0% found this document useful (0 votes)
4 views29 pages

Module 2 - Cyber Security

The document discusses the importance of cybersecurity and mobile device protection, highlighting the rapid advancements in mobile technology and the associated risks. It outlines various types of mobile devices, common security challenges, and popular attack vectors against mobile networks, particularly in the context of 3G technology. The document emphasizes the need for organizations to implement effective security policies and measures to safeguard sensitive information stored on mobile devices.

Uploaded by

divya.ypr.13
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd
0% found this document useful (0 votes)
4 views29 pages

Module 2 - Cyber Security

The document discusses the importance of cybersecurity and mobile device protection, highlighting the rapid advancements in mobile technology and the associated risks. It outlines various types of mobile devices, common security challenges, and popular attack vectors against mobile networks, particularly in the context of 3G technology. The document emphasizes the need for organizations to implement effective security policies and measures to safeguard sensitive information stored on mobile devices.

Uploaded by

divya.ypr.13
Copyright
© All Rights Reserved
We take content rights seriously. If you suspect this is your content, claim it here.
Available Formats
Download as PPTX, PDF, TXT or read online on Scribd

|| Jai Sri Gurudev||

Sri Adichunchanagiri Shikshana Trust (R)

SJB INSTITUTE OF TECHNOLOGY


(Affiliated to Visvesvaraya Technological University, Belagavi& Approve d by AICTE, New Delhi.)
No. 67, BGS Health & Education City, Dr. Vishnuvardhan Road Kengeri, Bengaluru – 560 060

Subject: Cyber Security & Cyber Law(23ISI421)


Module-2
By
Prof. Prarthana J V, Assistant Professor
for
4th Sem-ISE
Department of Information Science & Engineering
Aca. Year: EVEM SEM /2025-26
Syllabus
INTRODUCTION
Why should mobile devices be protected? Every day,
mobile devices are lost, stolen, and infected. Mobile
devices can store important business and personal
information, and are often be used to access University
systems, email, banking
Proliferation of mobile and wireless devices:
⚫ people hunched over their smartphones or tablets in
cafes, airports, supermarkets and even at bus stops,
seemingly oblivious to anything or anyone around them.
⚫ They play games, download email, go shopping or
check their bank balances on the go.
Rapid Advancements Mobile devices are becoming smaller, faster, and more powerful.
Evolution of Devices Earlier choice: Wireless phones vs. simple PDAs
Now:
 High-end PDAs with wireless modems
 Compact phones with web browsing capabilities
Wide Range of Options Users now have multiple device choices with varied functionalities.
Capabilities of Hand-held Devices Modern mobile devices can:
 Run applications
 Play games and music
 Support voice communication
Key Growth Driver Increasing use of mobile devices for business applications and
solutions
Broad Definition of Mobile Devices Includes a variety of products such as:
 Smartphones
 PDAs
 Tablets
 Other portable computing devices
Important Terminology Mobile Computing: Computing on the move using portable devices
Wireless Computing: Data communication without physical connections
Hand-held Devices: Small portable devices used for computing and communication
Concept Relationship These terms are interrelated, forming the foundation of modern
mobile technology.
Types of mobile computers

1. Portable computer: It is a general-purpose computer that can be easily moved from one place to
another, but cannot be used while in transit, usually because it requires some "setting- up" and an AC
power source.
2. Tablet PC: It lacks a keyboard, is shaped like a slate or a paper notebook and has features of a
touchscreen with a stylus and handwriting recognition software. Tablets may not be best suited for
applications requiring a physical keyboard for typing, but are otherwise capable of carrying out most tasks
that an ordinary laptop would be able to perform.
3. Internet tablet: It is the Internet appliance in tablet form. Unlike a Tablet PC, the Internet tablet does
not have much computing power and its applications suite is limited. Also it cannot replace a general-
purpose computer. The Internet tablets typically feature an MP3 and video player, a Web browser, a chat
application and a picture viewer.
4. Personal digital assistant (PDA): It is a small, usually pocket-sized, computer with limited functionality.
It is intended to supplement and synchronize with a desktop computer, giving access to contacts, address
book, notes, E-Mail and other features.
5. Ultramobile (PC): It is a full-featured, PDA-sized computer running a general-purpose operating system
(OS).
6. Smartphone: It is a PDA with an integrated cell phone functionality. Current Smartphones have a wide
range of features and installable applications.
7. Carputer: It is a computing device installed in an automobile. It operates as a wireless computer, sound
system, global positioning system (GPS) and DVD player. It also contains word processing software and is
Bluetooth compatible.
8. Fly Fusion Pentop computer: It is a computing device with the size and shape of a pen. It functions as a
writing utensil, MP3 player, language translator, digital storage device and calculator.
Trends in
Key Points on Mobile ComputingMobility:
& Security (3G Era)
Emergence of 3G Technology
Mobile computing has entered the third generation (3G) era.
Offers:
Higher data speeds
Improved usability
Wider range of applications
Examples of Smart Mobile Technology
Devices like Apple iPhone
Android-based smartphones
Represent the growth of advanced mobile ecosystems
Growing Popularity & Risks
Smart mobile devices are rapidly increasing in usage.
Attract attackers (hackers and crackers) due to vulnerabilities.
Importance of Understanding Trends
Studying mobile computing trends helps in:
Recognizing cybersecurity threats
Understanding risk severity in mobile environments
Security Limitations of 3G Networks
3G networks are not fully designed with strong IP data security.
Transition from voice-centric networks to data-centric networks introduces new risks.
Types of Attack Vectors
Mobile network attacks can originate from two main sources:
External Sources
Public Internet
Private networks
Other mobile operator networks
Internal Sources
Data-capable mobile devices (smartphones, handsets)
Notebook computers
Desktop systems connected to mobile networks
Key Concern
The shift to IP-based communication has increased exposure to cyber threats.
Popular types of attacks against 3G mobile
networks
1. Malwares, viruses and worms: Although many users are still in the transient process of
switching from 2G,2.5G2G,2.5G to 3G,3G, it is a growing need to educate the community
people and provide awareness of such threats that exist while using mobile devices. Here
are few examples of malware(s) specific to mobile devices:
Skull Trojan: I targets Series 60 phones equipped with the Symbian mobile OS.
Cabir Worm: It is the first dedicated mobile-phone worm infects phones running on
Symbian OS and scans other mobile devices to send a copy of itself to the first
vulnerable phone it finds through Bluetooth Wireless technology. The worst thing
about this worm is that the source code for the Cabir-H and Cabir-I viruses is
available online.
Mosquito Trojan: It affects the Series 60 Smartphones and is a cracked version of
"Mosquitos" mobile phone game.
Brador Trojan: It affects the Windows CE OS by creating a svchost. exe file in the
Windows start-up folder which allows full control of the device. This executable file is
conductive to traditional worm propagation vector such as E-Mail file attachments.
Lasco Worm: It was released first in 2005 to target PDAs and mobile phones running
the Symbian OS. Lasco is based on Cabir's source code and replicates over Bluetooth
connection
Popular types of attacks against 3G mobile
networks
2. Denial-of-service (DoS): The main objective behind this attack is to make the system
unavailable to the intended users. Virus attacks can be used to damage the system to
make the system unavailable. Presently, one of the most common cyber security threats to
wired Internet service providers (iSPs) is a distributed denial-of-service (DDos)
attack .DDoS attacks are used to flood the target system with the data so that the response
from the target system is either slowed or stopped.
3. Overbilling attack: Overbilling involves an attacker hijacking a subscriber's IP address
and then using it (i.e., the connection) to initiate downloads that are not "Free downloads"
or simply use it for his/her own purposes. In either case, the legitimate user is charged for
the activity which the user did not conduct or authorize to conduct.
4. Spoofed policy development process (PDP): These of attacks exploit the vulnerabilities
in the GTP [General Packet Radio Service (GPRS) Tunneling Protocol].
5. Signaling-level attacks: The Session Initiation Protocol (SIP) is a signaling protocol used
in IP multimedia subsystem (IMS) networks to provide Voice Over Internet Protocol (VoIP)
services. There are several vulnerabilities with SIP-based VolP systems.
Credit Card Frauds in Mobile and Wireless Computing Era
Emerging Cybercrime Trend Credit card fraud is increasing with the growth of:
• Mobile Commerce (M-Commerce)
• Mobile Banking (M-Banking)
Reason for Rise in Fraud: Affordable and powerful mobile devices are easily
available
Wider access → higher chances of misuse and fraud
Era of Mobile Computing “Anytime, anywhere computing” has become the norm
Driven by advancements in wireless technology
Impact on Financial Transactions: Credit card processing has moved to wireless
platforms
Enables transactions from remote/mobile locations
Wireless Credit Card Processing Allows businesses to:
• Process payments electronically
• Operate virtually anywhere
• Ensure fast and efficient transactions
Advantages for Businesses Convenience and flexibility
Professional and quick service delivery
Ideal for businesses operating in mobile environments (e.g., delivery, field services)
Security Challenges: Increased mobility introduces:
• Higher risk of fraud and data theft
• Vulnerabilities in wireless communication channels
As shown in Figure, the basic flow is as follows:
1. Merchant sends a transaction to bank
2. The bank transmits the request to the authorized
cardholder
3. The cardholder approves or rejects (password
protected)
4. The bank/merchant is notified
5. The credit card transaction is completed
Security Challenges Posed by Mobile
Devices:
Core Challenges of Mobility
Data Outside Controlled Environment
Sensitive information is carried on hand-held devices outside secure premises
Increases risk of data loss, theft, and unauthorized access
Remote Access to Secure Systems
Mobile devices enable remote login to protected organizational networks
Creates potential entry points for cyber attacks
Importance of Organizational Perception
Organizations must recognize risks properly
Helps in designing effective security policies and procedures

