Commentary

"Cough! Cough!" Yes, That Was Your Smartphone Wheezing At You

Believe it or not, the first mobile viruses began appearing back in mid-June 2004. The Cabir worm and Mosquito Trojan both targeted smartphones that run the Symbian Series 60 operating system, which is the most widely used smartphone platform across the world. Others targeting Windows Mobile appeared later. Should the enterprise be concerned? Hell, yeah!

Believe it or not, the first mobile viruses began appearing back in mid-June 2004. The Cabir worm and Mosquito Trojan both targeted smartphones that run the Symbian Series 60 operating system, which is the most widely used smartphone platform across the world. Others targeting Windows Mobile appeared later. Should the enterprise be concerned? Hell, yeah!With wireless devices becoming more sophisticated all the time (I found an app that let's my BlackBerry manage my multiple personality disorder), malicious jerks have decided to have even more fun at our expense (apparently destroying our hard drives, sending billions of spam messages from our IP addresses or accessing our bank accounts just isn't enough for them).

While your average run-of-the-mill Java or BREW phone (read: crappy feature phone) is probably safe for the time being, phones that run Symbian, Windows Mobile, Palm OS and RIM OS are much more at risk and it's surprising to see how quickly and in how many ways naughty code writers have found to use abuse them. With more and more sensitive corporate data stored on these devices, mobile viruses are a rising threat that can't be ignored by the enterprise.


More Mobility Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Unfortunately for IT departments, this means being the bad guy for a while, as there are some simple ways to protect enterprise data from this threat.

1. Don't let employees back-door the devices in. If they buy a smartphone over the weekend and want you to activate enterprise email, access, whatever, come Monday morning, tell them tough luck. I don't care if it's the CEO. Don't forget that employees are sneaky, and don't like hearing no for an answer. You may have to buy software that sniffs out unauthorized devices (the CEO's Treo, that S.O.B.!) that are accessing the network and pro-actively find them and terminate their access. (Don't worry, the CEO should thank you for protecting his network.)

2. Create strict policies for mobile equipment. Decide what can be accessed and what can't. Force employees to use security features, passwords, on-device encryption and so on. Make them pick hard passwords. Forbid employees from downloading anything not directly related to work, like games or wallpapers of Miss January.

3. Install antivirus software on the devices. Believe it or not, there is already an industry swelling here. Talk to your wireless carrier about the best options.

4. Control the phones' Bluetooth. Even though it's fun to say "Bluejacking" and "Bluesnarfing", Bluetooth has become an easy entry point for mobile viruses. Cabir took advantage of Bluetooth to sneak inside handsets and place calls to expensive 1-900 numbers, running up the bills.

5. Educate employees. Most people haven't heard of mobile viruses, and may not really believe in them. With threats to security increasing all the time, you should hold regular meetings or provide regular updates to inform employees about the risks they and their devices face every day.

If employees come to hate the IT managers for being strict policy enforcers, too bad. They aren't at work to be liked, they are there to keep the network and its data protected.


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links