/* -- STUFF -- */

iTnews: Forgetful mobile devices for careless users

Thursday, October 16, 2008


As a journalist at iTnews:

“Blessed are the forgetful: for they shall have done with their stupidities too,” German philosopher Friedrich Nietzsche once wrote.

The 19th Century philosophy seems to have struck a chord with modern day manufacturers, who tout mobile devices with remote memory erasure capabilities or that store no user data at all.

Securing mobile data has become an increasingly prevalent issue for businesses in recent times, as notebooks and smartphones gain ubiquity in the corporate world.

Employees who access corporate data remotely and out of office hours may threaten the security of sensitive information in cases of accidental loss or theft of their mobile devices.

IT contractor EDS recently was reported to have lost a portable hard drive containing data on as many as 1.7 million prospective U.K. armed forces recruits.

The incident follows the U.K. Ministry of Defence’s recent admissions to the loss of three hard drives containing details of more than 50,000 members of the Royal Air Force, and the loss of loss of 658 laptops and 121 USB data drives since 2004.

Other storage devices such as CDs and flash memory cards also have resulted in data leakage in the past.

Sensitive MI6 photos found their way to the public last month via a camera that was sold on eBay. Meanwhile, in March, HSBC lost a CD containing names, life insurance cover levels and dates of birth of 370000 of its customers, prompting industry criticisms of ‘basic stupidity’.

Microsoft has partnered with Nokia, Apple and Sony Ericsson to safeguard sensitive information through technology that wipes clean the memory of missing smartphones.

Dubbed Microsoft System Centre Mobile Device Manager 2008, the technology is a function of Windows Mobile 6.1, and allows system administrators to deliver a ‘kill command’ to a lost or stolen mobile device via Microsoft Exchange.

The kill command is executed as soon as the missing device is connected to a cellular or Internet-enabled network, after which a confirmation notice is delivered to the administrator.

Users also are able to encrypt external memory cards, such as SD cards, so that they can only be read by the smartphone. Because the encryption key is stored on the smartphone, an executed kill command would render data on encrypted memory cards inaccessible.

Personal data that is not backed up will be lost forever with the execution of a kill command. However, as most corporate data is stored on the Exchange server, it can easily be restored on a replacement device.

Rick Anderson, who is Microsoft’s Enterprise Mobile Solution Specialist, said that the technology is focussed on reducing the chance of corporate data being compromised by reducing the window of opportunity.

He noted that Windows Mobile 6 has attained the Common Criteria EAL2+ Assurance Level after assessment by the Defence Signals Directorate (DSD), and has been accepted for use in the Australian Government's official communications and information systems.

“You certainly have your mobile phone everywhere, so you have to be conscious of the fact that you can lose it, by leaving it on the train for example,” he said.

“Blackberry and us [Microsoft] would probably be the ones to look at in terms of corporate mobile solutions,” he told iTnews.

Meanwhile, Hewlett-Packard (HP) has added to its notebook range the HP Compaq 6720t, which features an embedded, write-protected operating system.

The 6720t is a mobile thin client which, like conventional desk-based thin clients, is designed to provide access to virtual computing solutions, such as blade PCs or virtual desktop infrastructure.

It is a solid-state system with flash memory and no moving parts. No data is stored on the device, so sensitive data is not compromised in case of loss of theft.

“From a thin client point of view, it’s [corporate data] all secured in a data centre,” said Fiona Wright, who is HP Australia’s Market Development Manager for Thin Clients.

“For example, if an agent is on the road and left the device somewhere, their sensitive information would not be lost or compromised,” she told iTnews.

The 6720t was released in July 2008 as the commercial world’s first thin client that has been built for mobility.

However, the fact that it relies on server-based data and applications may somewhat limit users’ movements.

IDC research manager of IT spending, Jean-Marc Annonier, expects a broadband connection to be the minimum requirement for the remote use of thin clients.

“Thin clients are not really good for mobility,” he said. “What you need is a live network connection for the thin client to connect to the server.”

“You can’t do this on a train, definitely, even if you have a 3G connection,” he told iTnews.

“The problem is latency,” he said. “With 3G, you may have one second of latency, [during which time] you can’t see what you’re doing.”

But for businesses whose employees work predominantly from the office, home, or a client’s broadband-enabled premises, mobile thin clients could deliver not only security, but economic benefits as well.

A recent report by IDC found thin clients to reduce hardware and software costs by 87 percent, IT costs by 61 percent, and worker downtime by 49 percent when compared with traditional PCs.

Through reducing the need for hardware upgrades and enabling software updates to be rolled-out centrally on the server, thin clients were found to produce a 466 percent return on investment for businesses that were studied.

Large organisations are expected to reap the greatest return on investments for thin client deployments. Annonier expects organisations with between 500 to 1000 workers, using between 300 and 700 devices, to have most to gain.

IDC estimates that one quarter of Australian organisations already have deployed thin clients, and deployments are roughly evenly split between production or pilot phases.

13 percent of organisations are found to be evaluating the technology, while six percent claimed to have no plans to deploy thin clients. The remaining 56 percent of organisations surveyed were either unable to respond, or unaware of the technology.

“Computer virtualisation, although not a new concept, has come of age,” Annonier wrote in the report.

“The days of the traditional PC and the distributed computing model as we know them are numbered and the trend towards centralised computing is already becoming increasingly evident,” he wrote.

According to HP’s Wright, customer feedback for the 6720t has been positive so far.

She expects mobile thin clients to appeal especially to mobile workers who deal with sensitive information, such as those in the health and finance industries.

“Being a new product, there’s a lot of conversation and a lot of hype,” she told iTnews. “From my point of view, it [the technology’s suitability] really does depend on what the IT manager wants to use the thin client for.”

“I do hear from customers that security is on their minds, and I do believe that mobile thin clients will offer what they are after,” she said.

more

iTnews: Economic crisis a 'return to normality', ANZ CEO says

Wednesday, October 08, 2008


As a journalist at iTnews:

Global economic uncertainty may be curbing jobs and investments, but according to Mike Smith, CEO of the ANZ bank, ‘good businesses’ should have nothing to fear.

Addressing 850 business delegates at a luncheon organised by the Australia-Israel Chamber of Commerce (AICC) last month, Smith described ‘one of the greatest economic crises since the Great Depression’.

“I’ve lived through -- and survived -- at least seven economic crises,” he said. “Everyone is very skittish, very nervous, and least bit of information is often taken out of context.”

“I believe we have 18 months to run of this extreme volatility,” he said.

Following the U.S. sub prime crisis and the subsequent collapse of major financial institutions, Australian businesses now face a tightening of credit availability and a softening local economy.

