Showing posts with label Universities. Show all posts
Showing posts with label Universities. Show all posts

Friday, July 19, 2013

Universities Face a Rising Barrage of Cyberattacks

University officials concede that some of the hacking attempts have succeeded. But they have declined to reveal specifics, other than those involving the theft of personal data like Social Security numbers. They acknowledge that they often do not learn of break-ins until much later, if ever, and that even after discovering the breaches they may not be able to tell what was taken.

Universities and their professors are awarded thousands of patents each year, some with vast potential value, in fields as disparate as prescription drugs, computer chips, fuel cells, aircraft and medical devices.

“The attacks are increasing exponentially, and so is the sophistication, and I think it’s outpaced our ability to respond,” said Rodney J. Petersen, who heads the cybersecurity program at Educause, a nonprofit alliance of schools and technology companies. “So everyone’s investing a lot more resources in detecting this, so we learn of even more incidents we wouldn’t have known about before.”

Tracy B. Mitrano, the director of information technology policy at Cornell University, said that detection was “probably our greatest area of concern, that the hackers’ ability to detect vulnerabilities and penetrate them without being detected has increased sharply.”

Like many of her counterparts, she said that while the largest number of attacks appeared to have originated in China, hackers have become adept at bouncing their work around the world. Officials do not know whether the hackers are private or governmental. A request for comment from the Chinese Embassy in Washington was not immediately answered.

Analysts can track where communications come from — a region, a service provider, sometimes even a user’s specific Internet address. But hackers often route their penetration attempts through multiple computers, even multiple countries, and the targeted organizations rarely go to the effort and expense — often fruitless — of trying to trace the origins. American government officials, security experts and university and corporate officials nonetheless say that China is clearly the leading source of efforts to steal information, but attributing individual attacks to specific people, groups or places is rare.

The increased threat of hacking has forced many universities to rethink the basic structure of their computer networks and their open style, though officials say they are resisting the temptation to create a fortress with high digital walls.

“A university environment is very different from a corporation or a government agency, because of the kind of openness and free flow of information you’re trying to promote,” said David J. Shaw, the chief information security officer at Purdue University. “The researchers want to collaborate with others, inside and outside the university, and to share their discoveries.”

Some universities no longer allow their professors to take laptops to certain countries, and that should be a standard practice, said James A. Lewis, a senior fellow at the Center for Strategic and International Studies, a policy group in Washington. “There are some countries, including China, where the minute you connect to a network, everything will be copied, or something will be planted on your computer in hopes that you’ll take that computer back home and connect to your home network, and then they’re in there,” he said. “Academics aren’t used to thinking that way.”

Bill Mellon of the University of Wisconsin said that when he set out to overhaul computer security recently, he was stunned by the sheer volume of hacking attempts.

“We get 90,000 to 100,000 attempts per day, from China alone, to penetrate our system,” said Mr. Mellon, the associate dean for research policy. “There are also a lot from Russia, and recently a lot from Vietnam, but it’s primarily China.”

Other universities report a similar number of attacks and say the figure is doubling every few years. What worries them most is the growing sophistication of the assault.

For corporations, cyberattacks have become a major concern, as they find evidence of persistent hacking by well-organized groups around the world — often suspected of being state-sponsored — that are looking to steal information that has commercial, political or national security value. The New York Times disclosed in January that hackers with possible links to the Chinese military had penetrated its computer systems, apparently looking for the sources of material embarrassing to China’s leaders.

This kind of industrial espionage has become a sticking point in United States-China relations, with the Obama administration complaining of organized cybertheft of trade secrets, and Chinese officials pointing to revelations of American spying.

This article has been revised to reflect the following correction:

Correction: July 18, 2013

An article on Wednesday about research universities in the United States facing a barrage of cyberattacks misidentified the employer of a researcher from China who was arrested and charged in April with trying to steal a cancer-fighting compound and related data. It was the Medical College of Wisconsin, not the University of Wisconsin’s medical school.

Saturday, April 13, 2013

Universities Offer Courses in a Hot New Field: Data Science

The field has been spawned by the enormous amounts of data that modern technologies create — be it the online behavior of Facebook users, tissue samples of cancer patients, purchasing habits of grocery shoppers or crime statistics of cities. Data scientists are the magicians of the Big Data era. They crunch the data, use mathematical models to analyze it and create narratives or visualizations to explain it, then suggest how to use the information to make decisions.

In the last few years, dozens of programs under a variety of names have sprung up in response to the excitement about Big Data, not to mention the six-figure salaries for some recent graduates.

In the fall, Columbia will offer new master’s and certificate programs heavy on data. The University of San Francisco will soon graduate its charter class of students with a master’s in analytics. Other institutions teaching data science include New York University, Stanford, Northwestern, George Mason, Syracuse, University of California at Irvine and Indiana University.

Rachel Schutt, a senior research scientist at Johnson Research Labs, taught “Introduction to Data Science” last semester at Columbia (its first course with “data science” in the title). She described the data scientist this way: “a hybrid computer scientist software engineer statistician.” And added: “The best tend to be really curious people, thinkers who ask good questions and are O.K. dealing with unstructured situations and trying to find structure in them.”

