<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>The FORWARD project blog &#187; conference</title>
	<atom:link href="http://blogs.ict-forward.eu/forward/tag/conference/feed/" rel="self" type="application/rss+xml" />
	<link>http://blogs.ict-forward.eu/forward</link>
	<description>blogging on emerging and future threats</description>
	<lastBuildDate>Wed, 21 Jul 2010 13:42:28 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>FORWARD future threats panel at EC2ND 2008</title>
		<link>http://blogs.ict-forward.eu/forward/forward-ec2nd08-panel/</link>
		<comments>http://blogs.ict-forward.eu/forward/forward-ec2nd08-panel/#comments</comments>
		<pubDate>Tue, 20 Jan 2009 16:20:14 +0000</pubDate>
		<dc:creator>Georgios Portokalidis</dc:creator>
				<category><![CDATA[conference]]></category>
		<category><![CDATA[forward]]></category>
		<category><![CDATA[panel]]></category>

		<guid isPermaLink="false">http://blogs.ict-forward.eu/forward/?p=56</guid>
		<description><![CDATA[The European Conference on Computer Network Defense (EC2ND) is an annual conference bringing together academia and industry to discuss topics in network and systems security. This year it was held at Dublin City University in Dublin, Ireland. The programme included a panel organised by FORWARD, where possible future threats on global ICT infrastructure were discussed. [...]]]></description>
			<content:encoded><![CDATA[<p style="text-align: justify">The <a href="http://www.ec2nd.org/">European Conference on Computer Network Defense</a> (EC2ND) is an annual conference bringing together academia and industry to discuss topics in network and systems security. This year it was held at Dublin City University in Dublin, Ireland. The <a href="http://2008.ec2nd.org/ec2nd/881-EE.html">programme</a> included a panel organised by FORWARD, where possible future threats on global ICT infrastructure were discussed. The panel constituted of members from all FORWARD working groups (WGs), and was headed by <a href="http://ics.forth.gr/~sotiris/">Sotiris Ioannidis</a>.</p>
<p style="text-align: justify"><span id="more-56"></span></p>
<p style="text-align: justify">The panel discussion revolved around the already defined project WGs:</p>
<ul>
<li><a href="http://www.ict-forward.eu/wg/smart-environments/">Smart environments</a></li>
<li><a href="http://www.ict-forward.eu/wg/critical-systems">Critical systems</a></li>
<li><a href="http://www.ict-forward.eu/wg/malware-fraud/">Malware &amp; fraud</a></li>
</ul>
<p style="text-align: justify">The discussion started with a talk on <em>smart systems</em>, which mainly focused on the threats introduced by the advent of smart devices. Smart-phones and other such mobile smart-devices are slowly replacing the older mobile phones greatly increasing the offered functionality. A smart-phone can be used for accessing email, online banking, e-commerce, etc same as with a PC. Furthermore, new location based services (via GPS) are offered, and plans are made to turn these devices to e-wallets. Also, since a phone is considered highly personal, users tend to store personal items such as photos, PIN and credit card numbers. All the above turn these devices to very attractive targets for attackers, while at the same time users are not even aware of the existence of threats against their new device. Applying already developed security solutions to mobile devices is not always possible, because of their inherent limitations such as limited battery life, and hardware resources. As such additional research is needed to address security in such devices.</p>
<p style="text-align: justify"><em>Critical systems</em> were discussed second in the panel. Such systems include telecommunications infrastructure, transportation, energy production and distribution, etc. These systems have been using computers for a long time, but in the future there are many plans to allow their management over the Internet. Extending their connectivity can leave them open to a multitude of attacks, if security is not considered early in the design and implementation. Unfortunately, in this case as well, people involved with critical systems are not always aware of the new threats and challenges they will be facing.</p>
<p style="text-align: justify">A very interesting example from the car industry was brought up. Cars today already include 40-50 computers connected via LAN. Security has not been an issue till today, but with plans to interconnect cars with each other,  or even with the Internet it is made obvious that security will be a prime concern. Failure to introduce security mechanisms could prove catastrophic, not in this example alone but on all critical systems.</p>
