[MDM] Research - Security Discussion

Hello everyone,
currently I am finishing up my Computer Science Security masters. I am writing my thesis on Mobile Device Management solutions on Android and I can use your help! My idea was to create a framework to structurally test the quality of the controls, but there has been some research on this subject (Rhee - A study on the security evaluation of a MDM system). My current idea is to create malware that destroys one (or more) control, implied by the MDM solution. What is your view on this subject and is anyone deep into MDMs?
Kind regards!

Related

OMA Mobile Device Management

I work in IT at an educational institution and I've recently been placed in charge of a new 'mobile' initiative with the goal of making our campus mobile device friendly for students and staff. At this point I'm investigating Device Management software and would like to hear from anyone who has experience in this area.
Google lead me to some promising looking open source software by Funambol. Can anyone provide some feedback about this or any similar solution?
Requirements:
1) Must be hosted in house. We cannot store any data on third party servers.
2) Must support multiple platforms (Android, iOS and BB are a must... windows not so much).
3) Must adhere to industry standards, such as the Open Mobile Alliance.
I would love to hear about your experience with implementing Device Management solutions. If you have information that you cannot share on a public forum, please PM me so I can send you my email address.
just wondering if you got any of your questions answered? I am in similar situation as you are for my company...
Have not heard anything yet, but I did spend a bit of time playing with Funambol before getting sidetracked with another project. Looks like it might do the trick, but it seems to lack the 'polish' that is expected of enterprise solutions. Being a proponent of open source I really want to give Funambol a serious run, but since my company is in bed with Dell I suspect we'll end up using their MDM solutions.
It'll be a few months before I have the cycles to get back on this project, but I'll try to keep this thread updated.
Device Management (DM) is one way to provision a device. Provisioning is updating the device after manufacture. This may or may not include bootstrapping a device. When an OEM or Operator bootstraps a device after manufacture, or makes any other update (except a firmware update) it is provisioning the device. When an OEM bootstraps a device during manufacture it is not provisioning.
Funambol DM not ready for Enterprise
I've had a bit more time to look into Funambol as a Device Management (DM) solution and determined that it is not going to work. They have a Device Sync (DS) solution that works well for backing up contacts/files/etc., but their DM system is incomplete. You have to compile the client software yourself and even then many of the key features are not yet implemented, such as remote lock and wipe. Funambol is something I plan to try at home, but cannot recommend it for business.
Take a look at this MDM report from Gartner. It is a very thorough examination of several of the top MDM solutions available today and might help you make a choice based on your requirements.
I'm in a similar situation and just evaluated Sybase Afaria.
http://www.sybase.com/products/mobileenterprise/afaria
It has a lot of features and as I've tested it, everything worked as it should - but the management website is just horrible. Afaik Sybase is aware of this issue and is working on a new management site.
Best Features: Working with Samsung and Motorola - means deep integration into its Systems, Touchdown integration.
MDM Solution
DeviceMax MDM can be a on-site solution where the hardware can be installed at the client’s server or a cloud based solution where the hardware is on the Kochar cloud and minimal integration with the client's network is required. It is a customized solution that can be either used as a licensed software or a managed service by the Enterprise. For managed service configurations, we can remotely support device diagnostics and even provide the end user service desk support for Enterprise.
MDM Solutions
We started using the Meraki MDM for our enterprise wide solution, but I highly recommend checking out Prey Project for personal or small scale use.
Question about Prey project
In reference to your recommendation of prey project, I see how they help with security of devices but how does it install the image of the tablet after a user uses it? I am looking for an MDM solution for an academic setting. Thanks.
Re: Question about Prey project
snpohrte said:
In reference to your recommendation of prey project, I see how they help with security of devices but how does it install the image of the tablet after a user uses it? I am looking for an MDM solution for an academic setting. Thanks.
Click to expand...
Click to collapse
I'm not sure if I understand what you mean by "install the image of the tablet"... do you mean install the PreyProject client application on a user's device after they have taken it outside of your physical control? As far as I know, all MDM solutions require the client to be installed before any remote administration can be done on the device. You could email your users a link to the app with instructions on how to install/configure it?
I'm not sure if PreyProject is the best solution for deployments of more than a few devices. It might work if each user wants to administer their own devices, but if you are in a scenario where a few IT people need to manage/maintain a fleet of mobile devices then something like the Meraki MDM solution is more suitable.
Hope this answers your question... if not then please clarify your query.
Regards,
Mobile Device Management
With increasing number of Smartphone’s and smart devices used within the organizations, Mobile device management (MDM) has become a vital discipline for IT departments. IT people are putting their focus towards mobile device management support where they will manage the mobile devices. Mobile device management solutions offer the security to the enterprises with full control on them. With mobile device management solutions you can configure your devices over the air, implement the corporate policies, wipe or lock the whole device etc. Nowadays organizations need MDM solutions that fully manage and organize all the devices and applications. It helps to give the whole picture of the mobile environment. It also analyzes the whole report and find out the gaps to resolve it. It also helps to get the critical device information.

[Q] Technical details for online mobile app stores

Hello everyone ,
First off, I apologize if this is the wrong type of question, but you are the only community I know that has the knowledge of the technical details am I looking for. I have asked this in several communities but failed to deliver a proper question and get a proper response.
Here is my train of thought, I hope you can follow:
So I have the presentation about mechanisms of online mobile app stores. I have to describe security and financial mechanisms (background asspects), protocols that are used when app is downloading from market. Also, I have to describe the architecture of that stores, although they don't have some unique architecture, but it describes their work as the principle. So, the main purpose of this presentation is to see how to implement online mobile app store and which technologies and protocols to use.
Thanks in advance

[Q] Writing my dissertation, need help with the data collection and organization.

Hi to everyone. I'm new to this forum. I'm currently due to finish my dissertation, however I'm only on the half way where I supposed to submit it in one week. The problem I have is the secondary data collection and its organisation for literature review chapter. The topic is about the applications that have malicious code on Android mobile platform and key threats to the data in this mobile platform from malware authors. I have already written about the android in general, its architecture, security measures and some of the threats that are in place. But the problem is that there is a lot of data out there and I don't know how to link them, organize them, what exactly more important than another. If anyone can help me with some tips on topics here and how to better outline (for example. Background, Architecture, security measures, and what is afterwards?). Any advice is appreciated, please post on here whatever information could be useful, even if I have already covered, such as background about android and its architecture with security measures. Thanks

[MDM] Malware approach

Hi guys.
Currently I am writing my Masters thesis for a Computer Science Security master in the Netherlands. The goal of my research is to circumvent the controls implemented by a mobile device management system (any) on Android. My current idea is to do this with malware. My question to you is: is it feasable that I can circumvent the controls? And: what kind of approach can I look in to when writing malware (i.e. intent forging, setting altering etc)
Any scientific sources you may have are welcome as wel!
In this topic I will keep you guys posted on my progress!
Kind regards.

Research Help on Communication Protocols

Greetings Everyone,
I'm am a mobile app noob. I'm currently doing some research on data/communication protocols between a mobile app and software. Could someone please point me in the right direction on finding out what current data protocols are currently available that let a mobile application 'talk' with a piece of software through an internet server?
Thank you
Replication of research findings across independent longitudinal studies is essential for a cumulative and innovative developmental science. Meta-analysis of longitudinal studies is often limited by the amount of published information on particular research questions, the complexity of longitudinal designs and sophistication of analyses, and practical limits on full reporting of results. In many cases, cross-study differences in sample composition and measurements impede or lessen the utility of pooled data analysis. A collaborative, coordinated analysis approach can provide a broad foundation for cumulating scientific knowledge by facilitating efficient analysis of multiple studies in ways that maximize comparability of results and permit evaluation of study differences. The goal of such an approach is to maximize opportunities for replication and extension of findings across longitudinal studies through open access to analysis scripts and output for published results, permitting modification, evaluation, and extension of alternative statistical models, and application to additional data sets.

Categories

Resources