Mobile

2/23/2016
04:00 PM
Connect Directly
Twitter
Twitter
RSS
E-Mail
50%
50%

Leaky Apps Far Riskier Than Mobile Malware

Even top enterprise apps are rampant with data leakage and privacy-invasive behavior.

Mobile malware may be the most intriguing thing to capture the attention of mobile-minded security researchers today. But according to a report out today by Appthority, the bigger risks statistically come from misbehaving legitimate apps.

The Appthority Enterprise Mobile Threat Team's quarterly Mobile Threat Report took a deep dive look into some of the most recent threats on the mobile app landscape. While significant iOS exploits like XcodeGhost, YouMi, and MobiSage certainly raised eyebrows, the researchers found that a risk analysis across the entire app ecosystem showed that these and other malware risks are eclipsed by data leakage and privacy invasive behaviors from otherwise legitimate applications.   

"While Apple and Google generally do a great job of reviewing apps for overall risk, they are mainly trying (sometimes unsuccessfully) to keep malware out of the app stores and are not monitoring apps for other enterprise risks like data exfiltration and privacy invasive behaviors," the report explained.

Some of the data leak behaviors include sending out or broadcasting unique device identifiers, address book, calendar, location or SMS messages, attempting to root a device or capabilities for recording calls, or other user-initiated activity. Privacy invasive activity includes tracking locations, accessing address book, calendar, SMS archives, microphone and other functions, and sending data to ad networks.

In examining over 315,000 unique iOS and Android apps from the respective platform's app stores, Appthority found that just over 48% of iOS apps and nearly 87% of Android apps displayed data leakage behaviors.

Meanwhile over 62% of iOS and 86% of Android apps engage in privacy invasive behavior. Even these behaviors pose risks to enterprises.

"For example, if an app is leaking employee address book data, it will be much easier for attackers to user the information collected from the address book to launch a targeted spear phishing, malware or other cyber attack," the report explains.

Interestingly, enterprise apps are no better in this department--in fact, they're just a tick more risky. Of the 100,000 apps already in enterprise mobile ecosystems or being pre-evaluated for risk to be entered in this enterprise app pool, nearly 50% of iOS apps and over 88% of Android apps display data leakage behaviors, and over 65% of iOS apps and 88% of Android apps engage in privacy invasive behaviors. Narrow that down to the top 150 apps in the enterprise and these numbers go up significantly, by as much as 30 percentage points.

Clearly, enterprises are facing an uphill battle with vetting these applications.

"Even if an enterprise were to focus on trying to whitelist the top 150 most popular apps, each of these apps may see up to 10 new versions per year, creating a bottleneck in the review and approval process," the report says.

 

Interop 2016 Las VegasFind out more about mobile security threats at Interop 2016, May 2-6, at the Mandalay Bay Convention Center, Las Vegas. Register today and receive an early bird discount of $200.

Ericka Chickowski specializes in coverage of information technology and business innovation. She has focused on information security for the better part of a decade and regularly writes about the security industry as a contributor to Dark Reading.  View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Four Faces of Fraud: Identity, 'Fake' Identity, Ransomware & Digital
David Shefter, Chief Technology Officer at Ziften Technologies,  6/14/2018
Meet 'Bro': The Best-Kept Secret of Network Security
Greg Bell, CEO, Corelight,  6/14/2018
Containerized Apps: An 8-Point Security Checklist
Jai Vijayan, Freelance writer,  6/14/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-9036
PUBLISHED: 2018-06-20
CheckSec Canopy 3.x before 3.0.7 has stored XSS via the Login Page Disclaimer, allowing attacks by low-privileged users against higher-privileged users.
CVE-2018-12327
PUBLISHED: 2018-06-20
Stack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher privileges via a long string as the argument for an IPv4 or IPv6 command-line parameter. NOTE: It is unclear whether there are any common situations in which ntpq ...
CVE-2018-12558
PUBLISHED: 2018-06-20
The parse() method in the Email::Address module through 1.909 for Perl is vulnerable to Algorithmic complexity on specially prepared input, leading to Denial of Service. Prepared special input that caused this problem contained 30 form-field characters ("\f").
CVE-2018-6563
PUBLISHED: 2018-06-20
Multiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers to hijack the authentication of users for requests that (1) change user settings, (2) send emails, or (3) change contact information by leveraging lack of an anti...
CVE-2018-1120
PUBLISHED: 2018-06-20
A flaw was found affecting the Linux kernel before version 4.17. By mmap()ing a FUSE-backed file onto a process's memory containing command line arguments (or environment strings), an attacker can cause utilities from psutils or procps (such as ps, w) or any other program which makes a read() call t...