed in the first victim's Microsoft Outlook address book.

When the attack emerged, Microsoft fixed the issue in Outlook so that attachments could no longer be executed automatically. "The whole world learnt a lesson [from the incident, as] to what e-mail security really meant," he said, noting that in principle, the security loophole could have been easily identified.

Similarly, cloud computing needs and will eventually have a "wake-up event" to compel people to understand more about the risks, learn from the setback and progress, added Kalkuhl.

In terms of technology, cloud infrastructure is also an attractive target for cybercriminals, Kalkuhl noted. Once hackers gain access to the main system, they would be able to gain control over other virtual machines connected to the main server, he explained.

In fact, conversations brewing in the hacker community suggest it would be "cool" to be the first to break cloud systems, he said.

However, for hackers to seriously consider making their move on cloud infrastructure, there must first be a substantial pool of users, Kalkuhl pointed out.

With 2010 earmarked as the year when many companies will start looking more closely or dipping their feet into cloud environments, he said it would take about two to three years for cloud computing to become mainstream--and therefore, lucrative targets for cybercriminals.

Rise of virtual identities
Kalkuhl added that he expects to see a stronger focus on virtual identities going forward, as more transactions and information are moved online.

The idea of a digital passport will evolve over time with Internet users having one or more digital identities, he explained, depending on the type of transaction they conduct. That way, consumers will not need to give out their real identity for every activity conducted online, and all the merchant or verifying organization needs to do is check the authenticity of the digital credentials.

These virtual identities, said Kalkuhl, may not necessarily be issued by the government. Banks, for example, can be an entity to which users are willing to entrust their actual identities and personal information.

Talkback

Cloud computing is coming, and I think it’s about time to embrace it. One provider I work with, PineApp, provides security systems, and had the idea to start providing their whole line, in addition to physical products, as SaaS and cloud services. As a market analyst, I think this is the way things are going, and the sooner we accept it, and start developing technologies built for it, the better.

LindseyK April 25, 2010
Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

#radio Radio Serbia by EnjoyIT 1.0 http://t.co/nGQFvX2E

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

Alibaba seeks $2.3B from shareholders for Yahoo deal. http://t.co/qLRAhRQk

CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

Quickflix WatchNow 2.0 http://t.co/XWti5VWT

Official UEFA #EURO2012 app with Orange 2.0 http://t.co/yoAOXTI1 #hotpeopleifollow

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate