ZDNet UK


Skip to Main Content

ZDNet.co.uk - Winner of Best Business Website 2007
  1. Home
  2. News
  3. Blogs
  4. Reviews
  5. Prices
  6. Resources
  7. Community
  8. My ZDNet

 

ZDNet UK RSS Feeds


IT Jobs

Mobile devices Toolkit

Major smartphone worm 'by 2007'

Munir Kotadia CNET News.com

Published: 22 Jun 2005 09:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies will not have to worry about a large-scale virus outbreak targeting their smartphones for another 18 months, security experts predicted.

However, after that, even antivirus software is unlikely to help, Gartner analysts John Pescatore and John Girard wrote in a research paper published earlier this month. The paper looks at how enterprises should prepare for the growing threat from malicious software for mobile phones and PDAs. According to the authors, a fast-spreading phone virus or worm is unlikely to appear before the end of 2007.

"Despite this intense vendor- and media-driven speculation — and several well-publicised hoaxes — the necessary conditions required for viruses or worms to pose a real rapidly spreading threat to more than 30 percent of enterprise mobile devices will not converge until year-end 2007," Pescatore and Girard said.

Two main factors will create an environment that would encourage a virus to propagate, the Gartner analysts said. First, smartphones capable of being infected by malicious software will have to make up about one-third of the market. Second, users of those phones will have to regularly exchange executable files.

"Viruses and worms cannot infect large numbers of wireless devices until at least 30 percent of users commonly receive emails with attachments," said Pescatore and Girard. "By year-end 2007, large-scale user-to-user sending of more-complex executables will be commonplace. Once smartphones account for 30 percent of all wireless telephones in use — likely no sooner than the end of 2007 — rapidly spreading attacks will be much more likely."

Warren Chaisatien, research manager for Wireless & Mobility at IDC Australia, agrees that there is unlikely to be a major outbreak until the start of 2008.

"Today, the penetration of mobile devices with an operating system (capable of being infected by a virus) is still relatively small. It is not an immediate concern for CIOs and CTOs. The major concern for virus infection continues to be the PC," Chaisatien said.

'Ineffective' defences
However, the analysts have warned that once smartphones do reach a critical mass, administrators will have to look further than client-based antivirus software, which the Gartner analysts have described as "ineffective".

"Smartphone or PDA antivirus approaches that rely on device software will always fail to block the most damaging viruses," Pescatore and Girard said. "Desktop antivirus software became largely ineffective — other than as a removal tool after infection occurred — as soon as email surpassed floppies as the dominant transmission mechanism."

James Turner, a security analyst at Frost & Sullivan Australia, agreed that client-based reactive antivirus protection is unlikely to provide adequate protection.

"Signature-driven antivirus tools are great for hindsight, but we are at a turning point where signatures are not enough…Currently the attackers are testing their tools against the most popular antivirus products, which means the threat they release has effectively been certified against what we are running," said Turner, who believes protection should be provided on the network layer. "We need to place more emphasis on tools that detect anomalies in network traffic and behaviour."

This sentiment was echoed by all the analysts interviewed.

Gartner's Pescatore and Girard wrote: "The mobile world should not repeat the mistakes of the PC world. Malware protection services should be built into the network first, and device-side protection should be the last resort."

IDC's Chaisatien said that it would be ideal if a network was able to recognise and eliminate threats, but he thought the concept was still "futuristic."

"A more futuristic approach is where the intelligence lies in the network — that would be ideal — but I don't know how long it will take us to get there. Prevention at the network level will always be better and smarter than using solutions at the device level, but I think it is easier said than done," Chaisatien said.

Mikko Hyppönen, director of antivirus research at Finnish security company F-Secure, which has developed an antivirus tool for mobile phones, said that although he does not expect to see a Slammer or Sasser-type virus attacking mobile phones for "a year or two", the attacks have already started.

"Commwarrior is spreading quite effectively via MMS already. In fact, I just got a call this morning from the editor of a large Scandinavian IT publication; he got infected on his own phone last Thursday, at a press conference for a mobile phone company," Hyppönen said.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly Print with Dell

Did you find this article useful?
54 out of 144 people found this useful


Full Talkback thread

1 comment

  1. THE FUTURISTIC VISION The menace created by techno... PRAVEEN DALAL

Related Jobs

Test Analysts & Senior Testers - Northamptonshire Test / QA

I am looking for a range of Test Analysts to work with a large financial company based out of Northamptonshire. I am looking for junior Testers, ...

2 x Bulge Bracket Investment Banking, Commodities Business Analysts

2 x Energy Trading Business Analysts sought by Tier One Bulge Bracket Investment Bank to join their London European HQ. Due to continued growth in ...

Senior Analysts required: North West 23-27K+ fantastic Benefits

SAS or Affinium Campaign Analysts required. My industry leading financial client is seeking competent and ambitious analysts to develop targeted ...

Featured Talkback

Put simply, what is the compelling reason to pay ~$200 extra for an Eee with Windows XP? A Windows Eee won't come with any useful applications and you'll have to buy anti-virus software to boot. The truth about low cost computing is that nobody really cares whether the machine is running Windows or Linux as long as its cheap, its easy to use and it works.

By: dogStar

Read full story:
Asus to ship 60 percent of Eee PCs with Windows XP

On The Road Blog

Mobile Security Expert: Your Camera Ph...

Mobile Security Expert: Your Camera Phone Got Hacked Author: Eric Everson, Founder MyMobiSafe.com Have you ever heard someone say “I’d like to be a fly on the wall in that room.”?... More

Post a comment

Eee 1000 + iPhone 3G = the ultimate mo...

Having left the comforting bosom of ZDNet.co.uk to strike out on my own as a freelance journalist recently, I found myself contemplating a shocking truth – I was going to have to shell... More

Post a comment

Think Your Skype Call is Secure? Read...

There is growing, and credible, speculation that Skype has built in a back door to allow monitoring of SKype calls. Heise Online has a good article about it. So, what we have now... More

1 comment

Discussions

319762 319762

Eve of Distraction

Saturday 26 July 2008, 4:37 AM

1 comment