mobile security - bristol.bcs.org security-david rogers.pdf · mff2 (machine-to-machine form...

40
Mobile Security Security Mini Spring School BCS Bristol Branch David Rogers 23 rd March 2015 Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved. http://www.mobilephonesecurity.org

Upload: others

Post on 08-Sep-2019

4 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Mobile Security

Security Mini Spring School

BCS Bristol Branch

David Rogers

23rd March 2015

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

http://www.mobilephonesecurity.org

Page 2: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g
Page 3: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Introduction

Mobile security is a huge topic

This is just a taster!

If you’re interested in more: http://www.cs.ox.ac.uk/softeng/subjects/MSS.html

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 4: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Some History

Phones have constantly been under attack – Fraudsters

• Premium rate / international calling

• Subsidy fraud

– Call interception

– Denial of Service

– Device Hacking

– Nation state attacks

– Journalists

– Etc.

Continuous security improvement – Networks and devices

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 5: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Hacking, Cracking, Jailbreaking and Rooting

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 6: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

THE THREAT LANDSCAPE

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

http://www.mobilephonesecurity.org

Page 7: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

The problem with devices

People tamper with things!

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 9: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Is it real?

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved. 9

From: http://www.littleredbook.cn/2009/07/06/obamas-sponsorship-of-shanzhai-blockberry-chinese-netizens-reactions/

http://www.mobilephonesecurity.org

Page 10: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Technical threat vectors

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

http://www.mobilephonesecurity.org

Page 11: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Handset theft

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

http://www.mobilephonesecurity.org

Page 12: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Anti-Theft Measures

Continued global industry work since 1999

GSMA Global Database

9 principles and other device hardware security work

IMEI weakness and reporting process

SG.24 – Anti-Theft Device Feature Requirements • Network operators already requesting in device requirements

• Input and comment from major manufacturers including Samsung, Google and Apple

Continuing to look at in-network measures

Partnership approach works industry / government / Police • Societal issue, not a technological one

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 13: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 14: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Police Theft Awareness Campaigns

UK Home Office TV Advert Campaign

Mobile Phone Security - David Rogers

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

http://www.mobilephonesecurity.org http://www.mobilephonesecurity.org

Page 15: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Mobile malware

Mainly an issue only for Android – but only where user goes ‘off-piste’ from the official appstore

Some drive-by downloads observed

Getting a lot more organised – much more focus on mobile

Lots of FUD still from anti-virus vendors

Lots of “Spouseware!” – Someone you know uses it combined with a jailbreak

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 16: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Mobile Malware (2)

Don’t believe everything you read in the press

Mobile is different to the PC world

Spouseware…

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 17: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Malware (3)

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

“You are more likely to get struck by lightning in your entire lifetime than you are to be infected by mobile malware”

Patrick Traynor, Georgia Tech, March 2013

http://www.mobilephonesecurity.org

Page 18: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

DEVICE SECURITY TECHNOLOGIES AND THE MOBILE INDUSTRY

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 19: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Hardware-level security

Has got significantly better in mobile phones

Still extensively targeted

What does the future hold? – Not just mobile handsets anymore – small cells, automotive etc.

– Step-change seems to have worked rather than ‘the-moon-on-a-stick’

– Classes of devices?:

vs

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 20: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Platform software updates

From Michael DeGusta http://theunderstatement.com/post/11982112928/android-orphans-visualizing-a-sad-history-of-support

http://www.mobilephonesecurity.org

Page 21: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Application security

General harmonisation of mechanisms – Digital signatures and encryption

– Application isolation

– No redistribution of apps from device

– Permissions - principle of least privilege

– Authorised app stores

– Software security methods

– Protection of sensitive keys and authentication info.

Some things (like user permissions) need to be improved

Future web-based mobile platforms need to implement and build/improve on this

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 22: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Responsible disclosure & incident handling

“USSD code attack” could reset and wipe Galaxy SIIIs – Dialler could be remotely called from web using ‘tel’ URI – USSD or proprietary MMI codes would execute with no user confirmation

Drive-by attack using rigged website or social engineering:

Mobile industry needs to get better at sharing information and working with researchers

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 23: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Industry winning?

