Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Experts: Don't panic over RFID viruses - yet

Jo Best silicon.com

Published: 16 Mar 2006 16:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Dutch researchers have announced they have successfully created a virus capable of infecting RFID tags.

In a new study, "Is Your Cat Infected with a Computer Virus?" scientists from the Computer Systems Group at the Vrije Universiteit in Amsterdam revealed that data from RFID tags can be used to exploit back-end software systems.

The academics also went on to create a proof-of-concept virus, which uses the track and trace tags to compromise middleware systems using a SQL injection attack.

"RFID malware is a Pandora's Box that has been gathering dust in the corner of our 'smart' warehouses and homes," the paper said. "While the idea of RFID viruses has surely crossed people's minds, the desire to see RFID technology succeed has suppressed any serious consideration of the concept. Furthermore, RFID exploits have not yet appeared in the wild. So people conveniently figure that the power constraints faced by RFID tags make RFID installations invulnerable to such attacks."

Adam Jura, analyst for manufacturing technology at Datamonitor, said the news of the virus could yet have a positive effect by helping to focus both vendors and users' minds on the security issues around the track and trace technology.

"At the moment, RFID isn't mainstream — we're still in the early adopter phase, so a virus would have very little impact," he said. "The best impact [the research] could have would be to get people to look at the security implications around RFID."

Security companies have also been quick to advise users that the potential threat from RFID viruses is minimal and any potential virus will have a hard time making it into the wild.

Graham Cluley, senior technology consultant for antivirus company Sophos, said the virus created by the Dutch researchers could only propagate in the specific environment the academics had created and that no known vulnerability currently exists in the wild.

He said: "Of course, any device that can store data can store virus code as well. But that does not mean that the virus would be able to spread or be in any way effective."

The researchers themselves state that there are problems with the virus, including the fact that it will be easily spotted by a database administrator. However, the paper hopes to prompt the RFID industry to take greater care of security in the future. It states: "Developers of the wide variety of RFID-enhanced systems will need to 'armour' their systems, to limit the damage that is caused once hackers start experimenting with RFID exploits, RFID worms and RFID viruses on a larger scale."

The controversial research has also found supporters. Katherine Albrecht of privacy group Caspian said she hoped the virus would help encourage big companies and governments to slow down their RFID rollouts.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
85 out of 155 people found this useful


Full Talkback thread

0 comments


Company/Topic Alerts

Create a new alert from the list below:





Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Jabra Stone Bluetooth headset

I don’t get on very well with Bluetooth headsets. But it is not a prejudice against them. I don’t get on well with those flat, saucer-like in-ear headphones either. My ears are just... More

Post a comment

Ion pleases the eye and kills off the...

The netbook has been a rapidly evolving beast. The idea was initially unveiled about four years ago by the OLPC initiative, who wanted to bring out a cheap educational tool for the... More

1 comment

BlackBerry developer chief demos new s...

Late last week I got to share milk and cookies with Mike Kirkup who is RIM’s director of developer relations. Mike was passing through London on the European leg of his 'press the flesh... More

1 comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters