Dutch researchers' proof of concept needn't derail rollouts...
By Jo Best
Published: 16 March 2006 14:47 GMT
Dutch researchers have announced they have successfully created a virus capable of infecting RFID tags.
In a new study, Is Your Cat Infected with a Computer Virus? scientists from the Computer Systems Group at the Vrije Universiteit in Amsterdam revealed that data from RFID tags can be used to exploit back-end software systems.
The academics also went on to create a proof-of-concept virus, which uses the track and trace tags to compromise middleware systems using a SQL injection attack.
-- Graham Cluley, senior technology consultant, Sophos
The paper noted: "RFID malware is a Pandora's Box that has been gathering dust in the corner of our 'smart' warehouses and homes. While the idea of RFID viruses has surely crossed people's minds, the desire to see RFID technology succeed has suppressed any serious consideration of the concept. Furthermore, RFID exploits have not yet appeared in the wild. So people conveniently figure that the power constraints faced by RFID tags make RFID installations invulnerable to such attacks."
Adam Jura, analyst for manufacturing technology at Datamonitor, said the news of the virus could yet have a positive effect by helping to focus both vendors and users' minds on the security issues around the track and trace technology.
He told silicon.com: "At the moment, RFID isn't mainstream – we're still in the early adopter phase, so a virus would have very little impact. The best impact [the research] could have would be to get people to look at the security implications around RFID."
Security companies have also been quick to advise users that the potential threat from RFID viruses is minimal and any potential virus will have a hard time making it into the wild.
Graham Cluley, senior technology consultant for antivirus company Sophos, said the virus created by the Dutch researchers could only propagate in the specific environment the academics had created and that no known vulnerability currently exists in the wild.
He said: "Of course, any device that can store data can store virus code as well. But that does not mean that the virus would be able to spread or be in any way effective."
The researchers themselves state that there are problems with the virus, including the fact that it will be easily spotted by a database administrator. However, the paper hopes to prompt the RFID industry to take greater care of security in the future. It states: "Developers of the wide variety of RFID-enhanced systems will need to 'armour' their systems, to limit the damage that is caused once hackers start experimenting with RFID exploits, RFID worms and RFID viruses on a larger scale."
The controversial research has also found supporters. Katherine Albrecht of privacy group Caspian said she hoped the virus would help encourage big companies and governments to slow down their RFID rollouts.
Corporations riddled with security holes
How safe is your network?
PC security warning for banking online
Banks may not always pick up the bill
E-crime unit on track, says police chief
But where's the funding?
Cotton Traders' site hacked: Thousands of details stolen
Customer credit cards breached
Cyber crime: The global battle
e-Crime Crackdown - does the UK measure up?
Stories from around the web...
Q&A: The man behind Cisco's security CNET News.com
Laws to clamp down on cyber crime BBC News
Hacking made easy Washington Post
Compliance, not malware, drives IT budgets TechWeb.com via InformationWeek
UK security experts fear for loss of high-tech crime unit Times Online
Make your voice heard
silicon.com and the Bathwick Group have created an opportunity for business and IT executives to share their experience with each other and thus enhance their knowledge of the IT marketplace.
Join our research panel, and you'll be asked to participate in short surveys - and then will be privy to the answers of all your colleagues, as we send you tailored versions of the results.
Extras include complementary passes to silicon.com events and survey prizes such as iPods. Plus, there are the obvious networking opportunities with your fellow panellists.
For more about the Research Panel and how to join, click here
Copyright ©1995-2008 CNET Networks, Inc. All rights reserved. Top of page