Symantec details Android malware threats

Opinion
Oct 14, 20116 mins

And what businesses can do to protect themselves

Google Android is one of the top operating systems for smartphones with a 43% market share. No wonder cybercriminals are starting to pay attention. A new Symantec report outlines the potential threats and the various monetization techniques employed in Android-focused malware.

For many people around the world, a smartphone is their primary — and sometimes only — means of accessing the Web. More than 85% of new handsets sold today are able to access the mobile Web. According to Gartner, Google Android is one of the top operating systems for smartphones with a 43% market share. As of May 2011, more than 100 million Android-based devices had been sold worldwide, and they are selling at a rate of 350,000 units per day.

With growth statistics like that, it’s no wonder cybercriminals are starting to pay attention to Android-based devices. As Android grows in both scope and popularity, so does the market for Android-focused malware. Unfortunately this isn’t just a consumer issue. As companies allow their employees to access corporate resources with their personally owned devices, the concern about malware becomes a corporate security issue as well.

HISTORY: Smartphone security follies

Symantec has been doing research on the global Android malware market and has just released its Motivations of Recent Android Malware report to help us understand the potential threats and the various monetization techniques employed today in the growing instances of Android-focused malware.

According to Symantec, there are three ingredients that make criminals flock to a digital market. The first is an open platform where practically anyone can develop and disseminate applications. Next, the platform must be ubiquitous so thieves can reach a sufficient number of people. And third, there must be a reliable way to make money off the exploits the criminals develop. With the notable rise of the Android platform, it appears that the first two conditions are by and large fulfilled, and Symantec believes we are now seeing the beginning of the third.

(In a report issued in May, Symantec compared the security attributes of Google Android to Apple iOS. Apple scored high marks for vetting developers and applications for the iPhone ecosystem, whereas Google takes a laissez-faire approach. Relative to Apple’s requirements, there’s a low bar to entry for cybercriminals to create and distribute miscreant Android applications. This could be why malware instances are rising.)

The Symantec report cites several Android malware monetization schemes, but notes that we are still in the early stages so it’s hard to know if they will have staying power. The key is whether criminals can garner a sufficient ROI for their efforts. Not all of the schemes impact business users, but some could have devastating effects if applied to corporate data or information.

The following categories of attack are highlighted in the study:

• Premium Rate Number billing (calls or text messaging)

• Spyware

• Search engine poisoning

• Pay-per-click fraud

• Pay-per-install of apps fraud

• Adware abuse

• Mobile Transaction Authorization Number (MTAN) theft

Symantec says these schemes have already been used by recent Android malware, but aren’t yet pervasive and that it’s not clear if they ever will be. Until attackers find a way to carry out these attacks on a massive scale, the threat of mobile malware and other attack techniques will remain relatively low. But the research suggests attackers will continue to invest in the creation of mobile malware as monetization schemes evolve.

The research also points out that the present low monetization rate per infection is poised to improve. The trigger will likely be advances in mobile payments and the increased adoption of mobile devices for payment processing. The key is that these applications will rely on core functionality within these devices to transmit financial information. Today, mobile payments utilize a number of different technologies to perform transactions, including SMS text messaging, a mobile browser or a purpose-built app.

With the increased power and prolific adoption of mobile devices, merchants and small businesses can run their businesses from a smartphone. Consumers are also using their smartphones for a variety of financial-related activities including checking their account balances, conducting bank transactions and making payments. According to the Smart Card Alliance, the numbers of mobile commerce applications and app types have grown at rates matching the rate at which websites were launched during the early days of the Internet commerce boom.

The convenience of mobile applications of all types comes with a level of risk. And just like with PC-based malware, consumers do not really understanding the issues behind the growing threats to these open-platform smart devices. Enterprises may also find themselves at risk due to mobile malware; this threat is compounded by the growing consumerization of IT trend and its accompanying management challenges.

What businesses can do to protect themselves

As long as companies allow their employees to connect to the corporate network via a personally owned smartphone, the organization must take steps to protect its computing environment. Best practices include:

• Use a mobile device management (MDM) application to set policies and determine how mobile devices can gain access to the network. If a device fails to meet the predetermined policies, it should be denied access.

• Set and communicate a policy about when the company has the right to wipe a mobile device clean to protect corporate assets. This includes personal data and contact information that may be on the employee-owned device.

• Educate employees not only from the network standpoint but also the consumer standpoint about the risks associated with these devices. For example, consumers should not download public applications that are new and have no reviews. And, device owners need to understand the permissions that the applications are asking for before accepting the terms of use.

• Install anti-malware and other protective software on smartphones. These devices are really small form-factor computers and should be treated as you would a laptop computer.

For both consumers and businesses, smartphones are a boon to convenience and productivity, but they come with risk and responsibility, too. The sooner we all realize this, the sooner we can stem the tide of malware and other problems.

Linda Musthaler and Brian Musthaler are co-founders and the principal analysts of Essential Solutions Corp. You can write to Linda at LMusthaler@essential-iws.com and to Brian at bmusthaler@essential-iws.com. ______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.