Home > Security Tips > Network Security Tactics > The key to locking out mobile threats
Security Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

NETWORK SECURITY TACTICS

The key to locking out mobile threats


Brien M. Posey
04.04.2005
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Mobile devices today are so commonplace that few people pay much mind to them, but mobile devices can pose threats to your network that must not be ignored. Here I'll explain how they can harm your network and what you can do to prevent exploits.

New storage features call for greater precautions

Mobile devices can threaten your network by allowing hackers to haul away sensitive data or letting malicious freeloaders into your space. Let me explain. PDAs have a much greater storage capacity now than they previously had, in a sense acting as portable hard drives. For instance, an unhappy user or unknown intruder who connects a PDA to an office PC could potentially copy sensitive files from the network to the PDA and walk right out the door with them. He could also use a PDA to bring in virus-infected files, whether it be intentional or accidental, or to copy and install a small application on an office workstation.

The fact that many people do not think of mobile devices as security concerns is a major issue. These days, viruses and Trojans are specifically designed to attack mobile devices. This becomes a problem when a device is used to connect to a corporate network over a VPN, Wi-Fi or dial-up link. If a mobile device is infected with a keystroke logger, access credentials to the network can be stolen and transmitted to a server on the Internet, compromising a user's authentication credentials for potential hack attempts.

Locking down mobile devices

To protect your Windows network from mobile threats, create a corporate policy that bans the use of privately-owned mobile devices. If anyone in the company has a legitimate need for a mobile device, it will be the company's responsibility to provide that device. This will cost the company some money up front, but I believe the benefits outweigh the cost.

The first benefit is that you know exactly who is authorized to use mobile devices, and you can take steps to prevent anyone else from attaching a mobile device to the network. Since many mobile devices attach to PCs through a Universal Serial Bus (USB) or Firewire port, try a product like GFI Software Ltd.'s Portable Storage Control to prevent users from attaching mobile devices or any other portable storage device to their PCs.

Company ownership of mobile devices also enables you to dictate what must be running on the devices, insuring the devices are used properly. Insist that the mobile device is running all of the latest patches and the latest antivirus definitions (yes, there are antivirus programs for mobile devices).

Following those steps should greatly increase mobile device security in your organization, but I also recommend occasionally performing random device audits. Check for unauthorized mobile applications, such as hacker tools, and anything else that might compromise security. People tend to have a personal attachment to their mobile devices and might be reluctant to allow the IT department to inspect them. Remember though that the device is company property, and you have the right to inspect it anytime you feel like it.

Mobile devices pose one additional risk, which is what could happen if the device were lost or stolen. If a user has passwords cached within the device, whoever finds it can instantly access your network using that information. Insist that mobile device users have power-on passwords (if supported), and prevent them from caching passwords for connecting to your network, the Internet or anything else. Some users have been known to create text files of passwords, ATM PINs and other highly sensitive information. Make it clear to your users that such files are a very bad idea.

As you can see, mobile devices can easily threaten the integrity and security of your network unless they are properly secured.

About the author
Brien M. Posey, MCSE, is a Microsoft Most Valuable Professional for his work with Windows 2000 Server and IIS. He has served as CIO for a nationwide chain of hospitals and was once in charge of IT security for Fort Knox. As a freelance technical writer, he has written for Microsoft, TechTarget, CNET, ZDNet, MSD2D, Relevant Technologies and other technology companies.

This tip originally appeared on our sister site, SearchWindowsSecurity.com.


Rate this Tip
To rate tips, you must be a member of SearchSecurity.com.
Register now to start rating these tips. Log in if you are already a member.




BROWSE BY TAG
Network Security Tactics,   Wireless Network Security: Setup and Tools,   Handheld and Mobile Device Security Best Practices,   Enterprise Network Security,   Application and Platform Security,   Web Security Tools and Best Practices,   Web Server Threats and Countermeasures,   Web Application and Web 2.0 Threats,   Smartphone and PDA Viruses and Threats,   VIEW ALL TAGS

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Network Security Tactics
How to keep networks secure when deploying an 802.11n upgrade
Screencast: Find rogue wireless acess points with Vistumbler
How to prepare for a secure network hardware upgrade
Preventing SQL injection attacks: A network admin's perspective
Screencast: How to launch an OpenVAS scan
Wireless network guidelines for PCI DSS compliance
Aligning network security with business priorities
Scanning with N-Stalker offers basic Web application security assessment
Lifecycle of a network security vulnerability
Screencast: BackTrack 4 offers an arsenal of penetration testing tools

Handheld and Mobile Device Security Best Practices
Screencast: Find rogue wireless acess points with Vistumbler
Secure your remote users in 2010
Researchers find thousands of flawed embedded devices
Best Mobile Data Security Products
Should Windows Mobile updates come from Microsoft?
MMS messaging spoof hack could have global ramifications
How to prevent mobile phone spying
Unified communications: Securing a converged infrastructure
RIM patches serious BlackBerry Attachment Service flaws
How secure are iPhone App Store mobile applications?
Handheld and Mobile Device Security Best Practices Research

Web Server Threats and Countermeasures
Increase in Gumblar backdoors poses FTP credential problems
VeriSign extends DDoS attack protection service
Microsoft issues IIS FTP advisory, exploit code circulates
Panda reports fast-spreading rogueware antivirus fraud rakes in millions
Oracle issues quarterly patches, fixes database flaws
Latest DDoS attacks extremely unsophisticated, experts say
Stolen FTP credentials likely in massive website attacks
Microsoft warns of IIS zero-day vulnerability
How to find and stop automated SQL injection attacks
How to spot attacks through Apache Web server log analysis

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
cache cramming  (SearchSecurity.com)
content filtering  (SearchSecurity.com)
Web filter  (SearchSecurity.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Research Solutions for Network Security, Access Control and Security Threats
TechTarget Security Media
Information Security View this month\\'s issue and subscribe today.
Information Security Decisions Apply online for free conference admission.
SearchSecurity.com
HomeNewsMagazineMultimediaWhite PapersLearningAdviceTopicsEventsAbout Us

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts