RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Saturday, August 1, 2026
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
Add RCR Wireless as a preferred source on Google
  • Qualcomm 6G Insights
  • Huawei Content Hub
  • Qualcomm – 6G Vision
  • OSS/BSS Channel
  • RCRTech Roundtable: AI Infrastructure
RCR Wireless
RCR Wireless
  • Advanced Mimo
  • Mobile mmWave
  • 5G Positioning
  • Green Networks
  • Metaverse
  • Automotive
  • Industrial and Wide-area IoT
Copyright 2021 - All Right Reserved
Home - Reality Check: Protecting the mobile network and devices
Network InfrastructureOpinionReality Check

Reality Check: Protecting the mobile network and devices

by Dan Meyer April 17, 2012
written by Dan Meyer April 17, 2012 Share
LinkedinEmail
Share 0LinkedinEmail
103

Editor’s Note: Welcome to our weekly Reality Check column. We’ve gathered a group of visionaries and veterans in the mobile industry to give their insights into the marketplace.

Despite the increases in today’s mobile malware, many mobile operators and subscribers continue to be virtually blind to the full extent of the problem – they simply react to incidents as they occur and have no proactive processes in place to address malware. As more and more applications come to mobile devices, this reactive approach becomes increasingly risky – and will ultimately result in service issues, outages and lost data.

The enterprise world provides a good example of the type of two-pronged strategy needed to combat malware effectively. In corporate environments, both the network and the device are protected: the network via intrusion detection/prevention appliances, firewalls and policy-based controls on the types of traffic allowed in and out; and mobile devices primarily with anti-virus applications. The two modes of protection work in concert – and a similar approach is required for mobile subscribers, where operators are in fact ideally positioned to offer both.

Network versus client-based security

Although client-based security has its strengths, there are a number of factors that can reduce the effectiveness of security apps installed on mobile devices. Infection detection technologies integrated directly into the mobile operator’s network offers a much-needed additional layer of protection.

Rather than directly scanning a user’s smartphone or tablet for malware, network-based detection systems analyze the mobile Internet traffic for specific malware communications. Such an approach is effective because malware must engage in network activity to communicate with controllers, transmit stolen information and to spread or update itself. Each of these activities is easily observed at the network level and can provide conclusive evidence of malware infection.

Network-based detection also serves to enhance the security process. In their ongoing “arms race” with security vendors, criminals are continuously updating and repackaging their malicious apps – but very rarely do they change their malware’s communication protocols. So where mobile device-based security software needs to keep track of hundreds or even thousands of signatures related to the variations of a malicious app, a network-based system needs only to monitor for the signatures of just a few distinct protocols. Network-based security techniques provide zero-day protection against the new versions of malware that use existing command and control protocols.

In general, network-based security systems offer the following advantages over client-based systems:

–Cannot be disabled: Network-based systems are not susceptible to the techniques modern malware uses to defeat and bypass client-based security measures. Because the detection system is embedded within the service provider network itself, it is practically invisible to cybercriminals.

–Always-on: Client-based anti-virus software can be deactivated by the end user. However, some users will inadvertently forget to turn it back on. Because a network-based system cannot be shut off by the user, it is always on and always doing its job.

–Always up-to-date: Because service providers maintain the equipment, it is easier to ensure the network-based security system remains up to date and aware of the latest threats.

Increasingly, mobile operators need to come to the conclusion that security is not an “either/or” proposition; both client-based and network-based solutions are important layers of an overall security strategy.

Signature-based network detection is needed

One specific technique that can be leveraged in a network-based security system is signature-based detection, which analyzes Internet traffic to look for a specific traffic pattern – the signature – known to be associated with malware C&C activity. If a computer is seen to be communicating with a traffic pattern that matches a known signature, it can be determined with great certainty that the user is infected with the specific malware that uses that C&C protocol.

Typically, a detected malware signature triggers an alert in the network when the characteristic traffic pattern is observed. But before notifying users that their devices are infected and leading them through the remediation process, mobile operators must be extremely confident the devices are actually infected – and that they know for sure which type of malware is infecting each user’s system.

To ensure accuracy and identify the malware involved, the signatures should look for C&C communications, backdoor connections, attempts to infect others (e.g. exploits), denial of service and hacking activity, and excessive e-mail activity.

By minimizing false positives, users will not be asked to perform remediation on non-existent threats or receive too many alerts where they become immune to the entire process and refuse to act should their systems actually become infected.

Do you still need an app?

While network-based security is a key component, mobile device-based anti-virus software is still an important element of any approach to online security. It can scan the device for malicious apps even if the subscriber is roaming or connected via Wi-Fi and not on the network where the sensor is analyzing traffic. The app can also help in the remediation of known threats.

