Antivirus vendors gear up for phones, PDAs

With the recent emergence of the first virus aimed at Palm computers, antivirus software vendors are scrambling to develop products that protect against malicious code aimed at PDAs (personal digital assistants), mobile phones and other wireless devices.

To be sure, the problem today is a small one, and industry analysts say it could be 12 months or more before PDAs and mobile phones are hit with the kind of crippling viruses that have brought PC networks to their knees. Their bare-bones operating systems make it harder to write viruses that spread automatically from one device to the next, and most PDAs still don't make use of wireless connections, analysts said.

But with Palm and Microsoft hell-bent on expanding the wireless features in their platforms, and an expected explosion in data-enabled mobile phone use on the horizon, the possible emergence of a virus that is able to spread itself rapidly between devices will increase quickly over the next year, according to various industry analysts.

Antivirus vendors are pursuing several angles to protect phones and PDAs against malicious code. Their limited processing power and memory capacity compared to desktop PCs make the challenge a tough one, forcing the vendors to come up with some creative solutions.

Late last month, Network Associates' McAfee division released McAfee VirusScan Wireless, a product designed primarily to guard corporate networks from viruses carried into work on a PDA by employees. The software, which works with Palm OS, Windows CE and Epoc, doesn't run on the device itself, but scans data and files as they are synchronised between the device and a PC.

That may be a welcome line of defence for IS managers but doesn't protect users from downloading viruses directly to their handheld devices, either via the Web and e-mail, or through the infrared beaming feature on some PDAs.

Symantec claims its AntiVirus for the Palm OS, released in beta earlier this month, is the first product that actually scans for known trojans, worms and other viruses on the device itself. Symantec rebuilt its antivirus scanning engine from the ground up to come up with the product, which is less than 20Kbytes in size - small enough to fit on just about any mobile phone or PDA, according to Carey Nachenberg, chief researcher at the Symantec Antivirus Research Centre.

Helsinki-based F-Secure has developed a similar product for Epoc, an operating system designed primarily for mobile phones. Called F-Secure Antivirus for Epoc, the application is available now and measures about 60Kbytes in size, a company official said. Wireless data services for phones are more advanced in Northern Europe than in the US, so it made sense for the Finnish company to aim the first version of the product at phone users.

Like their counterparts on the desktop, the products from Symantec and F-Secure work by using a database of known virus signatures that is stored on the device itself. That method works fine today, because the number of known viruses for handhelds is so small. But if the number of viruses were to increase sharply - there are some 50,000 known desktop viruses around now - then the applications will become too bloated for the devices they sit on.

Finjan Software has one possible answer. Rather than scanning for particular viruses, the company's software examines code for types of behaviour. If a malicious program attempts to delete a file or open a network connection, for example, the software blocks the behaviour and alerts the user.

Finjan is developing an antivirus product for Palm and Microsoft Pocket PC devices that uses this method, although it doesn't expect to release it before the end of the year. Next month, however, it plans to release a kind of interim product that, like McAfee's, looks out for viruses while data is synchronised between a Palm computer and a PC, according to Dave Kroll, Finjan's director of marketing.

McAfee, Symantec, F-Secure and a fourth antivirus vendor, Trend Micro, each said it is exploring the behavioural approach as they look for the ultimate portable solution. Officials at all the companies, including Finjan, said they expect a hybrid solution will work best, combining behaviour monitoring and scanning for known viruses.

Trend Micro also advocates a server-based approach and is developing WAP gateway software that will scan files for malicious code before they are distributed to users. As unified messaging grows up, allowing users to access e-mail, voice mail and Web content from a single device, this server-based approach makes the most sense, according to David Lu, vice president of product business development at Trend Micro.

To a large extent, analysts said, antivirus vendors are at the mercy of device makers. As Microsoft and Palm expand the functionality of their devices by including support for features like e-mail attachments, for example, then virus writers will be equipped with more tools to do their work.

Join the newsletter!


Sign up to gain exclusive access to email subscriptions, event invitations, competitions, giveaways, and much more.

Membership is free, and your security and privacy remain protected. View our privacy policy before signing up.

Error: Please check your email address.

More about FinjanF-SecureGatewayKrollMcAfee AustraliaMicrosoftPalm ComputerSymantecTrend Micro Australia

Show Comments