Types of Security Challenges


Micro-Level Challenges (Device Level)
• Issues specific to individual mobile devices
• Examples:
• Device theft or loss
• Weak authentication
• Malware attacks
Macro-Level Challenges (Organizational Level)
• Challenges affecting the entire organization
• Examples:
• Managing multiple devices
• Ensuring secure network access
• Policy enforcement across users
Analysis of recent data
through survey
Technical Security Challenges

Configuration Management
Securing registry settings and device configurations
Authentication Security
Protecting user identity verification mechanisms
Cryptography Security
Ensuring safe encryption and decryption of data
LDAP Security(Lightweight Directory Access Protocol)
Securing directory services (user credentials and access control)
RAS (Remote Access Server) Security
Protecting remote connectivity to networks
Media Player Control Security
Preventing malicious content through media applications
Networking API Security (Application Programming Interface)
Securing application interfaces used for network communication
Registry Settings for Mobile Devices
Registry settings store important configuration and control information for mobile devices
They determine how applications access, transfer, and manage data
Example: Microsoft ActiveSync
Acts as a gateway between PC and mobile device
Enables synchronization with Windows-powered PCs
Transfers various types of data:
Emails (via Microsoft Outlook)
Documents
Pictures, music, videos
Applications
Integration with Microsoft Exchange Server
Supports direct wireless synchronization
Keeps data updated even when users are away from PCs
Syncs:
Emails
Calendar
Contacts
Notes
Security Concerns with Registry Settings
Free flow of data increases risk of:
Unauthorized access
Data leakage
Improper registry configurations can:
Allow malicious applications to exploit the system
Lead to security vulnerabilities
Importance of Secure Registry Management
Proper control of registry settings ensures:
Secure data synchronization
Controlled access between devices and servers
Protection of sensitive information
Authentication Service Security
• There are two components of security in mobile computing: security of
devices and security in networks.
• A secure network access involves authentication between the device and the
base stations or Web servers.
• This is to ensure that only authenticated devices can be connected to the
network for obtaining the requested services.
• No Malicious Code can impersonate the service provider to trick the device
into doing something it does not mean to. Thus, the networks also play a
crucial role in security of mobile devices.
• Some eminent kinds of attacks to which mobile devices are subjected to are:
push attacks, pull attacks and crash attacks.
• Authentication services security is important given the typical attacks on
mobile devices through wireless networks: Dos attacks, traffic analysis,
eavesdropping, man-in-the-middle attacks and session hijacking.
• Security measures in this scenario come from Wireless Application Protocols
(WAPs), use of VPNs, media access control (MAC) address filtering and
development in [Link] standards.
Authentication Service Security