However, a mobile security app needs to be designed differently than its PC-based counterparts. It needs to minimize data and battery usage and be as inconspicuous as possible so that the user does not turn it off to increase the performance of the device.

Ideally, mobile device-based and network-based solutions should work together. For example, if the network component detects an infection, it means that some malware – probably a new version of the malware that has been repackaged to avoid detection – must have slipped past the device-based security app. At the same time, if the network component sends a security alert, the device-based app should combine that information with what processes were running at the time of the alert to pinpoint the infected app and help the user remove it from their mobile device. Used this way, both components strengthen each other to provide a much higher level of protection.

Kevin McNamee is security architect and director of Kindsight Security Labs. With over 30 years of security and networking experience, Kevin was director of security research at Bell Labs and also held security development and design roles at TimeStep, Milkyway Networks, Newbridge Networks and Alcatel-Lucent.

You Might Also Like
  • Building the AI backbone, waiting on the AI billions
  • Ensuring colocation success by eliminating network observability blind spots (Reader Forum)
  • Thursday (telco diary) | Vodafone resets, AT&T reloads
  • Japan’s private 5G market is finally moving beyond demo experiments (Analyst Angle)
  • Wednesday (telco diary) | Orange leads Euro telco revival
  • The rise of agentic infra – why NetOps must outpace AI ambitions (Reader Forum)
Share 0 LinkedinEmail
Dan Meyer

Contributor

previous post
Venezuela’s Movilmax to migrate from WiMAX to LTE
next post
Report: Smartphones could replace credit cards by 2020

White Papers

  • Norton eBook: The 2026 Telco Playbook

  • Enea White Paper: Why Intelligent AAA is the Swiss Army Knife of Telecom

  • CSG White Paper: Telco AI Enabler: Mediation’s Defining Role

  • Enea White Paper: Scalable Database Design for 5G and Beyond

  • Supermicro and NVIDIA Whitepaper: Powering sovereign AI at scale

Editorial Reports

  • Market Pulse Report: Telco AI in 2026 – Trends, Challenges and Opportunities

  • Nvidia Report: The State of AI in Telecommunications: 2026 Trends

  • Report: Scaling Optical Networks For The Hyperscale And AI Era

Webinars

  • Webinar: Building 6G — aligning technology, policy and purpose

  • SIMCom Webinar: Scaling your next deployment – from plastic to provisioning

  • Webinar: Rethinking the RAN as AI, cloud and openness converge

  • Webinar: Scale-Up, Scale-Out, Scale-Across – Building AI-Era Network Fabrics

  • Webinar: NTN in motion – evolving standards, expanding services

Since 1982, RCR Wireless News has been providing wireless and mobile industry news, insights, and analysis to mobile and wireless industry professionals, decision makers, policy makers, analysts and investors.

Facebook Twitter Youtube Linkedin Envelope Rss

Useful Links

  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive
  • Subscribe
  • About RCR Wireless News
  • Contact Us
  • Advertise
  • Editorial Calendar
  • Archive
  • RSS
  • Wireless News Archive

Edtior's Picks

Building the AI backbone, waiting on the AI billions
Ensuring colocation success by eliminating network observability blind spots (Reader Forum)
Thursday (telco diary) | Vodafone resets, AT&T reloads

Latest Articles

Building the AI backbone, waiting on the AI billions
Ensuring colocation success by eliminating network observability blind spots (Reader Forum)
Thursday (telco diary) | Vodafone resets, AT&T reloads
SK Telecom’s A.X K2 is South Korea’s biggest bet yet on sovereign AI

© 2026 RCR Wireless News All Right Reserved. Developed by Eight Hats.

Cookie Policy | Privacy Policy

RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
RCR Wireless
  • News
  • Channels
    • 5G
    • 6G
    • BSS OSS
    • Carriers
    • IoT
    • Network Infrastructure
    • Open RAN
    • Private 5G
    • Telco AI
    • Telco Cloud
    • Test & Measurement
  • Resources
    • Reports
    • Webinars
    • White papers
    • AI Fundamentals
    • Analyst Angle
    • Editorial Calendar
    • Fundamentals
      • 5G NR Release 17
      • AI
        • Telco AI in 2025
    • Podcasts
      • Let’s Get Digital with Carrie Charles
      • Wireless Connectivity to Enable Industry 4.0 for the Middleprise
      • Well Technically…
      • Will 5G Change the World
      • Accelerating Industry 4.0 Digitalization
  • AI Infrastructure
  • Programs
  • Events
  • RCRtv
  • Advertise
  • Subscribe
@2020 - All Right Reserved. Designed and Developed by PenciDesign