Malicious programmers focus on smartphones, tablets
May 4, 2011 By Brandon Bailey
Malicious programmers are always looking for new targets. While smartphones and tablets replace PCs as the gadgets we use for messaging, Web surfing and even doing business, some shady characters are starting to target these devices with new forms of viruses, Trojans and spyware.
Researchers at several security software companies say that in recent months they've identified a handful of malicious programs hidden in seemingly innocuous applications, including games and video players, that could make Android phones send information and receive commands without the owners' knowledge.
In some cases the purpose was unclear. But one app used a phone's locating software to transmit the owners' whereabouts without permission. Another was designed to quietly send repeated text messages, while charging hefty fees to the owner's wireless account.
The number of threats is tiny compared with the vast array of malware targeting PCs. And at this stage, some experts say it's more important for smartphone users to follow common-sense precautions than to purchase one of the commercial antivirus products now offered for mobile devices. But even though the most popular smartphone operating systems may be less vulnerable than PCs, experts say the growing popularity of mobile gadgets means malicious coders will inevitably target them more often in the future.
"There hasn't been an example of malware affecting thousands or millions of devices yet, but that doesn't mean it's not possible or it won't happen," said analyst Chris Hazelton, who tracks mobile technology for the 451 Group, a tech research firm.
"We don't want to be the scaremongers," added Lyle Frink, a spokesman for security software company Avast. "But the development curve for these things is accelerating."
Researchers at another security company, McAfee, say the bulk of the smartphone malware they detected last year was written to target the Symbian operating software used by Nokia, long an international leader in the smartphone industry. But they and other experts have noted an uptick in malicious applications written for Google's Android, which late last year overtook Symbian as the most popular smartphone operating system, according to Canalys, a tech research firm.
"There's a growing installed base of Android users. And it's a very open platform - you can do a lot of good things with it, but if you want, you can also be more nefarious," said Mark Kanok, a spokesman for security software maker Symantec.
Historically, smartphones have used a variety of operating systems. And since a virus written for one platform wouldn't necessarily work on another, the pool of potential targets for any particular virus was small. Also, operating systems and mobile Web browsers have technical features that make it difficult to transfer files or data onto a device without the user's permission.
"They're much more locked down," said Andrew Jaquith, a former mobile industry analyst who is now chief technology officer at Perimeter E-Security.
But as smartphones become ubiquitous, the Android platform has become a prominent target. And experts say another reason they're seeing more Android malware is because Google, seeking to encourage independent developers, makes it relatively easy for anyone to offer an app through the official Android Market.
While Apple is known for closely screening every program offered through its App Store, analysts say Google does virtually no pre-testing or screening of apps in the Android Market. And Android apps can be downloaded from a variety of other sites, which increases the opportunity for bad guys to create a seemingly harmless app that contains malicious code, and then distribute it to an unwitting pool of Android device users.
A Google spokesman declined to comment on the issue of pre-screening apps, but the company said in a statement that it takes security very seriously and has numerous safeguards.
Android's design includes a "sandboxing" feature that prevents individual applications from reading or changing information in other applications or the underlying operating system, without first getting permission. That's why users who download an Android app typically get a message asking permission to access other services or software on the device.
Experts say smartphone users should not agree to anything that seems suspicious, although less savvy users may not understand what they're allowing.
The Android Market also displays user ratings and reviews, and Google encourages users to consider those before downloading any app. When the company has learned of a problem, it has yanked apps from the Android Market. And twice in the last year, Google has used its ability to remotely remove certain apps from any device that had downloaded them, under the "terms of service" that Android Market users agree to accept.
In the most recent incident, Google disclosed last month that it had remotely killed several malicious apps that were transmitting information about the host device and its location. The company also used its ability to automatically install a security update on the affected devices to prevent further unauthorized transmissions.
"We are adding a number of measures" that would prevent similar apps from being distributed in the future, the company said in a blog post.
While crediting Google with reacting quickly, Hazelton noted that Google only learned of the malware from an independent developer after it had been downloaded an estimated 250,000 times. And as more users download more kinds of apps from a variety of sources, he said there's an increasing risk of malware getting past the security safeguards.
