{"50972":{"#nid":"50972","#data":{"type":"news","title":"Making Mobile Devices, Cellular Networks More Secure","body":[{"value":"\u003Cp\u003EATLANTA \u2013 November 10 2009 \u2013 Smart phones -- like BlackBerrys and iPhones -- have become indispensable to today\u0027s highly mobile workforce and tech-savvy youngsters. While these devices keep friends and colleagues just a few thumb-taps away, they also pose new security and privacy risks. \u003C\/p\u003E\n\u003Cp\u003E\u0022Traditional cell phones have been ignored by attackers because they were specialty devices, but the new phones available today are handheld computers that are able to send and receive e-mail, surf the Internet, store documents and remotely access data -- all actions that make them vulnerable to a wide range of attacks,\u0022 said Patrick Traynor, assistant professor in the School of Computer Science at the Georgia Institute of Technology.\u003C\/p\u003E\n\u003Cp\u003ETraynor and Jonathon Giffin, also an assistant professor in the School of Computer Science, recently received a three-year $450,000 grant from the National Science Foundation to develop tools that improve the security of mobile devices and the telecommunications networks on which they operate. These Georgia Tech faculty, together with a team of graduate students, are developing methods of identifying and remotely repairing mobile devices that may be infected with viruses or other malware.\u003C\/p\u003E\n\u003Cp\u003EMalware can potentially eavesdrop on user input or otherwise steal sensitive information, destroy stored information, or disable a device. Attackers may snoop on passwords for online accounts, electronic documents, e-mails that discuss sensitive topics, calendar and phonebook entries, and audio and video media. \u003C\/p\u003E\n\u003Cp\u003E\u0022Since mobile phones typically lack security features found on desktop computers, such as antivirus software, we need to accept that the mobile devices will ultimately be successfully attacked. Therefore our research focus is to develop effective attack recovery strategies,\u0022 explained Giffin.\u003C\/p\u003E\n\u003Cp\u003EThe researchers plan to investigate whether cellular service providers -- such as AT\u0026amp;T and Verizon Wireless -- are capable of detecting infected devices on their respective networks. Since infected devices often begin to over-utilize the network by sending a high volume of traffic to a known malicious Internet server or by suddenly generating a high volume of text messages, monitoring traffic patterns on the network should allow these infected phones to be located, according to the researchers.\u003C\/p\u003E\n\u003Cp\u003E\u0022While a single user might realize that a phone is behaving differently, that person probably won\u0027t know why. But a cell phone provider may see a thousand devices behaving in the same way and have the ability to do something about it,\u0022 said Traynor.\u003C\/p\u003E\n\u003Cp\u003EOnce infected devices are located, those phones will need to be cleared of the malicious code. To accomplish this, the researchers are developing remote repair methods, which will allow service providers to assist in the cleaning of infected devices without requiring that the phones be brought to a service center. The methods will also have to work without much effort on the part of the customer.\u003C\/p\u003E\n\u003Cp\u003EThis repair may require disabling some functionality on the phone, such as the ability to use downloaded programs, until the malicious program is located and removed. While the repair is underway, phone calling and text messaging functionality would continue to operate.\u003C\/p\u003E\n\u003Cp\u003E\u0022Using this remote repair strategy, the service provider no longer has to completely disable a phone. Instead they just put the device into a safe, but reduced, mode until the malware can be removed,\u0022 said Giffin.\u003C\/p\u003E\n\u003Cp\u003ETo assess their proposed methods of finding and repairing infected mobile devices, the researchers plan to build a cellular network test bed at Georgia Tech that will simulate how cellular devices communicate over a network.\u003C\/p\u003E\n\u003Cp\u003E\u0022We hope that developing these attack recovery strategies will let potential mobile phone and network attackers know that these response mechanisms are in place, ultimately making their attacks far less widespread or successful,\u0022 said Traynor.\u003C\/p\u003E\n\u003Cp\u003E\u003Cem\u003EThis material is based upon work supported by the National Science Foundation (NSF) under Award No. CNS-0916047. Any opinions, findings, conclusions or recommendations expressed in this publication are those of the researcher and do not necessarily reflect the views of the NSF.\u003C\/em\u003E\u003C\/p\u003E\n\u003Cp\u003E###\u003C\/p\u003E\n\u003Cp\u003EResearch News \u0026amp; Publications Office\u003C\/p\u003E\n\u003Cp\u003EGeorgia Institute of Technology\u003C\/p\u003E\n\u003Cp\u003E75 Fifth Street, N.W., Suite 100\u003C\/p\u003E\n\u003Cp\u003EAtlanta, Georgia\u0026nbsp; 30308\u0026nbsp; USA\u003C\/p\u003E\n\u003Cp\u003EMedia\u003Cbr \/\u003E\nRelations Contacts: Abby Vogel (404-385-3364); E-mail:\u003Cbr \/\u003E\n(\u003Ca href=\u0022mailto:avogel@gatech.edu\u0022\u003Eavogel@gatech.edu\u003C\/a\u003E) or John Toon (404-894-6986); E-mail:\u003Cbr \/\u003E\n(\u003Ca href=\u0022mailto:jtoon@gatech.edu\u0022\u003Ejtoon@gatech.edu\u003C\/a\u003E).\u003C\/p\u003E\n\u003Cp\u003EWriter: Abby Vogel\u003C\/p\u003E","summary":null,"format":"limited_html"}],"field_subtitle":"","field_summary":[{"value":"\u003Cp\u003EATLANTA \u2013 November 10 2009 \u2013 Patrick Traynor and Jonathon Giffin, also an assistant professor in the\nSchool of Computer Science, recently received a three-year $450,000\ngrant from the National Science Foundation to develop tools that\nimprove the security of mobile devices and the telecommunications\nnetworks on which they operate. These Georgia Tech faculty, together\nwith a team of graduate students, are developing methods of identifying\nand remotely repairing mobile devices that may be infected with viruses\nor other malware. \u003Cem\u003ESource: Office of Communications\u003C\/em\u003E\u003C\/p\u003E","format":"limited_html"}],"field_summary_sentence":"","uid":"27154","created_gmt":"2010-02-09 21:39:23","changed_gmt":"2016-10-08 03:04:20","author":"Louise Russo","boilerplate_text":"","field_publication":"","field_article_url":"","dateline":{"date":"2009-11-09T00:00:00-05:00","iso_date":"2009-11-09T00:00:00-05:00","tz":"America\/New_York"},"extras":[],"groups":[{"id":"47223","name":"College of Computing"}],"categories":[],"keywords":[],"core_research_areas":[],"news_room_topics":[],"event_categories":[],"invited_audience":[],"affiliations":[],"classification":[],"areas_of_expertise":[],"news_and_recent_appearances":[],"phone":[],"contact":[],"email":[],"slides":[],"orientation":[],"userdata":""}}}