According to Smith, the credit crunch could re-establish a divide between ‘good’ and ‘bad’ businesses -- a divide that he said has blurred due to Australia’s strong economic growth in recent times.

“If you think about Australia, for 15 years, we’ve had very good credit growth and access to equity has been extraordinary,” he said. “That has meant that good businesses have been doing well, but so have bad businesses.”

“What we’re seeing is a return to normality. Good businesses will continue to do well, but bad businesses may not,” he said.

“Access to credit should not be a problem for a good project -- if it stacks up, it will work,” he said. “If you’re a good customer of the bank, there should not be an issue. You should have access to credit.”

Event sponsor IBM echoed Smith’s optimism, citing a global expansion strategy that has resulted in 63 percent of its revenue coming from outside the U.S., including 21 percent from the Asia Pacific region, during the past year.

Glen Boreham, managing director for IBM Australia and New Zealand, highlighted recent Gartner research that predicts regional spending to increase by 8 percent from last year, despite the U.S. downturn.

As well as striking recent deals with BHP Billiton, Customs, and QLD Motorways, IBM also has invested $10.8 million in a new IT Services Centre at the University of Ballarat Technology Park (UBTP).

“In the last 12 months, IBM has hired over 1,000 people through acquisitions, contracts, graduate and professional recruitment,” Boreham told iTnews. “Currently IBM employs nearly 15,000 people in Australia.”

“IBM has a proven record of providing high value to clients during turbulent times, which reflects the market's confidence in our strategy and business direction,” he said.

“For IBM in Australia, we are continuing to win major deals and our clients are continuing to look to IT to help transform their organisations by improving productivity through innovation and automation.”

more

iTnews: Poor IT performance surprises job market survey

As a journalist at iTnews:

Advertisements for IT jobs have fallen 19 percent during the past twelve months, signalling the beginning of a buyers market for jobs in Australia, the Olivier Job Index claims.

Of 385,488 online job vacancy advertisements surveyed in September, vacancies in the IT sector fell 3.27 percent in the month.

September was the fourth consecutive month of decline, and saw the overall Olivier Job Index fall 1.17 percent in the month and 2.03 percent in the year to reach a five-year low.

A year ago, IT was the second largest job sector after Sales and Marketing. It has fallen behind Engineering, Trades and Services, and Building and Construction to be ranked fifth.

“I've been surprised at how poorly IT has performed,” said Olivier Group’s Director, Robert Olivier, noting that IT has experienced the second largest fall during the past year, after the Banking and Finance sector.

“In a year it’s gone from a sellers market to a buyers market. It’s been a slow painful decline -- a death by a thousand cuts.”

“I think this is because banking and the public sector are big IT users and demand has fallen. Also, many Australian operations are part of US global businesses and the squeeze is coming from head office,” he speculated.

Although the ‘innovative spirit and drive’ is unlikely to be lost, a decline in the availability of venture capital cash and monetary investment could curb commercial development, Olivier said.

Meanwhile, he expects employers to be gambling on how long the economic slowdown will last by cutting back on temporary staff and contractors, and graduate hires.

Job advertisements for temporary staff and contractors fell 4.7 percent in September and 14.3 percent during the past year. Meanwhile, advertisements for graduate positions fell 2.2 percent in the month and 16.03 percent in the year.

“There’s no point letting people go if you’re going to have to rehire in 12 months or less,” Olivier said, highlighting the security of permanent positions so far.

“But if employers see the problems lasting longer, then we’ll see a rise in the jobless rate,” he said.

For the younger generation of employees and job hunters, there may be tough times ahead, as the falling value of superannuation and investment funds may lead mature workers to defer retirement, and in some cases, bring people out of retirement.

“When employers become more careful about whom they employ and supply exceeds demand, job tenure becomes a critical factor,” Olivier said. “In the 2001-2 downturn, we saw employers penalising the job hoppers.”

“They [Gen Y] have never experienced a contracting labour market and with all the talk of an aging population and skills shortages perhaps were not expecting it either!”

Olivier said workers should consolidate with one employer, and make sure that they are considered core staff and high performance / low maintenance.

He said the global economic slowdown could put an end to part of the widely-touted skills shortage. However, he noted that demand for staff in some sectors will be stronger than in others.

“If the global meltdown gets worse or stays for longer then overall supply will exceed demand and some of the shortage will be over,” he said.

“But it’s also important not be generalise and to consider matters on an occupational basis,” he said.

“Healthcare, mining and engineering will continue to have shortages, but there will be a lot of pain in financial services, IT and a wide range of white collar professions.”

more

iTnews: iPhone startup brings fuel price app to Australia

Friday, October 03, 2008


As a journalist at iTnews:

A team of developers from Australia and the U.S. is monetising consumers’ petrol price concerns with the launch of a free-to-use iPhone application.

Dubbed ‘GasBag’, the application is designed to locate the cheapest local petrol station using user-submitted price information and rich mapping framework.

Since its launch in the U.S. last month, GasBag has attracted about 75,000 unique users across the country. The application is expected to launch in Australia, Canada and the U.K. by the end of this month.

GasBag was conceptualised in May, and its parent company, jamcode LLC, was incorporated one month later.

Although three of the four jamcode founders are Australian, the team chose to focus its initial development efforts in the U.S. due to the popularity of the iPhone and consumers’ sensitivity to fuel prices.

“Everyone here [in California] talks about fuel all the time,” said Mick Johnson, an Australian GasBag developer who currently resides in California.

“We saw that need, and realised that if we could cater to it, we could do very well,” he told iTnews.

The application currently is offered as a free download from Apple’s iTunes App store and is supported by target advertisements through a partnership between jamcode and mobile advertising company, Mobclix.

As GasBag develops, jamcode expects to provide improved targeting according to information such as car model, trip destination, how often the user fills up, and users’ advertising preferences.

“Our current modelling shows GasBag to be monetisable to the tune of roughly one to five dollars per user per year, once you take into account how often someone fills up, how many ads they'll see, and how much each ad is worth,” Johnson told iTnews.

“We are currently targeting to hit 400,000 to 500,000 users by the end of 2008 across four countries,” he said.

Prior to launching in Australia, GasBag developers will be working on locating petrol stations using street directories and public maps, and converting units from gallons to litres and miles to kilometres.

Another challenge could be competition from Google, which recently partnered with petrol price monitoring company Motormouth to provide a similar Web-based application.

However, Johnson views competition from Google in a positive light, noting that GasBag has become the most popular application of its kind on the App Store despite competition from ‘four or five’ similar applications in the U.S.

“I'm very happy to see the Google-Motormouth collaboration,” he said. “For starters, it's a direct validation of the Australian market for GasBag.”

