2014 - dss - mobile devices & security overview

53
Innovations in data security Mobile Security Basics Andris Soroka 09.04.2014

Upload: andris-soroka

Post on 19-Jan-2015

318 views

Category:

Technology


0 download

DESCRIPTION

Short overview of security issues regarding mobile phone usage. Examples of mobile threats, common mistakes of users, sophistication of cyber criminals and some futuristic vision of mobility development in technology era.

TRANSCRIPT

Page 1: 2014 - DSS - Mobile devices & security overview

Innovations in data security

Mobile Security Basics

Andris Soroka

09.04.2014

Page 2: 2014 - DSS - Mobile devices & security overview

The Saga Begins – Scared vs. Informed

Page 3: 2014 - DSS - Mobile devices & security overview

Some words about history…

PHONE Elisha Gray & Alexander Granham Bell

2013Xperia Z UltraSONY

Page 4: 2014 - DSS - Mobile devices & security overview

What this is not about (left side)...

Page 5: 2014 - DSS - Mobile devices & security overview

What this is about..

Page 6: 2014 - DSS - Mobile devices & security overview

What is all about

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 7: 2014 - DSS - Mobile devices & security overview

“Data Security Solutions” business card

Specialization – IT Security

IT Security services (consulting, audit, pen-testing, market analysis, system testing and integration, training and technical support)

Solutions and experience portfolio with more than 20 different technologies – cyber-security global market leaders from more than 10 countries

Trusted services provider for banks, insurance companies, government and private companies (critical infrastructure etc.)

Page 8: 2014 - DSS - Mobile devices & security overview

Role of DSS in Cyber-security Development in Baltics

Cyber-Security Awareness Raising

Technology and knowledge transfer

Most Innovative Portfolio

Trusted Advisor to its Customers

Page 9: 2014 - DSS - Mobile devices & security overview

Cybersecurity Awareness Raising

Own organized conference “DSS ITSEC”5th annual event this yearMore than 400 visitors + more than 250 online live streaming watchers from LV, EE, LT4 parallel sessions with more than 40 international speakers, including Microsoft, Oracle, Symantec, IBM, Samsung and many more – everything free of charge

Participation in other events & sponsorshipCERT & ISACA conferences & eventsRIGA COMM, HeadLight, IBM Pulse Las vegasRoadshows and events in Latvia / Lithuania / Estonia (f.i. Vilnius Innovation Forum, Devcon, ITSEC HeadLight, SFK, business associations)

Participation in cyber security discussions, strategy preparations, seminaries, publications etc.

Page 10: 2014 - DSS - Mobile devices & security overview

Innovations – technology & knowledge transfer

Innovative Technology Transfer Number of unique projects done with different technology global leadership vendorsKnowledge transfer (own employees, customers – both from private & public, other IT companies in LV, EE, LT) Specialization areas include:

Endpoint SecurityNetwork SecuritySecurity ManagementApplication SecurityMobile SecurityData SecurityCyber-securitySecurity Intelligence

Page 11: 2014 - DSS - Mobile devices & security overview
Page 12: 2014 - DSS - Mobile devices & security overview

Some just basic ideas

Page 13: 2014 - DSS - Mobile devices & security overview
Page 14: 2014 - DSS - Mobile devices & security overview
Page 15: 2014 - DSS - Mobile devices & security overview

Agenda

Prologue

Digital world 2014

Threats & Security

Recommendations

Exit scene

Page 16: 2014 - DSS - Mobile devices & security overview

Prologue: The Digital World 2014 & future

Page 17: 2014 - DSS - Mobile devices & security overview

Fastest technology development in time..

Page 18: 2014 - DSS - Mobile devices & security overview

Prologue: Some new technologies

3D PrintersGoogle Glasses (“glassh**es)Cloud ComputingBig Data & SupercomputersMobile Payment & Virtual MoneyRobotics and Intraday DeliveriesInternet of thingsAugmented RealityExtreme development of ApsDigital prototypingGadgets (devices) & MobilityTechnology replaced jobs (automation)

Geo-location powerBiometricsHealth bands and mHealthElectronic carsAvegant Glymph and much, much more

Page 19: 2014 - DSS - Mobile devices & security overview
Page 20: 2014 - DSS - Mobile devices & security overview

Prologue: Mobility & Gadgets

Page 21: 2014 - DSS - Mobile devices & security overview

Prologue: Mobility & Gadgets

Page 22: 2014 - DSS - Mobile devices & security overview
Page 23: 2014 - DSS - Mobile devices & security overview

