You are here: silicon.com > Software > Security Strategy

Security Strategy

'Security not just about user education'

Trojans can lurk in all manner of places...

Tags: security, trojan, malware

By Victoria Ho

Published: 15 October 2007 08:51 GMT

Education is not a viable solution for preventing security issues, according to Patrik Runald, F-Secure's senior security specialist.

Runald said systems are often compromised in spite of the user practising safe computing. "Even if the user is doing all the right things - making sure the page is encrypted, not opening attachments, for example - they [still] get infected. Education can only go so far," he noted.

Runald said the rising occurrence of "drive-by" downloads is "most worrying", referring to the situation whereby a Trojan, embedded in a website, surreptitiously downloads itself onto a user's system when the page is visited.

He said: "It doesn't have to be a dodgy site. It could be anywhere. You visit the site - bang - you get hit."

A Trojan could be sitting undetected in a user's system until it gets activated, for example when a user logs into a banking website.

The only solution, the security expert said, is vigilance in ensuring all security software is constantly updated, so the user can be protected from threats they do not see.

He said: "Even if people have been educated on safe surfing, they either forget or don't care."

Runald also noted that the technology is available to cause serious damage on mobile devices: "All the pieces are in place for a mobile malware outbreak."

According to the security expert, 99 per cent of mobile malware is targeted at the Symbian operating system because it is the market leader and its source code is open, making it easier to examine the OS for vulnerabilities.

Malware can also be spread quickly via Bluetooth or MMS, making its proliferation easier, Runald said.

But closed operating systems are not necessarily safer. Referring to Apple's iPhone, Runald said: "In theory, by having a closed OS, it should be safer. But remember that it didn't take long after its release for people to crack it and run third-party applications. Its file system was also made accessible through cracking, and this opened the system to a lot of danger."

Offering an explanation as to why a mobile malware pandemic has not yet occurred, Runald said there has not been a concerted effort by mobile virus coders because they tend to be "kids" who are interested in "a bit of fame and mischief", rather than being motivated by profit like those who code for PCs.

However, Runald cautioned that this does not rule out the possibility of a mobile malware outbreak. "The end game is money. Phones have a built-in billing system by being connected to a user's account. We're certain something will eventually happen," he said.

Victoria Ho writes for ZDNet Asia

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

Bob Tarzey Why you must rein in your power users When they do damage, it can be catastrophic to your business

Jon Collins Is losing a mobile device really such a big deal? How to minimise the damage to your business


  • Jobs
iPhone/Mac Software Engineer

Experience Required: - A minimum of 2 years experience of software development for iPhone and/or Mac OS X using Cocoa and Objective C Understanding ...

IT Service Manager c40K + Bens

An appreciation of mobile devices will also be required with a focus on Blackberry, iphone and the ability to provide excellent Technical support, ...

Mac/PC Service Desk Analyst- Mac OS X, Windows, Adobe, Office, ARD

Mac/PC Service Desk Analyst- Mac OS X, Windows, Adobe, Office, ARDA Progressive and rapidly expanding Central London Group of Agencies are seeking to ...

Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.





Quick Sitemap Links: