iPhones and BlackBerry security problems tackled

Georgia Tech researchers to plug smartphone holes

Georgia Tech researchers have received a $450,000 NSF grant to boost security of iPhones, BlackBerry and other smartphones and the wireless networks on which they run. And it’s those networks where the researchers are really zeroing in.

The researchers are looking into ways US wireless carriers such as AT&T and Verizon can detect malware on devices and clean up the devices before they do further damage.

"While a single user might realise that a phone is behaving differently, that person probably won’t know why," says Patrick Traynor, assistant professor at Georgia Tech’s School of Computer Science, in a statement. "But a cell phone provider may see a thousand devices behaving in the same way and have the ability to do something about it."

The issue of smartphone malware attacks has gained fresh attention this week in light of a couple of jailbroken iPhone malware attacks, including one that replaced users’ wallpaper with a picture of singer Rick Astley. 

Registration is free, and gives you full access to our extensive white paper library, case studies & analysis, downloads & speciality areas, and more.

Security watchers have been monitoring smartphone threats for years, but haven’t had a lot of real action until recently in the form of attacks in the wild. F-Secure chief security advisor Patrik Runald said that, "In a way, we’ve already seen more serious vulnerabilities in the iPhone in a year and a half than we’ve seen in the whole life of Symbian and Windows mobile OSes. It shows the difficulty of squeezing these operating systems into small phones and making sure you only have the necessary parts that are required for the phone to work."

The Georgia Tech researchers echo those sentiments in that they point out that malware writers have largely ignored cellphones that were specialty devices but are licking their chops over smartphones based on more general computer operating systems. One problem, they say, is that smartphones typically aren’t equipped with antivirus and other such computer security tools.

That’s why they’re targeting the carriers themselves in an effort to crack down on mobile device security. The researchers are developing remote repair techniques that would enable carriers to clean up devices with little or no involvement by the end user. Such methods might require temporarily disabling some of the phone’s functionality, such as the ability to download apps.

Georgia Tech is going to build out a cellular network test bed to try out its remote repair techniques.



Email Updates

CIO Newsletters: Expert insight, advice and tools for technology, business, leadership and the CIO career.


Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.


CIO White Papers

Legal risks of uncontrolled email and web use

Exploring the challenges facing IT Mangers today and vital steps to ensure safe internet an email use by employees.

The challenge of strategic alignment

Recent research also shows that many organisations give too much prominence to internally generated KPIs – controlling the controllable – rather than looking outwards at threats and opportunities on the horizon which can ultimately be far more influential on performance.

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Managing email: Exploring common email management challenges (and how to overcome them)

We surveyed 157 IT professionals to understand the difficulties and opportunities faced by email managers. From this we were able to highlight some easy-to-manange solutions to their most pressing problems.


CIO UK - Business - Technology - Leadership

Differentiate your company with complete CRM

Focused on productivity and empowerment and leveraging the natural rhythms people work
What defines Complete CRM? How businesses can better engage customers and users, manage customer transactions, and analyse results to adapt and take advantage of changing business and economic circumstances.

DOWNLOAD

Oracle White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One.

CIO are running a short survey to discover how UK businesses are managing internet and email misuse in the Enterprise.

COMPLETE SURVEY

Virtualisation - The 'black hole' of security?

Covering the set of issues, ideas and perceptions discussed during a recently held debate about the effect of virtualisation techniques on organisational security. This paper provides a comprehensive account of all the subject matters debated and concludes with key takeaways and IDC recommended actions.

DOWNLOAD

Trend Micro



* *