• Push attacks: Attacker sends malicious data directly to the victim


device without request.
• Pull attacks: Victim unknowingly downloads malicious content while
accessing services.
• Crash attacks: Attacker sends crafted data to make the device or
application fail or crash.
Attacks on Mobile-Cell Phones
• Mobile Phone Theft:
Mobile phones have become an integral part of everbody's life and the mobile phone has
transformed from being a luxury to a bare necessity. Increase in the purchasing power and
availability of numerous low cost handsets have also lead to an increase in mobile phone
users. Theft of mobile phones has risen dramatically over the past few years. Since huge
section of working population in India use public transport, major locations where theft
occurs are bus stops, railway stations and traffic signals.
The following factors contribute for outbreaks on mobile devices:
1. Enough target terminals: The first Palm OS virus was seen after the number of Palm
OS devices reached 15 million. The first instance of a mobile virus was observed during
June 2004 when it was discovered that an organization "Ojam" had engineered an
antipiracy Trojan virus in older versions of their mobile phone game known as Mosquito.
This virus sent SMS text messages to the organization without the users' knowledge.
2. Enough functionality: Mobile devices are increasingly being equipped with office
functionality and already carry critical data and applications, which are often protected
insufficiently or not at all. The expanded functionality also increases the probability of
malware.
3. Enough connectivity: Smartphones offer multiple communication options, such as
SMS, MMS, synchronization, Bluetooth, infrared (IR) and WLAN connections. Therefore,
unfortunately, the increased amount of freedom also offers more choices for virus
writers.
•Self study- Peer review of concepts

