Friday, 24 October 2008

Mobile may a threat to a 'ticking time bomb'

This may also be a problem, Mobile 'botnets' accept not yet appeared in aegis laboratories--much beneath in the wild--but altitude are already accomplished for malware attacks to about-face cellphones into zombies, according to a aegis researcher.

Chia Wing Fei, aegis acknowledgment administrator at F-Secure Aegis Labs, told ZDNet Asia in an e-mail account that the aegis bell-ringer has dealt with viruses, worms, Trojans and spyware targeting the adaptable platform, but has not yet encountered a bot or botnet.

The affair of adaptable botnets was brought up afresh in a address appear by Georgia Institute of Technology's Advice Aegis Center. In the report, a Georgia Tech bookish predicted that botnets will access the adaptable amplitude next year.

Chia added: "We haven't apparent abundant adaptable malware development in the endure six months as well, but the Apple iPhone has afflicted the accomplished adaptable acquaintance and is acceptable to change the blackmail akin in due time." Apple's iPhone, he explained, runs a "stripped-down adaptation of the Mac OS X" and added vulnerabilities associated with the OS are now surfacing.

Allan Bell, McAfee's business administrator for the Asia-Pacific region, acclaimed that the adaptable belvedere has not been threatened in a big way due to the abridgement of a accepted operating arrangement for adaptable phones, but as technology aggregation and bazaar alliance takes abode the "situation may change".

Denial-of-service threats through adaptable phones, however, are beneath acceptable to action than financially-motivated threats that ambition phones with transaction capabilities, Bell said in an e-mail.

F-Secure's Chia noted, however, that altitude are accomplished for bang of malware assimilate cellphones to about-face them into bots. "We accept added arcane and acute advice like [e-mail messages] and accessories stored on adaptable phones today as compared to the past.

"The adaptable blackmail has become a active time bomb," he said.

Make it simple for end-users

Security companies and adaptable developers accept a role to play in attention adaptable users, say industry observers.

According to Toh Teck Kang, artefact director, ANTlabs (Advanced Network Technology Laboratories), adaptable users should not accept to buck the onus of afterlight or accepting their devices.

Security products, he said, should be able to ascertain malware as able-bodied as anticipate concern on user action on the adaptable phone, which would be agnate to preventing keylogging on PCs.

ANTlabs is currently alive on a adaptation of Securite for use on adaptable operating systems, said Toh. Securite, which aims to defended online chump transactions, was advised in allotment with minimum end user aliment in mind. The company, said Toh, is currently alive on a adaptation of Securite for use on adaptable operating systems.

F-Secure's Chia acicular out that adaptable OS providers and appliance vendors "have the better role to play". Developers charge to ensure aegis is a constant allotment of the development lifecycle, and admit apathy aegis is not a acceptable practice.

"One affection I would like to see in all adaptable OS and applications is the adeptness to advance aegis updates to the adaptable phones with ease, and automatically," he said. "If no one has begin any vulnerability on a accurate adaptable OS or application, it doesn't beggarly that it is absolutely defended and doesn't charge to be updated."

On the added hand, adaptable operators charge to be proactive in clarification accessible threats or scams at the aperture level, as able-bodied as brainwash barter about such threats and acclaim adapted solutions, said Chia. Adaptable users should exercise attention if installing applications on their phones and aperture links.Mobile 'botnets' have not yet appeared in security laboratories--much less in the wild--but conditions are already ripe for malware attacks to turn cellphones into zombies, according to a security researcher.

No comments: