Abro
70
3.3 Mobile Security Lifecycle Functions
Security lifecycle functions for mobile device and networks are developed to protect
the end‐to‐end security posture of mobile systems and networks. It addresses the security at individual stages of mobile provisioning, configuration, assessment and security
monitoring. Lifecycle functions leverage security systems, tools and processes are
required to protect the confidentiality, integrity and availability of mobile devices and
networks.
As 5G networks are going to introduce new tools to carry out mobile‐ecommerce and
new business use cases for mobiles, such as IoT and ultra‐broadband. Such enterprises
will especially look towards a well‐defined security management and governance system
for their mobile end users to further protect their critical data and applications residing
on end‐user personal mobile device uses as an extension of a corporate network, as in
the case of BYOD (Bring Your on Device).
Key security failures in such cases are [9]:
1) inconsistent security policies;
2) leakage in shared media;
3) minimal device management;
4) readable data stays in disposed devices; and
5) inter‐application data leakage.
A security lifecycle, as show in Figure 3.7, can help address the above and other common security challenges and reduce risks at various stages of the mobile device during
its participation in the network. Key stages of a mobile addressed by the security
Threat
Threat description
Impact Severity
(Minor, Moderate,
Severe, Extreme)
Threat Occurrence
Probability
(1‐5, Low‐High)
IoT Botnets
IoT and mobile devices hosting a
control agent/bot receiving remote
commands and continuously
leaking telemetry information to a
remote bot‐master running a
central command and control
(C&C) system. Used for both
passive and active attacks
Severe
2
Critical
Infrastructure
Threats
Threats that are focused, damaging
critical infrastructure services
such as SCADA, i.e. Stuxnet,
Shamoon attacks
Extreme
3
Zero‐day Attacks
An advance attack exploiting the
undiscovered vulnerabilities of a
system. Can be a combination or
package of multiple attack types,
malware, rootkits and botnets
Extreme
1
Table 3.2 (Continued)
Précédent

- 112/483

Suivant