Calling an iPhone a phone is like calling Mount Everest a hill. Smart devices based on the iOS or Android mobile operating systems are powerful computers. They can run quite a few apps and increase the user’s productivity, whether it’s for personal or company use, or both. Unfortunately, these devices have security vulnerabilities, just as desktop and notebook computers do. Security and systems management vendor Symantec has produced a good guide to help you compare the security postures of the iOS and Android operating systems and understand where the greatest vulnerabilities are.
In recent years, Apple has sold nearly 100 million iPhone and iPad devices that use the iOS operating system. And as of June 2011, Google reports that more than 500,000 Android-based devices are being activated every day. The owners of all these smartphones and tablets are using them to do more than just make phone calls and take notes; many of these gadgets are also come-and-go endpoints on enterprise networks. That got me thinking about what risks these devices might pose to enterprise security.
Symantec has pondered this same question and has come up with some very good answers. You can read them in the security vendor’s whitepaper “A Window into Mobile Device Security.” This paper offers a detailed analysis of the security models employed by both the Apple iOS and Google’s Android platforms. It’s a great source of information if you want to understand the security risks of deploying these devices in the enterprise. Symantec has assessed the effectiveness of each platform in defending itself against today’s major threats, including Web-based resource and service availability abuse; malicious and unintentional data loss; and attacks on the integrity of the device’s data.
ROUNDUP: Smartphone security follies: A brief history
While these mobile operating systems were explicitly designed with security in mind, both iOS and Android devices are still vulnerable to many categories of attacks. Though we may call the devices phones, they are really powerful computers, and they are vulnerable to some of the same problems as any other computer. For example, did you ever consider that your smartphone could become a node on a botnet where it can be used to relay spam email or participate in a DDoS attack? Yep, it happens.
Symantec tells us that the iOS security model offers strong protection against traditional malware, primarily due to Apple’s sandboxing of Web services and the vendor’s rigorous application and developer certification processes. Even with more than 300,000 iPhone apps and 60,000 iPad apps, Apple makes an attempt at vetting the identity of each software author to weed out malicious coders. Google, on the other hand, has opted for a less rigorous validation model, permitting any software developer to create and release applications anonymously and without inspection. It can be construed that this lack of validation could be behind the proliferation of Android-specific malware. (See “Malware writers gunning for Google Android.”)
And what about “jailbroken” devices that have been liberated from the protections built into the operating system? Naturally they further exacerbate security and risk concerns because it’s possible to gain root access to these devices, making them attractive targets for attackers.
Even though these mobile OSs have security build into their base architectures, the risks mentioned above are magnified when personally owned devices are used for both consumer and enterprise purposes. Marc Fossi, research and development manager for Symantec Security Response, points out that today’s mobile devices are increasingly being connected to and synchronized with an entire ecosystem of third-party cloud- and desktop-based services (such as app stores) which are outside the enterprise’s control. Such connectivity exposes enterprise assets on the phone to increased risk; for example, email address lists that can be tapped to receive spam.
No amount of inherent security measures can offer defense against social engineering attacks such as phishing. With device owners using their smartphones to access everything on the Web from email to social networks, people are just as vulnerable to phishing via a handheld device as they are with their notebook or desktop computers. All it takes is one lapse in judgment for the user to be tricked into releasing login details or other sensitive information, or clicking on a link that will surreptitiously plant a Trojan horse. This allows hackers to gain access to the device and possibly to the wider corporate network when the device is synced to both home and business computers and networks.
Phishing affects both the consumer and the enterprise user. In either case education is essential in preventing these types of attacks. As Symantec’s Fossi points out, “You can’t patch the human to prevent phishing.” (See “Don’t open that email! How to reduce the risk of phishing” and “A clever way to increase employee awareness about phishing.”)
Fossi says that better mobile security comes down to policy enforcement. To the extent possible, organizations need to extend their corporate network policies to these smart devices. Some companies choose to completely lock down the devices, just as they would a laptop or desktop device. Other companies are less rigid, allowing some flexibility for both personal and company use of the smartphones. Come back next week and I’ll cover some of the options for policy enforcement.
Clearly there’s a balancing act with these consumer-oriented devices. The real challenge is for companies to embrace the usability and productivity these devices bring while ensuring security at the same time.
Brian Musthaler is a principal consultant with Essential Solutions Corporation. You can write to him at Bmusthaler@essential-iws.com.
______________________________________________________________
About Essential Solutions Corp:
Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.