Tools such as Google’s Bouncer cause the attackers to focus on the castle walls

Samsung Knox, Blackberry OS10 and others are all increasingly improving overall device security

Source: http://cadw.wales.gov.uk/daysout/harlechcastle/?lang=en

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 24: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

USER EDUCATION & SECURITY BEHAVIOURS

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 25: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Secure, usable, affordable devices?

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 26: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Usability of security

Users will always choose dancing kittens over security.

They will get over any hurdle to get to the kittens…

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 27: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Consumer education

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 28: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

UPCOMING TECHNOLOGY AND THE CONVERGING THREAT

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 29: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Convergence across vastly different sectors

Televisions & Set-top boxes

Vehicle

s

White Goods Other Consumer Electronics

Security & Privacy?

Streaming Media

Temperature sensors

Timers

Location

Messaging

Gallery

Weight

Speed

Diagnostics / telematics

Fares / charging

Gallery

Street

furniture

Electronic street sign: via Wikimedia / Ross

Smart pills from: http://www.themalaysianinsider.com/features/article/sensorised-smart-pills-to-launch-in-uk

mHealth Patient monitoring

Dosage

Information

Control

Smart pills

http://www.mobilephonesecurity.org

Page 31: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Truly connected devices

phone

http://www.mobilephonesecurity.org

Page 32: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

What is Home Security?

From: http://www.independent.co.uk/news/world/americas/hacker-takes-control-of-ohio-couples-baby-monitor-and-screams-bad-things-9296986.html www.nest.com

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 33: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Mobile Cyber Security?

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 34: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Emerging Device Security & Privacy

http://www.mobilephonesecurity.org

Page 35: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

MFF2 (machine-to-machine form factor) – embedded SIM

– surface mount

– mainly used for M2M

Some security issues e.g. Karsten Nohl ‘Rooting SIM cards’ 2013

The ever-evolving SIM

http://www.mobilephonesecurity.org

http://m2mworldnews.com/2012/07/18/47198-rapid-migration-to-embedded-sim-forecast-for-cellular-m2m/

• UICC supports multiple javacard applets • SIM, USIM and ISIM all applications • Embedded NFC • Updateable and configurable remotely

http://commons.wikimedia.org/wiki/File:GSM_SIM_card_evolution.svg

https://srlabs.de/rooting-sim-cards/

Page 36: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Biometrics

Still immature on mobile devices – Early solutions easy to defeat (e.g. gummy finger etc.)

– Other types difficult to use

– Requires significant processing power

– iPhone 5S introduced TouchID

– 990 million devices with fingerprint sensors predicted by 2017

Increased risk for the user – User as unlock key means user becomes the target of attack

– Same issue as car crime

http://www.mobilephonesecurity.org

Also see: http://blog.mobilephonesecurity.org/2013/09/you-are-key-fingerprint-access-on.html Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 37: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Challenges for biometrics

False negatives:

– Eyelashes too long

– Long fingernails

– Arthritis

– Circulation problems

– People wearing hand cream

– People who’ve just eaten greasy foods

– People with brown eyes

– Fingerprint abrasion, includes: Manual labourers, typists, musicians

– People with cuts

– Disabled people

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 38: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

The Future?

Mobile extending outwards – Internet of Things / Machine-to-machine

– Embedded SIM

– Next generation networks

– Connected car

– Connected homes / businesses

– Payment and banking

What about privacy?

Mobile handset will be at heart of everything

The “things” will need securing

Fraud / security issues won’t go away, they’ll just evolve

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.

Page 39: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Products & Services

Management Committee

Fraud & Security Group

Device Security Group

Mobile Malware

Group

Fraud & Security

Architecture Group

Roaming & Interconnect

Fraud & Security

Fraud & Security Comms.

Security & Fraud Risk

Assessment

Security Assurance

Group

Fraud & Security Advisory

Panel

Asia

Africa

Latin America

GSMA Fraud and Security Group

http://www.mobilephonesecurity.org

Page 40: Mobile Security - bristol.bcs.org Security-David Rogers.pdf · MFF2 (machine-to-machine form factor) –embedded SIM –surface mount –mainly used for M2M Some security issues e.g

Questions?

david.rogers @ copperhorse.co.uk

@drogersuk

Mobile Security: A Guide for Users: http://www.lulu.com/gb/en/shop/david-rogers/mobile-security-

a-guide-for-users/paperback/product-21197551.html

http://www.mobilephonesecurity.org

Copyright © 2015 Copper Horse Solutions Ltd. All rights reserved.