Study: RFID Tags Subject to Viruses


Wed, March 15, 2006

CIO

Three computer science researchers are warning that viruses embedded in radio tags used to identify and track goods are right around the corner, a danger so far overlooked by the industry’s high interest in the technology.

No radio frequency identification (RFID) viruses have been released live as of now, according to the researchers at Vrije Universiteit Amsterdam in the Netherlands. But RFID tags have several characteristics that could be engineered to exploit vulnerabilities in middleware and back-end databases, they wrote in a paper presented Wednesday at a conference in Pisa, Italy.

"RFID malware is a Pandora’s box that has been gathering dust in the corner of our ‘smart’ warehouses and home," the paper stated.

The attacks can come in the form of a SQL injection or a buffer overflow attack even though the tags themselves may store only a small bit of information, the paper said. For demonstration purposes, the researchers created a proof-of-concept, self-replicating RFID virus.

It took a master’s student at the university, Patrick Simpson, only four hours to write a virus small enough to fit on an RFID tag, something previously thought unworkable, said Andrew S. Tanenbaum, a professor at Vrije Universiteit Amsterdam. RFID tags can contain as little as 114 bytes of memory, he said.

Tanenbaum expects vendors to be angry about the publishing of the code. Vendors have dismissed the possibility of RFID viruses, saying that the amount of memory in the tags is too small, he said.

"You publish all of the code on the website, and all of [a] sudden, [vendors] are going to start panicking," Tanenbaum said. "This hopefully will make them take it seriously. This is a wake-up shot before this stuff is deployed in a large scale."

The purpose of the exercise, the authors wrote, is to encourage RFID middleware designers to be more careful when writing code. Back-end middleware can contain millions of lines of source code, and if software faults number between six to 16 per 1,000 lines of code, the programs are likely to have many vulnerabilities, the paper said.

RFID tags are increasingly being used in a variety of industries to track items and give a real-time view of inventories. The tags contain data on a particular object or, in some cases, embedded in animals, and that data is typically stored in a database.

Companies can save money by using the tags to keep closer tabs on their property. However, this "pervasive computing utopia has its dark side," the authors wrote.

Continue Reading

Virtualization and cloud are driving new requirements for data center network performance, VM support, automation and simplified orchestration. This paper outlines Extreme Networks® open fabric approach to high speed, low latency networks for modern data centers.
The evolution of the network to provide the intelligence needed to address user, device and application mobility is underway. In this white paper, Extreme Networks® outlines the five phases required to bring mobility into the network.
Individuals and businesses alike are embracing the digital revolution. Social networks and digital devices are being used to engage government, businesses and civil society, as well as friends and family.
Whether you need to build a business case for a UC system, or are ready to select a new solution, this white paper offers a thorough, side-by-side comparison of ShoreTel and Avaya offerings to help you make informed decisions.
Compared with Cisco products, ShoreTel UC can offer numerous advantages, including streamlined deployment and management, easier scalability, and a significantly lower total cost of ownership (TCO).
This must-read publication features independent research from Gartner, providing a wealth of information around best in breed Unified Communication systems. 12 Unified Communications vendor ratings, along with their strengths and cautions, are provided.
Join us for this live web event where featured Forrester Research principal analyst, Art Schoeller and Interactive Intelligence senior vice president, Joe Staples will discuss these topics and help you be ready to take the best advantage of the upcoming year and the contribution your contact center can make to the success of your business.
Tune into this insightful webinar to see Riverbed Technology product marketing manager Joe Ghory present the facts on how you can ensure consistent performance wherever workers connect, get the most out of limited connectivity, and accomplish more by eliminating round trips and slow latency.
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
VMware recently announced VMware vFabric™ Data Director, a new database deployment and operations platform that enables enterprise IT organizations to offer database as a private cloud service. Built on top of VMware vSphere 5, vFabric Data Director enables IT organizations to ontrol database sprawl through automation and consistent policy enforcement and accelerate application development cycles with self-service database management. Attend this webcast to learn how vFabric Data Director can help you build database-as-a-service in your datacenter.
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center