Home > Information Security Magazine > Features > Future
EMAIL THIS
Information Security Magazine

  CURRENT ISSUE  

  FEATURES  

  COLUMNS  

  HOT PICK & PRODUCT REVIEWS  

  ARCHIVES  

  SUBSCRIBE/RENEW  
 

Future
Issue: Jan 2008
printer-friendly
< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   11  |   12  |   13  |   14  |   15  |   16  |   NEXT PAGE  >

Web of Worry



Himanshu Dwivedi and Zane Lackey of security firm iSEC Partners warn that VoIP protocols such as IAX and H.323 remain open to easy exploits. The latter, they say, is particularly vulnerable to attack but that most users assume it's secure because there has been little evidence to the contrary.

Dwivedi says it's important to shed light on the threat because VoIP use has exploded in the last three years without much consideration of the security risks. Lackey agrees, saying, "While companies are in the same mindset with VoIP as they were a couple years ago, there are more and more tools out there that can be used to both attack and defend it."

While the security implications of virtualization are cloudier, Core's Arce is convinced of a gathering threat there.

"I see big imp...



lications for virtualization, though the impact isn't yet clear," Arce says. "Flaws in the technology could be used to disrupt virtual environments, and if you run a bunch of virtual machines on a server and that server is compromised, there could be a lot of damage. The flip side of using virtualization to reduce your number of servers is that you can do more damage by hitting fewer servers."

Some of the dangers associated with the technology surfaced earlier this year, when virtualization giant VMware was forced to fix 20 security holes. The flaws plagued all supported versions of VMware ESX Server, VMware Server, VMware Workstation, VMware ACE and VMware Player. The company quietly acquired host intrusion prevention vendor Determina to help bolster its defenses from within, but has offered little by way of a clear security vision.


< PREV PAGE   |   1  |   2  |   3  |   4  |   5  |   6  |   7  |   8  |   9  |   10  |   11  |   12  |   13  |   14  |   15  |   16  |   NEXT PAGE  >





TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts