Home > Mobile Computing Tips > Mobile Security > Chasing away your wireless blues
Mobile Computing Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

MOBILE SECURITY

Chasing away your wireless blues


Lisa Phifer
11.17.2005
Rating: -4.55- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


While Wi-Fi security has been grabbing headlines, Bluetooth has been creeping quietly into corporate networks. Today, Bluetooth interfaces are common on many office devices, including laptops, PDAs, cellphones, and headsets. Bluetooth can also be found in printers, keyboards, cameras, broadband routers, and access points. According to AirDefense, Bluetooth-capable devices will top one billion by 2006. In fact, unsecured Bluetooth interfaces may already be putting your business assets at risk today.

Why you should care

Bluetooth is a cable replacement technology, designed to connect paired devices within 10 meters of each other. Given limited range and application, many incorrectly discount Bluetooth as a serious business threat. But new Bluetooth devices can reach up to 100 meters, using internal antennas. Most are promiscuous by default, responding to pages, service discovery probes, and connect requests from anyone. And many harbor security programming flaws associated with the Bluetooth Object Exchange (OBEX) protocol. This has fostered development of new attacks that exploit Bluetooth, such as:

[TABLE]

Companies may not really care if an employee's wireless headset or keyboard gets BlueSmacked or BlueStabbed. But they should care if an executive's PDA gets BlueSnarfed or BlueSpooofed. They should care if Bluetooth is used to infect employee laptops or rack up company telephone charges. And they should care whenever any unauthorized link is used to circumvent corporate security policies – for example, using Bluetooth to exchange unsecured data between peers in an office where Wi-Fi Ad Hoc is forbidden and 802.11i security is required on the corporate WLAN.

What you can do about it

Bluetooth standards define optional security measures that can authenticate paired devices and encrypt the data exchanged between them. Companies should require that all Bluetooth-capable devices carried by employees employ such meas

Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


RELATED CONTENT
Hackers and Threats to your Mobile Enterprise
Mobile security threats
Securing corporate data on your laptops
iPhone hacking: Lessons from the front line
Trends in mobile computing
Traditional security threats coming soon to mobile device near you
Prevent mobile malware: Learn how to protect your enterprise and devices
On-device defenses for mobile malware
Is malware coming to a smartphone near you?
New challenges in mobile device discovery
Mobile security – Understanding and controlling risks

Bluetooth
Boosting business productivity with Bluetooth
Interop 2007: Mobile highlights
A Bluetooth update
Wireless options for PDAs and smartphones
Wireless adapters for PDAs and smartphones
Securing Bluetooth
Near-field communications: The next small thing
Nokia's Wibree vs. Bluetooth as PAN of choice
"Mobile Computing," Chapter 4: Emerging technologies
Palm Treo 700p 3G smartphone
Bluetooth Research

Mobile Security
Mobile security threats
Two-factor authentication: Mobile security at your fingertips
Securing your Windows Mobile devices
In-the-cloud defenses for mobile malware
On-device defenses for mobile malware
Is malware coming to a smartphone near you?
Protecting data on your BlackBerry
Defining your mobile security policy
Government regulations and mobile security policies
Symbian: Protect your data, not just your device

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
bluesnarfing  (SearchMobileComputing.com)
drive-by spamming  (SearchMobileComputing.com)
mobile phone virus  (SearchMobileComputing.com)
SMiShing  (SearchMobileComputing.com)
war driving  (SearchMobileComputing.com)
warchalking  (SearchMobileComputing.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary


ures, in accordance with corporate security policies. For example, you might require encryption for all file transfers conducted over Bluetooth. Or you may require PIN-based authentication for all Bluetooth connections, no matter what service is used. You may also want to educate employees about safe Bluetooth practices, including how to avoid unsolicited service discovery and improper pairing.

Security capabilities do vary across Bluetooth products. Employees may own devices that are missing security patches or cannot comply with company-defined policies. In that case, you must decide how to deal with out-of-spec Bluetooth devices. Do you confiscate them? Instruct the device owner to disable Bluetooth at your office? Forbid employees from carrying corporate data on vulnerable devices? You'll need to answer such questions to enforce your company's Bluetooth security policy.

Enforcing those decisions

Periodically scan your offices to find legitimate-but-misconfigured Bluetooth devices and unknown Bluetooth rogues. In a small office, this might be done by walking around with an off-the-shelf Bluetooth adapter, operating in discovery mode. But spotting more than a few devices this way would be tedious and error-prone. A more rigorous and systematic approach is to use a portable Bluetooth scanner like Network Chemistry BlueScanner, AirMagnet BlueSweep, or AirDefense BlueWatch.

For example, BlueScanner and BlueSweep are free tools that run on Windows XP SP2. To use either, you'll need a Bluetooth adapter, running Microsoft's Bluetooth driver. These tools actively poll for other Bluetooth devices and query the services that each supports. Reported details may include the discovered device's name and address, manufacturer, type, class, advertised services (e.g., serial port, dialup networking, file transfer, fax, headset), and active connections with other Bluetooth devices.

Distance varies by adapter, and you'll only discover active Bluetooth devices, within range, that respond to polling (i.e., you won't find disabled devices, or devices with discovery turned off). Sampling a large office this way is labor intensive, so decide what you're really trying to accomplish and devote effort accordingly. To find "hidden" Bluetooth devices (i.e., those that won't respond to polls), you'll need to invest in a spectrum analyzer (e.g., BVS Mantis Bluetooth) or a Bluetooth traffic analyzer (e.g., Frontline Bluetooth Protocol Analyzer). For full-time distributed Bluetooth monitoring, consider a Wireless IDS with Bluetooth-capable sensors (e.g., Red-Alert Pro).

Conclusion

Bluetooth has been flying under IT security radar for quite some time. Given increasing deployment and broader usage, Bluetooth really deserves more attention. Scanning your office for Bluetooth devices and exposed services may yield surprising results. But assessing those vulnerabilities can help you take steps to reduce Bluetooth risk.

To learn more about Bluetooth security standards, attacks, and vulnerability testing, visit http://www.bluetooth.org or http://trifinite.org.


[TABLE]About the author Lisa Phifer is vice president of Core Competence Inc., a consulting firm specializing in network security and management technology. Phifer has been involved in the design, implementation, and evaluation of data communications, internetworking, security, and network management products for nearly 20 years. She teaches about wireless LANs and virtual private networking at industry conferences and has written extensively about network infrastructure and security technologies for numerous publications. She is also a site expert to SearchMobileComputing.com and SearchNetworking.com.

Rate this Tip
To rate tips, you must be a member of SearchMobileComputing.com.
Register now to start rating these tips. Log in if you are already a member.




DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



Mobile Computing Security - Device Security, Mobile Authentication, Mobile Threats

Notebook Deals at Notebook Review

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts