By Jennifer LeClaire TechNewsWorld
05/30/06 10:42 AM PT
Colleges identified security as the most critical issue facing their computer systems for the first time in seven years, according to a survey of about 600 colleges released this month by Educause, a nonprofit group that promotes information technology use. In a 2000 survey, security wasn't even among the top five concerns.
In a hack attack that reflects a worrisome trend in the education arena, Fairfield, Conn.-based Sacred Heart University in early May discovered that the security system on one of its computers containing students' personal data was breached. The university has not confirmed that sensitive files were actually accessed, but said the intruder did have the expertise to access them.
"While the University maintains a state-of-the-art computer security system and employs a highly qualified outside computer security firm, it is impossible to be 100 percent secure from illicit intrusion into confidential, personal and financial information," the university said in a statement.
A Hacking Epidemic
Sacred Heart is hardly the only educational institution to face a hack attack in recent months. Ohio University in May also reported its servers had been compromised in a series of break-ins that put personal data of more than 300,000 people at risk. About 60,000 students fell victim to the attack.
In March, a Georgetown University network server holding data on 40,000 Washington, D.C., residents was hacked, leaving their names, addresses and Social Security numbers accessible to identity thieves.
In fact, since February 2005, over 50 million people have had their personal information potentially exposed by unauthorized access to the computer systems of companies and institutions, according to The Privacy Rights Clearinghouse, and 50 percent of all reported security breaches since that time have occurred at colleges and universities.
Growing Concern
"Universities have been a target of attackers for well over a decade, because there is a wealth of information there that is useful for exploitation. There are young students there who have credit cards, Social Security numbers, bank accounts and other types of online assets that are valuable to criminals," Ken Dunham, senior engineer at threat intelligence firm iDefense, told TechNewsWorld.
While corporations may have large security budgets and IT staff, universities often do not enjoy the same level of resources to safeguard information. Universities are typically understaffed, and their IT employees often are undertrained to deal with computer security, Dunham noted. These educational IT gurus may be ale to deal with standard system administration, but the challenge is to move beyond mere functionality into security.
"Unlike a corporation, universities have unique challenges that are extremely difficult to manage. They often have a very large number of users and support a wide range of computers," said Dunham. "It's very different from a small business that wants to adopt a bunch of Microsoft (Nasdaq: MSFT) computers and call it good. These guys might have to support Apples and PCs and have them talk to each other. It makes it increasingly complex."
Paying Closer Attention
Colleges are finally taking notice. For its part, Sacred Heart is conducting a full review of the incident and its computer security policies and procedures with the help of outside agencies.
Moreover, colleges identified security as the most critical issue facing their computer systems for the first time in seven years, according to a survey of about 600 colleges released this month by Educause, a nonprofit group that promotes information technology use. In a 2000 survey, security wasn't even among the top five concerns.
New Zero Day Attack Targets Word Users May 22, 2006
"Prevention is key," said iDefense Senior Engineer Ken Dunham. "Indications are that a patch should be coming out by the next Patch Tuesday or sooner. This is not considered to be a major threat for everyone, but it is a threat for whoever is targeted by these attackers."
Related Stories
Physical Security Goes High Tech May 17, 2006
Imagine this type of technology brought to bear on border security, port security, or on any aspect of critical infrastructure. It's not a question of whether, but of when. When physical security meets cyber-security, it's a win-win.
Security Hot Issue for Open-Source Database Developers January 24, 2006
According to Evans Data's Fall Database Development Survey, open-source database deployments were up more than 20 percent in the last six months. MySQL use, for example, increased by more than 25 percent in six months and is approaching majority status in the database space. Currently, forty-four percent of developers use the open-source MySQL system.
Related News Alerts
More by Jennifer LeClaire
The Digital Car: Cool Automotive Accessories, Part 2 January 16, 2007
Not all the latest high-tech automotive electronics are built to entertain. Many give the driver more information and more control. Vehicle tracking devices can tell where the car is at any time, software installed in a smartphone can turn off a vehicle's security system whenever the owner approaches, and diagnostic tools can tell what's wrong with the engine -- and how much it'll be to fix it.
'World of Warcraft' Wows 8 Million Subscribers January 12, 2007
"World of Warcraft," the massively multiplayer online role-playing game, has reached the 8 million subscriber mark. Since debuting in North America in Nov. 2004, "World of Warcraft" has become the most popular MMORPG in the world. The franchise is available in seven different languages and is played on at least four continents.
AT&T Bids Goodbye to Cingular Brand January 12, 2007
Starting Monday, AT&T will launch a multimedia campaign to transition the Cingular Wireless brand name into its advertising and customer communications. The campaign will integrate popular imagery, phrases and icons from Cingular's traditional advertising, including the "raising the bar" tagline, the "Jack" character and the color orange.