“Secondly, I think their [Google’s] model of receiving data from their own fleet of sources is a good reliable pulse, but I also think GasBag's inherent advantage is the extremely strong user community it's built on. As such, we can update our list of stations, our prices, and our addresses much more rapidly,” he said.

Johnson said the iPhone provides developers with opportunities for innovation through its extra features and the coherence of the iPhone SDK code base.

He expects GasBag to be just the beginning of products and opportunities for jamcode.

“It [GasBag] looked like a good application to start with, as we can now leverage this user base to bring out a suite of applications with similar functionality but for different use cases, such as finding parking lots, ATMs, hotels, etc,” he told iTnews.

“The iTunes store has been great for GasBag - it really let us provide our application to an extremely wide market very quickly,” he said.

more

iTnews: Non-equilibrium chips could avoid overheating laptops

Thursday, October 02, 2008


As a journalist at iTnews:

Researchers are re-examining the Second Law of Thermodynamics in a bid to manage heat from laptops and other miniaturised electronics.

As chip manufacturers cram increasing numbers of transistor switches in small areas to make faster, cheaper chips, heat dissipation has become a growing concern.

The Pentium II processor, introduced in 1997, was said to generate more heat than a hot plate, and Intel in 1999 predicted that the amount of heat generated by computer chips would increase linearly as chip sizes decrease.

Should the trend continue, future electronic devices could generate more heat than nuclear reactors and be ‘as hot as the Sun’ within two decades, researchers say.

“Laptops are very hot now, so hot that they are not 'lap' tops anymore,” said Avik Ghosh, who is researching new heat dissipation methods at the University of Virginia's School of Engineering and Applied Science.

“It [heat] is probably the most critical impediment to continued miniaturisation of transistors, which carry out logic operations in computers,” he told iTnews.

Ghosh and his colleague Mircea Stan are investigating a concept known as ‘non-equilibrium Brownian ratchets’ which could revolutionise how heat is dissipated between computer components.

Currently, devices are engineered to operate near thermal equilibrium, in accordance with the Second Law of Thermodynamics which states that heat tends to transfer from a hotter unit to a cooler one.

However, using the concept of Brownian ratchets, which are systems that convert non-equilibrium energy to do useful work, the researchers hope to allow computers to operate at low power levels, and harness power dissipated by other functions.

“The main quest we have is to see if by departing from near-equilibrium operation, we can perform computation more efficiently,” Ghosh told iTnews.

“We aren't breaking the Second Law -- that's not what we are claiming,” he said. “We are simply re-examining its implications, as much of the established understanding of power dissipation is based on near-equilibrium operation.”

But while the physics of non-equilibrium Brownian ratchets has been studied extensively for some time, the concept’s application in a technology context has not.

Ghosh expects to face challenges ranging from proof-of-concept demonstration, to going beyond models to experimental testing, and analysing the practicality, robustness and cost-effectiveness of these schemes.

“Until we do a proper study, we can't be sure whether this method would suffice
to address the considerable challenges of heat generation and removal,” he said.

“Our short-term plan is to study this over the next three to five years at this time to see where we end up with non-equilibrium switching, and whether it could offer a solution.”

more

iTnews: GPS spoofing device developed to thwart spoofing

Wednesday, October 01, 2008


As a journalist at iTnews:

Researchers have developed a portable Global Positioning System (GPS) spoofing device in a bid to explore aspects of civilian spoofing and how such attacks may be thwarted.

By providing researchers with information about which aspects of spoofing are most easily implemented, the project could allow device manufacturers to prioritise their spoofing defences.

Spoofing is a term used to describe the transmission of fake signals that navigation devices accept as authentic signals from GPS satellites.

As GPS devices become more pervasive in home and business use, spoofing could have a serious impact -- for example, through large enterprises such as utility companies that use GPS in their core operations.

“A spoofed GPS device can be tricked into computing the wrong position or time,” said Brent Ledvina, an assistant professor of electrical and computer engineering at Virginia Tech who conducted the research in collaboration with Cornell University.

“This can be devastating for some receivers and a nuisance for others,” he said.

The research was presented at the Institute of Navigation GNSS conference in Georgia last month, after more than a year of equipment building and experimentation.

While GPS spoofing has attracted some U.S. government attention during the past half-decade, manufacturers have yet to address these security concerns, Ledvina said.

“Currently, GPS receiver equipment manufacturers do not have spoofing on their
radar,” Ledvina told iTnews.

“[Cornell researcher] Todd Humphreys and I talked with the leading receiver manufacturers at the Institute of Navigation conference … and not a single individual we spoke with was knowledgeable of the topic.”

“That doesn't mean these companies are not interested or concerned, per se, but their representatives at this conference certainly were not,” he said.

Ledvina expects most current GPS receivers to be vulnerable to spoofing attacks, with the yet-to-be verified exception of multi-antenna receivers that use special signal processing.

The researchers have proposed two software modifications that they expect to make receivers less vulnerable to spoofing by changing how they react to signals.

They have filed a provisional patent application for the technology and are in discussion with ‘a couple’ of companies about commercialisation.

However, Ledvina expects the only long-term solution to come from encrypting signals broadcast by the GPS satellite constellation by adding an authentication signal.

“The truth is there is no perfect solution for a stand-alone, single-antenna receiver that does not use any type of authentication,” he told iTnews.

“It would most likely take a long time [for authentication signals to be added] because the signal specifications for the broadcast GPS signals are difficult to modify, and satellites on orbit today have a long lifetime.”

“Note that adding an authenticating signal is not a technical issue; it's more of a political issue,” he said.

more

iTnews: HP collaborates to identify Wi-Fi dead zones cheaply

Tuesday, September 30, 2008


As a journalist at iTnews:

A collaborative effort by HP Labs and Rice University has produced a technique that could lower the cost of identifying ‘dead zones’ in large wireless networks.

The technique enables Wi-Fi architects to test and refine their layouts before a network is deployed.

According to Joshua Robinson, a graduate student at Rice University, there currently is no standard industry practice to identify Wi-Fi dead zones.

“The frequency of dead zones have actually been a huge obstacle to deploying city-wide wireless networks,” he told iTnews.

“Since companies don't advertise how they find dead zones, it's hard to say authoritatively what happens.”

Some providers employ expensive, exhaustive measurement studies that require the network to be tested from every location from which potential users may wish to connect.

Other approaches involve taking a few measurements in an ad hoc fashion and fixing any remaining dead zones after the network is deployed.

According to Robinson, the goal of the new technique is to focus measurement efforts on ‘trouble areas’ that potentially could be dead zones.