<p style="text-align: justify">The final subject of the panel was <em>malware and fraud</em>. The discussion centred on the new incentives and modus operandi of malware writers today. Malware is no longer written &#8220;for fun&#8221;, but for profit. One can easily be made aware of this by considering the very successful worms of the past such as CodeRed, Blaster, and Sasser. Even though millions of systems were infected, the damages inflicted were relatively small. Today on the other hand, malware writers are driven by profit, and form groups that resemble traditional crime organisations. Botnets such as the renowned Storm botnet are used to circulate spam e-mail, which is either directly providing income to the botnet &#8220;owners&#8221;, or is used to perform fraud. Botnets have even been observed being rented out in the cyber underground through IRC channels and web pages. To better understand this new generation of criminals, traditional investigation is needed to provide warning of new attacks and frauds, while at the same time more research is needed on disrupting malware operation and propagation.</p>
<p style="text-align: justify">The conclusions extracted from the panel discussion can be summarised into that: a) <em>additional security research</em><em> is needed</em> to address future threats on new technologies, and b) well established industries need to be made <em>aware of the new threats</em> they will be exposed to, because of the interconnection of previously unconnected components.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.ict-forward.eu/forward/forward-ec2nd08-panel/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>FORWARD in &#8220;Future of Trust in Computing&#8221; Conference</title>
		<link>http://blogs.ict-forward.eu/forward/forward-in-future-of-trust-in-computing-conference/</link>
		<comments>http://blogs.ict-forward.eu/forward/forward-in-future-of-trust-in-computing-conference/#comments</comments>
		<pubDate>Wed, 13 Aug 2008 14:20:32 +0000</pubDate>
		<dc:creator>Manolis Stamatogiannakis</dc:creator>
				<category><![CDATA[conference]]></category>
		<category><![CDATA[berlin]]></category>
		<category><![CDATA[paper]]></category>
		<category><![CDATA[trust]]></category>

		<guid isPermaLink="false">http://blogs.ict-forward.eu/forward/?p=12</guid>
		<description><![CDATA[The Future of Trust in Computing Conference took place in Berlin from June 30th to July 3rd 2008. FORWARD participated in the conference with a paper titled &#8220;Future threats to future trust&#8221; which was presented by Sotiris Ioannidis from FORTH-ICS. The presentation evolved around the results of the 1st FORWARD Workshop and the established working [...]]]></description>
			<content:encoded><![CDATA[<p align="justify">The <a title="Future of Trust in Computing Conference" href="http://conference.get2us.com/">Future of Trust in Computing Conference</a> took place in Berlin from June 30th to July 3rd 2008. FORWARD participated in the conference with a paper titled &#8220;<a title="FORWARD Publications" href="http://www.ict-forward.eu/publications/">Future threats to future trust</a>&#8221; which was presented by <a href="http://www.ics.forth.gr/%7Esotiris/">Sotiris Ioannidis</a> from <a title="FORTH-ICS" href="http://www.ics.forth.gr/">FORTH-ICS</a>. The presentation evolved around the results of the <a title="1st FORWARD Workshop" href="http://www.ict-forward.eu/workshop/">1st FORWARD Workshop</a> and the established <a title="FORWARD Working Groups" href="http://www.ict-forward.eu/wg/">working groups</a>.</p>
<p align="justify">The FORWARD paper seemed to spark interest in the conference which was mostly  dedicated to analyzing the benefits and applications of <a title="Trusted Computing Group" href="https://www.trustedcomputinggroup.org/">Trusted Computing</a>. An interesting proposal posed by the audience was to move beyond technical analysis of future threats into investigating the economy and motives underlying the various malicious activities.</p>
<p align="justify"><span id="more-12"></span>Apart from FORWARD&#8217;s paper, we found of particular interest <a title="Symantec" href="http://www.symantec.com">Symantec</a>&#8216;s Richard Archdeacon presentation of today&#8217;s malware landscape. An interesting finding on their latest <a title="Symantec Internet Security Threat Report" href="http://www.symantec.com/business/theme.jsp?themeid=threatreport">Internet Security Threat report</a> is that the malware market has become much more streamlined than we imagine. Symantec identified trust chains between malware-suplier and malware-users which in some cases are formalized by means of End User Licence Agreements (EULAs), just like mainstream software is. They also hinted for a future switch from blacklisting to whitelisting for protecting from malware.</p>
<p align="justify">Overall, the conference was an interesting experience and we hope that FORWARD&#8217;s paper has managed to attract the interest of the very active trusted computing community for the project.</p>
]]></content:encoded>
			<wfw:commentRss>http://blogs.ict-forward.eu/forward/forward-in-future-of-trust-in-computing-conference/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