•Mobile - Viruses

•Concept of Mishing

•Concept of Vishing

•Concept of Smishing

•Hacking - Bluetooth
Organizational security Policies and Measures in Mobile
Computing Era:
•The rapid proliferation of hand-held devices has made cybersecurity risks
more serious than often perceived.
•Users have become so dependent on their mobile devices that they treat them
like wallets, storing large amounts of confidential information such as credit
card details, bank account numbers, passwords, sensitive emails, and even
strategic organizational data.
•This widespread but careless storage of critical information increases
vulnerability, especially since many users and organizations are unaware of the
extent of data stored on these devices.
•The situation becomes more alarming in cases of device loss or theft, such as
mobile phones, USB drives, or laptops, which can expose highly sensitive
customer data including financial records, personal identification details, and
contact information.
•Such incidents can result in severe financial loss, privacy breaches, and
significant damage to an organization’s reputation.
Physical Security Countermeasures
1. Cables and hardwired locks: The most cost-efficient and ideal solution to safeguard any mobile
device is securing with cables and locks, specially designed for laptops. Kensington cables are one of
the most popular brands in laptop security cable. These cables are made of aircraft-grade steel and
Kevlar brand fiber, thus making these cables 40% stronger than any other conventional security
cables. One end of the security cable is fit into the universal security slot of the laptop and the other
end is locked around any fixed furniture or item, thus making a loop. These cables come with a
variety of options such as number locks, key locks and alarms.
2. Laptop safes: Safes made of polycarbonate - the same material that is used in bulletproof
windows, police riot shields and bank security screens-can be used to carry and safeguard the
laptops. The advantage of safes over security cables is that they protect the whole laptop and its
devices such as CD-ROM bays, PCMCIA cards and HDD bays which can be easily removed in the case
of laptops protected by security cables.
3. Motion sensors and alarms: Even though alarms and motion sensors are annoying owing to their
false alarms and loud sound level, these devices are very efficient in securing laptops. Once these
devices are activated, they can be used to track missing laptops in crowded places. Also owing to
their loud nature, they help in deterring thieves. Modern systems for laptops are designed wherein
the alarm device attached to the laptop transmits radio signals to a certain range around the laptop.
4. Warning labels and stamps: Warning labels containing tracking information and identification
details can be fixed onto the laptop to deter aspiring thieves. These labels cannot be removed easily
and are a low-cost solution to a laptop theft. These labels have an identification number that is
stored in a universal database for verification, which, in turn makes the resale of stolen laptops a
difficult process. Such labels are highly recommended forthe laptops issued to top executives and/or
key employees of the organizations
Reduce the risk that confidential information will be accessed
from lost or stolen mobile devices through the following steps:
• Assess Need for Devices
Evaluate whether employees actually require mobile devices
Consider risks, benefits, and regulatory requirements
• Implement Security Technologies
Use strong encryption
Enable device passwords and physical locks
Apply biometric authentication for better security
• Standardization
Use uniform mobile devices and security tools
Avoid diversity that weakens security controls
• Develop Security Framework
Define guidelines for:
Data synchronization
Firewall and anti-malware usage
Type of data allowed on devices
• Centralized Device Management
Maintain an inventory of devices
Track users and device usage
• Software Patching
Establish regular update and patching procedures
Integrate with centralized management or syncing systems
• User Training & Awareness
Educate employees on secure usage practices
Improve awareness of cybersecurity risks
Other measures for protecting laptops are as follows

• Engraving the laptop with personal details


• Keeping the laptop close to oneself wherever possible
• Carrying the laptop in a different and unobvious bag making it unobvious to
potential thieves
• Creating the awareness among the employees to understand the responsibility of
carrying a laptop and also about the sensitivity of the information contained in the
laptop
• Making a copy of the purchase receipt, laptop serial number and the description
of the laptop
• Installing encryption software to protect information stored on the laptop
• Using personal firewall software to block unwanted access and intrusion
• Updating the antivirus software regularly
• Tight office security using security guards and securing the laptop by locking it
down in lockers when not in use
• Never leaving the laptop unattended in public places such as the car, parking lot,
conventions, conferences and the airport until it is fitted with an anti theft device;
• Disabling IR ports and wireless cards and removing PCMCIA cards when not in
use.
Logical (access) controls in information systems security
•Authentication – Verifying the identity of a user (e.g., username and password,
biometrics, OTP).
•Authorization – Granting or restricting access rights based on user roles (e.g., admin,
user, guest).
•Multi-Factor Authentication (MFA) – Using two or more verification methods for
stronger security.
•Access Control Lists (ACLs) – Defining which users or systems can access specific
resources and what actions they can perform.
•Role-Based Access Control (RBAC) – Assigning permissions based on roles within an
organization.
•Encryption – Protecting data by converting it into unreadable form without a
decryption key.
•Firewalls – Controlling incoming and outgoing network traffic based on security rules.
•Intrusion Detection and Prevention Systems (IDPS) – Monitoring systems for
suspicious activities and taking action.
•Password Policies – Enforcing strong password creation, expiration, and reuse rules.
•Session Management – Automatically logging out inactive users to prevent
unauthorized access.
•Audit Trails and Logging – Recording user activities to track access and detect security
breaches.
•Single Sign-On (SSO) – Allowing users to access multiple systems with one set of
credentials.

You might also like