The technique identifies locations at which the network should be tested by combining wireless signal models with publicly-available information about basic topography, street locations and land use.

“We develop accurate predictions and use these predictions to avoid spending a lot of measurements in areas that have clearly very good or very poor performance,” he explained.

“This is how we are able to use a small number of measurements to more accurately find a network's performance and identify all the dead zones.”

The research won best-paper honours at the annual MobiCom ’08 wireless conference in San Francisco this month.

By requiring five times fewer measurements when compared with a grid sampling strategy, and ‘far fewer’ measurements than needed for an exhaustive measurement strategy, the new technique could reduce labour and equipment costs, researchers say.

Robinson expects the municipalities, companies, and non-profit organisations looking to deploy city-wide wireless mesh networks to benefit most from the new technique.

He named for example the Technology-for-All (TFA) network that is being built by Rice University in partnership with a local non-profit organisation to wirelessly provide free Internet access to an under-served neighbourhood in Houston, Texas.

“We currently serve around 4000 people,” he told iTnews. “Since we do not have a big budget to test the network, techniques to reduce the cost and time involved in finding our dead zones are very helpful.”

Besides the TFA deployment, the new technique also has been tested on Google’s wireless network in Mountain View, California.

When compared with exhaustive measurement studies of both networks, the technique was found to achieve approximately 90 percent accuracy while requiring less than two percent of the number of measurements performed.

In the short term, Rice University researchers will be focusing on extending their research for use in the network planning process.

HP Labs has a definite commercial interest in the project and has been involved in prior deployments in Taipei. However, no plans for commercialisation of the technique have been announced as yet.

more

iTnews: Beware smartphone data leakage, Marshal warns

Friday, September 26, 2008


As a journalist at iTnews:

The increasing use of Blackberry, iPhone and other smartphone devices in the enterprise could put corporate data at risk, content security vendor Marshal warns.

According to Marshal’s Asia-Pacific Vice President, Jeremy Hulse, companies need to govern the use of smartphones, which enable a greater number of people to access company data from anywhere.

While notebook computers have enabled similar data mobility in the past, Hulse expects the burgeoning smartphone culture to introduce new risks to enterprise security.

“You don’t really pull a notebook out as much as a smartphone,” he noted. “The risk is pulling a smartphone out with friends at a bar, leaving it around, or losing it in a public place.”

Highlighting the importance of financial and strategic data to a corporation, Hulse said businesses should pay more attention to defining and protecting their critical information.

“The level of risk [posed by smartphones] depends on the type of information that people are pushing down to mobile devices, and the locations they are accessing this information from,” he told iTnews.

“They [businesses] have to ask themselves, ‘Do people need to access corporate information on mobile devices?’”

Market pervasion and a diminutive size have contributed to the fact that mobile phones and PDAs currently are far more commonly lost, or left behind, than notebook computers.

According to a recent survey by privacy vendor Credant technologies, a total of 62000 mobile devices have been left in London cabs during the past six months.

While personal data and identity fraud has been the main worry of lost mobile devices in the past, Hulse expects corporate data loss soon to steal the spotlight.

“It’s only a matter of time, especially with the amount of storage available in new devices,” he said.

Besides instilling a corporate culture of greater care when accessing company data on a smartphone, Hulse suggests the use of technologies such as content filtering, hardware and software locks.

While he could not identify manufacturers of mobile devices that offer particularly good or bad security, Hulse noted that some vendors have collaborated with Microsoft to install technology that wipes clean a devices’ memory in case of loss or theft.

Other vendors offer software that provides a standard operating environment across mobile devices and enterprise desktop computers, which could enable organisations to monitor and filter the transfer of sensitive data.

Noting that smartphone technology could benefit employees’ productivity, Hulse said security should not be seen as a barrier to mobility, but an enabler to maximise the benefit from mobile technology investments.

“I think smartphones can actually be really productive, but I think they need to be looked at in terms of security,” he told iTnews.

“The capability [for increased productivity] is there, but training for staff needs to be there too,” he said.

more

iTnews: In-the-cloud security to grow in economic crisis, Webroot predicts

Thursday, September 25, 2008


As a journalist at iTnews:

The economic downturn could give the software as a service (SaaS) model an edge over traditional security software provision, Webroot believes.

In Sydney this week to speak at Gartner’s IT Security Summit, Webroot CTO Gerhard Eschelbeck highlighted the difficulty of managing an evolving threat landscape amid staff shortages and tightening budgets.

While e-mail security has dominated the spotlight previously, Webroot research indicates that the Web has been a greater source of threats in recent times.

The research also found that more than half of Web security decision makers feel that keeping security products up-to-date is challenging, and almost 40 percent believe their companies devote insufficient resources to Web security.

“Nowadays, the threat landscape is changing in so far that the variants of malware is exploding compared to five years ago,” Eschelbeck said, noting that malware variants in circulation today are five times as numerous as those five years ago.

“It is clear that the traditional applications are reaching some of their physical limits,” he told iTnews.

Compared to traditional, on-premise security applications, Webroot’s SaaS offerings provide businesses with the ability to outsource the burden of security.

Companies’ e-mail and Web traffic is filtered through Webroot’s data centres in Australia to detect and remove any malware.

Webroot has invested approximately $1m in its Australian operations, including a newly-launched data centre in Sydney and eight support staff across Sydney and Melbourne.

According to Charles Heunemann, Webroot’s Managing Director of Asia Pacific Operations, the company has provisioned for ‘significant growth’ in the region.

The Sydney data centre currently is used to only a ‘single digit percentage’ of its capabilities, he said.

“What we’ve got is a situation where we’ve come from an early adaptor stage to a wider use of SaaS,” Heunemann said of the growing market for in-the-cloud security applications.

The rise of SaaS was said to be a result of economic pressure to deliver more value through IT and a trend towards outsourcing ‘non-core’ applications.

In the Asia-Pacific region, the market for SaaS is experiencing a Compound Annual Growth Rate (CAGR) of 44 percent, Heunemann said, compared to a CAGR of 13 percent for on-premise software.

Webroot estimates in-the-cloud security applications currently to have a market penetration of 8 percent in Australia, 4 percent in Asia and 25 percent in the U.K.

“The genesis of security technology tends to be in the U.K.,” Eschelbeck said, expecting Australian adoption to reach similar figures ‘before long’.

In terms of Eschelbeck’s research into the ‘Laws of Vulnerabilities’, the SaaS model could reduce the threat posed by current Web-based malware by narrowing organisations’ window of exposure.

“The Laws of Vulnerabilities is to do with how quickly organisations are patching their systems,” he explained. “There is a physical limit to how quickly companies can patch, so there is always a window of exposure of five to nine days.”

