• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register For Membership | Member Login

 
 
DOMAINS
  • Business Issues
  • Channels
  • Enterprise
  • Services
  • SME
  • Technology
FEATURED EVENTS
  • Free Webinar - ISO 22301: The New Standard for Business Continuity Best Practice
    23rd May
    Webinar (online)
  • Telecoms Tech World
    4th June - 5th June
    London, United Kingdom
POPULAR PAPERS
  • FM, IT and Data Centres by Quocirca
  • The next frontier for managed print services by Quocirca
  • Beyond Big Data - The New Information Economy by Quocirca
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Sitewide
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Famous Slights - "Pushing forty? She's hanging on for dear life." - Ivy Compton-Burnett

PAGE TOOLS
ADVERTISEMENT
MORE FROM AUTHOR
  • December 2012
    Bring your own Device or Build your own Demise: Promises and Pitfalls of BYOD
  • May 2012
    BYOD Video at Infosecurity 2012
  • May 2012
    Infosec: Jailbroken devices are a threat to the network
  • May 2012
    SC Magazine Virtual Summit - Lock Down the Mobile Front
  • April 2012
    Keynote Panel at InfoSec 2012 - Smart Devices
  • April 2012
    Enterprise Readiness of Consumer Mobile Platforms
  • March 2012
    Security at Mobile World Congress 2012
Analysis

Google Android vs. Windows Phone 7.0 - A Comparative Analysis of Smartphone Security

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 19th April 2012
Copyright Bloor Research © 2012
Logo for Bloor Research

I recently completed an MSc at Royal Holloway, University of London. My dissertation undertook a comparative analysis of Google Android and Windows Phone 7.0 security using a range of practical tests and experiments.

Why Study Smartphone Security?

Smartphones are one of the most exciting computing developments in recent years. They capture people's desire to remain connected and at the same time offer far more functionality than ever believed possible on a humble mobile phone. Couple this with an upsurge of interest in social networking, new device releases weekly and executives demanding access to corporate data from their smartphones we have a perfect storm of activity that will challenge security professionals for a long time to come.

This inspired the study of this subject in more depth.

What Platforms?

There are a number of smartphone operating systems that can be studied; Apple iPhone, Google Android, Symbian, Blackberry and Windows Phone. Although it would have been interesting to study each one in detail time and resource limitations prevented this and so it was decided to focus on Google Android and Windows Phone 7.0. These were chosen as they both offer different security challenges and the contrast between them can be quite stark.

Google Android is an open source platform, meaning that the operating system software is available for review and redevelopment by anyone with the time and inclination. This appeals to hobbyist and professional developers alike as they are easily able to get to the heart of the device. Google Android has also been available for a reasonable length of time and has a significant and growing market share, supported by many applications from third parties that can be downloaded to a user's device. Google Android has also attracted the attention of malware authors and hackers due to the relatively open nature of the Android application market place.

In contrast Microsoft Windows Phone 7.0 is a relatively new operating system released in the autumn of 2010. The operating system is proprietary, meaning that it is owned and managed by Microsoft and developers do not have direct access to the operating system programming code, rather they are restricted to using the application programming interfaces alone. The application market is less vibrant for Windows Phone 7.0, as developers will choose to write for a platform that provides best return for their time and effort, and that will inevitably be the market leader first and foremost. The upside of this lack of interest is that malware targeting Windows Phone 7.0 is currently minimal, as like application developers hackers want to get the best return on their 'hacking investment'.

Smartphone Security Threats

As well as operating system and device based vulnerabilities there are a set of security threats that can present a problem for any smartphone. These include the use of rogue network connections as well as phishing based emails designed to lure a user into responding to an offer they can't refuse. The small form factor of the smartphone, coupled with the 'always on' nature of many users prompts them to respond quickly to incoming messages, and therefore miss the visual clues that normally indicate a phishing email.

Not only are users worried about their data being compromised, both personal and commercial, network operators are concerned about reputational risk if one of their customers has a 'bad experience'. Often the network provider will be the first port of call, for want of anyone else to address the issue to, which of course has a cost impact on the network provider. This may also lead to 'churn', the process of customers moving to another network operator, with a damaging impact on operator revenues. Operating system development companies are also concerned about reputational risk and the impact of being associated with an insecure platform, leading to reduced platform adoption impacting market share objectives.

This acadmic study provides a security comparison of the chosen platforms in the context of generic threats that face any smartphone device. Some of these threats are then evaluated in a set of practical experiments followed with some specific advice and recommendations for users and network operators to secure their devices and networks.

It is hoped that any reader of this dissertation will leave better informed and better equipped to secure their own and their user's smartphone devices.

The full project dissertation is available here

Reader Comments

We have not received any comments against this entry. Why not be the first?

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

  • Contact
  • | Site Map
  • | Terms of Use
  • | Privacy Policy
  • | Cookie Policy

Published by: IT Analysis Communications Ltd.
T: +44 (0)190 888 0760 | F: +44 (0)190 888 0761