• Jump to Left Menu
  • Jump to Right Menu
  • Jump to Main Content
  • Jump to Footer
  • Accessibility Page
IT-Director.com Logo

 

Main navigation - go to a section of this website:

  • ARCHIVE
  • PAPERS
  • EVENTS
  • NEWSWIRE
  • BLOGS

  

Register | Login to Member's Area

 
 
DOMAINS
  • Enterprise
  • SME
  • Business Issues
  • Technology
    • Data Management
    • Applications
    • Infrastructure
    • Systems Mgmt
    • Security
    • Mobile
    • Storage
    • Personal Productivity
  • Services
  • Channels
FEATURED EVENTS
  • NDL Seminar: Take the office with you - easily
    8th February
    London, United Kingdom
  • NDL Seminar: Take the office with you - easily
    9th February
    Greater Manchester, United Kingdom
USEFUL LINKS
  • Last 7 Days
  • Archives
  • Top Articles
SHARE THIS PAGE
  • Delicious Icon Delicious
  • Digg Icon Digg
  • reddit Icon reddit
  • Facebook Icon Facebook
  • StumbleUpon Icon StumbleUpon
CONTENT FEED

Technology -> Mobile
RSS Feed:

RSS Icon

What is RSS?

RANDOM QUOTE
Observations - "The trouble with America isn't that the poetry of life has turned to prose but that it has turned to advertising copy." - Louis Kronenberger

PAGE TOOLS
  • Request Reprints
  • Tell A Friend
  • Contact Author
ADVERTISEMENT
fotoSENSE - Click here!
MORE FROM AUTHOR
  • December 2011
    Intellectual Property Theft: Protecting Data Against Cyber Criminals
  • December 2011
    Now hold your breath - the Olympic year is nearly upon us
  • October 2011
    BSIMM Version 3 - A Joy to Behold!
  • September 2011
    The Technology Behind Cyberterrorism
  • August 2011
    Cyber Threats to National Security
  • June 2011
    Nigel Stanley Presents at Jane's Cyberwar Webinar
  • April 2011
    Mobile Phone Voice Protection with Morrigan Secure Application
Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now
Analysis

Cell Phone Hacking Attacks - A Real and Present Danger (Part 1)

Nigel Stanley By: Nigel Stanley, Practice Leader - IT Security, Bloor Research
Published: 30th July 2010
Copyright Bloor Research © 2010
Logo for Bloor Research

If you stop and take a look at all the objects that sit within an arms length of where you are sitting the chances are that a mobile phone, in all its guises, is one of the first that you see. The reality is that the cell phone is the first piece of IT that we take with us wherever and whenever we go. If we forget our cell phones we feel naked, isolated and more than a little bit worried. Whilst few would take a fully-fledged PC to bed, the cell phone has pride of place next to the bedside lamp.

From an information security perspective this poses an interesting challenge.

Quite simply, if you can compromise a cell phone then you are more or less assured that you can collect the most relevant, current and possibly damaging data possible. The breadth and depth of current cell phone technology is staggering, with new models, features and innovations delivered weekly. Whilst few would doubt the huge appeal of interactive applications, the challenge these devices give information security professionals is overwhelming. After all, we now have presidents and prime ministers touting these devices as part of their need to be in touch. No doubt this appeals to a deep-seated and basic human need to be part of something at all times.

This series of articles will explore the reality of hacking attacks against cell phones and what we need to do to prevent them.

Aside from the risk of losing emails and SMS messages, few have considered that voice data is similarly at risk from being compromised. This risk is now a reality and we need to be considering how we deal with it sooner rather than later.

Consider these scenarios:

  • Bob is attending a major trade show where the brightest and the best in his industry are negotiating deals worth millions. Bob has a meeting planned with a potential client to discuss pricing options. Eve works for a competitor. She pays a third party to install spyware on Bob's cell phone, turning it into a listening device. Eve listens into the negotiations and meets the potential client later that day with a bid that mysteriously undercuts Bobs by 1%. Eve wins the business.
  • A CEO staying in a hotel room needs to take part in a conference call discussing end of year financial data, prior to a big announcement to the stock market. Fraudsters set up a fake cell phone base station and intercept the conversation, getting advanced notice on likely stock movements.
  • A foreign government is keen to acquire as much hi-tech intellectual property as it can. It has targeted one company in particular that sells advanced missile systems and has information that a senior engineer from that company will be staying in a downtown hotel one weekend. Following a covert operation, it was established that the engineer used a specific handset and Bluetooth headset. This data was fed back to intercept technicians who were able to remotely monitor the engineer's conversations, having hacked the Bluetooth headset.

For many people these targeted attacks would seem extreme and not something they should be bothered about. The reality is that those after your data will target the weakest link, and the prevalence of cell phones is making them a top target.

If you lose a laptop, USB stick or CD it can be fairly obvious that the data has gone missing. Voice data is very different, as a successful interception can leave no physical trace so there is little chance of realising your data has actually been intercepted until it is too late. For many, this realisation may be when they have been undercut by a competitor or see their products copied in another country. This makes the promotion of voice security more of a challenge, as a direct link to an incident is often difficult to make.

Of course this lack of detection and traceability is a real bonus for the eavesdropper. When a victim realises the loss of data the attacker is long gone, hiding their trail as they go.

In order to understand the cost of lost voice data, the Ponemon Institute, in collaboration with Cellcrypt, recently undertook a study called The Security of Voice Data.

The study reveals that 67% of those 75 organisations surveyed were not confident that the information passed during a cell phone conversation was adequately secured and only 14% use technologies to secure cell phone calls when travelling to sensitive areas. The cost to the organisation each time a corporate secret is revealed to competitors or their agents has been averaged at $1.3 million.

The next article in this series will explore cell phone technology in more detail and identify the weaknesses that are being exploited.

Reader Comments

Posted: 4th August 2010 | By Recover Data :

Hi,This is really a nice article that shows possible attacks to the cell phones. As nowadays cell phones are used to access internet, therefore all the attack that were possible in a PC now can occur on cell phones. As there are very limited checking of site digital certificate in cell phones, so malicious users can make various attacks while performing transactions through it.Thanks for sharing this.

The messages above were all contributed by IT-Director.com readers. Whilst we take care to remove any posts deemed inappropriate, we can take no responsibility for these comments. If you would like a comment removed please contact our editorial team.

We automatically stop accepting comments 180 days after a post is published. If you would like to know more about this subject, please contact us and we'll try to help.

Voipfone VoIP 30 Day FREE Trial Click To Sign Up Now


  • Feedback
  • | Site Map
  • | Terms of Use
  • | Privacy

Published by: IT Analysis Communications Ltd. | Tel: 01908 880760