“The huge advantage that it [SaaS] brings is moving the responsibility [of patching] from the organisation to the provider,” he said.

Heunemann noted that through providing a specialised security service to multiple organisations, service providers such as Webroot also have access to economies of scale and greater visibility of the overall threat landscape.

Webroot also is able to provide its customers with some level of insurance, through guaranteeing a minimum malware capture and detection rate.

“Compared to the traditional model where you’re looking at deploying an on-site application to protect against malware, the SaaS model essentially is a pay-as-you-go option that scales very well linearly, as you grow,” Eschelbeck said.

“Typically, IT departments are not overstaffed -- I’ve never heard of overstaffing as an being an issue for these departments -- so the advantage [of SaaS] is taking the burden [of security] away from end users,” he said.

more

iTnews: Ruxcon hacker conference opens arms to security pros

Wednesday, September 24, 2008


As a journalist at iTnews:

Community-organised hacker conference, Ruxcon, is aiming to attract a ‘more diverse field’ of attendees to its annual event in November.

Now in its sixth year, Ruxcon is expected to bring together some 350 vulnerability enthusiasts from across Australia.

Ruxcon 2008 will be the sixth such event since its launch in 2003. Over the years, the conference has evolved from a technical, specialist event to have a broader security focus, according to conference organiser Chris Spencer.

“The focus is going to be a little more professional this time around,” Spencer told iTnews. “We want to start attracting a more diverse field of security professionals.”

“I don’t think there is much of an Australian hacking community anymore; the security industry has commercialised vulnerability research, so that there just isn’t a vibrant hacking community,” he said.

Spencer compared Ruxcon to high-profile hacker conferences such as Defcon and Black Hat in the U.S., describing Ruxcon as a hobbyist, community-driven event.

Since its inception, the conference has been organised by the same group of volunteers, all of whom have day jobs in the Australian security industry.

When not organising Ruxcon, Spencer works as a vulnerability researcher. Other organisers include consultants and security administrators.

Ruxcon 2008 will be held at the University of Technology, Sydney from 29 to 30 November, and costs $60 to attend.

Presenters hailing from Australia, New Zealand, Italy and France will discuss topics such as how Graphics Processing Units (GPUs) can be used by malware, and heap exploitation theory in Windows Vista.

Despite the vulnerabilities and methods that will be discussed at the conference, Spencer notes that Ruxcon has not encountered any resistance from vendors to date.

And previous years’ sponsorship by vendors such as Google and VeriSign’s iDefense has not impacted presentations such as ‘Google Hacking’, which will be discussed this year.

“When they [Ruxcon presenters] present on these topics, they are doing it from a research background and not a malicious standpoint,” Spencer said of the risks of revealing vulnerabilities.

“As a whole, it’s [Ruxcon] just about putting on a demonstration of the talent we have in Australia,” he said.

more

iTnews: Angel investor seeks geek chic innovations

Tuesday, September 23, 2008


As a journalist at iTnews:

Australian Web site developer Geekdom is seeking geeky ideas for its online business incubation program.

The program, dubbed ‘Geeksville’, targets projects in Australia and offers successful applicants angel funding, mentoring and business resources.

According to Ian Naylor, Chief Technology Officer of Geekdom, the program aims to ‘bridge the gap’ between budding and business-ready stages of an idea.

“Typically VCs will not fund an idea from inception,” Naylor explained. “Effectively, they are stage two investors once the business has been bootstrapped for a period and a modicum of success has been achieved.”

“The core area of our business is developing with investment in mind,” he said. “Using our venture capital connections, we have a good idea of what has a chance to be picked up.”

Geeksville was formed early this year, when Geekdom executives realised that its core Web site development business structure could support external as well as internal innovations.

The incubation program has now been running for six months and is slated to publically launch its first batch of start-up companies soon.

A six month time to market is among a loose set of selection criteria for Geeksville hopefuls. Other criteria include: innovative ideas for the online market; and a project’s manageability.

While the incubator program has a distinct focus on Australian innovations, it encourages applicants to focus on both local and international markets to create scalable opportunities.

Along with salary, resources, mentoring and business structure, successful applicants also receive access to other resources within Geekdom’s parent organisation, the Photon Group.

The Photon Group encompasses more than 50 other companies, including strategic communications company Love, Naked Communications, and European public relations consultancy Hotwire.

“As an incubator we see our value not just in providing money, but structure and resources,” Naylor told iTnews, “so really the less you [applicants] have, other than the idea, the more value we can add.”

more

iTnews: Video game GPUs find use in biological modelling

Monday, September 22, 2008


As a journalist at iTnews:

Forget supercomputers -- researchers have devised a method of using graphics processing technology from video games in complex biological modelling.

Applied to a new area in biology called agent-based modelling, the technology could enable a wider range of researchers and medical practitioners to simulate processes graphically.

Agent-based modelling simulates the behaviours of complex systems by predicting the actions and interactions of its various components.

Currently, researchers in this field of work either manually develop, or use toolkits to build, code which runs directly on a computer’s CPU (central processing unit).

According to Roshan D'Souza of the Michigan Technological University, such code often has limited scalability, so large-scale models often require the use of a supercomputer.

D’Souza is attempting to make large-scale modelling more accessible with the use of graphic processing units (GPUs) that currently are used in video games to do parallel computation for the purpose of realistic rendering of scenes.

Using GPUs, researchers could simulate large-scale models with tens of millions of cells on a regular desktop costing under US$1400, he expects.

“Currently, if you want to simulate a model anywhere close to what we are handling, you have to go to a supercomputer costing a few million quid,” he told iTnews.

“GPUs are cheap – [costing around] $400 -- and are a bang for the buck,” he said. “You can do sufficiently large models to handle quite a large portion of the scenarios.”

Another benefit of using GPUs is that they produce real-time simulations, whereas supercomputers calculate simulations offline without real-time visual display.

Results of GPU simulations may not be any better than those produced by a supercomputer, nor do GPUs replace supercomputers in simulating ultra-large models comprised of billions of agents, D’Souza said.

However, by providing a cost-effective method for large-scale modelling, GPUs could be used by physicians to do diagnostics or to plan individualised treatment plans for patients.

“The big picture is this: in the near future, when your local physician starts using ABMs [agent-based models] … he/she will not be able to access a supercomputer,” D’Souza said.

“But for sure he/she can buy a GPU and insert in into his/her desktop,” he said.

In the past, GPUs have been used for research into fluid simulation, n-body dynamics and protein folding.

The application of GPUs in agent-based modelling came as an ‘accident’, D’Souza said, when investigating CAD (computer-aided design) tools to detect design errors in mechanical engineering designs.

