10.06.2013 Views

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

Study into the Implications of Smartphone Operating System Security

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

<strong>Study</strong> <strong>into</strong> <strong>the</strong> implications <strong>of</strong> <strong>Smartphone</strong> operating system security<br />

Privacy controls<br />

App reputational services<br />

Android mobile security products operate in a similar fashion to <strong>the</strong>ir desktop cousins with<br />

background processing, where <strong>the</strong> platform supports it, signature-file checking, regular<br />

signature file updates (usually OTA) and checks on messaging, removable media, mobile<br />

internet and mobile App installation and execution.<br />

How effective are <strong>the</strong>y?<br />

There has been debate as to <strong>the</strong> effectiveness <strong>of</strong> mobile security apps but it all depends on<br />

what you are trying to protect against.<br />

Using a locate and wipe app to find a <strong>Smartphone</strong> after it has been lost and stolen and <strong>the</strong>n<br />

to wipe <strong>the</strong> data on it is a useful utility whe<strong>the</strong>r it is a native (part <strong>of</strong> <strong>the</strong> operating system) or<br />

provided by a third party. Although <strong>the</strong>re have been questions as to how effective <strong>the</strong>se<br />

services are and whe<strong>the</strong>r <strong>the</strong>y are reliant on <strong>the</strong> SIM card still being present in <strong>the</strong> device for<br />

location purposes – Note: one <strong>of</strong> <strong>the</strong> first things that a phone thief may do is to pull out <strong>the</strong><br />

SIM card from <strong>the</strong> device and to disable <strong>the</strong> WiFi services.<br />

The fiercest debate has been around <strong>the</strong> effectiveness <strong>of</strong> anti-malware on <strong>the</strong> device.<br />

Executives at Apple and Google have long criticised <strong>the</strong> anti-virus industry stating that <strong>the</strong><br />

security <strong>of</strong> <strong>the</strong> operating system and ecosystem is more effective at preventing <strong>the</strong> spread <strong>of</strong><br />

malicious code.<br />

The security vendors <strong>the</strong>mselves will admit that <strong>the</strong>re are problems in running anti-malware<br />

services on <strong>the</strong> <strong>Smartphone</strong>. In an interview with Rapid 7, a security vendor, <strong>the</strong>ir CEO and<br />

Founder Giri Sreenivas stated that <strong>the</strong>re is a “weakness in mobile anti-malware products in<br />

that <strong>the</strong>y cannot be run in a privileged state on <strong>the</strong> device restricting <strong>the</strong>ir ability to detect all<br />

malware and vulnerabilities”.<br />

A fur<strong>the</strong>r problem is with <strong>the</strong> limited battery life <strong>of</strong> <strong>Smartphone</strong>s. Lookout Mobile <strong>Security</strong>’s<br />

CTO and Co-Founder, Kevin Mahaffey, told Goode Intelligence that “<strong>Smartphone</strong> battery life<br />

is an issue for us as it prevents us from continuously checking for Malware. We don’t want to<br />

drain <strong>the</strong> battery so we have to resort to o<strong>the</strong>r techniques such as scanning for Malware<br />

when a user downloads or updates an App”.<br />

The German-based independent anti-virus test organisation, AV Test, have been testing<br />

Android anti-malware products and <strong>the</strong>ir recent study <strong>of</strong> 22 products was published in<br />

January 2013 93 . The good news is that only one <strong>of</strong> <strong>the</strong> products failed <strong>the</strong> test and did not<br />

receive <strong>the</strong> AV Test certificate. The products are tested for protection usability and additional<br />

security functions. Top points were awarded to products from TrustGo, Lookout, Symantec<br />

and Trend Micro.<br />

93 The full test results can be found here (http://www.av-test.org/fileadmin/pdf/avtest_2013-<br />

01_android_testreport_english.pdf) in PDF format from <strong>the</strong> AV Test website<br />

Goode Intelligence © 2013 P a g e | 94 www.goodeintelligence.com

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!