Risk
9/30/2011
12:41 PM
50%
50%

Mobile Security Exploits To Double

Many of the threats involve mobile operating systems with easy-to-exploit vulnerabilities that can lead to arbitrary code execution.

Lookout Mobile Security Protects Android Smartphones
Slideshow: Lookout Mobile Security Protects Android Smartphones
(click image for larger view and for slideshow)
Expect the number of mobile device exploits to double by year's end.

That prediction comes from a new report released by IBM's X-Force research group, which examined attack trends for the first half of 2011.

IBM found that the number of known mobile operating system vulnerabilities, which more than doubled from 2009 to 2010, seems set to increase only slightly from 2010 to 2011. But the number of mobile device exploits--using those vulnerabilities--increased by 400% from mid-2009 to mid-2010, and now seems set to double from 2010 to 2011.

"For years, observers have been wondering when malware would become a real problem for the latest generation of mobile devices," said Tom Cross, manager of threat intelligence and strategy for IBM X-Force, in a statement. "It appears that the wait is over."

[ The mobile security landscape is changing. Learn more: Mobile Security's Future: 4 Expert Predictions ]

Malware creators, notably, continue to hone their craft. Notably, of the 24 mobile operating system vulnerabilities seen in the first half of 2011, half involve easy-to-exploit vulnerabilities that can lead to arbitrary code execution on the targeted device.

"Almost all of these vulnerabilities represent client software remote code execution vulnerabilities that are exploitable by malicious Web servers through the browser or the browser environment," according to IBM's report. "These vulnerabilities directly fit the drive-by-download approach of attracting victims to malicious websites that has been the pattern of a great deal of attack activity in the past few years."

At the same time that the quantity and sophistication of exploits has been increasing, so has the adoption of smartphones and tablets by business users. Many users also naturally bring their device to work, yet don't add security tools before using the devices to store sensitive data, which puts business information at risk. That risk is further compounded by many cell phone carriers failing to push security updates to their customers, and many mobile application developers failing to secure their applications.

What can mobile device users do to prevent their device from being exploited? First, consider mobile security tools. But also practice mobile security smarts. For starters, IBM recommends sticking with reputable application marketplaces, "such as the official Google Market or Amazon's Android application market."

Of course, malware sometimes sneaks into those application markets, especially since Google doesn't vet applications before it allows them into its application store, instead relying on users to spot any issues. Accordingly, keep an eye on access. For example, "a game should not require GPS or SMS access," said IBM. Also avoid "free" copies of normally paid applications. Finally, consider crowdsourcing to help vet applications before installing them. "Only install applications that have a large number of installs (100,000 or more) with a high review rating," said IBM.

Managing the password proliferation from mobility, partner access, and online apps requires a cohesive strategy. But our research on the state of ID management shows troubling trends. That and more in the new, all-digital issue of InformationWeek. Download it now. (Free with registration.)

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-3580
Published: 2014-12-18
The mod_dav_svn Apache HTTPD server module in Apache Subversion 1.x before 1.7.19 and 1.8.x before 1.8.11 allows remote attackers to cause a denial of service (NULL pointer dereference and server crash) via a REPORT request for a resource that does not exist.

CVE-2014-4801
Published: 2014-12-18
Cross-site scripting (XSS) vulnerability in IBM Rational Quality Manager 2.x through 2.0.1.1, 3.x before 3.0.1.6 iFix 4, 4.x before 4.0.7 iFix 2, and 5.x before 5.0.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6076
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allow remote attackers to conduct clickjacking attacks via a crafted web site.

CVE-2014-6077
Published: 2014-12-18
Cross-site request forgery (CSRF) vulnerability in IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 allows remote attackers to hijack the authentication of arbitrary users for requests that insert XSS sequences.

CVE-2014-6078
Published: 2014-12-18
IBM Security Access Manager for Mobile 8.x before 8.0.1 and Security Access Manager for Web 7.x before 7.0.0 FP10 and 8.x before 8.0.1 do not have a lockout period after invalid login attempts, which makes it easier for remote attackers to obtain admin access via a brute-force attack.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.