Presentazione Vodafone

Mobile network
Risks and
opportunities
Presented to IASD – Cyber Session
Fabio Ortolani
Head of Security Operations & Privacy
Vodafone Italia
Security Operations & Privacy – C2 Vodafone Restricted
Private Operator and CERT – Computer Emergency
Private Operators
have a central role in managing National and European critical
Response
Team
Prevent Security issues infrastructures in terms of security.
Detect Security Alerts
Threat Modelling
Intelligence Gathering
• Sed.
React to security threats
Security monitoring
Threat analysis
Compliance monitoring
Reporting
Intelligence exchange
Identification
Vulnerability detection
Event triage
Prioritization and
reporting
Response
Forensic
Log management
Incident triage
Statistical data analysis
communication
Statistical data analysis
Big Data analysis
Data quality management
Big Data analysis
National
CERT
2
C1 | 03 March 2014
Other
One billion smartphones over the
world
Security Operations & Privacy – C2 Vodafone Restricted
3
Mobile devices and wireless networks continue to grow strongly
Mobile Devices
• Over 7Bn within the year
Mobile Web Traffic
• 119% web traffic growth
Mobile App Projects
• 4:1 proportion App Mobile to PC
Security Operations & Privacy – C2 Vodafone
Restricted
4
5
Security Awareness Strategy
GCS
C2 – VODAFONE RESTRICTED
Version 1.0
03 March 2014
Some figures..
Dati relativi alla popolazione italiana, 2012
40 utenti internet su 100 vittima di crimini informatici (Symantec Norton Cybercrime Report
2012)
Dati relativi agli utenti internet (28,5 mln 2 su 3
Gen13):
75% delle password non rispettano i
fanno acquisti online
con carta di credito
&
(Rapporto CPP Italia sulla sicurezza nel web 2011)
&
97% dei malware su internet sono
ospitate dai social network
(Symantec Norton Cybercrime Report 2012)
2 su3 visitano i social network
da smartphone
(Symantec Norton Cybercrime Report 2012)
requisiti minimi di sicurezza
(SYM Internet Security Threath Report 2011)
E il trend e in forte crescita, soprattutto su mobile
“Il numero di utenti colpiti su mobile raddoppia
in un anno” (Norton Cybercrime Report 2012)
“Il numero di nuovi malware Android aumenta
di 10 volte” (Q3 vs Q2, F-Secure)
Security Operations & Privacy – C2 Vodafone Restricted
6
A right protection from malware on mobile devices
• Smartphones and tablets are similar to PCs
same security issues
• Connectivity to Internet (for browsing, e-mail, etc) first attack method to
smartphones and tablets
• Many malware require active user intervention (eg. clicking on a link, accept
app installation, accept a configuration sms, etc.)
Need of a client support that aim to customer service to get more information on
cyber threats and countermeasures
Security Operations & Privacy – C2 Vodafone Restricted
What users can do to defend from logical attacks?
Minimum checks to be set on your smartphone
Advise customer to:
Install a software for mobile device management, allowing location or device remote wipe in case of
theft or loss
Setting a password for phone access
Setting a Lockout time
Setting a Timeout
IMEI storage. Needed to lock your phone preventing usage by others
Contacts and messages storage on the SIM card and not on the phone
Regular phone data backup (contacts, messages, files, photos, etc)
In case of phone dismissal (sale, gift or simple dismission) delete all data contained on the
smartphone (contacts, messages, files, photos, etc)
Smartphone antivirus installation
Security Operations & Privacy – C2 Vodafone Restricted