Research Paper Computer Science
E-ISSN No : 2454-9916 | Volume : 9 | Issue : 3 | Mar 2023
SECURE ENCRYPTED MOBILE : USER REQUIREMENT AND POLICY CONSTRAINTS Ayan Dhanda Undergraduate Student, Computer Science Engineering, International Centre for Applied Sciences (ICAS), Manipal Academy of Higher Education (MAHE). ABSTRACT There is no stop to technology, every day new tools or techniques are emerging, and with the increase in technologies and use of mobile devices, digital crimes are also increasing. Companies are starting to face an enormous amount of data loss. The world is run by technology and networks and it becomes important for everyone to understand that cyber security, company assets, or the individual's data are at risk without the protection added to it. The usage of business applications on mobile devices has become common to keep the production environment active. IT companies use updated technologies to protect their data, but attackers are always enhancing new techniques to break through these technologies. Cyber Security becomes important to make sure the assets, information/data, and personal or financial details are safeguarded and not at risk. This paper aims to review the threats and crimes involving mobile devices and discuss the requirement of secure mobile phones including policy constraints of various governments owing to posing significant challenges to public safety. 1. Introduction The future of computers and communication lies with mobile devices, such as laptops, tablets and smartphones with desktop-computer capabilities. Their size, operating systems, applications and processing power make them ideal to use from any place with an internet connection. And with the expansion of ruggedized devices, the Internet of Things (IoT) and operating systems, such as Chrome OS, mac OS and Windows 10, every piece of hardware that's enhanced with this software and capabilities becomes a mobile computing device. Because mobile devices have become more affordable and portable, organizations and users have preferred to buy and use them over desktop computers. And with ubiquitous wireless internet access, all varieties of mobile devices are becoming more vulnerable to attacks and data breaches. Authentication and authorization across mobile devices offer convenience, but increase risk by removing a secured enterprise perimeter's constraints. For example, a smartphone's capabilities are enhanced by multi-touch screens, gyroscopes, accelerometers, GPS, microphones, multi-megapixel cameras and ports, allowing the attachment of more devices. These new capabilities change the way users are authenticated and how authorization is provided locally to the device and the applications and services on a network. As a result, the new capabilities are also increasing the number of endpoints that need protection from cyber security threats. Today cybercriminals can hack into cars, security cameras, baby monitors and implanted healthcare devices. And by 2025, there could be more than 75 billion “things” connected to the internet including cameras, thermostats, door locks, smart TVs, health monitors, lighting fixtures and many other devices. 2. Current And Emerging Security Threats New security threats are beginning to emerge as technology continues to develop and grow. The increased use of cloud services in the corporate world will face enormous attacks as per the Security Threat Report 2022 by Sophos. With the emergence of attacks on endpoints, mobile devices will be targeted as corporate businesses are moving to cloud services to provide better service to their customers. It is predicted that the attacking methods will be improvised and adapted to Advance Persistent Threats (APTs). It is also predicted that the attackers will make use of Artificial intelligence (AI) to target the victims with more specialized malwares [1] (Sophos, 2021). While it's certainly critical to establish and enforce an enterprise-wide security policy, a policy alone isn't sufficient to counter the volume and variety of today's mobile threats. In 2019, Verizon conducted a study, with leading mobile security companies, including IBM, Lookout and Wandera, surveying 670 security professionals. The study found that 1 out of 3 of those surveyed reported a compromise involving a mobile device. 47% say remediation was "difficult and expensive," and 64% say they suffered downtime. Companies embracing bring-your-own-device (BYOD) policies also open themselves to higher security risks. They give possibly unsecured devices access to corporate servers and sensitive databases, opening them to attack. Cybercriminals and fraudsters can exploit these vulnerabilities and cause harm or damage to the user and the organization. They seek trade secrets, insider information and unauthorized access to a secure network to find anything that could be profitable
3. Cybercrimes Cybercrime is defined by Dr. Latika Kharb as “a criminal activity committed on the internet and is a broad term that describes everything from electronic cracking to denial of service attacks that cause electronic commerce sites to lose money” (Kharb, 2017). Cybercrime can take place against persons, property, and the government. Cybercriminals or hackers commit crimes demanding money from the victims. 3.1 Types of Cyber Crimes Cybercrimes can be committed through the internet by any medium such as computers or smartphones. There are various kinds of cybercrimes, and the few top crimes include Phishing Phishing is a scamming attempt to steal users' credentials or sensitive data, such as credit card numbers. Fraudsters send users emails or short message service (SMS) messages (commonly known as text messages) designed to look as though they're coming from a legitimate source, using fake hyperlinks. [2] Malware and Ransomware Mobile malware is undetected software, such as a malicious app or spyware, created to damage, disrupt or gain illegitimate access to a client, computer, server or computer network. Ransomware, a form of malware, threatens to destroy or withhold a victim's data or files unless a ransom is paid to decrypt files and restore
Copyright© 2023, IERJ. This open-access article is published under the terms of the Creative Commons Attribution-NonCommercial 4.0 International License which permits Share (copy and redistribute the material in any medium or format) and Adapt (remix, transform, and build upon the material) under the Attribution-NonCommercial terms.
International Education & Research Journal [IERJ]
27