Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Mobile

CrowdStrike Debuts Mobile Threat Detection System at RSA Conference

Falcon for Mobile offers detection and response capabilities for mobile platforms.

RSA CONFERENCE 2019 – San Francisco – Detecting and responding to malware and threats on workstations and laptop computers has been a regular part of enterprise IT security for years. A service launching this week aims to bring those same capabilities to the smartphones that have become part of the enterprise application landscape.

CrowdStrike Falcon for Mobile is an endpoint detection and response (EDR) suite based on CrowdStrike's Falcon product for the more traditional workstations found in the enterprise. "What we've seen in 2018 is a much wider attack surface and instances of attacks against mobile devices," said Amol Kulkarni, chief product and engineering officer at CrowdStrike. "The field being shared equally, across desktops, laptops, and mobile, it was inevitable that the attack surface is going to be leveraged by attackers."

Kulkarni said that the most critical need for protecting mobile devices is visibility. "Some of the attacks are known, but a lot of the attacks that we suspect are happening are unknown. And that's because there isn't really a good solution which provides visibility and which has taken the EDR approach to mobile," he said.

The second major feature set Falcon for Mobile provides is proactive threat hunting and aid to red team members. This feature set includes capabilities such as mobile network activity tracking, highlighting clipboard actions, and monitoring peripherals and attached devices.

With the new capabilities, though, Kulkarni said that privacy remains a key concern. "Privacy is crucial in the mixed, 'bring your own device' world that we have," he said, because, "we will only monitor corporate applications, designated by corporate admins, and clearly visible to the end user." Kulkarni added, "And we would not monitor personal applications or personal data on the device."

Designing the Falcon for Mobile device agent was a challenge because performance requirements dictated that the app be as small as possible. "These are battery-powered devices so the performance impact has to be super, super minimal," Kulkarni said.

Related content:

 

 

 

Join Dark Reading LIVE for two cybersecurity summits at Interop 2019. Learn from the industry's most knowledgeable IT security experts. Check out the Interop agenda here.

Curtis Franklin Jr. is Senior Editor at Dark Reading. In this role he focuses on product and technology coverage for the publication. In addition he works on audio and video programming for Dark Reading and contributes to activities at Interop ITX, Black Hat, INsecurity, and ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
For Cybersecurity to Be Proactive, Terrains Must Be Mapped
Craig Harber, Chief Technology Officer at Fidelis Cybersecurity,  10/8/2019
A Realistic Threat Model for the Masses
Lysa Myers, Security Researcher, ESET,  10/9/2019
USB Drive Security Still Lags
Dark Reading Staff 10/9/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
7 Threats & Disruptive Forces Changing the Face of Cybersecurity
This Dark Reading Tech Digest gives an in-depth look at the biggest emerging threats and disruptive forces that are changing the face of cybersecurity today.
Flash Poll
2019 Online Malware and Threats
2019 Online Malware and Threats
As cyberattacks become more frequent and more sophisticated, enterprise security teams are under unprecedented pressure to respond. Is your organization ready?
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-17552
PUBLISHED: 2019-10-14
An issue was discovered in idreamsoft iCMS v7.0.14. There is a spider_project.admincp.php SQL injection vulnerability in the 'upload spider project scheme' feature via a two-dimensional payload.
CVE-2019-17553
PUBLISHED: 2019-10-14
An issue was discovered in MetInfo v7.0.0 beta. There is SQL Injection via the admin/?n=tags&c=index&a=doSaveTags URI.
CVE-2019-17408
PUBLISHED: 2019-10-14
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
CVE-2019-17545
PUBLISHED: 2019-10-14
GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded.
CVE-2019-17546
PUBLISHED: 2019-10-14
tif_getimage.c in LibTIFF through 4.0.10, as used in GDAL through 3.0.1 and other products, has an integer overflow that potentially causes a heap-based buffer overflow via a crafted RGBA image, related to a "Negative-size-param" condition.