Eurry Kim, a 30-year-old “wannabe data scientist,” is studying at Columbia for a master’s in quantitative methods in the social sciences and plans to use her degree for government service. She discovered the possibilities while working as a corporate tax analyst at the Internal Revenue Service. She might, for example, analyze tax return data to develop algorithms that flag fraudulent filings, or cull national security databases to spot suspicious activity.

Some of her classmates are hoping to apply their skills to e-commerce, where data about users’ browsing history is gold.

“This is a generation of kids that grew up with data science around them — Netflix telling them what movies they should watch, Amazon telling them what books they should read — so this is an academic interest with real-world applications,” said Chris Wiggins, a professor of applied mathematics at Columbia who is involved in its new Institute for Data Sciences and Engineering. “And,” he added, “they know it will make them employable.”

Universities can hardly turn out data scientists fast enough. To meet demand from employers, the United States will need to increase the number of graduates with skills handling large amounts of data by as much as 60 percent, according to a report by McKinsey Global Institute. There will be almost half a million jobs in five years, and a shortage of up to 190,000 qualified data scientists, plus a need for 1.5 million executives and support staff who have an understanding of data.

North Carolina State University introduced a master’s in analytics in 2007. All 84 of last year’s graduates in the field had job offers, according to Michael Rappa, who conceived and directs the university’s Institute for Advanced Analytics. The average salary was $89,100, and more than $100,000 for those with prior work experience.

“This has become relevant to every company,” said Michael Chui, a principal at McKinsey who has studied the field. “There’s a war for this type of talent.”

Because data science is so new, universities are scrambling to define it and develop curriculums. As an academic field, it cuts across disciplines, with courses in statistics, analytics, computer science and math, coupled with the specialty a student wants to analyze, from patterns in marine life to historical texts.

Claire Cain Miller is a technology reporter for The Times.

Sunday, November 18, 2012

10 Universities to Form Semester Online Consortium

Starting next fall, 10 prominent universities, including Duke, the University of North Carolina at Chapel Hill and Northwestern, will form a consortium called Semester Online, offering about 30 online courses to both their students — for whom the classes will be covered by their regular tuition — and to students elsewhere who would have to apply and be accepted and pay tuition of more than $4,000 a course.

Semester Online will be operated through the educational platform 2U, formerly known as 2tor, and will simulate many aspects of a classroom: Students will be able to raise their hands virtually, break into smaller discussion groups and arrange and hold online study sessions.

The virtual classroom is a cross between a Google+ hangout and the opening sequence of “The Brady Bunch,” where each student has his or her own square, the equivalent of a classroom chair. However, with Semester Online courses, there is no sneaking in late and unnoticed, and there is no back row.

Unlike the increasingly popular massive open online courses, or MOOCs, free classes offered by universities like Harvard, M.I.T. and Stanford, Semester Online classes will be small — and will offer credit.

“Now we can provide students with a course that mirrors our classroom experience,” says Edward S. Macias, provost and executive vice chancellor for academic affairs at Washington University in St. Louis, one of the participants.

“It’s going to be the most rigorous, live, for-credit online experience ever,” said Chip Paucek, a founder of 2U.

For many of the participating schools, which include Brandeis, Emory, Notre Dame, the University of Rochester, Vanderbilt and Wake Forest, Semester Online offerings will be their first undergraduate for-credit online courses, and the first to offer credit to students from outside the universities.

One draw for the colleges is the expansion in their course catalogs.

“No university can deliver the full range of courses that both might be interesting and useful and enlightening to our students,” said Peter Lange, the provost of Duke. “Imagine if you don’t have a person who works on the Sahel region in Africa, but another school does.”

Friday, October 5, 2012

Bits Blog: Hackers Breach 53 Universities and Dump Thousands of Personal Records Online

Hackers published online Monday thousands of personal records from 53 universities, including Harvard, Stanford, Cornell, Princeton, Johns Hopkins, the University of Zurich and other universities around the world.

The group of hackers, calling themselves Team GhostShell, claimed responsibility for the attack on Twitter and published some 36,000 e-mail addresses and thousands of names, usernames, passwords, addresses and phone numbers of students, faculty and staff, to the Web site Pastebin.com. In most cases the data was already publicly available, but in some instances the records included additional sensitive information such as students’ dates of birth and payroll information for university employees.

Typically, hackers seek such information because it can be used to steal identities, crack bank accounts or can be sold on the black market. Universities make ripe targets because they store vast numbers of personal records, often in decentralized servers. The records can be a gold mine because students often have pristine credit reputations and do not monitor their account activity and credit scores as vigilantly as adults.

Dozens of universities have been plagued by breaches recently. Last August alone, the University of Rhode Island warned that students and faculty that their information may have been exposed. And at the University of Arizona, a student discovered a breach after a Google search exposed her personal information — and that of thousands of others at the university. Smaller computer breaches at Queens College and Marquette University were also reported.

In this case, the hackers said they were not motivated by profit but to “raise awareness towards the changes made in today’s education.” In a message accompanying the stolen data, they bemoaned changing education laws in Europe and spikes in tuition fees in the United States. But they also noted that in many cases, the servers they breached had already been compromised.

