10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

BlackBerry<br />

BlackBerry is renowned for its device and operating system security. In a recent interview<br />

with BlackBerry, a spokesperson told Goode Intelligence that “BlackBerry has a moral<br />

obligation to protect <strong>the</strong>ir user’s security and privacy”.<br />

It is still <strong>the</strong> only <strong>Smartphone</strong> that has been accredited by CESG, using CESG’s Assisted<br />

Products Service (CAPS), for handling UK Government (HMG) ‘Restricted’ information. 81<br />

In an interview with BlackBerry in March 2013, Goode Intelligence was informed that for<br />

vulnerability management:<br />

BlackBerry holds regular security meetings and conferences where independent<br />

security researchers will attend and discuss <strong>the</strong> latest vulnerabilities and threats<br />

BlackBerry has a security team <strong>of</strong> around 160 people and a good proportion <strong>of</strong> <strong>the</strong>se<br />

will be security researchers (white hats). They will be looking at <strong>the</strong> latest threats and<br />

exploits<br />

Enterprise users will be pushed vulnerability advisories, using RSS, and <strong>the</strong>se<br />

advisories will also be sent to national CERTs and o<strong>the</strong>r vulnerability databases "as<br />

soon as possible”<br />

Consumer users will be notified using public notification channels including<br />

BlackBerry’s Knowledge Base<br />

Goode Intelligence discovered only three unique CVE entries whilst performing a search on<br />

<strong>the</strong> CVE vulnerability database for ‘BlackBerry OS’, 33 entries were discovered for ‘RIM’ and<br />

41 when ‘BlackBerry’ was used. The search term ‘BlackBerry’ also included vulnerabilities<br />

recorded for <strong>the</strong> BlackBerry Enterprise Server (BES).<br />

The BlackBerry <strong>Security</strong> Incident Response Team (BSIRT) provides 24/7 monitoring,<br />

vulnerability analysis, remediation and guidance in order to help keep BlackBerry customers<br />

protected from security issues.<br />

BBISRT addresses both internally and externally identified vulnerabilities through a triage<br />

and monitoring process. Once a potential issue is identified, BBSIRT uses <strong>the</strong> Common<br />

Vulnerability Scoring <strong>System</strong> (CVSS) internally to rank and prioritise security vulnerabilities<br />

in BlackBerry products. If an issue is classified through CVSS as critical or severe,<br />

BlackBerry will begin <strong>the</strong> process to develop a security update to address <strong>the</strong> issue.<br />

Depending on BlackBerry’s analysis on <strong>the</strong> threat landscape, <strong>the</strong>y may release a security<br />

notice while <strong>the</strong> security update is being developed to help protect customers by providing<br />

<strong>the</strong>m with available mitigations.<br />

Once <strong>the</strong> security update is ready for customers, <strong>the</strong>y will release a security advisory that<br />

details <strong>the</strong> vulnerability, <strong>the</strong> fix, and any applicable mitigations and workarounds.<br />

BlackBerry follows <strong>the</strong> ‘Patch Tuesday’ schedule for releasing s<strong>of</strong>tware updates by releasing<br />

on <strong>the</strong> second Tuesday <strong>of</strong> <strong>the</strong> month. The security update information is widely shared<br />

through several communication channels, such as <strong>the</strong> external BlackBerry website,<br />

81 BlackBerry OS 7.1 was accredited by CESG in November 2012:<br />

http://www.cesg.gov.uk/News/Pages/BlackBerry-7.1-OS-now-Approved.aspx<br />

Goode Intelligence © 2013 P a g e | 86 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!