Advertisement
Promo

Mobile devices Toolkit

Major smartphone worm 'by 2007'

Munir Kotadia CNET News.com

Published: 22 Jun 2005 09:25 BST

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Companies will not have to worry about a large-scale virus outbreak targeting their smartphones for another 18 months, security experts predicted.

However, after that, even antivirus software is unlikely to help, Gartner analysts John Pescatore and John Girard wrote in a research paper published earlier this month. The paper looks at how enterprises should prepare for the growing threat from malicious software for mobile phones and PDAs. According to the authors, a fast-spreading phone virus or worm is unlikely to appear before the end of 2007.

"Despite this intense vendor- and media-driven speculation — and several well-publicised hoaxes — the necessary conditions required for viruses or worms to pose a real rapidly spreading threat to more than 30 percent of enterprise mobile devices will not converge until year-end 2007," Pescatore and Girard said.

Two main factors will create an environment that would encourage a virus to propagate, the Gartner analysts said. First, smartphones capable of being infected by malicious software will have to make up about one-third of the market. Second, users of those phones will have to regularly exchange executable files.

"Viruses and worms cannot infect large numbers of wireless devices until at least 30 percent of users commonly receive emails with attachments," said Pescatore and Girard. "By year-end 2007, large-scale user-to-user sending of more-complex executables will be commonplace. Once smartphones account for 30 percent of all wireless telephones in use — likely no sooner than the end of 2007 — rapidly spreading attacks will be much more likely."

Warren Chaisatien, research manager for Wireless & Mobility at IDC Australia, agrees that there is unlikely to be a major outbreak until the start of 2008.

"Today, the penetration of mobile devices with an operating system (capable of being infected by a virus) is still relatively small. It is not an immediate concern for CIOs and CTOs. The major concern for virus infection continues to be the PC," Chaisatien said.

'Ineffective' defences
However, the analysts have warned that once smartphones do reach a critical mass, administrators will have to look further than client-based antivirus software, which the Gartner analysts have described as "ineffective".

"Smartphone or PDA antivirus approaches that rely on device software will always fail to block the most damaging viruses," Pescatore and Girard said. "Desktop antivirus software became largely ineffective — other than as a removal tool after infection occurred — as soon as email surpassed floppies as the dominant transmission mechanism."

James Turner, a security analyst at Frost & Sullivan Australia, agreed that client-based reactive antivirus protection is unlikely to provide adequate protection.

"Signature-driven antivirus tools are great for hindsight, but we are at a turning point where signatures are not enough…Currently the attackers are testing their tools against the most popular antivirus products, which means the threat they release has effectively been certified against what we are running," said Turner, who believes protection should be provided on the network layer. "We need to place more emphasis on tools that detect anomalies in network traffic and behaviour."

This sentiment was echoed by all the analysts interviewed.

Gartner's Pescatore and Girard wrote: "The mobile world should not repeat the mistakes of the PC world. Malware protection services should be built into the network first, and device-side protection should be the last resort."

IDC's Chaisatien said that it would be ideal if a network was able to recognise and eliminate threats, but he thought the concept was still "futuristic."

"A more futuristic approach is where the intelligence lies in the network — that would be ideal — but I don't know how long it will take us to get there. Prevention at the network level will always be better and smarter than using solutions at the device level, but I think it is easier said than done," Chaisatien said.

Mikko Hyppönen, director of antivirus research at Finnish security company F-Secure, which has developed an antivirus tool for mobile phones, said that although he does not expect to see a Slammer or Sasser-type virus attacking mobile phones for "a year or two", the attacks have already started.

"Commwarrior is spreading quite effectively via MMS already. In fact, I just got a call this morning from the editor of a large Scandinavian IT publication; he got infected on his own phone last Thursday, at a press conference for a mobile phone company," Hyppönen said.

Munir Kotadia reported from Sydney for ZDNet Australia. For more ZDNet Australia stories, click here.

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?
54 out of 144 people found this useful


Full Talkback thread

1 comment

  1. THE FUTURISTIC VISION The menace created by techno... PRAVEEN DALAL
Video icon

Video

Enterprise Smartphones Special Report Special Report

Nokia E63

Nokia E63

Review Although it's missing some features (chiefly HSDPA and GPS), Nokia's E63 is a well-thought-out, ergonomic and affordable smartphone.

More Special Reports

On The Road Blog

Logitech Bluetooth Mouse M555b

Last week I wrote about The RIght Mouse for the Job, and mentioned that Logitech had a new Bluetooth mouse which was not yet available in Switzerland. Sure enough, a couple of days... More

Post a comment

Ubuntu Netbook Remix "Acid Test" - Wra...

Time to wrap up one more open item - my informal "Acid Test" of UNR. The size of my test group has doubled (from one to two), and the results have been consistent. The conclusion... More

Post a comment

Sony goes in-between with the W-Series...

Last December, UK Vaio chief Nicolas Barendson told ZDNet UK that Sony wouldn't do netbooks in their current form factor, because such devices were in-between products that were neither... More

1 comment

Discussions

hkommedal hkommedal

About collecting data etc.

Thursday 9 July 2009, 10:18 PM

9 comments
Moley Moley

Re: Privacy Issues

Thursday 9 July 2009, 8:15 PM

9 comments

Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters