IBM Addresses Web 2.0 Security Concerns With 'SMash'

##AUTHORSPLIT##<--->

IBM announced new technology to secure "mashups," Web applications that pull information from multiple sources, such as Web sites, enterprise databases, or e-mails, to create one unified view. Mashups allow users to gain insight on complex situations but, as with all Web-based initiatives, security has been a concern.

IBM researchers have created a new technology, codenamed "SMash," short for secure mashup, that allows information from different sources to talk to each other, but keeps them separate so malicious code can't be introduced into systems.

IBM is contributing the SMash technology to the OpenAjax Alliance, an organization of vendors, open source projects and companies using AJAX, of which it is a part.

"Web 2.0 is fundamentally about empowering people, and has created a societal shift in the way we organize, access, and use information," said Rod Smith, IBM Fellow and vice president. "Security concerns can't be a complete inhibitor, or clients lose out on the immense benefit mashups bring. The same way you wouldn't buy a car and then later decide to have the seatbelts or airbags installed, as an industry we've learned how to build security into business operations from the ground up instead of tacking it on after the fact."

SMash addresses a part of the browser mashup security issue by keeping code and data from each of the sources separated, while allowing controlled sharing of the data through a secure communication channel. IBM said it plans to include SMash technology in WebSphere products and its commercial mashup maker, Lotus Mashups, expected in the summer. Lotus Mashups is IBM's first commercial mashup maker for organizations. It will allow non-technical users to create and share mashups in a secure way.

A detailed description of SMash will appear in the 17th International World Wide Web Conference, to be held in Beijing, China, in April 2008.

Get daily news from THE Journal's RSS News Feed


About the author: Dian Schaffhauser is a writer who covers technology and business for a number of publications. Contact her at [email protected].

Proposals for articles and tips for news stories, as well as questions and comments about this publication, should be submitted to David Nagel, executive editor, at [email protected].

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • magnifying glass with AI icon in the center

    Google Releases Learning-Themed AI Mode Features for Search

    Ahead of back-to-school season, Google has introduced new AI Mode features in Search, including image and PDF queries on desktop, a Canvas tool for planning, real-time help with Search Live, and Lens integration in Chrome.

  • abstract pattern of cybersecurity, ai and cloud imagery

    Report Identifies Malicious Use of AI in Cloud-Based Cyber Threats

    A recent report from OpenAI identifies the misuse of artificial intelligence in cybercrime, social engineering, and influence operations, particularly those targeting or operating through cloud infrastructure. In "Disrupting Malicious Uses of AI: June 2025," the company outlines how threat actors are weaponizing large language models for malicious ends — and how OpenAI is pushing back.

  • laptop displaying a phishing email icon inside a browser window on the screen

    ED Grant Portal Target of Phishing Campaign

    Threat researchers at BforeAI have identified a phishing campaign spoofing the U.S. Department of Education's G5 grant management portal.

  • laptop displaying AI-powered educational content

    Kira Introduces AI-Generated Lesson Tool

    AI company Kira has announced a new AI-powered lesson generation tool that it says delivers complete, standards-aligned lessons that are personalized to each student.