Home > Security Tips > Network Security Tactics > The key to locking out mobile threats
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

The key to locking out mobile threats


Brien M. Posey
04.04.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Mobile devices today are so commonplace that few people pay much mind to them, but mobile devices can pose threats to your network that must not be ignored. Here I'll explain how they can harm your network and what you can do to prevent exploits.

New storage features call for greater precautions

Mobile devices can threaten your network by allowing hackers to haul away sensitive data or letting malicious freeloaders into your space. Let me explain. PDAs have a much greater storage capacity now than they previously had, in a sense acting as portable hard drives. For instance, an unhappy user or unknown intruder who connects a PDA to an office PC could potentially copy sensitive files from the network to the PDA and walk right out the door with them. He could also use a PDA to bring in virus-infected files, whether it be intentional or accidental, or to copy and install a small application on an office workstation.

The fact that many people do not think of mobile devices as security concerns is a major issue. These days, viruses and Trojans are specifically designed to attack mobile devices. This becomes a problem when a device is used to connect to a corporate network over a VPN, Wi-Fi or dial-up link. If a mobile device is infected with a keystroke logger, access credentials to the network can be stolen and transmitted to a server on the Internet, compromising a user's authentication credentials for potential hack attempts.

Locking down mobile devices

To protect your Windows network from mobile threats, create a corporate policy that bans the use of privately-owned mobile devices. If anyone in the company has a legitimate need for a mobile device, it will be the company's responsibility to provide that device. This will cost the company some money up front, but I believe the benefits outweigh the cost.

The first benefit is that you know exactly who is authorized to use mobile devices, and you can take steps to prevent anyone else from attaching a mobile device to the network. Since many mobile devices attach to PCs through a Universal Serial Bus (USB) or Firewire port, try a product like GFI Software Ltd.'s Portable Storage Control to prevent users from attaching mobile devices or any other portable storage device to their PCs.

Company ownership of mobile devices also enables you to dictate what must be running on the devices, insuring the devices are used properly. Insist that the mobile device is running all of the latest patches and the latest antivirus definitions (yes, there are antivirus programs for mobile devices).

Following those steps should greatly increase mobile device security in your organization, but I also recommend occasionally performing random device audits. Check for unauthorized mobile applications, such as hacker tools, and anything else that might compromise security. People tend to have a personal attachment to their mobile devices and might be reluctant to allow the IT department to inspect them. Remember though that the device is company property, and you have the right to inspect it anytime you feel like it.

Mobile devices pose one additional risk, which is what could happen if the device were lost or stolen. If a user has passwords cached within the device, whoever finds it can instantly access your network using that information. Insist that mobile device users have power-on passwords (if supported), and prevent them from caching passwords for connecting to your network, the Internet or anything else. Some users have been known to create text files of passwords, ATM PINs and other highly sensitive information. Make it clear to your users that such files are a very bad idea.

As you can see, mobile devices can easily threaten the integrity and security of your network unless they are properly secured.

About the author
Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Windows 2000 Server and IIS. He has served as CIO for a nationwide chain of hospitals and was once in charge of IT security for Fort Knox. As a freelance technical writer, he has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies.

This tip originally appeared on our sister site, SearchWindowsSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Network Security Tactics
Using Nessus Attack Scripting Language (NASL) to find application vulnerabilities
Screencast: Recovering lost data with WinHex
How to build security into a virtualized server environment
How to install and configure Nessus
How to run a Nessus system scan
Nessus: Vulnerability scanning in the enterprise
Screencast: An introduction to the Open Source Security Testing Methodology Manual (OSSTMM)
Understanding multifactor authentication features in IAM suites
Network intrusion prevention systems: Should enterprises deploy now?
Webmail security: Best practices for data protection

Handheld and Mobile Device Security
Has proof-of-concept mobile device malware translated into any meaningful attacks?
Product review: Credant Mobile Guardian 6.0
Should enterprises implement a mandatory iPhone VPN?
Should iPhone email be sent without SSL encryption?
Employee-owned handhelds: Security and network policy considerations
How secure is a mobile phone platform that has an open source framework?
Defining mobile device security concerns
Is the mobile malware threat overblown?
Secure remote access: Closing the Windows Mobile Smartphone loophole
iPhone security in the enterprise: Mitigating the risks
Handheld and Mobile Device Security Research

Mobile Code
Information security book excerpts and reviews
When will attackers go mobile?
Kaminsky on DNS rebinding attacks, hacking techniques
Discovery of malware cesspool triggers attack fears
Should the contents of a USB token be copied to a hidden directory called 'IEDW?'
Are USB storage devices a serious enterprise risk?
Controlling U3 smart drive use in the enterprise
Mobile carriers admit to malware attacks
Dozens of Web sites spread malicious Trojan
Do USB memory sticks pose enterprise threats?

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineWebcastsWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts