THE STATE OF SECURITY IN THE MOBILE ENTERPRISE (Presented By The Cloud Security Alliance)Join APPNATION and The Cloud Security Alliance for a two-part session on the state of security in the mobile enterprise. To kick things off, Cesare Garlati, VP, Mobile Security at Trend Micro, will present an unfiltered look at the state of security as the enterprise mobility revolution pushes forward at a blistering pace. Cesare will showcase, in real-time, security flaws that all business-line and I.T. managers should know about and discuss other emerging issues that are coming to the fore as the pace of mobile innovation and connectivity in a BYOD world. Cesare’s presentation will be followed by an executive-level roundtable led by Cloud Security Alliance Executive Director, Jim Reavis, and comprised of leading enterprise security experts to discuss the remedies for short-term security gaps and flaws and explore what longer-term security issues remain on the horizon as the Consumerization and BYOD uber-trends continue to accelerate across the enterprise.PART I: YOU ARE NOT READY FOR THIS!CESARE GARLATI, VP, MOBILE SECURITY, TREND MICROPART II: LEADING MOBILE SECURTY EXECUTIVES WEIGH INSESSION LEADER: JIM REAVIS, EXECUTIVE DIRECTOR, CLOUD SECURITY ALLIANCECESARE GARLATI, VP, MOBILE SECURITY, TREND MICRODORON ROTMAN, MANAGING DIRECTOR & NATIONAL PRIVACY SECURITY LEADER, KPMGBRIAN REED, CHIEF MARKETING AND PRODUCT OFFICER, BOXTONEDENNIS DEVLIN, ASSISTANT VICE PRESIDENT, INFORMATION SECURITY & COMPLIANCE SERVICES, GEORGE WASHINGTON UNIVERSITY
High level overview of the top mobile threats findings – basic discussions around these…not spending too much time.
As Vice President of Mobile Security at Trend Micro, Cesare Garlati serves as the evangelist for the enterprise mobility product line. Cesare is responsible for raising awareness of Trend Micro’s vision for security solutions in an increasingly consumerized IT world, as well as ensuring that customer insights are incorporated into Trend solutions. Prior to Trend Micro, Mr. Garlati held director positions within leading mobility companies such as iPass, Smith Micro and WaveMarket. Prior to this, he was senior manager of product development at Oracle, where he led the development of Oracle’s first cloud application and many other modules of the Oracle E-Business Suite. Cesare has been frequently quoted in the press, including such media outlets as The Economist, Financial Times, The Register, The Guardian, Le Figaro, El Pais, Il Sole 24 Ore, ZD Net, SC Magazine, Computing and CBS News. An accomplished public speaker, Cesare also has delivered presentations and highlighted speeches at many events, including the Mobile World Congress, Gartner Security Summits, IDC CIO Forums, CTIA Applications and the RSA Conference. Cesare holds a Berkeley MBA, a BS in Computer Science and numerous professional certifications from Microsoft, Cisco and Sun. Cesare is the chair of the Consumerization Advisory Board at Trend Micro and co-chair of the CSA Mobile Working Group - Cloud Security Alliance.
Transcript of "APPNATION IV - The State of Security in the Mobile Enterprise - Cesare Garlati"
The State of Security in The Mobile EnterpriseCesare GarlatiVP Consumerization & Mobile Security – Trend MicroCo-Chair Mobile Group – Cloud Security AllianceAPPNATION – December, 2012
Cloud Security Alliance: Mobile Guidance V1 Security Guidance for Critical Areas of Mobile Computing Mobile Computing Definition Threats to Mobile Computing Maturity of the Mobile Landscape BYOD Policies Mobile Authentication App Stores Mobile Device Managementhttps://cloudsecurityalliance.org/research/mobile/
CSA Top Mobile Threats – Evil 81. Data loss from lost, stolen or decommissioned devices.2. Information-stealing mobile malware.3. Data loss and data leakage through poorly written third-party apps.4. Vulnerabilities within devices, OS, design and third-party applications.5. Unsecured Wi-Fi, network access and rogue access points.6. Unsecured or rogue marketplaces.7. Insufficient management tools, capabilities and access to APIs.8. NFC and proximity-based hacking.
How Secure and Manageable? Raimund Genes Chief Technology Officer, Trend Micro http://trendmicro.com/our-contributors/raimund-genes Chris Silva Industry Analyst, Altimeter Group http://www.altimetergroup.com/about/team/chris-silva Nigel Stanley Practice Leader, Bloor Research http://www.bloorresearch.com/about/people/nigel-stanley.html Philippe Winthrop Managing Director, Enterprise Mobility Foundation http://www.enterprisemobilitymatters.com/about.htmlhttp://trendmicro.com/cloud-content/us/pdfs/business/reports/rpt_enterprise_readiness_consumerization_mobile_platforms.pdf
Ratings By Mobile Platform Consumer Technology Gap
No Platform is immune: Apple iOS DetailSource: National Vulnerability Database via CVEDetails.com – as of October 4, 2012
Apple iOS Jailbreaking Trends June 2007 July 2008 July 2009 June 2010 Oct 2011 Sept 2012 iPhone iPhone 3G iPhone 3GS iPhone 4 iPhone 4S iPhone 5Source: Google Trends – as of October 4, 2012
Android is the most exploitedSource: Trend Labs, Trend Micro Inc. – as of Q2 2012
Malicious Apps on Legit Marketplace March 2011 – 58 malicious apps (approx 250,000 victims) May 2011 – 24 malicious apps (up to 120,000 victims) December 2011 – 27 malicious apps (approx 14,000 victims). February 2012 – 37 “Fan Apps” stealing handset information and aggressive advertising August 2012 – many, many more …
Android Versions Distribution 73% Fragmentation Vulnerable DevicesSource: Google http://developer.android.com/resources/dashboard/platform-versions – as of August1, 2012
Mobility is not the problem“Consumerization will bethe most significant trendaffecting IT duringthe next 10 years”GartnerNew technology emerges first in the consumer market and thenspreads into business organizations brought in by the employeesIT and consumer electronics converge as individuals rely on the samedevices and applications for personal use and work-related activitiesOverwhelmed by the wave of consumer technology flooding theenterprise, IT managers lose control and struggle to enforce policies
You are not ready for this • Consumer mobile technology is invading the enterprise and you won‟t be able to resist it 1 Embrace Consumerization • Consumer technology is not as secure as Understand the risk profile manageable as required by 2 of the various platforms the enterprise Deploy new security and • No platform is immune 3 management tools from attack, although some are safer than others
As VP of Mobile Security at Trend Micro, Cesare Garlati serves as the evangelist for the enterprise mobility product line. Cesare is responsible for raising awareness of Trend Micro‟s vision for security solutions in an increasingly consumerized IT world. Prior to Trend Micro, Mr. Garlati held director positions within leading mobility companies such as iPass, Smith Micro Software and WaveMarket – now LocationLabs. Prior to this, he was senior manager of product development at Oracle, where he led the development ofCesare Garlati Oracle‟s first cloud application and many other modules of the Oracle E-Business Suite.Cesare Garlati | Vice PresidentConsumerization & Mobile Security Cesare holds an MBA from U.C. Berkeley, a BS inBlog: BringYourOwnIT.com Computer Science and professional certifications fromlinkedin/in/CesareGarlati Microsoft, Cisco and Sun. Cesare is Chair of Trend Microtwitter/CesareGarlatiCesare_Garlati@trendmicro.com Advisory Board for Consumerization and Mobile and Co- Chair of the CSA Mobile Working Group.Skype: Cesare.GarlatiMobile: +1 408.667.3320 Blog: http://BringYourOwnIT.com
How To: Jailbreak iOS (5.1.1)Download LinksXxxx v2.0.4 MacOSX (10.5, 10.6, 10.7)Xxxx v2.0.4 Windows (XP/Vista/Win7)Xxxx v2.0.4 Linux (x86/x86_64)How To Use Xxxxx 2.0:1. Make a backup of your device in iTunes by right clicking on your device name under the „Devices‟ menu and click „Back Up‟.2. Open Xxxxx and be sure you are still connected via USB cable to your computer.3. Click „Jailbreak‟ and wait…. just be patient and do not disconnect your device.4. Once jailbroken return to iTunes and restore your backup from earlier.Xxxxx 2.0 supports the following devices on 5.1.1:iPad 1, iPad 2, iPad 3 (iPad2,4 is now supported as of Xxxxx 2.0.4)iPhone 3GS, iPhone 4, iPhone 4SiPod touch 3rd generation, iPod touch 4th generation
Taller screens like Cydia too. :) @saurik – Jay Freeman Cydia: 1.5M Apps per day 5% to 10% of Apple iOS devices $8M rev 2011 (to developers)
Apple iOS Jailbreaking Trends – U.S. June 2007 July 2008 July 2009 June 2010 Oct 2011 Sept 2012 iPhone iPhone 3G iPhone 3GS iPhone 4 iPhone 4S iPhone 5Source: Google Trends – as of October 4, 2012