"We're seeing these things come almost in development cycles, where people are putting out different versions, testing their capabilities and incorporating new methodologies," added Symantec's Kanok.
Symantec, McAfee and several other software companies sell products that combine mobile antivirus software with features that allow consumers to back up their data, locate a missing phone and lock or "wipe" personal data if the device gets lost or stolen. Experts say these can be useful, but several said the most important thing owners can do is lock their device with a password.
While not every smartphone user currently needs antivirus software, Hazelton said the need likely will increase as banks and financial institutions offer more apps and online services for mobile devices.
"It comes down to each user and what they do with that device," he added.
(c) 2011, San Jose Mercury News (San Jose, Calif.).
Distributed by McClatchy-Tribune Information Services.
-
From lemons to lemonade: Reaction uses carbon dioxide to make carbon-based semiconductor,
32 comments
-
Thioridazine kills cancer stem cells in human while avoiding toxic side-effects of conventional cancer treatments,
3 comments
-
SpaceX private rocket blasts off for space station (Update),
42 comments
-
Climate scientists say they have solved riddle of rising sea,
31 comments
-
Research team claims to have found evidence Lake Cheko is impact crater for Tunguska Event,
18 comments
-
Need a rigid insulation material???
7 hours ago
-
magnets or EMF in car bumpers to protect from fender bender
May 26, 2012
-
length of wire in a coil of known dimensions?
May 25, 2012
-
India Engineering Powerhouse
May 25, 2012
-
electromagnet core dereference between hard and soft iron
May 25, 2012
-
Measuring water pressure in an open tank
May 24, 2012
- More from Physics Forums - General Engineering
More news stories
Browser wars flare in mobile space
The browser wars are heating up again, but this time the fight is for dominance of the mobile Internet.
2 minutes ago |
not rated yet |
0
SpotterRF debuts Radar Backpack Kit (w/ Video)
(Phys.org) -- SpotterRF has announced a special radar backpack kit designed to enhance situational awareness for soldiers on the ground. The company says its special radar is designed for warfighters as part ...
Probability of contamination from severe nuclear reactor accidents is higher than expected: study
Catastrophic nuclear accidents such as the core meltdowns in Chernobyl and Fukushima are more likely to happen than previously assumed. Based on the operating hours of all civil nuclear reactors and the number ...
Technology / Energy & Green Tech
May 22, 2012 |
3.6 / 5 (21) |
56
|
Delphi gasoline-injection engine technique rivals hybrid's edge
(Phys.org) -- Running a diesel like engine on gasoline is something Delphi is doing in notable fashion. They claim they are on to a promising way to enjoy an engine that gives the vehicle owner high efficiency ...
HyperSolar shows dirty water no barrier to power world
(Phys.org) -- The Santa Barbara, California, company, HyperSolar, is set to transparently share the ups and downs of its research experiences toward the companys ultimate vision, successfully producing ...
Scientist: Evolution debate will soon be history
(AP) -- Richard Leakey predicts skepticism over evolution will soon be history. Not that the avowed atheist has any doubts himself.
Dell tablet leak: 10.1-inch display, two-battery choice
(Phys.org) -- Headline after headline talks about vendors tablets in the wings as likely number-one contenders for the iPad. Such claims have justifiably been taken with a grain of salt, considering ...
SpaceX capsule has 'new car' smell, astronauts say (Update)
SpaceX's Dragon cargo vessel smells like a new car, said astronauts at the International Space Station after opening the hatches Saturday following the spacecraft's landmark mission to the orbiting lab.
Thousands of shellfish found dead in Peru
Thousands of crustaceans were found dead off the coast of Lima following the mystery mass death of dolphins and pelicans, the Peruvian Navy said Friday.
Australia hails surprise super-telescope decision
Australia has hailed a surprise decision giving it a role in a radio telescope project aimed at revolutionising astronomy, vowing to draw on its decades of experience in space science.
Astronomers seize last chance in lifetime for Venus Transit
Astronomers are gearing for one the rarest events in the Solar System: an alignment of Earth, Venus and the Sun that will not be seen for another 105 years.