Advertisement
Promo

Network management Toolkit in association with http://ad.doubleclick.net/clk;217618582;14453422;e?http://www.citrix.com/lang/English/lp/lp_1688615.asp

Experts: Don't panic over RFID viruses - yet

Jo Best silicon.com

Published: 16 Mar 2006 16:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Dutch researchers have announced they have successfully created a virus capable of infecting RFID tags.

In a new study, "Is Your Cat Infected with a Computer Virus?" scientists from the Computer Systems Group at the Vrije Universiteit in Amsterdam revealed that data from RFID tags can be used to exploit back-end software systems.

The academics also went on to create a proof-of-concept virus, which uses the track and trace tags to compromise middleware systems using a SQL injection attack.

"RFID malware is a Pandora's Box that has been gathering dust in the corner of our 'smart' warehouses and homes," the paper said. "While the idea of RFID viruses has surely crossed people's minds, the desire to see RFID technology succeed has suppressed any serious consideration of the concept. Furthermore, RFID exploits have not yet appeared in the wild. So people conveniently figure that the power constraints faced by RFID tags make RFID installations invulnerable to such attacks."

Adam Jura, analyst for manufacturing technology at Datamonitor, said the news of the virus could yet have a positive effect by helping to focus both vendors and users' minds on the security issues around the track and trace technology.

"At the moment, RFID isn't mainstream — we're still in the early adopter phase, so a virus would have very little impact," he said. "The best impact [the research] could have would be to get people to look at the security implications around RFID."

Security companies have also been quick to advise users that the potential threat from RFID viruses is minimal and any potential virus will have a hard time making it into the wild.

Graham Cluley, senior technology consultant for antivirus company Sophos, said the virus created by the Dutch researchers could only propagate in the specific environment the academics had created and that no known vulnerability currently exists in the wild.

He said: "Of course, any device that can store data can store virus code as well. But that does not mean that the virus would be able to spread or be in any way effective."

The researchers themselves state that there are problems with the virus, including the fact that it will be easily spotted by a database administrator. However, the paper hopes to prompt the RFID industry to take greater care of security in the future. It states: "Developers of the wide variety of RFID-enhanced systems will need to 'armour' their systems, to limit the damage that is caused once hackers start experimenting with RFID exploits, RFID worms and RFID viruses on a larger scale."

The controversial research has also found supporters. Katherine Albrecht of privacy group Caspian said she hoped the virus would help encourage big companies and governments to slow down their RFID rollouts.

  • Email
  • Trackback
  • Clip Link
  • Print friendlyPrint with EPSON

Did you find this article useful?
85 out of 155 people found this useful


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:





Related Citrix Resources

Achieving the lowest server virtualization TCO

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Achieving the lowest server virtualization Total Cost of Ownership

Consolidation through server virtualization is a powerful agent for datacenter change, but...

Citrix XenDesktop: The Best Desktop Delivery System For Today's Demanding Business Needs

Whether you're considering your first virtual desktop solution or trying to salvage an existing...

Desktop Virtualization: A buyer's checklist

Desktop virtualization should do more than just move desktop management to the datacenter—its real...

Five reasons why you need Citrix Essentials for Hyper-V now

This paper explores common challenges associated with server virtualization deployments and the...

See All White Papers

Video icon

Video

On The Road Blog

Mobile apps to get pushy, have presenc...

Most of the time, computers sit there waiting for you to ask them to do something. Phones tell you when they have something you care about. Most smartphones are more like a computer... More

Post a comment

Mobile business social network tools c...

The APIs that RIM is opening up for the BlackBerry platform leapfrog what’s available on other mobile platforms, with free push updates, unified advertising and payment options and... More

Post a comment

The Crabble stand for your phone

Sometimes something comes along that is so simple yet so very useful that you can’t believe you didn’t think of it first. The Crabble is one such object. Once upon a time smartphones... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters