Home

Mobile Threats Are Increasing But Are Still Nothing Compared To PC Crime

Comments | Larry Seltzer, BYTE | April 30, 2012 12:37 PM

Category: Tablets, Smartphones, Social Networking

Smartphone security threats are increasing, according to a new Symantec report. The latest edition of the Symantec Internet Security Threat Report is out, which looked at security risks during 2011. As usual, things are getting worse overall, but the threat in the world of mobile computing is still a small side show.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

Almost all security vendors note steady increases in mobile malware, as does Symantec. As you can see from the graph below, growth took off in 2011, but the overall numbers are still small.

The types of malware found reveal that criminals appear to be adapting to the new environment. See the graph below:

The two biggest categories of malware spy on the device and the user. The third makes money by sending text messages to premium rate numbers set up by the attacker. When your phone calls or texts these numbers, your account is charged and the owner of the number paid. Typically attackers will charge a small number, perhaps $10, once a month on the theory that you won't notice it. According the Symantec report, the story of one gang earned $1 million/year using this technique. The criminals don't need a huge number of phones to do it.

Most of the remaining threats are more like PC malware. As with other areas of computer crime, mobile hackers move around from one technique to another looking for what will make them money.

Besides making a quick dollar, the more serious threat occurs when criminals use smartphones as a way to hijack data on the network. According to the report, Symantec saw examples of attackers using their control of smart phones to access data on enterprise networks to which they were connected. Indeed, the point of most mobile malware is to steal information. When the attacker has access to company data the threat becomes far more serious. This is the point where BYOD (Bring Your Own Device) becomes a disaster to the company.

Of the 187 million compromised identities found by Symantec in 2011, about 10% (18.5 million) were as a result of a lost device. This is clearly a big number, but it pales in comparison to the identity theft impact of network intrusions of a more conventional sort, such as by compromising a PC on the network.

Lost and stolen devices are a big problem and an up-and-comer, but it's not scalable from the criminal's point of view. You may be able to break into numerous databases and compromise thousands of identities from the comfort of your own home, but stealing a large number of smartphones is hard work. Symantec did a test where they purposely "lost" smartphones running monitoring software and then tracked the phones to see what happened to them. No, people who found the phones didn't look up "home" and call to return it. Instead, the test found that someone looked at private data on 96% of the phones and 50% of the phones were never recovered.

Computer criminals are a surprisingly conservative bunch, and they tend to stick with what they know works. Consumers have been much more adventurous by comparison, rapidly adopting mobile technologies and cloud services. The bad guys are working on these fronts, but it's not mainstream and may not be for some times.

Follow Larry Seltzer and BYTE on Twitter, Facebook, LinkedIn, and Google+:



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events