10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

communicating vulnerability information to system administrators and security pr<strong>of</strong>essionals<br />

and by providing a searchable database <strong>of</strong> known vulnerabilities nationally managed<br />

CERTs, including <strong>the</strong> UK’s own GovCertUK, are important centres for vulnerability<br />

management.<br />

From Goode Intelligence’s research CERT’s are currently performing a limited role in <strong>the</strong><br />

<strong>Smartphone</strong> operating system security and vulnerability management process.<br />

In discussion with a number <strong>of</strong> <strong>the</strong> UK’s mobile operators <strong>the</strong>y had little involvement with<br />

CERTs including GovCertUK.<br />

<strong>Smartphone</strong>s and o<strong>the</strong>r smart mobile devices have definitely started to turn up on <strong>the</strong> radar<br />

<strong>of</strong> CERTs. US-CERT has published a number <strong>of</strong> security publications specifically on mobile<br />

security that act as advisories.<br />

Recommendations<br />

This is a constantly evolving landscape and <strong>the</strong>re is a need to reach out to industry<br />

stakeholders to ensure that <strong>the</strong>y are kept informed <strong>of</strong> <strong>the</strong> latest vulnerabilities that can affect<br />

UK consumers.<br />

Goode Intelligence believes that all <strong>of</strong> <strong>the</strong> major <strong>Smartphone</strong> operating system vendors are<br />

proactive in vulnerability management. They are doing a pretty good job <strong>of</strong> discovering and<br />

remediating vulnerabilities.<br />

However, <strong>the</strong>re can be problems in pushing out ‘fixed’ or patched s<strong>of</strong>tware updates to<br />

millions <strong>of</strong> <strong>Smartphone</strong> users in an appropriate period <strong>of</strong> time. There can be instances where<br />

vulnerabilities go unpatched for many months. This can lead to <strong>Smartphone</strong> owners being<br />

exposed to exploitable vulnerabilities for an excessive period <strong>of</strong> time. This situation is more<br />

acute with Android and is a consequence <strong>of</strong> <strong>the</strong> platform’s ‘fragmentation’ issue.<br />

As national CERTs are currently playing a limited role in <strong>the</strong> <strong>Smartphone</strong> operating system<br />

vulnerability management process <strong>the</strong>y may want to improve <strong>the</strong>ir role by taking a more<br />

proactive stance and by improving <strong>the</strong>ir relationships with UK MNOs.<br />

Goode Intelligence © 2013 P a g e | 20 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!