Ensuring that mobile applications are truly secure

Opinion
May 25, 20126 mins

Mobile devices are the next big platform for serious business and consumer applications. Smartphones and tablets are now home to apps for mobile payments, banking, healthcare, customer service, product inventory, law enforcement and so much more. But they may be putting sensitive data at risk. viaForensics offers a unique service to uncover vulnerabilities.

The phenomenal worldwide growth of smartphone sales is not attributed to the ability to make flawless phone calls. No, most people buy a smartphone because they want to access the Internet and use applications on the go. Application developers have taken note: Mobile devices are the next big platform for serious business and consumer apps. Smartphones and tablets are now home to apps for mobile payments, banking, healthcare, customer service, product inventory, law enforcement and much more.

The growth trajectory for mobile applications is steep. According to the mobile marketing firm MobiThinking, as many as a billion people worldwide will access mobile financial services by 2015. PayPal alone expects to see $7 billion in mobile payment volume in 2012.

ANALYSIS: What enterprise mobile apps can learn from mobile games

But have you ever stopped to think about how secure these mobile apps are? When you use your mobile wallet, is it possible that your credit card information could be exposed to cyberthieves? When you visit your doctor and he pulls up your medical records on a tablet, are you confident your private information is destined to remain private? People assume the applications and the sensitive data they use are secure, but often that assumption is wrong.

“It’s challenging to write secure mobile applications,” according to Andrew Hoog, chief investigative officer and co-founder of security consulting firm viaForensics. “It takes a focus on the security aspects of the application, plus time, money and effort to make sure that what’s put out there is as secure as possible.”

Hoog says people are already skeptical about the security of mobile applications. “The industry has a responsibility to put the emphasis on security so we can move things forward to allow people to do what they want to do — whether it’s banking or shopping or healthcare — and let them feel secure about it.”

Hoog points to Google Wallet as an example of a popular mobile app that has security shortcomings. According to Hoog, “Google controls the Android operating system and even some of the hardware platforms. Google has very smart developers who wrote the wallet application. Despite this high level of control over the mobile environment and application, we still found significant issues in Google Wallet that could be exploited.” (To see what those issues are, read the blog post Forensic security analysis of Google Wallet.) 

viaForensics offers a service called appSecure that involves conducting extensive tests on a mobile app to determine if it has vulnerabilities. The unique aspect of what viaForensics does involves applying forensics to proactively detect security problems instead of after the fact. Hoog says that when you apply the science of forensics to security problems, you come up with interesting new solutions.

In an appSecure engagement, viaForensics researchers come at the application like an attacker would to find vulnerabilities. The process leverages viaForensics’ expertise as well as takes an overarching holistic approach to mobile security which includes the device, the network and the back-end data center. The chart below illustrates all of the areas of a mobile application that can become a vector in a mobile attack. (See Anatomy of a Mobile Attack.)

An appSecure engagement typically lasts between two and four weeks. Half of that time is spent testing and the other half is for writing the results of the tests and recommendations for remediation of any problems discovered. “We come at the application from every angle,” says Hoog. “Anything we can do, motivated criminals can do. They stand to make a lot of money if they can find and exploit security issues.”

Mobile platforms have special security issues that aren’t found on other platforms. If a developer tries to treat a smartphone like, say, a PC platform or a Web browser, he’ll overlook important things. For example, mobile devices have a special kind of memory to preserve the life of the device. As a result, smartphones hold on to information as long as they possibly can because the memory has a limited read/write capability. If a developer designs an application that writes information to the phone, either intentionally or as a by-product of some action, the information is almost always recoverable. “A developer has to have a different way of thinking about where data gets written, and how to get rid of it and completely clear it out,” says Hoog. In an appSecure audit, forensic analysis will uncover whether or not residual data can be recovered from the device.

Hoog tells developers they shouldn’t rely on the security that’s built into a smart device. For example, passcodes and the default encryption on an iPhone or iPad can easily be circumvented. “If the application uses sensitive data, developers have to do more to protect it,” he says.

During an appSecure audit, the research team will often go down rabbit holes to uncover issues. Hoog cites the recent testing of a mobile banking application. “We came across an unusual file that had high entropy — it was a random file that didn’t look like anything we’ve seen before. This is a clear sign that it’s an encrypted file,” says Hoog. “We looked at the application to determine if it was encrypting data, and if so, how, and could we break it? After a few hours, we had identified the encryption technique, recovered the keys, decrypted the data and sent it back to the client with remediation advice.”

Once an application goes through an appSecure audit and has no failures, or the failures that were found have been remediated, viaForensics offers an appSecure certification. “We put our name on it to verify that the application has been thoroughly tested and validated to be secure,” says Hoog.

For more information about appSecure, click here. Next week we’ll look at viaForensics’ appWatchdog and the 42-plus best practices for creating secure mobile applications for iOS and Android.

Linda Musthaler is a principal analyst with Essential Solutions Corporation. You can write to her at LMusthaler@essential-iws.com.

______________________________________________________________

About Essential Solutions Corp:

Essential Solutions researches the practical value of information technology, and how it can make individual workers and entire organizations more productive. Essential Solutions offers consulting services to computer industry and corporate clients to help define and fulfill the potential of IT.