| OUR EXPERTS: Randy Abrams, research director, NSS Labs
|
Additionally, Tyler (left) points out, in emerging markets, where older mobile devices are more commonplace, exploits that may have been discovered or even stamped out in the U.S. and Europe are easily propagating and may remain in place for years to come. Mobile users in these areas have limited ways to protect themselves, Tyler says, adding that the information users once accessed by laptop is just a fraction of what is now used on smartphones today. The threat is also on the rise as “people are starting to move money with mobile devices,” says Dave Frymier, vice president and chief information security officer at Unisys, a global information technology company based in Blue Bell, Penn. Apple Pay is the latest boost to this trend in the United States, he says, but mobile malware has been a growing problem in Europe for years now. “Mobile device hygiene issues – such as weak passwords, downloading apps from questionable places, clicking on the wrong things – are the key factors predicating these attacks,” Frymier explains. “This is pretty much the same list of security hygiene issues that applies to a regular PC.”While for many CISOs, vendors and analysts, mobile malware is still relatively rare in comparison to other threats, “It's another avenue of attack, another source of cost for IT departments,” says Frymier. And he expects the risk to only rise. “As mobile devices spread and are used for financial transactions, the amount of exploits will increase.”Indeed, the ease of monetizing attacks makes the return on investment very attractive for would-be mobile attackers, according to Abrams. Attacking smartphones enables attackers to circumvent some methods of two-factor authentication even when users are using their computers, he points out, and development tools for Android are free and the cost to make apps available for download is insignificant. “The ease of getting malware installed on Android phones, which is what almost all mobile malware is written for, sets a low bar for a successful attack,” Abrams says. “A lack of accountability for developers results in a low likelihood of criminal apprehension.”Malware writing is a very lucrative endeavor, echoes Lysa Myers, security researcher at ESET, a global IT security company with U.S. headquarters in San Diego. “Criminals are able to get into phones or tablets by way of social engineering or vulnerabilities in software, especially as few people understand the importance of securing their mobile devices,” she says.Risk managementIn fact, most industry observers agree that the overall situation is likely to get worse before it gets better, especially since mobile devices – even those used to access sensitive information – are not always routinely updated, according to Ziring. Further, Somaini says that organizations may need to take a step back and look for new ways of dealing with this threat. While the controls around the device and the content have not changed from traditional platforms, there are definitely greater limitations on the operating system level. And conventional anti-virus approaches are not cutting the mustard in mobile. “What we need is more vendors focused on the mobile space,” Somaini says. In particular, new solutions need to take into account that, increasingly, employees are using their mobile devices to access corporate assets that are not necessarily resident on the device, but in the cloud, through services like Salesforce.com and Box. Predicting attacks is a new area organizations are just starting to investigate, according to Walsh, who, like other cybersecurity experts, is seeking to reduce if not eliminate malware's ability to attack information. In the case of government employees' devices, software is tested, verified and secured before it can be used. And his organization within the U.S. Army is working to establish mobile application development standards for developing and using secure applications. “The most difficult way to predict malware is to think like the malware developers and build proactive controls and tools that allow the mobile device to have protection before it is attacked,” Walsh says. “This is, however, a change to current practice, which traditionally is a reactive posture where we wait to see what the malware does then we work to stop it.”Deepak Rout, chief security officer for The Co-operators Group, a Canadian insurance company, admits that it is not easy to create data security architecture in the mobile world. The key, he says, lies in understanding the value of data being considered for mobility. He recommends classifying all data into multiple security classes and understanding which classes are involved in business processes enabled by mobile devices. As well, it is imperative to understand the consequences should data be exposed, and systematically develop layered controls for managing those identified risks. “So, it's essentially the age-old risk management, but at a data level,” Rout says. “And, of course, this is hard on three levels: IT risk management is little understood, hard to implement in practice and rarely goes to the level of data.” Malware threat: MitigationIn the face of heightened concern and a rising threat, how can organizations start to tame the potential for mobile malware attacks? For Justin Somaini, chief trust officer, Box, the plan starts first with education. In order to support employees in protecting themselves and their access to mobile assets (both personal and corporate), security practitioners need a “near-world plan on driving education and culture change,” he says. Information technology and support desks should regularly communicate to employees information about security updates or emerging or recurring malware threats that target mobile. Also, he says, organizations need to consider fundamental security precautions, like making sure that the company maintains a network for guest mobile users or contractors that is completely separate from the corporate network. In addition, companies need to review both their mobile device management solution providers and mobile-oriented vendors that handle application-level products and services to determine whether they are well-positioned to combat potential malware threats. Several vendors have embraced the mobile device fundamentals profile put forth by the NSA, according to Neal Ziring, technical director, information assurance directorate, National Security Agency. But, vendors and user organizations need to focus on the fact that mobile device security must extend beyond the end-point device. “The overall architecture matters too,” says Ziring. “Organizations should ask, ‘What is the potential exposure to my enterprise? How is my back end? Do I have adequate monitoring and am I protecting my most important data?' The awareness of the attack surface matters a lot more.”While it is critical to investigate the controls on the device and application level, Deepak Rout, chief security officer for The Co-operators Group, says that fellow CISOs must first consider the risks. Figuring out an organization's mobile risk profile is “a huge gap in a world empowered by mobility,” Rout says. He maintains that foundational controls are no-brainers: Organizations should deploy authentication systems to access applications, services and data; vulnerability and patch management; monitoring and incident management; and device-level security, including password, encryption and wiping on reported losses, he says. In the military, John R. “Rick” Walsh, mobile lead for cybersecurity, U.S. Army, says IT security efforts currently focus on both the users and the ultimate targets of malware players. “A piece of malware is written ultimately for one of two purposes: either to steal information or to deny the user from accessing information,” Walsh says. “So if we focus on the goal of the attack we can better defend against the attack.”
Organizations should install a management product and lock down any mobile devices they actually own, according to Dave Frymier, VP and CISO, Unisys. And, if an employee brings their own device and installs applications supplied by their organization, he says CISOs should consider “app wrapping” technology, which allows corporate apps to live in their own software sandbox separated from a user's personal environment on the device. Some cybersecurity experts, such as Lysa Myers (left), a security researcher at ESET, believe that companies and agencies that allow users to access their network with mobile devices must use more than passwords to protect access. She recommends using multi-factor authentication, encrypting sensitive data in storage and in transit (especially if users are able to access network resources from public wireless network), and limiting users' access to network resources to the minimal level that allows them to do their job. “Mobile malware will become a much more significant problem unless we drive solutions here,” says Somaini. – KEHPhoto of Justin Somaini by Grace Photography