Mobilination Ntymoshyk Personal Mobile Security Final Public

34
YOUR MOBILE SECURITY Nazar Tymoshyk Ph.D, R&D Manager/Security Consultan

description

 

Transcript of Mobilination Ntymoshyk Personal Mobile Security Final Public

Page 1: Mobilination Ntymoshyk Personal Mobile Security  Final Public

YOUR MOBILE SECURITY

Nazar Tymoshyk Ph.D, R&D Manager/Security Consultant

Page 2: Mobilination Ntymoshyk Personal Mobile Security  Final Public

always with you!

Always on

Page 3: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Call HistoryMessages

Social Networking

Visited websites

Contacts

Mobile Banking

VideosPhotosDocuments

PINs & Passwords

Who knows more about you than your

smartphone?

Page 4: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 5: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 6: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 7: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 8: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 9: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 10: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 11: Mobilination Ntymoshyk Personal Mobile Security  Final Public

You think you are SECUREDenough?

Page 12: Mobilination Ntymoshyk Personal Mobile Security  Final Public

• Resource abuse attacks

• Social engineering attacks

Major Mobile Threats

Page 13: Mobilination Ntymoshyk Personal Mobile Security  Final Public

TYPICAL SITUATION?

Page 14: Mobilination Ntymoshyk Personal Mobile Security  Final Public

DEMOLets look at small

Page 15: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 16: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Mobile malware -spyware

• Commercial spyware focus on information spying

• Flexispy(cross-platform commercial spyware)– Listen in to an active phone call (CallInterception)– Secretly read SMS, Call Logs, Email, Cell ID and

make Spy Call– Listen in to the phone surrounding– Secret GPS tracking– Highly stealth (user Undetectable in operation)

• A lot small software made for lawful and unlawful use by many small companies

Page 17: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Application Permissions

Page 18: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Reduced security by hw design

• Poor screen, poor control• User diagnostic

capabilities are reduced. No easy checking of what’s going on

• Critical situation where user analysis is required are difficult to be handled (SSL, Email)

Page 19: Mobilination Ntymoshyk Personal Mobile Security  Final Public

SMS Security

Page 20: Mobilination Ntymoshyk Personal Mobile Security  Final Public

SMS Security

• Easy social engineering for provisioning SMS

Page 21: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Mobile+malware=BOTNET

Page 22: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Mobile Browser attacks

Page 23: Mobilination Ntymoshyk Personal Mobile Security  Final Public

New attack direction

• Racketeering• VPN usage• Spam • Botnets• Contacts stealing• Device blocking• Photo folder stealing• Storage card mirroring• Phishing• Paypal and other payment system

password extraction

Page 24: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Application Backend Security

Application farm security vulnerabilities:• Web server security bugs• Database server security

bugs• Storage server security bugs• Load balancer security bugs

Web application security vulnerabilities-OWASP Top 10 security problems-Advanced Web application attacksWeb service security vulnerabilitiesClient application security vulnerabilities

Page 25: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Mobile security specific issues

• Secure data storage on removable card?

• Multiple user support with security?

• Strong authentication with poor keyboard?Try to type a passphrase: P4rtyn%!ter.nd@‟01

Page 26: Mobilination Ntymoshyk Personal Mobile Security  Final Public

• Constrained browsing environment?• Information disclosure

Mobile security specific issues

Page 27: Mobilination Ntymoshyk Personal Mobile Security  Final Public
Page 28: Mobilination Ntymoshyk Personal Mobile Security  Final Public

How to stay safe?

Page 29: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Control your Wireless environment!

Page 30: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Password protect your device and change this regularly

Page 31: Mobilination Ntymoshyk Personal Mobile Security  Final Public

USE ANTI VIRUS

USE ANTI MALWARE

Page 32: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Regularly update

Page 33: Mobilination Ntymoshyk Personal Mobile Security  Final Public

REMEMBER:About your personal responsibility

for corporate information lost

Page 34: Mobilination Ntymoshyk Personal Mobile Security  Final Public

Do you have anyQUESTIONS?