* Adding smart phones to endpoint security
Last week, I discussed a recent report that concluded that mobile usage is outpacing enterprises’ ability to secure mobile devices, networks, and access.
This week, results from Network Chemistry’s six-month Wireless Threat Index are being made public, and they seem to jibe with those findings. The index indicates that mobile usage is significantly up – and, correspondingly, so is the number of incidents of mobile users engaging in risky behavior.
The Wireless Threat Index is a running status report of wireless security threats and trends. It is culled from usage and security information continually reported to Network Chemistry by the thousands of laptops that run the company’s RFprotect Endpoint security product and the more than 1 million connections made by these devices over six-month periods. The latest reveals usage and security activity from May – November 2006.
According to the latest index report:
* Wireless usage increased by 8.2%, while VPN policy violations also increased – by 11.8%. In fact, 76% of the devices committed a VPN violation at least once during the six-month time frame.
* Attempts to create ad-hoc Wi-Fi networks (undesirable from a security standpoint) increased 9.5%, with 69% of the devices doing so.
* Connections to unknown access points (AP) increased by 8%. In fact, 94% of the devices connected to an unknown AP at least once, and 44% of all the wireless AP connections made were with an unknown AP.
Meanwhile, smart phones are gaining dual-mode cellular and Wi-Fi capabilities, “which puts them on a par with laptops, in terms of them being an IT-enabled client,” says Joe Stocker, manager of network engineering at SunCal, a large land developer in Irvine, Calif. SunCal has 250 employees using dual-mode cell/Wi-Fi smart phones.
“Companies…need to be aware that those clients could connect to their corporate network and have a strategy for securing them,” says Stocker. Particularly important is preventing a smart phone-targeted worm from spreading to the rest of the network, he says.
Stocker said he thinks most companies prefer to deploy a single endpoint security solution throughout their entire enterprise, but “I don’t know that there’s one magic bullet that can do everything.”
IT departments might end up with multiple systems for this reason. Network Chemistry, which just extended its RFprotect Endpoint product to also work on smart phones, is an example.
“I haven’t heard of any other endpoint security for smart phone clients,” says Stocker. Companies may already have an endpoint security system or service in place for laptops but may need to turn to another vendor if they have Wi-Fi-enabled smart phones to get the capabilities for that form factor.




