| Abstract: | Web 2.0 applications, especially client-side processing, Extensible Markup Language (XML) syndication, mashups and shared content, and social networking, bring unique vulnerabilities to our institutional environments. This Burton study clarifies the attack objectives and techniques that must be specifically defended against as risks increase, as well as the role of application security in the risk management process. Links to documents within this file might require secure access to restricted Web sites. Burton Group (www.burtongroup.com) provides technically in-depth research and advisory services for colleges and universities, government agencies, and commercial enterprises. Burton Group's practical and unbiased research and advice helps technologists make smart IT infrastructure decisions in increasingly complex environments. Burton Group covers directories, identity management, application platforms, architecture, and network and telecom infrastructure topics. Like ECAR, Burton Group is an unbiased advocate for the user and more than 80% of Burton Group's clients are user organizations rather than suppliers. EDUCAUSE member institutions can become users of Burton Group research services through EDUCAUSE pricing. Burton Group is an ECAR partner and can be contacted by email at slesueur@burtongroup.com or by telephone (801-373-5767). |