Advertisement
Promo

Security threats Toolkit

Mobile-botnet threat 'a ticking time bomb'

Vivian Yeo ZDNet Asia

Published: 27 Oct 2008 13:20 GMT

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Mobile botnets have not yet appeared in security laboratories or the wild but conditions are already ripe for malware attacks to turn mobile phones into zombies, according to a security researcher.

Chia Wing Fei, security response manager at F-Secure Security Labs, told ZDNet Asia in an email interview that the security vendor has dealt with viruses, worms, Trojans and spyware targeting the mobile platform, but has not yet encountered a bot or botnet.

The issue of mobile botnets was brought up recently in a report released by the Georgia Institute of Technology's Information Security Center. In the report, a Georgia Tech academic predicted that botnets will infiltrate the mobile space next year.

Chia added: "We haven't seen much mobile-malware development in the last six months as well, but the Apple iPhone has changed the whole mobile experience and is likely to change the threat level in due time." Apple's iPhone, he explained, runs a "stripped-down version of the Mac OS X" and more vulnerabilities associated with the OS are now surfacing.

Allan Bell, McAfee's marketing director for the Asia-Pacific region, noted that the mobile platform has not been seriously threatened due to the lack of a common operating system for mobile phones but, as technology convergence and market consolidation occur, the "situation may change".

Denial-of-service threats through mobile phones, however, are less likely to occur than financially motivated threats that target phones with payment capabilities, Bell said in an email.

F-Secure's Chia noted, however, that conditions are ripe for the injection of malware onto mobile phones to turn them into bots. "We have more confidential and sensitive information like [email messages] and attachments stored on mobile phones today, compared to the past. The mobile threat has become a ticking time bomb," he said.

Make it easy for end users
Security companies and mobile developers have a role to play in protecting mobile users, industry observers have said.

According to Toh Teck Kang, product director at ANTlabs, the onus should not be on mobile users to update or secure their devices.

Read this

Q&A: Symbian squares up to mobile rivals

ZDNet talks to Nigel Clifford, CEO of mobile OS maker Symbian

Read more +

Mobile-phone security products, he said, should be able to detect malware as well as prevent snooping on user activity, in a way that would be similar to preventing keylogging on PCs.

ANTlabs is currently working on a version of Securite for use on mobile operating systems, said Toh. Securite, which aims to secure online customer transactions, was partly designed with minimum end-user maintenance in mind. F-Secure's Chia pointed out that mobile OS providers and application vendors "have the biggest role to play". Developers need to ensure security is a consistent part of the development life cycle, and recognise that neglecting security is not a good practice.

"One feature I would like to see in all mobile operating systems and applications is the ability to push security updates to the mobile phones with ease, and automatically," he said. "If no-one has found any vulnerability on a particular mobile OS or application, it doesn't mean that it is fully secure and doesn't need to be updated."

On the other hand, mobile operators need to be proactive in filtering possible threats or scams at the gateway level, as well as educating customers about such threats and recommending appropriate solutions, said Chia. Mobile users should exercise caution when installing applications on their phones and opening links.

Credit: Mobile threat a 'ticking time bomb' from ZDNet Asia

  • Email
  • Trackback
  • Clip Link
  • Print friendly
  • Post Comment

Did you find this article useful?


Full Talkback thread

0 comments

Company/Topic Alerts

Create a new alert from the list below:






Video icon

Video

Sentry Posts Blog

Met will not reopen phone hack investi...

The Metropolitan Police will not reopen its investigation into alleged phone hacking by the News of the World. In a press statement delivered outside Scotland Yard on Thursday, Assistant... More

Post a comment

FUD over ChromeOS's security already?

It hasn't taken long for the security vendors to wake to the potential of Google's new ChromeOS. The potential that is, to create FUD – fear uncertainty and doubt. In a release today,... More

Post a comment

Feds take DDoS in their stride

The US Department of Homeland Security has said that a series of distributed denial-of-service attacks began on US government networks on 4 July. However, Amy Kudwa, deputy press... More

Post a comment


Skip Sub Navigation Links to CNET Brand Links

Help

Become part of the ZDNet community.

Newsletters