The Grey Area in App Behaviors: It’s Not Malware, But It’s Still a Concern

Beyond the glitzy hardware and the mind-blowing specs of your smartphone and tablet, the real factor for determining functionality comes from the apps. Most apps are not out do harmful things, but some are.

Malware, by definition, are apps that are out to do subversive and often harmful things. They are operating on a hidden agenda of the attacker’s design. There’s no question that malware is something that must be prevented as part of an enterprise mobile security strategy.

One challenge here is that some app behaviors are not so easily defined. There’s a range of behaviors that fall into a grey zone, because they make use of personal data in unexpected ways. Many apps access information about the mobile device, the user, app data, location, and contacts, sometimes for purposes unknown because the app doesn’t even need the information. With all the network services available via a mobile device, that also means this data can be sent to third parties as well.

In many cases, there are a few reasons for these activities, including ambivalence about the permissions granted to an app and the growing use of third party mobile ad network libraries. In the former, the permissions granted come as a result of the click-through presented to users when they install an app. Most users do not pay close attention to what these permissions do or why they’re necessary, they just want to use the app.

Many app developers use mobile ad networks to create a source of income for apps that are otherwise very cheap or free. These ad networks sometimes take very aggressive measures to collect user information. We have seen these ad networks used for the delivery of malicious code as well.

Thus, we have a growing grey area of apps that may not be malicious in the same vein as malware, but could aggressively collect end user information often without the user’s knowledge. This presents a set of dangerous conditions because the user isn’t fully aware of what’s happening, the data is being shared outside of the context of the device, and there’s no transparency on what’s happening with the data once it leaves the device.

These conditions create a large, undefined problem space: what are apps trying to do with your data and do you know about it? Researchers from Carnegie Mellon University have sought to address this issue by grading apps based on metrics for privacy concerns. The results are interesting, because they do shine light on just how many issues exist, and how even very popular apps are not as straightforward as they might appear to be.

The article does call attention to the prevalence of issues in apps targeted at children. I suspect this is largely to do with the economics of children’s apps, as the casual games market typically relies on free-to-play models subsidized by advertising or in-app purchases, thus introducing the third party library that performs additional data gathering.

Today, people expect to use both personal and business apps on the same device. Whether it’s a personally owned device or a corporate device, there are going to be mix of non-business apps installed on it as well. As a result, the concern over how to protect data on mobile devices becomes far more complex, as bad actors cover a gamut of privacy and security behaviors.

As your mobile security strategy evolves, consider how you will plan to address apps and threats. From one standpoint, your organization must clearly take a proactive stand to stop malware and spyware. But you should also consider protecting data from the apps that fall in this grey area: not exactly malware, but definitely a concern. This requires protecting business data and keeping it away from the other apps installed on the device. All of these efforts should be applied and tied together with network security to enforce policy.

These are all principles that underline the philosophy behind GlobalProtect, the mobile security solution from Palo Alto Networks. To learn more about GlobalProtect, visit our resources page here.

[Palo Alto Networks Blog]

Palo Alto Networks Named to Deloitte’s 2014 Technology Fast 500

Palo Alto Networks was again named to Deloitte’s Technology Fast 500™, a ranking of the 500 fastest growing technology, media communications, life sciences and clean technology companies in North America. We’re proud to be one of a few enterprise security companies to make the Top 50 rank, which we attribute to rapid adoption this past year of our Enterprise Security Platform. (See the full 2014 Deloitte Technology Fast 500 list here.)

 

By focusing on prevention of both known and unknown threats, versus detection and remediation, we can offer network security, cloud-based threat intelligence and Advanced Endpoint Protection in one integrated, automated platform. See how our platform protects every corner of your organization, from your mobile workers to the core of your virtualized data centerhere.

[Palo Alto Networks Blog]

NIST Marks Top Security Requirements for Government Cloud

Cloud computing offers both unique advantages and challenges to government users. The advantages are well-advertised: Greater efficiency, economy and flexibility that can help agencies meet rapidly changing computing needs quickly and cheaply while being environmentally friendly.

Among the challenges, security is the most commonly-sited concern in moving mission-critical services or sensitive information to the cloud.

To address this, a recently released roadmap from the National Institute of Standards and Technology recommends a plan to ensure cloud offerings meet government security needs while being flexible enough to adapt to the policies and requirements of multiple tenants, including foreign governments. The plan involves periodic assessments of security controls and development of international profiles and standards.

The recommendations are brief and make up a small part of the 140-page document released by NIST in October but categorized as “high priority.”

The final version of the U.S. Government Cloud Computing Technology Roadmap has been several years in the making and reflects more than 200 comments on the initial draft, released in 2011.

Security is the first of three high-priority requirements addressed in volume one. Interoperability and portability – the ability of data to be moved from one cloud facility to another—are the others.

The government already has established the Federal Risk and Authorization Management Program (FedRAMP), which became operational in 2012 to ensure that cloud service providers meet a baseline set of federal security requirements, easing the task of certifying and authorizing the systems for government operations. But the NIST roadmap addresses security requirements that extend beyond federal users.

Security in the cloud is complicated by a number of factors. First, it upsets the traditional IT security model that relies on logical and physical system boundaries. “The inherent characteristics of cloud computing make these boundaries more complex and render traditional security mechanisms less effective,” the roadmap says.

Second, a cloud system has to meet not only U.S. government security needs, but also those of other customers sharing the environment, and so security policy must be de-coupled from U.S. government-specific policies. “Mechanisms must be developed to allow differing policies to co-exist and be implemented with a high degree of confidence, irrespective of geographical location and sovereignty.”

Moreover, a comprehensive set of security requirements have not yet been fully established, the roadmap says. “Security controls need to be reexamined in the context of cloud architecture, scale, reliance on networking, outsourcing and shared resources,” the authors write. “For example, multi-tenancy is an inherent cloud characteristic that intuitively raises concern that one consumer may impact the operations or access data of other tenants running on the same cloud.”

NIST says recommended priority action plans for cloud security are:

  • Continue to identify cloud consumer priority security requirements, on at least a quarterly basis.
  • Periodically identify and assess the extent to which risk can be mitigated through existing and emerging security controls and guidance. Identify gaps and modify existing controls and monitoring capabilities.
  • Develop neutral cloud security profiles, technical security attributes and test criteria.
  • Define an international standards-based conformity assessment system approach.

[GCN]

Moving Cybersecurity Discussions Beyond the IT Department and Into the Board Room

Earlier this week more than 100 participants gathered at the Copenhagen Marriott in Denmark for an emergency meeting on Cyber Crime, coordinated through AmCham Denmark in cooperation with the Overseas Security Advisory Council and partners Deloitte, Palo Alto Networks and Symantec.

We’re pleased to have been part of this important event, titled “Align Business and Security Now” and focused on how to move discussions of security beyond the IT department and into the board room. Along with presentations from the Danish Center for Cyber Security, the U.S. Federal Bureau of Investigation, Deloitte and Symantec, our own Stijn Rommens, systems engineering manager for Northern Europe, discussed why aligning all processes, technology and people — not just perimeter protection — is crucial to an effective security posture.

From left to right: Lars Bennetzen (moderator), Stijn Rommens (Palo Alto Networks), Janus Friis Bindslev (Deloitte), James Hanlon (Symantec), Sigurd Hellums (Palo Alto Networks) and Morten Efferbach (Symantec). 

Click here to see more details and a full photo gallery from the event.

[Palo Alto Networks Blog]

PA-7050 Series Named a 2014 Readers’ Choice Award Winner

We’re pleased to announce that the PA-7050 Series was named a winner in the Enterprise Firewall category of the Information Security™ magazine and SearchSecurity.com™ 2014 Readers’ Choice Awards, presented by the editors of the two publications.

As noted in Information Security magazine and on SearchSecurity.com, “The Palo Alto Networks PA-7050 received top scores from Readers’ Choice voters for its ability to identify users via directory integration and for the company’s service and support. The firewall’s ability to block intrusions, attacks and unauthorized network traffic; its logging, monitoring and reporting capabilities –and the overall return on investment –impressed Information Securityreaders.” Read more on why the PA-7050 was 2014 Readers’ Choice Award recipient.

The 2014 Readers’ Choice Award winners were selected based on an extensive, in-depth survey of Information Security magazine and SearchSecurity.com readers that included over 1,700 information security executives and managers, who were asked to assess and rate products deployed within their organizations from a listing of more than 400 products spanning 22 product categories.

Learn more about the PA-7050

[Palo Alto Networks Blog]

English
Exit mobile version