“I used GPUs for this,” he recalls, “then I was looking around for other ‘stuff’ to do with the GPU. I found that people had already worked on molecular dynamics, fluids, protein folding etc – but agent-based modelling was open.”

“With a $1,400 desktop, we can beat a computing cluster,” he said of the technology. “We are effectively democratising supercomputing and putting these powerful tools into the hands of any researcher.”

“Every time I present this research, I make it a point to thank the millions of video gamers who have inadvertently made this possible,” he said.

more

iTnews: 'Spoken tokens' touted as ultimate security

Friday, September 19, 2008


As a journalist at iTnews:

An Australian market for biometric voice authentication is taking shape from early adopters in the banking, government and service industries.

According to Chuck Buffum, who is Vice President of Caller Authentication Solutions for Nuance Communications, more Australian companies are likely to be authenticating their customers with ‘spoken tokens’ within the next few months.

In Sydney to meet with customers this week, Buffum expects the local voice authentication market to grow to within three months of more mature markets such as the U.S., U.K. and Canada by mid-2009.

“It’s very early in the market take up,” he said, estimating there to be eight to 10 consumer-facing biometric voice authentication deployments in the world currently.

“That will change in the next few months,” he said, citing discussions with Australian banks and government agencies, which are expected to deploy the technology within six to nine months.

Currently, Nuance’s voice authentication technology is used by subscription television provider Austar to handle orders for its premium services and movies.

The authentication and call steering system is said to have achieved an initial return on investment in less than 12 months, and currently handles more than 1.5 million (51 percent) calls per year.

Besides the convenience and cost benefits of an automated voice authentication system, Buffum expects the biometric technology to provide consumers with greater account security.

“All around the world, there is more and more attention on protecting personal information and keeping that secure,” he told iTnews.

“Companies need to be encouraged to recognise that vulnerability and use suitable technologies to protect their customers,” he said.

Buffum warned of the public availability of personal information on the Internet. Such information often is used to secure accounts with traditional authentication protocols, he noted.

Social networking sites such as Facebook were highlighted as sources from which malicious persons may obtain information such as a person’s date of birth and hometown.

Search engine queries can be used to obtain yet more personal information about a target, as evidenced by the hacking of U.S. vice presidential candidate Sarah Palin’s e-mail account this week.

With the right design and security settings, biometric voice authentication methods could provide greater security by combining ‘something you know’, such as a password, with ‘something you are’, through your voice print, Buffum said.

Binary voice prints in Nuance’s software consist of 28 features, which are vocal characteristics such as the geometry of one’s vocal tract and behavioural patterns such as cadence, rhythm and volume.

The system determines the statistical likelihood of a caller and his or her saved voice print, and authenticates the caller in accordance with the security threshold set by the company.

Some transactions such as airline timetables may require lower security thresholds than others, such as banking, Buffum said.

Noting that ‘nothing is as good as iris scanning’, Buffum estimates the security level of voice authentication to be similar to that of fingerprint technology, and ahead of face scanning.

A hacker could make an audio recording of an account holder’s interaction with a voice authentication system and play it back to gain access, but such attacks could be thwarted by requesting the caller to repeat a random series of words, he said.

“The Mission Impossible squad can always break in,” he said, “but with this technology, you can at least keep everyone else out.”

“2009 is the year of the early adopters,” Buffum said of the Australian voice authentication market.

“Hopefully you’ll be counting them [deployments] on more than one hand -- but that’s around the figure we’re looking at.”

more

iTnews: Mobile operators warned of 'dumb pipes' ISP scenario

Wednesday, September 17, 2008


As a journalist at iTnews:

Mobile broadband operators need to look beyond flat-rate access offerings to future-proof their business, analysts say.

Recent research from analyst firm Ovum suggests that operators could bolster their revenues by leveraging subscriber information and network-based assets.

Melbourne-based Ovum analyst Nathan Burley likened the current mobile broadband market to last decade’s fixed broadband offerings that bundled access with services such as e-mail, hosting and content.

As consumers turned to other Web sites for their online activities, fixed broadband ISPs were muscled out of content revenue and into what analysts call a ‘dumb pipes’ scenario.

Mobile broadband operators such as Telstra currently support a bulk of their customer’s activities through services such as mobile TV, games and customised music sites.

But with the growing popularity of smartphones that feature more user-friendly Web browsers, mobile broadband operators may soon go in the way of their fixed-line counterparts, Ovum predicts.

“If you look at these smartphones, browsers on the phones are getting better and you are seeing users of these handsets use the phones for their own content on the Internet,” he said.

Burley named the Blackberry Bold, Nokia N96, HTC Touch Diamond and Apple’s iPhone as examples of game-changing devices.

“In terms of the iPhone, Apple’s strategy to some degree is to relegate the [mobile broadband] operator to offering access only,” he said.

“It’s a very open model for content providers,” he told iTnews.

While this open model could mean less content-based revenue for mobile operators, Burley points out that external content could bolster data access revenue.

Additionally, mobile operators could have a place in the value chain for supporting third-party content and other services by leveraging in-depth information about their customers and network-based assets such as location.

Areas such as social networking applications could benefit from customer metadata, Burley said, highlighting opportunities for advertising revenue.

“On the Internet, if you look at the people [companies] who have prevailed in terms of advertising revenue, it [their success] sits on a lot of information about their subscribers,” he said.

But not all operators will be successful in gaining a share of the advertising pot, analysts predict, due to the strong competition between broadcasters, Internet businesses and traditional media.

Ovum suggests that mobile broadband operators consider options such as: having their own paid-for content and service offerings; offering their own and third-party content on an ad-supported basis; and providing access to free Internet-based content to drive usage and hence access revenues.

more

iTnews: 'Cognitive radios' to improve wireless devices

Tuesday, September 16, 2008


As a journalist at iTnews:

Researchers are developing intelligent radios that can sense their surroundings and adjust their mode of operation accordingly.

Dubbed ‘cognitive radios’, the technology is expected to reach the market within five years, finding uses in public safety devices and wireless networks.

Cognitive radios build on the concept of ‘software defined radio’, in which most functions in a radio device are performed by software-controlled digital electronic circuits.

Similar to how a modern day cell phone signs on to different networks while roaming, a cognitive radio is designed to be adaptive to its situation.

“A cognitive radio is aware of its environment, its own capabilities, the rules within which it can operate, and its operator’s needs and privileges,” explained Charles W. Bostian, an Alumni Distinguished Professor of Electrical and Computer Engineering at Virginia Tech.

“It is capable of changing its operating modes in ways that maximise things that the user wants while staying within the rules ... is capable of learning in the process and of developing configurations that its designer never anticipated.”

Adaptive, cognitive radios could enable techniques such as dynamic frequency sharing, in which radios automatically locate unused frequencies, or share channels based on a priority system.

In public safety, cognitive radios also could be used to provide interoperability between various signals and automatically adjust radio performance.

“For example, if its user is inside a building where there is little or no public safety radio coverage, the radio may automatically switch to a VoIP mode and reach the dispatcher through a WiFi access point and a telephone line,” Bostian said.

“These ideas are research topics now, and some of them will soon reach the market,” he said.

“It will mean more business and more equipment to sell for the wireless infrastructure manufacturers. They have nothing to lose and a lot to gain.”

Microsoft is researching the technology’s potential to alleviate bandwidth scarcity in wireless networking through its Kognitiv Networking Over White Spaces (KNOWS) research project.

The project works towards opportunistically accessing unused portions of the TV spectrum, and already has birthed a prototype that scans for unused frequencies by sensing the TV spectrum.

When an open frequency band is located, the device is designed to dynamically switch to it in a way that does not hurt incumbent TV receivers.

“I think dynamic spectrum access will be the first application for commercial wireless services like WiFi and WiMax,” Bostian told iTnews. “There is movement toward doing this in vacant U.S. TV channels.”

According to Bostian, current challenges in the development of cognitive radio are reducing cost and improving battery life.

While the technology is expected to reach the market within five years, it will take twice as long to become commonplace, Virginia Tech researchers predict.

more

iTnews: Contact centres urged to look offshore for staff

Monday, September 15, 2008


As a journalist at iTnews:

Australian contact centres need to look offshore to solve staffing issues, claims customer service outsourcing agency, Convergys.

Convergys’s statement comes on the heels of the 2008 Australian Contact Centre Industry Benchmark Study, which highlighted high levels of employee attrition in the contact centre industry.

Conducted by ACA Research, the study found staff turnover, difficulty in recruiting and inadequate headcount to be the industry’s three greatest challenges.

Staff attrition was ascribed to the fact that only one-third of contact centre staff view their job as a career, while other survey respondents described their job as part-time, gateway, and transition gigs.

“In Australia, a lot of industries just don’t see a contact centre job as a career,” said Max Tennant, Senior Account Executive of Convergys.

“Top that off with the highly transactional functions in most contact centre jobs, and it just doesn’t make it [contact centre work] an appealing job for young people,” he said.

Tennant suggests that contact centre operators move some functions offshore, where the ‘highly transactional, monotonous functions’ that are required may be considered appealing.

He named the Philippines and India as prime offshore locations due to the language and customer service skills that are available.

“Culturally, the offshore agents are a lot more open to these transactional tasks that Australian agents may find monotonous,” he said, describing ‘hierarchical’ tendencies in the Asian culture, and adding that offshored contact centres tend to pay three times the minimum wage in host countries.

Contact centre operators could direct specific customer requests to locations with staff adept at those functions, Tennant said, noting that while Indian contact centres have been found to excel in backoffice functions, staff in the Philippines traditionally provide a better customer service experience.

“If you ask your customers, ‘would you prefer an offshore or onshore agent’, they will ask for onshore, because that’s what they’re culturally used to,” he noted.

“But if you say, ‘look, here’s our situation -- you can wait 45 minutes for XYZ and our operating hours are 9-5 -- would you like 24/7 service and all these other options if we provide offshore agents?’ They will say yes.”

“It’s important that offshoring needs to be a part of an organisation’s overall strategy and is not just a cost savings thing,” he said.

Teleworking and process automation previously have been heralded as solutions to staffing problems in the Australian contact centre industry.

However, Tennant said that there are some transactions that once automated, do not provide a satisfactory customer experience, and expects there to be insufficient Australian teleworkers to provide the required headcount to satisfy customer demands around the clock.

Convergys maintains 84 contact centres worldwide, which house a total of 45,000 agent stations -- most of which are staffed around the clock, Tennant said.

A majority of Convergys’s facilities are located in the U.S., where the business originated. The company plans to direct more of its clients to its 9 contact centres in India, and 14 in the Philippines.

more

iTnews: Supercomputing revenue to grow $6.4b by 2012

Friday, September 12, 2008


As a journalist at iTnews:

High Performance Computers (HPC) are extending their reach from academic research to government, manufacturing and financial industries, analysts say.

According to analyst firm IDC, revenue from HPCs -- which are commonly termed ‘supercomputers’ -- will grow by $6.4 billion during the next five years.

Industries experiencing the most growth in HPC applications are expected to be software engineering, mechanical design, weather, financial and digital animation.

Universities, which in 2007 spent more than $2.1 billion on HPCs, will continue to lead HPC spending with a forecasted spending of $3.2 billion in 2012.

Although optical and quantum technologies have received much attention as potential supercomputing technologies, most HPCs today are comprised of high performance configurations of ordinary technologies.

“Most high performance computers today are based on commodity technologies that are readily available in the open market,” explained Steve Conway, who is IDC’s Research Vice President of Technical Computing and Steering Committee Member of the HPC User Forum.

Speaking with iTnews in the lead up to IDC’s HPC roadshow in Sydney this month, Conway said that common HPC configurations include standard x86 microprocessors from AMD or Intel, and the standard Linux or Microsoft Windows operating system.

“The trick is in how these technologies are connected together in supercomputers that may have 100,000 or more processors each in some cases,” he said. “Increasingly, fibre optical connections are used to link the components together.”

Outside of the academic sphere, current supercomputers have found uses in aircraft design for Boeing, assembly line modelling for Proctor and Gamble, and manufacturing simulation for Whirlpool.

IBM and Hewlett-Packard lead the fray, each occupying 32.9 percent of the HPC market. Dell currently owns 17.8 percent market share, while Cray owns 1.1 percent.

During the next decade, Conway expects supercomputers to reach speeds 1,000 times faster than today’s best by 2017.

These ‘exaflop’ computers will perform 10^18 calculations per second and will be able to process the informational equivalent of all 20 million volumes in the New York Public Library system in less than one second, Conway said.

But as energy concerns come to the fore, analysts expect the cost and availability of electricity to be biggest challenge for the HPC market.

While petascale supercomputers slated for delivery in the 2010 timeframe are expected to require as much as 20MW of power, similar projects could demand 60MW in the 2015-2017 timeframe.

“Today's biggest supercomputers consume enough electricity to power a small city,” Conway said. “In some cases where the infrastructure is lacking, adequate power is simply not available to an HPC site at any price.”

“The biggest challenge will likely be the cost and availability of adequate electricity to operate computers this large and power-hungry,” he said.

“When the sharply rising costs of oil and gas, it is no surprise that power and cooling has become one of the top few issues for HPC users.”

more

iTnews: University of Sydney takes records management online

Thursday, September 11, 2008


As a journalist at iTnews:

The University of Sydney has completed the second stage of a decade-long move from paper to an electronic records keeping system.

Working with systems integrator Alphawest during the past four years, the university has implemented the Records Online 2 Web interface, which allows staff to create and manage student records online.

The implementation, which is estimated to have cost $160,000, has already delivered an annual return on investment of $675,000.

According to University of Sydney’s acting registrar Tim Robinson, Records Online 2 currently has 1,500 users out of a prime audience of 2,800 administrative staff.

It is estimated to have saved 10 minutes per week of physical filing work and reduced the need to create 10 or more physical files each year for 40 percent of its users.

Staff members are being introduced to the system in groups, in line with the project’s cautious approach to change management.

“One of the fundamental things we decided from the outset was that we weren’t going to go for the big king hit,” Robinson told iTnews.

“Making things simple is always time consuming,” he said, describing an aim to make the records keeping system user-friendly while maintaining a suitable privacy and access regime.

“An enormous amount of thought went into it; we knew that if it wasn’t simple, it would not be used,” he said.

The university took its first step away from its traditional paper registry in 2000, with the implementation of the Captira management tool in the back end.

Online search functionality was added shortly after, but it wasn’t until 2007 when users were able to access 98 percent of records management functions online.

The latest implementation of Records Online 2 now integrates the university’s records system with its business system, as well as allowing staff to access records via Microsoft Outlook.

Robinson noted that each stage of the implementation required ‘a lot’ of training for staff, estimating the cost of training to equal that of hardware and software combined.

“With an organisation as big as the Uni, we knew that we couldn’t train all these people in one go,” he told iTnews, describing one-on-one, roadshow, and small group training options.

After all administrative staff members are trained, the next challenge for Robinson’s team will be to introduce the Records Online 2 to academic staff, so they can access student records more efficiently.

Looking forward, Robinson expects the university to be looking to update its records management system again within the next three years.

He mentioned Microsoft Office SharePoint and an Open Source system that is in development at Curtin University as candidates.

“We’re always looking at what the next stage is,” he said. “I’m guessing by three years time, there will be some significant changes, and we’d be looking to update our systems.”

more

iTnews: Researchers find racial bias in virtual worlds

As a journalist at iTnews:

Real-world behaviours and racial biases could carry forward into virtual worlds such as Second Life, social psychologists say.

According to a study that was conducted in There.com, virtual world avatars respond to social cues in the same ways that people do in the real world.

There.com is a relatively unstructured virtual world that brands itself as an online getaway where users can hang out with friends and explore an immense, unusual landscape.

Users, who were unaware that they were part of a psychological study, were approached by a researcher’s avatar for either a ‘foot-in-the-door’ (FITD) or ‘door-in-the-face’ (DITF) experiment.

The FITD technique works by first asking a participant to comply with a small request -– which, in this experiment, was “Can I take a screenshot of you?” -- followed by a moderate request: “Would you teleport to Duda Beach with me and let me take a screenshot of you?”

Participants who fulfilled the small request are expected to be likely to see himself or herself as being helpful, and thus be more likely to fulfil the subsequent larger request.

The DITF technique work works in an opposite way: the experimenter first makes an unreasonably large request to which the responder is expected to say no, followed by a more moderate request.

In the DITF condition, that large request was to have screenshots taken in 50 different locations, which would have required about two hours of teleporting and travelling.

As the researchers expected, DITF participants were found to be more likely to comply with the moderate request when it was preceded by the large request, than when the moderate request was presented alone.

But while results of the FITD experiment revealed no racial bias, the effect of the DITF technique was significantly reduced when the experimenter took the form of a dark-skinned avatar.

White avatars in the DITF experiment received about a 20 percent increase in compliance with the moderate request; however, the increase for the dark-toned avatars was 8 percent.

According to the researchers, skin colour had no effect on FITD experiments because the elicited psychological effect is related to how a person views himself or herself, and not others.

However, the DITF technique is said to reflect a psychological tendency to reciprocate the requester's ‘concession’ from a relatively unreasonable request to a more moderate request, and thus is affected by whether the requester is deemed worthy of impressing.

The finding is consistent with previous DITF studies -- in real and virtual worlds -- that demonstrate that physical characteristics, such as race, gender and physical attractiveness, affect judgment of others.

Numerous studies done in the real world show that people are more uncomfortable with minorities and are less likely to help them.

“This study suggests that interactions among strangers within the virtual world are very similar to interactions between strangers in the real world,” said Paul W. Eastwick, who conducted the study at the Northwestern University.

“You would think when you're wandering around this fantasyland … that you might behave differently,” he said. “But people exhibited the same type of behaviour -- and the same type of racial bias -- that they show in the real world all the time.”

more

iTnews: Kaspersky Lab patents dynamic antivirus technology

Wednesday, September 10, 2008


As a journalist at iTnews:

Kaspersky Lab has patented a method of antivirus scanning that assesses files according to when and how they first appeared on the computer.


The method has been granted Patent No. 7 392 544 by the U.S. Patent and Trademark Office. Internally, it has been unofficially named ‘FirstTimeCheck’.

By dynamically varying the scanning level and set of tools used for file scanning, FirstTimeCheck is expected to minimise the impact of antivirus scanning on the overall system performance.

The technology also makes it possible to extend the time taken to scan new files and files received via ‘high-risk’ sources such as suspicious Web sites, P2P networks and e-mail attachments.

“In the past, antivirus products were scanning files with a standard set of technologies,” said Nikolay Grebennikov, Kaspersky Lab’s Vice-President for Research & Development.

“Now, the antivirus arsenal includes many new technologies, which significantly raise detection rate, but use more RAM and CPU time.”

“The standard solution for this situation is to limit the usage of these technologies to a level where antivirus scanning will not affect users’ activities too much," he told iTnews.

Grebennikov explained that the ‘standard solution’ to limit the resource usage of antivirus programs has been to set strict limits on the time taken to scan files.

He described such methods as a ‘compromise’ that may affect the quality of scanning and decrease the level of user protection.

“The main advantage of our method is that it minimises the impact on the overall system performance,” Grebennikov told iTnews.

“Normally such a deep system scan would greatly affect performance of the computer it is running on, but our new technology manages to bypass this negative effect to ensure maximum system performance all the time,” he said.

Kaspersky Lab is working on implementing FirstTimeCheck in current products and plans to implement the technology in the next version of its consumer products.

more