BlackBerry Security Exec Warns of Smartphone DDoS Attacks

Research In Motion's VP of BlackBerry Security says he's concerned that online miscreants could increasingly target BlackBerry devices and other smartphones in the future, in attempts to take control of the handsets and employ them to bring down wireless carriers' cellular networks via distributed-denial-of-service (DDoS) attacks.

By
Wed, November 18, 2009

CIO — BlackBerry and smartphone security in general hasn't garnered much attention or concern over the past few years--at least from a consumer, or user, perspective; enterprises have been invested in mobile device security since the advent of the PDA.

image of RIM BlackBerry
RIM BlackBerry "Trusted Application Status" App Install Warning

But that's going to have to change, thanks largely to the vast number of consumers embracing new, flashy smartphones like Apple's iPhone, Motorola's DROID and Research In Motion's (RIM) BlackBerry Bold 9700.

This plethora of new smartphone users means the potential for gain by hackers or other online baddies looking to crack smartphone security measures is drastically increasing; The more smartphone users, the more devices that could potentially be commandeered and used in various attacks. That means smartphone users are going to have to smarten up when it comes to mobile security awareness and be more vigilant in spotting and stopping potential problems before they happen.

Scott Totzke, RIM's VP of BlackBerry security, agrees, and he recently spoke with Reuters on the subject. Totzke told Reuters that he's concerned compromised or "rogue" smartphones could be used in the future to target and bring down wireless carrier's cellular networks via distributed-denial-of-service (DDoS) attacks.

Traditional DDoS attacks occur when hackers take control of large groups of computers and then order them to all access one website or service at the same time, overloading servers and eventually crashing or disabling the site.

Popular micro-blogging service Twitter was hit with a high-profile DDoS attack last August that brought the site down for hours.

RIM's Totzke warned that DDoS attacks could also be perpetrated on smartphone users, with wireless data packets being used to overload and disable carriers' wireless networks.

Reuters also spoke with Flexilis, a maker of mobile security software. The company's CTO suggests that such an attack could start with users carelessly installing infected or tainted mobile applications.

BlackBerry smartphones feature safeguards that prompt users after downloading new applications to determine whether or not owners want to grant the apps "Trusted Application status." (See image above.) And most applications require users to grant certain permissions before the software can access potentially sensitive information like location- or voice-data. But because serious smartphone-related security threats are few and far between at this point, most users simply click on through the warnings without actually considering the implications of downloading and installing what should really be considered "untrusted" apps.

Flexilis told Reuters that it has already identified "virus-tainted" versions of well-known, and generally trusted, applications like Google's Google Maps for mobile, so avoiding dangerous apps may not be as simple as only installing applications that seem to come from reputable sources.

RIM's Totzke says the most effective way to protect yourself from BlackBerry viruses and other security threats is to aggressively monitor RIM's site for security patches and then promptly install them whenever new fixes become available.

You can keep track of the various RIM security patches as they're issued by following me on CIO.com--I posted about RIM's most recently listed BlackBerry-related security risks here and here--and by bookmarking RIM's security bulletins page.

AS

Reuters via CrackBerry.com


FREE CIO BlackBerry Newsletter
Get better use out of your BlackBerry and keep up-to-date on the latest developments. Sign-up »
As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.
Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.
Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.
This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.
Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.
This white paper describes the business challenges and opportunities that are driving interest in Identity Governance while discussing considerations your organization should make to help achieve project success.
Learn how Gartner's criteria for next generation IPS helps organizations achieve effective threat prevention despite changes in network communications, new applications, and changes in the threat landscape.
3 minute Flash video - overview of the need for and value of Configuration Control.
Cloud deployments are playing a critical role in propelling innovation for many companies. At the same time security has become the #1 one of the top concerns for IT and business leaders as they migrate into the cloud. In this webinar, learn from Accenture discusses how to recast the cloud as a "fresh chance to rethink your approach to security."
As greater numbers of datacenter servers transition from the physical to the virtual world, the components of virtualization success come to the fore. What scores of organizations have discovered is that success is derived from an optimal pairing of the right software platform with the right hardware platform.
Have you been looking to hear about customer's experiences with the new VMware vCenter Site Recovery Manager product? View this webcast to learn about VMware customer, Navicure, and their experiences testing and evaluating the recovery manager, their progress in implementing it in their environment and their advice other customers considering using vCenter.
Many enterprises have discovered that the use of virtualization to support desktop workloads creates a range of significant benefits. These benefits include price efficiencies, improved IT management and greater agility and choice for end users.

This VMware sponsored webcast with IDC will provide both quantitative measurement of the business value -- defined as the expected ROI -- and qualitative analysis associated with the use of VMware View™. IDC will also provide an analysis of the View Composer and ThinApp™ features of VMware View, including the business value of these solutions and an overview of how they work.

Attend this webcast to learn about:
- Challenges and barriers that might impede the adoption of desktop virtualization
- Navigating roadblocks to facilitate a strategic implementation
- Optimizing qualitative and quantitative benefits to IT and your business
Newsletter Sign-Up »

Receive the latest news test, reviews and trends on your favorite technology topics

Choose a newsletter
  1. View all Newsletters | Privacy Policy
Resource Center