“When we got there, we found that a lot of them have malware injected,” the hackers wrote on Pastebin.

To breach servers, the hackers used a technique known as an SQL injection, in which they exploit a software vulnerability and enter commands that cause a database to dump its contents. In the case of some universities, the hackers breached multiple servers.

IdentifyFinder, a firm that works to prevent identify theft from security breaches, analyzed the published data and said it appeared to be legitimate. The company analyzed the data and found 36,623 unique e-mail addresses and tens of thousands of student, faculty and staff names as well as thousands more usernames and passwords, some encrypted but many stored in plain text.

Aaron Titus, a spokesman for IdentityFinder, said that in analyzing the hackers’ attack methods, there was evidence that in many cases they had been inside the universities’ systems for “at least four months.”

Lisa Ann Lapin, a spokeswoman for Stanford University, said that the university discovered the breach Tuesday evening. She confirmed that two departmental Web sites belonging to the university had been accessed, but said the servers “have been secured.”

“Our information security officers consider the breaches to be minor in nature,” Ms. Lapin said. “No restricted or prohibited data was compromised, nor was any sensitive or other personal information that could lead to identity theft.”

At colleges across the country, some students set up sites that allowed students and faculty to search the leaked data for their information. For instance, at the University of Pennsylvania, Matt Parmett, a junior, created a Web site that made it possible for classmates to search the leaked data by name.

Thursday, July 19, 2012

News Analysis: Top Universities Test the Online Appeal of Free

In a major development on Tuesday, a dozen highly ranked universities said they had signed on with Coursera, a new venture offering free classes online. They still must overcome some skepticism about the quality of online education and the prospects for having the courses cover the costs of producing them, but their enthusiasm is undimmed.

But at universities that have not yet seized a piece of this action, the response ranges from curiosity to fear of losing a crucial competition. When University of Virginia trustees ousted their president last month — a decision they later reversed — one reason cited was concern about being left behind online. (Virginia was included in Tuesday’s announcement.)

“There’s panic,” said Kevin Carey, director of education policy at the New America Foundation, a nonpartisan research group. “Whether it’s senseless panic is unclear.”

Massive open online courses, or MOOCs, let colleges reach vast audiences at relatively low cost, but they have not yet made money from them. And if it becomes possible in years to come to get a complete college education from an elite institution online, free or at relatively low cost, experts wonder whether some colleges will find it harder to attract students willing to pay $20,000, $40,000 or even $60,000 a year for the traditional on-campus experience.

Online classes have been around for years, with technology evolving to include multimedia features and interaction among students and faculty. What is new is the way top colleges are jumping in with free courses — in effect, throwing open the doors digitally.

So far, most people signing up live in foreign countries. But MOOCs will become more appealing to domestic students when they give course credits toward a degree, something the elite universities have not yet done. The University of Washington says it plans to do so, and it may be just a matter of time before earning credits becomes standard.

“The people who should be worried about this are the large tier of American universities — especially the expensive private schools — that are not elite and don’t have the same reputation” as the big-name universities now creating MOOCs, said Anya Kamenetz, an author who writes on the future of higher education.

Residential colleges already attract far less than half of the higher education market. Most enrollment and nearly all growth in higher education is in less costly options that let students balance classes with work and family: commuter colleges, night schools, online universities.

Most experts say there will always be students who want to live on campus, interacting with professors and fellow students, particularly at prestigious universities. But as a share of the college market, that is likely to be a shrinking niche.

The elite universities will be best able to compete with low-cost alternatives because their large endowments make them less dependent on tuition income, and they can lower their effective prices through generous financial aid, said John Nelson, a managing director at Moody’s Investors Service who analyzes higher education finances.

Analysts say that universities will inevitably try to make money from MOOCs, whether by charging tuition or not. Software companies working with colleges have looked into advertising, or selling information on students to prospective employers.

William E. Kirwan, chancellor of the University System of Maryland, noted that a few public colleges, including his system’s University College, already offer mostly online courses. In the future, he said, the standard class will be a hybrid of in-person and online elements, which Maryland is experimenting with.

“We think this approach can cut costs by about 25 percent,” he said, “enabling each professor to work with more students, while producing a clear improvement in learning outcomes.”

For a decade, Carnegie Mellon University’s Open Learning Initiative has created free online courses. But for many educators, Stanford fired the starting gun last fall, with a free online course in artificial intelligence that drew 160,000 students.

The Massachusetts Institute of Technology started a free class project, MITx, in December. The next month, a Stanford professor who helped teach the artificial intelligence class founded Udacity, a company offering free courses in partnership with colleges and professors.

In April, Stanford, Princeton, the University of Pennsylvania and the University of Michigan joined forces with Coursera to offer free classes. In May, Harvard teamed with M.I.T. to create a similar venture, edX.

In the last week, more universities signed on with Coursera.

“Our participation was finalized literally over the weekend,” said J. Milton Adams, vice provost at the University of Virginia, which listed five free courses. “I’m going to have some unhappy faculty members saying, ‘Why can’t my course be on there?’ ”