Home > Ask the Security Experts > Application Security Questions & Answers > Has proof-of-concept mobile device malware translated into any meaningful attacks?
Ask The Security Expert: Questions & Answers
EMAIL THIS

Has proof-of-concept mobile device malware translated into any meaningful attacks?

Michael Cobb EXPERT RESPONSE FROM: Michael Cobb

Pose a Question
Other Security Categories
Meet all Security Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 28 March 2008
Has proof-of-concept malware for mobile devices translated into any meaningful attacks? Should we expect real attacks at any time?

>
EXPERT RESPONSE
If we assume that "mobile devices" equate to popular gadgets like the iPhone, then indeed we should expect real attacks. The hard part is knowing when an attack on mobile devices will take place. In September 2007, we saw the first shellcode that could turn the iPhone into a portable hacking platform.

With increasingly powerful mobile devices selling in large numbers and software development kits readily available, the mobile device scene has all the hallmarks of a classic malware environment. Kids who hack smartphones for fun and fame will be joined by those who abuse these devices for profit. Perhaps the biggest difference from historic malware scenarios today is the existence of a readily accessible market of stolen data and compromised hosts -- and yes, mobile devices are hosts.

We can expect mobile device attacks that target the following:

1. Confidential data stored on the device.
2. Confidential data transmitted to and from the device.
3. Services enabled by the device.

As an enterprise security rule, we can assume that the smarter the device, the more complex, valuable and voluminous the data stored on it is; likewise the data sent to and from the handheld. Another rule of thumb tells us that newer devices prove to be less secure than more mature devices. Put the two rules together, and you have ample reason to think that mobile attacks will be heavily focused on the stored data sent to and from the device.

The wild card may be point three, the services enabled by smartphones. Historically, phone companies have had the most complete and sophisticated network traffic-monitoring and control systems. They may be able to prevent the abuse of connectivity better than the loose-knit patchwork of ISPs who formed the basis of the Internet. If mature technology is not used, you can expect to see some serious and widespread attempts to turn high-speed, always-on mobile devices into botnets.

At the moment, the biggest threats posed by "smart" devices are probably the simplest and oldest: the handhelds get easily lost and stolen, along with the data they contain; people talk too loudly on them, with too little awareness of who might be listening or "shoulder surfing"; people check email with the devices insecurely, exposing passwords and content. There will definitely be sophisticated threats in the future, and the future may be sooner than we expect.

More information:

  • Security experts have been warning of growing mobile phone malware attacks for more than three years. See if you should believe the hype.
  • Mike Chapple explains how today's popular non-corporate smartphones and other gadgets can still fit into an organization's network security plan.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Application Security
    Can IBM's SMash technology secure Web applications?
    Why is backscatter spam so difficult to block?
    What are the risks of disabling the User Account Control (UAC) feature on Windows Vista?
    Protecting exposed servers from Google hacks (and Google 'dorks')
    Which automated quality assurance tools can be used to test software?
    Is it possible to ban chat programs on an enterprise LAN?
    How to test the security of personal details submitted to a website
    Is security improved when the number of Internet gateways is reduced?
    Are Internet cafe users' email credentials at risk?
    Which operating system can best secure an FTP site?

    Handheld and Mobile Device Security
    Smartphones opening up enterprise risks
    BlackBerry server faced with critical zero-day
    Does the iPhone SDK effectively increase the risk iPhones pose?
    Product review: Credant Mobile Guardian 6.0
    Recently I found my computer's serial number had been reported stolen. Will I face legal repercussions?
    Should enterprises implement a mandatory iPhone VPN?
    Should iPhone email be sent without SSL encryption?
    Employee-owned handhelds: Security and network policy considerations
    How secure is a mobile phone platform that has an open source framework?
    Defining mobile device security concerns
    Handheld and Mobile Device Security Research

    Emerging Information Security Threats
    Weaponizing Kaminsky's DNS discovery
    Linux systems actively targeted using SSH key attacks
    What warning signs will indicate the presence of a P2P botnet?
    Adobe investigates clipboard hijackings
    How to patch Kaminsky's DNS vulnerability
    Researchers use browser to elude Vista memory protections
    Hacking techniques compromise Windows Vista heap
    Kaminsky: DNS flaw capable of attacks on many fronts
    Hoffman to demonstrate new hacking techniques
    Black Hat Las Vegas 2008: News, podcasts and videos

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    DNS rebinding attack  (SearchSecurity.com)
    drive-by pharming  (SearchSecurity.com)
    JavaScript hijacking  (SearchSecurity.com)
    man in the browser  (SearchSecurity.com)
    phlashing  (SearchSecurity.com)
    polymorphic malware  (SearchSecurity.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice



    Find Security Solutions for Your Business
    Targeted Security Channel Tips for Resellers, Integrators and Consultants
    TechTarget Security Media
    Information Security View this month\\'s issue and subscribe today.
    Information Security Decisions Apply online for free conference admission.
    SearchSecurity.com
    HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




    All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts