Ads by TechWords

See your link here
Receive the latest technology news and information.
Security
Computerworld Daily News (First Look and Wrap-Up)
Computerworld Blogs Newsletter
The Weekly Top 10
Cloud Computing
View all newsletters




Privacy Policy
 

BlackBerry security exec warns of smartphone DDoS attacks

November 18, 2009 03:09 PM ET

CIO - BlackBerry and smartphone security in general hasn't garnered much attention or concern over the past few year, at least from a consumer, or user, perspective. Enterprises have been invested in mobile device security since the advent of the PDA.

But that's going to have to change, thanks largely to the vast number of consumers embracing new, flashy smartphones like Apple's iPhone, Motorola's Droid and Research In Motion's (RIM) BlackBerry Bold 9700.

This plethora of new smartphone users means the potential for gain by hackers or other online baddies looking to crack smartphone security measures is drastically increasing. The more smartphone users, the more devices that could potentially be commandeered and used in various attacks. That means smartphone users are going to have to smarten up when it comes to mobile security awareness and be more vigilant in spotting and stopping potential problems before they happen.

Scott Totzke, RIM's vice president of BlackBerry security, agrees, and he recently spoke with Reuters on the subject. Totzke told Reuters that he's concerned compromised or "rogue" smartphones could be used in the future to target and bring down wireless carrier's cellular networks via distributed-denial-of-service (DDoS) attacks.

Traditional DDoS attacks occur when hackers take control of large groups of computers and then order them to all access one Web site or service at the same time, overloading servers and eventually crashing or disabling the site.

Popular microblogging service Twitter was hit with a high-profile DDoS attack last August that brought the site down for hours.

RIM's Totzke warned that DDoS attacks could also be perpetrated on smartphone users, with wireless data packets being used to overload and disable carriers' wireless networks.

Reuters also spoke with Flexilis, a maker of mobile security software. The company's CTO suggests that such an attack could start with users carelessly installing infected or tainted mobile applications.

BlackBerry smartphones feature safeguards that prompt users after downloading new applications to determine whether owners want to grant the apps "Trusted Application status." And most applications require users to grant certain permissions before the software can access potentially sensitive information like location- or voice-data. But because serious smartphone-related security threats are few and far between at this point, most users simply click on through the warnings without considering the implications of downloading and installing what should be considered "untrusted" apps.

Flexilis told Reuters that it has already identified "virus-tainted" versions of well-known, and generally trusted, applications like Google's Google Maps for mobile, so avoiding dangerous apps may not be as simple as only installing applications that seem to come from reputable sources.

RIM's Totzke says the most effective way to protect yourself from BlackBerry viruses and other security threats is to aggressively monitor RIM's site for security patches and then promptly install them whenever new fixes become available.

You can keep track of the various RIM security patches as they're issued by following me on CIO.com--I posted about RIM's most recently listed BlackBerry-related security risks here and here--and by bookmarking RIM's security bulletins page.


Originally published on www.cio.com. Click here to read the original story.

Jump to comments

Research In Motion

Additional Resources

EFD vs. HDD - What You Need to Know
WHITE PAPER
Enterprise flash drives provide a new Tier 0 storage layer capable of delivering high I/O performance at a very low latency. Proper use of EFDs in an Oracle environment can deliver increased performance compared to fibre channel drives. Read the recommendations for identification of the best DB components for EFDs.
Gartner Research Report: Magic Quadrant for Application Delivery Controllers, 2009
WHITE PAPER
The market for products to improve the delivery of application software over networks remains dynamic and innovative. Vendors focused on solving enterprises' most-pressing application problems have become the top players.
Eight Criteria for Server Load Balancing
WHITE PAPER
Server load balancers are a simple yet highly effective means to scale an application environment while ensuring its availability. Today's solutions should also address application performance and security. Read about the top eight criteria you should consider when choosing a server load balancer and how Citrix NetScaler meets those requirements.

What People Are Saying

White Papers & Webcasts

Death to PST Files
Download Now  

Web 2.0, Social Media and the Dark Web - A Web Criminals Paradise?
In this discussion, learn about the challenges of protecting your users from the potentially unsafe content hidden in the "Dark Web".

eGuide: Enterprise Security
Smart Security Strategies for 2010. Read now!  

Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...


IT Jobs