Quantcast
Latest Stories

IT security problems shift as data moves to ‘cloud’

By

Assistant US Attorney Kathryn Warma speaks at a news conference about how credit cards are hacked, Monday, June 11, 2012, in Seattle. The new trend of storing data in the “cloud” has created a new range of security concerns, including attacks on the Sony PlayStation Network, LinkedIn and Google's Gmail service. One hacker recently claimed to have stolen credit card numbers from 79 major banks. AP PHOTO/ELAINE THOMPSON

WASHINGTON—The Internet “cloud” has become the hottest topic in computing, but the trend has created a new range of security issues that need to be addressed.

The cloud is associated with things like personal e-mails and music, which can be accessed on computers and a range of mobile devices.

But the US military and government agencies from the CIA to the Federal Aviation Administration also use cloud systems to allow data to be accessed anywhere in the world and save money – and, ostensibly, to enhance security.

Microsoft, Google, Amazon and others are major players in the cloud, which seeks to transfer some of the data storage issues to more sophisticated data centers. Firms like Oracle, SAP and Salesforce.com offer cloud services for business.

Strategy Analytics forecasts US spending on cloud services to grow from $31 billion in 2011 to $82 billion by 2016.

But some experts say security implications of the cloud have not been fully analyzed, and that the cloud may open up new vulnerabilities and problems.

“If past is prologue I don’t think any system is absolutely secure,” said Stelios Sidiroglou-Douskos, a research scientist at the Massachusetts Institute of Technology’s Computer Science and Artificial Intelligence Laboratory.

“The analogy most people give is having a lock on your door. It’s not a guarantee no one will break in, but it’s a question of how much time it will take, and if your lock is better than your neighbor’s.”

In a cloud environment, “this makes the job of the attacker so much harder, which means the amateur hacker might be obsolete,” said Sidiroglou-Douskos, who is working on a US government-funded research project to develop “self-healing” clouds.

Potential gold mine for cybercriminals

But if a system is breached, analysts say, the amount of information lost could be far greater than what is in a single computer or cluster.

“You can have better defenses” in the cloud, “but if an attack happens, it’s highly amplified,” says Sidiroglou-Douskos.

The four-year MIT project funded by the Defense Advanced Research Projects Agency seeks to develop systems that automatically fix data breaches in a manner similar to “human immunology,” says the researcher.

A number of cloud security breaches have raised concerns, including attacks on the Sony PlayStation Network, LinkedIn and Google’s Gmail service. One hacker recently claimed to have stolen credit card numbers from 79 major banks.

“Crimes target sources of value. Large company networks offer more targets to hackers,” says Nir Kshetri, a professor of economics who studies cybercrime at the University of North Carolina at Greensboro.

“Information stored in clouds is a potential gold mine for cybercriminals.”

Kshetri said in a paper submitted to the journal Telecommunications Policy that when questions come up, “the cloud industry’s response has been: Clouds are more secure than whatever you’re using now. But many users do not agree.”

‘Fake clouds’

Marcus Sachs, former director of the Sans Technology Institute’s Internet Storm Center, said the cloud may be more secure but also opens up new questions.

“In the cloud, you don’t necessarily know where your data sits,” Sachs told AFP.

“That doesn’t make it less vulnerable to attack, but there are questions when it comes to (an) audit, or if you want to take the data back or destroy it, how do you know you’ve erased it?”

Sachs said that analysts have also discovered “fake clouds,” which are offered as low-cost alternatives but are in fact operated by “criminal groups which monitor and steal the data.”

“We have seen instances of this not in the US, but in the former Soviet Union and in China,” he said.

Still, the cloud market is burgeoning, with companies and government agencies moving to either “public” clouds that are easily accessed or so-called “private clouds” that are segregated from the Internet.

Some analysts say other issues need to be resolved about cloud computing, such as who is liable if data is lost, and how data can be accessed for government investigations.

Outages have recently affected Apple’s and Amazon’s cloud services, causing some websites to be affected.

“Privacy, security and ownership issues in the cloud fall into legally gray areas,” Kshetri says.

Sidiroglou-Douskos said there is no single answer for people or companies choosing between cloud systems and holding the data themselves.

“If you are trying to protect yourself from the government, then having it in the public cloud makes it easier for them to get it,” he said.

“If your main worry is a hacker in Russia, maybe (cloud) infrastructure is better for your own security.”

Follow us on Facebook Follow on Twitter Follow on Twitter




Recent Stories:

‘Election is over, let’s work together’—Nancy Binay 1 hour elapsed Zest Air cancels flights to Taipei 1 hour elapsed PSE board gets new manadate 2 hours elapsed It’s up to MMDA chief to explain jump in net worth–Palace 2 hours elapsed MMDA chief: No new assets, just different SALN form 2 hours elapsed ‘Prove them wrong,’ Binay tells daughter 2 hours elapsed Ejercito-Estrada, Honasan happy to be in Senate but saddened by partymates’ loss 2 hours elapsed Villar banking on 9 years in House, husband’s work to help her in Senate 3 hours elapsed
Complete stories on our Digital Edition newsstand for tablets, netbooks and mobile phones; 14-issue free trial. About to step out? Get breaking alerts on your mobile.phone. Text ON INQ BREAKING to 4467, for Globe, Smart and Sun subscribers in the Philippines.

Tags: Cloud , computing , Cybercrime , Internet , IT , security , US



Copyright © 2013,
.
To subscribe to the Philippine Daily Inquirer newspaper in the Philippines, call +63 2 896-6000 for Metro Manila and Metro Cebu or email your subscription request here.
Factual errors? Contact the Philippine Daily Inquirer's day desk. Believe this article violates journalistic ethics? Contact the Inquirer's Reader's Advocate. Or write The Readers' Advocate:
c/o Philippine Daily Inquirer Chino Roces Avenue corner Yague and Mascardo Streets, Makati City, Metro Manila, Philippines Or fax nos. +63 2 8974793 to 94
Advertisement

News

  • Police arrest call center executive
  • Youngest gov to rule CamSur
  • Arroyo vows better service in 2nd term in Congress
  • Arroyo son wins in Camarines Sur
  • Reyes proclamation in Marinduque questioned
  • Sports

  • US training pays off as returning San Beda nips FEU at Filoil Flying V
  • UE draws perfect game from Olivarez to thwart UST
  • Adamson bests CSB on Jericho Cruz’s 25-point burst
  • Report: Michael Phelps planning comeback
  • Former lawyer says OJ Simpson knew about guns
  • Lifestyle

  • Make the good choice with Android Handsets
  • Caribbean talks conservation on Branson’s island
  • My (forced) Boracay summer of 2013
  • Daisy Hontiveros Avellana–Why she will always be the ‘First Lady of Philippine Theater’
  • ‘The only thing wrong with the Filipino audience is that there isn’t enough of it’
  • Entertainment

  • Flamboyant celeb wins back beau via intrigue
  • Leaving a coliseum full of positive vibes
  • Ser Chief, Maya in Toronto today
  • HEARD: Celeb poll volunteer
  • J.J. Abrams: Wildly exciting to direct new ‘Star Wars’
  • Business

  • PSE board gets new manadate
  • World hypertension day: Know your numbers
  • Mining output plunged 18% in 2012
  • Stocks continue to decline
  • AUB debuts strong on PSE
  • Technology

  • Hong Kong launches first electric taxis
  • DepEd website now up and normal
  • Report: Yahoo nearing $1.1B acquisition of Tumblr
  • ‘Sonic’ video games coming to Nintendo
  • ‘Hatchet hitchhiker’ arrested in US murder
  • Opinion

  • An interesting challenge
  • Premature, imprudent and illegal
  • Nations and their governments
  • Come, Holy Spirit!
  • A room in heaven
  • Global Nation

  • Zest Air cancels flights to Taipei
  • No alternative for Filipino workers in Taiwan, says recruitment expert
  • De Lima appeals for calm as NBI completes probe into Taiwanese fisherman’s killing
  • Mexico violence claims hundreds of US lives
  • Malacañang rejects Taiwan ‘murder’ claims
  • Marketplace
    Advertisement
    © Copyright 1997-2013 INQUIRER.net | All Rights Reserved