Showing posts with label mobile malware. Show all posts
Showing posts with label mobile malware. Show all posts

Tuesday, January 16, 2018

Self-protecting software, application shielding, and RASP

Many of my recent posts have provided insights regarding the Mobile Threat Defense (MTD) space; in this post I wanted to explore other mobile security segments as they relate to enterprises.

Mobile Threat Defense (MTD)
First, for background, here's how MTD is defined by Gartner:
The MTD solutions market is made up of products that protect organizations from threats on mobile platforms, including iOS, Android and Windows 10 Mobile. MTD solutions provide security at one or more of these four levels: Device behavioral anomalies, Vulnerability assessments, Network security, or App scans.
MTD solutions are designed to protect enterprises from mobile threats. The primary threat landscape that MTD addresses is mobile malware, and data leakage of enterprise data. Skycure/Symantec, Lookout, Zimperium and Appthority are vendors in this space.

Application Security Testing (AST)
As mentioned above, other mobile solutions exist besides those that fall into the MTD category. The most mature mobile security segment is part of the Application Security Testing (AST) market, which broadly applies to both web-based and mobile applications. Sometimes referred to as SAST (static application security testing) and DAST (dynamic application security testing), these solutions are applied against internally developed apps deployed for internal use for employees and contractors. There are often called private apps or custom apps. Veracode, HPE and IBM are leaders in this segment.

Application Shielding 
Another mobile security market segment, and the focus of this post, is emerging as of early 2018 and doesn't have a consensus segment name. It's referred to by participating vendors as "Protecting Apps in Untrusted Environments," "Autonomous Application Protection," and "Self Protecting Software." Gartner refers to it as Application Shielding, and names over 20 vendors with relevant solutions. The underlying technology is called Runtime Application Self-Protection (RASP). What's this all about?

Enterprises often must deploy mobile apps in support of their core business. Think of public apps from banks, retailers, gaming companies, and any app-based business. These are generally B2C apps, or consumer mobile apps, and are deployed in environments outside of the developers' control. The app could be reversed engineered for intellectual property theft or to determine and exploit whatever vulnerabilities might exist. The app could be installed on rooted or jailbroken devices, which opens it up to a wide array of attacks. The app could be re-packaged with keyloggers, spyware or other forms of malware, which could result in brand damage. Other exploits and misuse of the app are possible. How can app developers protect their app when it's in the wild?

Runtime Application Self-Protection (RASP)
Enter RASP. Gartner defines RASP as a security technology that is built or linked into an application or application runtime environment, and is capable of controlling application execution and detecting and preventing real-time attacks. Secure app development practices (often based on OWASP) and security testing remains a best practice and is not replaced by RASP. In fact, RASP solutions are applied not to the source code but to the binary (executable) app. RASP can usually be integrated into the build process but does not require SDLC changes or app developers' participation.

RASP technology is not unique to application shielding, as is it utilized by some AST vendors. But it has experienced considerable growth of late because of the application shielding requirements of mobile apps. Furthermore, RASP usage is expected to mushroom as it gets applied to IoT-based apps.

What Mobile Security Solution Should An Enterprise Adopt?
So what does all this mean to an enterprise that is developing its mobile security strategy? In short, one size does not fit all. MTD is required to protect the enterprise from attacks against its employees and its data. SAST and DAST are required to secure mobile apps developed for internal use as productivity tools. RASP is required for consumer mobile apps. The rapid adoption of mobile in the workplace and as the primary means of reaching customers requires a broad mobile security strategy with multiple components.

Enterprises seek best of breed solutions for all of their security requirements. But enterprises are not always willing to be their own system integrators, where they must glue various platforms together from a management and operations perspective. It seems likely that at the end of the day enterprises will gravitate towards single-vendor solutions, to the extent they emerge. I believe that the window of opportunity for mobile security startups is still wide open to those with innovative solutions who can execute, but history suggests the ultimate winners will be the established, mega security vendors.

Tuesday, November 21, 2017

We're All Under Attack!! Buy My Product Now!


It is generally the role of security vendors to alert potential customers as to the dangers from certain threats, namely threats that the vendors' products provide protection for. There's a fine line between education and scare tactics, and sometimes the desire to make a point can cause that line to become blurred.

Which brings us to an article published last week entitled Mobile Malware Incidents Hit 100% of Businesses. The article describes research by Check Point that may or may not confirm our worst fears: Every enterprise has experienced mobile malware attacks.

Furthermore, Check Point's research also revealed that "89% of organizations experience a least one man-in-the-middle incident stemming from users connecting to a risky WiFi network." Well, that's a relief, I was worried that the figure would be 11 percent higher.

Now, let's ask ourselves a question: Where's the enterprise breach that resulted from either mobile malware or man-in-the-middle (MiTM) attacks?

That's okay, take your time. I can wait.

Still waiting.

Maybe the answer is that mobile malware and mobile MiTM attacks represent only a negligible risk to enterprises. As we've noted previously, while there's a significant risk to enterprises from use of mobile apps that leak corporate data, mobile malware is almost exclusively a threat to consumers--not enterprises.

Yes, the term "malware" connotes real risk to enterprise desktop and infrastructure systems, and has been the cause of breaches from Target to Home Dept to Sony to Equifax. But mobile malware is different, and while trojans (otherwise called fake apps or camouflage apps) can perpetrate financial fraud against you or me, it has not yet shown itself to be a threat to enterprises. Mobile ransomware can lock up an individuals files and lead to temporary loss of functionality by a single user. However, mobile ransomware is not a threat to enterprises in the same way ransomware that locks up hospital servers is. Other mobile malware that perpetrates toll fraud and click fraud are annoying, but hardly existential threats to enterprises.

Mobile malware should be considered in two categories: broad-based attacks; and targeted attacks. The examples cited above, including trojans and ransomware, are broad-based attacks, aimed at a large population of users. An example of a targeted attack is Pegasus, which we know has occurred in the wild at least twice, both times against political dissidents in the Middle East and Mexico. So far, no mobile targeted attacks have been publicly reported against enterprise executives or key knowledge workers.

So what's an enterprise to do to ensure their use of mobile is secure? Think about how to protect data that's accessed by mobile devices, and be aware of concentrations of user data in the cloud resulting from mobile use. In general, it's apps that access and manipulate data, and an app-centric approach is likely to provide the most value from a security perspective.

Thursday, November 9, 2017

Eavesdropper: Can You Hear Me Now?


Appthority released research today on a newly discovered vulnerability dubbed Eavesdropper. This is yet another case where enterprise data is leaked from mobile devices, in this scenario by legitimate app developers failing to secure cloud storage (specifically, by including hard coded credentials in mobile applications that are using the Twilio REST API or SDK).

Quoting from Appthority's blog,
Eavesdropper does not rely on a jailbreak or root of the device, take advantage of a known OS vulnerability, or attack via malware. 
In other words, Eavesdropper does not result from malicious code on the mobile device. The vulnerability is app developer error, pure and simple, and the exposure is not on the device but in the cloud. But this error, multiplied by hundreds of apps and millions of downloads, causes text/SMS messages, call metadata, and voice recordings to be exposed to any and all comers. Once the data is exposed, malicious actors can easily find it and launch an attack based on that data. The "attack" may be cyber or it may be in the real world, based on proprietary knowledge acquired from the exposed enterprise data.

Headlines about the latest malware threat get our attention, but there are no known malware attacks that have exposed nearly the amount of data--measured in terabytes--as Eavesdropper and HospitalGown. As we've noted previously, data leakage from mobile devices is a real, demonstrable threat but enterprises often focus on malware and legacy endpoint paradigms. A broader perspective than simply a focus on the device is required to detect and remediation such threats and protect enterprise data.

Tuesday, November 7, 2017

Interpreting Mobile Malware Headlines for Enterprises

Another week, another onslaught of scary mobile malware headlines. Whether it's a fake app on an app store (WhatsApp this week), a triple whammy attack, or just a theoretical exploit that hasn't yet occurred in the wild, the headline informs us that millions if not billions of users are at risk.

But are enterprises at risk? Yes, but rarely from mobile malware.

JR Raphael posted an interesting article at CSO that suggests we may be asking the wrong question if we're asking what's the best Android security app to protect ourselves from mobile malware attacks. In suggesting why third-party security is rarely the right answer, Raphael lists several points, including this:
Even if you do happen to encounter Android malware, it's highly unlikely to compromise corporate data
Mobile malware represents a threat, but mostly to the individual user. Not to the enterprise. Why? It's mostly because the major mobile platforms, Android and iOS, are really quite secure. As a result, attackers have limited options. The major mobile attack vectors are:

  • ransomware
  • trojan or fake app
  • spyware
  • toll and ad fraud
Toll and ad fraud are mostly an annoyance, but the other attacks can result in a ransom payout (or lost data), financial fraud, or identity theft. Such attacks can cause my privacy to be violated or my bank account to be emptied, but represents no threat to my enterprise's finances or infrastructure. Unlike in the enterprise desktop environment, cross-platform attacks that jump from the compromised endpoint into the soft underbelly of the enterprise infrastructure are rare and relatively unsophisticated. Therefore, while mobile malware represents a serious threat to consumers, there are no known cases where a mobile malware has led to a major enterprise breach.

It's unfortunate that we use the same term for mobile and desktop attacks. "Malware" in the mobile context refers to attacks with a blast radius of one; "malware" in the desktop context is an existential threat, with a potential enterprise-wide blast radius. Protecting against such exploits has been and continues to be the top priority of any enterprise, and we've seen cases where a enterprises business prospects are harmed and executives' careers are damaged.

So does this mean there's no threat resulting from mobile use in the enterprise? Hardly. As noted in prior posts, employee use of mobile devices in the workplace can lead to data leakage of privacy and corporate data that could reveal confidential initiatives, plans and strategies. But malware is not the threat here, it's mostly legitimate public store apps gathering far more data than most people realize. Stay tuned as we develop those concepts in future posts.