Prologue: Mobility & Gadgets

Page 24: 2014 - DSS - Mobile devices & security overview

21st Century – Mobility century

PC era Mobile era

Page 25: 2014 - DSS - Mobile devices & security overview

Prologue: Mobility & Gadgets

Multi-OS

Page 26: 2014 - DSS - Mobile devices & security overview

Tablets now and future of tablets

Page 27: 2014 - DSS - Mobile devices & security overview

Mobility future forecast

1 Cisco IBSG Horizons Study of 600 U.S. IT and business leaders

“Globally  in  2013  an  average economically  active  person  owns 2.8  mobile  devices.  In  2014  it  is forecasted  that  such  person  will own 3.3 devices. Forecast is giving taking  in  mind  also  that population increases.” 1

Page 28: 2014 - DSS - Mobile devices & security overview

Millions of mobile applications

Page 29: 2014 - DSS - Mobile devices & security overview
Page 30: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 31: 2014 - DSS - Mobile devices & security overview

Digital Agenda for European Union

Page 32: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 33: 2014 - DSS - Mobile devices & security overview

Privacy is gone?

Page 34: 2014 - DSS - Mobile devices & security overview

What exactly phone can collect...

- Emails & other data- Location- Social Media data- Personal information- Degrees of contact- Web-based data

Page 35: 2014 - DSS - Mobile devices & security overview

Mobility & Security...

Page 36: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 37: 2014 - DSS - Mobile devices & security overview

Governments as malware writers

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 38: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 39: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 40: 2014 - DSS - Mobile devices & security overview

Mobility & Security – Use cases

We give mobile devices to children or any other friendly souls (multiuser factor)

We install as many differerent applications as possible - games, social media etc. (apps vulnerability factor)

We experience lost or stolen devices & mostly those won’t be returned

We don’t care about securty basics (updates, security programms, encryption, passwords etc.)

We connect to anything that is FREE

We open EVRYTHING

We give 3rd party apps any possible rights

We don’t make «seasonal» clearings of our devices

Page 41: 2014 - DSS - Mobile devices & security overview

Mobile device as entry point

Page 42: 2014 - DSS - Mobile devices & security overview

Mobility for enterprise

M - the need for mobility O - the need to improve operations B -  the need to break business barriers I -  the need to improve information quality L -  the need to decrease transaction lag E -  the need to improve efficiency

Page 43: 2014 - DSS - Mobile devices & security overview

Mobility and enterprises (cont.)

ITMobile

2-3x as many employees using mobile

Devices not Windows-based

>50% owned by employees

>50 apps per device

Most mobile apps built outside IT

Constant OS migration

Page 44: 2014 - DSS - Mobile devices & security overview
Page 45: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 46: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 47: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 48: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 49: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 50: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

Page 51: 2014 - DSS - Mobile devices & security overview

Mobility & Security

“2014.gadā  vidēji  katram izglītotam  darbiniekam  būs  vidēji 3.3  mobīlās  ierīces,  salīdzinot  ar vidējo statistiku ar 2.8 mobīlajām ierīcēm 2013.gadā.” 1

4 Roll out at scale

Group-basedUser self-service

Multi-tier management

EmailAD/LDAP

CertificatesBES

2 Integrate tightly

Email and appsPolicy and identity

Connectivity (Wi-Fi, VPN)By group, individual, or ownership

1 Configure securely

3 Protect privacy

BYOD programsRegional regulations

Across OSFor apps and devices

For BYOD and corporate programs

5 Manage inventory

Wipe corporate data15 Limit roaming costs14

Deliver apps at scale

Protect app container12

11

Tunnel app data13Apps

6 Monitor risk

8 Enforce identity

9 Automate workflow

7 Control access

Security

Access and protect docs10Docs

Page 52: 2014 - DSS - Mobile devices & security overview

Korporatīvā vide

Drošu pašu veidoto mobīlo aplikāciju izveide

Pilnvērtīgi ieviest un izmantoto korporatīvajā vidē tā saucamo «Nāc ar savu ierīci» («BYOD») tendenci

Mobīlo ierīču pārvaldība un drošībaMobīlo aplikāciju pārvaldības politika

Datu nošķirtības sasniegšanaPrivātie datiKorporatīvie dati

Nodrošināt drošu piekļuvi pie korporatīvajiem datiem un darba aplikācijām

Drošs savienojums (šifrēts)Identitātes kontrole, autentifikācija un autorizācija, arī auditsDroša pašmāju aplikāciju izstrāde un testēšana

Page 53: 2014 - DSS - Mobile devices & security overview

Think security first

[email protected]

+371 29162784