Thursday | 8 January, 2009
Are smartphone viruses a threat to your network?
As iPhones, other devices grow in popularity, so will risky Web browsing
John Cox (Network World) 24/06/2008 11:14:41

All evidence points to the fact that smartphone viruses will be a threat to your network even though they aren't at this moment. After all, the latest mobile devices are packed with more and more applications and corporate data, are enabled for real Web browsing and online collaboration, and can access corporate servers. What's more, they live outside your firewall and often make use of three wireless networks (Bluetooth, Wi-Fi and cellular).

"It's definitely something I worry about a lot," says Sam Lamonica, CIO of Rulph and Sletten, a general contractor. "With the proliferation of smartphones throughout our business, it poses a great risk if and when hackers get good at pumping malware through those devices."

A 2007 survey of 450 IT managers found Lamonica is not alone. Eighty per cent had antivirus products installed. Yet about 40 per cent had been hit by a worm or virus in the past 12 months Of those that were hit, 30 per cent said that being unable to reach mobile users who were disconnected from the network contributed to the intrusion or failure that allowed a virus onto their network.

"The phone has advanced exponentially, while users have not caught up and realized that they are walking around with a computer," says Mark Olson, Manager, Beth Israel Deaconess Medical Center.

That's shown by the success of Apple's iPhone. Its users are among the first to do intensive and extensive mobile Web browsing, enabled by the performance of the phone's Safari browser. But Web browsing also enables a range of malware for smartphones in general. "If you go to Twitter [on the Web], you have to rely on Twitter security," says Tom Henderson, managing director for ExtremeLabs. "You can get cross-site exploits that can dive down into the phone's browser. Then, it's a problem."

"Anything that is network connected and can be altered is a potential threat,' says Rob Enderle, principal analyst for Enderle Group, a technology advisory firm. The growing "socialableness" of smartphones, via everything from e-mailing to instant messaging and even texting, all provide opportunities for tricking users into downloading malware, he says.

To date, major malware outbreaks on smartphones, on the scale of PC infections of past years, are almost unheard of. Early mobile phone viruses, such as Cabir, Skulls and Fontal, targeted a specific operating system, usually Symbian, and required users to accept a download and then actually install files. Infections were limited to a few score of devices typically.

But if those few score smartphones are all yours, it's actually worse than some malware romping through millions of PCs. As companies standardize on a specific smartphone platform, they run a growing risk of malware reaching a significant percentage of those devices, Olson says.

"Most of the known viruses and Trojans will propagate through Bluetooth or Multimedia Messaging [MMS]," Olson says. "So all it takes is one person walking into a meeting with an infected device, and the rest of the room now needs a dose of 'penicillin.'"

Now is the time to start thinking systematically about these issues, because there is no simple, formulaic solution to the problem of smartphone security.

Computerworld Buyer's Guide - Vendors Matched to this Article
Computerworld Buyer's Guide - Vendors Matched to this Article
Additional Resources
Executive Guides
Whitepapers
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Sign up for our Computerworld newsletters!
RSS Feeds
Market Place

 

Smart SOA World Tour

Discover how SOA can create smarter outcomes for your business.

Attend and learn:

  • How SOA is helping leading companies to become more agile
  • Where you should be applying SOA processes in your company
  • The top SOA implementation mistakes to avoid

Click here for more information.
Whitepaper

Email Archiving Implementation: Five Costly Mistakes to Avoid

Email Archiving is essential for managing email data, but is potentially expensive to implement. Read on to discover the five key areas where email archiving costs can be contained, including data capture methods and default configuration methods.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links