Home > Mobile Computing Tips > Mobile Security > Mobile security -- Are antivirus and firewalls enough?
Mobile Computing Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

MOBILE SECURITY

Mobile security -- Are antivirus and firewalls enough?


Jack Gold
12.20.2006
Rating: -4.67- (out of 5)


Mobile advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Security on mobile devices continues to be a major challenge as companies struggle with increased levels of attacks and as mobile devices become the preferred platform for enterprise users. We expect notebooks to represent more than 50% of enterprise PC deployments within two to three years, and more than 85% of enterprise users will deploy smartphone devices within the same time frame. It is clear, then, that mobile security must be at the forefront of most enterprises' security planning.

Most companies currently focus on protecting PCs by providing antivirus and firewall capabilities. Few companies currently provide antivirus and firewalls on smart devices, but we expect this market to grow dramatically in the next one to two years as new threats emerge and awareness grows. But with increasingly sophisticated attacks and with more complex machines and operating systems (OS) emerging, can a machine be fully protected just through antivirus and firewall software without killing its performance? The move to multicore chips and virtual machines will help, as security can run effectively in parallel with user applications instead of competing for resources, but this is not a panacea. And current security subsystems (e.g., TPM chips) tackle only part of the problem. It may be time to consider an alternative -- a dedicated hardware solution to tackle increasing threat levels.

We expect the effort to protect various devices to move from today's purely software-directed approach to one that uses more sophisticated and harder-to-break technology that includes external hardware devices. These devices can be assigned to a user and can easily be managed from a corporate location (via connection over broadband networks to a management server), and they can easily be moved to other devices or even to the front end of a small network (e.g., in front of a wireless hub in a home network) to protect multiple machines. These devices are currently standalone external devices, but there is no reason they can't ultimately be integrated directly into machines.

Though not the perfect solution, the personal hardware security appliance does provide some real benefits that, if conveniently provided at a low enough cost, could raise the level of security of mobile devices. First, it could bypass the need to keep the OS patched to stay ahead of the hackers -- a near impossible task. Next, it would provide the ability to enhance a firewall with incoming and outgoing data traffic monitoring to allow easier detection of problems. Third, it would allow policies to be set by an enterprise or trusted source. Finally, it could more easily track virus-like behavior by examining specific packets of information using a heuristics model. These devices would need to be upgraded periodically with new algorithms via a subscription service -- much as antivirus is now.

We expect to see a variety of devices become available in the market in the next two years, at price points well below $100. In order to be successful, however, these devices must be extremely simple to deploy, they must prove they are not vulnerable to attack by hackers, and they must not significantly affect the performance of the machines and/or networks they are meant to protect. We expect this capability to ultimately be embedded in machines rather than continue as external devices that users must carry.

Here are a few hardware security appliance for mobile devices:
Yoggie Gatekeeper
Eli Security Appliance
ZyWall

About the author: Jack E. Gold is a recognized expert in mobile computing and is founder and principal analyst at technology research firm J. Gold Associates. He can be contacted at jack.gold@jgoldassociates.com.


Rate this Tip
To rate tips, you must be a member of SearchMobileComputing.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Mobile Security
Protecting data on your BlackBerry
Defining your mobile security policy
Government regulations and mobile security policies
Symbian: Protect your data, not just your device
Mobile security policies: Why a policy is important
Avoiding data breaches through mobile encryption
Mobile security: Setting responsible goals
Mobile security: Top oversights
Mobile device management -- Controlling risks and costs for better security
Using Exchange Server for mobile device security

Mobile Device Security
Protecting data on your BlackBerry
Going green: Recycling and energy saving tips for mobile devices -- podcast
New challenges in mobile device discovery
Quiz: Mobile Device Security -- Who else can hear me now?
Mobile device security: Guarding the gate
Mobile voice encryption gets cheaper, easier to do
Top mobile tips of 2007
Mobile device security: Improving mobile authentication
Mandate security training to safeguard your mobile fleet
Google's Android platform could complicate security
Mobile Device Security Research

Mobile Security Software and Tools
Sybase adds antivirus and firewall to mobile management suite
Detecting rogue mobile devices on your network
Symbian: Protect your data, not just your device
Mobile devices: Corporate security strategies
Mobile phone spyware -- it's here
Smartphones, PDAs left in cabs at alarming rates
Endpoint security extended to smartphones
Locating a lifted laptop
Mobile security policy useless if not enforced
Access on the road: Putting hotspot security to the test

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
mobile VPN  (SearchMobileComputing.com)
screaming cell phone  (SearchMobileComputing.com)
SMiShing  (SearchMobileComputing.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersProducts
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2003 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts