Java 2 ME - a playground for malicious code?

Markus Schmall T-Mobile

Java itself has been known for several years. Within the last years this programming language gained enormous importance and, as a logical consequence, the first pure Java 2 ME (mobile edition) enabled mobile phones were introduced in 2001. Is security an issue for mobile phones?

Obviously, yes ...

In 2001 we heard of problems related to i-mode phones (NTT Docomo) and malicious emails. The presentation takes as first step a brief look at the overall architecture of Java 2 ME, the limitation in comparison to the Java 2 Standard Edition and the built-in security features.

In the following possible attack scenarios, possibilities for malicious code and possibilities how to test for common attacks will be discussed.

As a practical example, the presentation shows the propriatary Java packages shipped with Siemens SL42i/45i mobile phones and discusses security related features and dedicated attack scenarios.

Additionally, the presentation shows results of a security orientated check of Java 2 ME API calls from the Siemens Java package. Furthermore, the presentation discusses the need for digital rights management within Java 2 ME applications, which e.g. can be used to sign applications as trusted.


Poll

Who in your company is responsible for installing software patches?
System administrators
End users
I don't know

Leave a comment

Jobs Career Sidebar

VB2009

VB2009 VB2009 will take place 23-25 September 2009 at the Crowne Plaza Geneva, Switzerland. VB is currently seeking submissions from those wishing to present papers at VB2009. Full details are in the call for papers.
Virus Bulletin currently has 148,287 registered users.