Why Mobile Security Limits Threat Detection

455 views
•
February 23, 2017
by
RSAC Cybersecurity
YouTube video player
Why Mobile Security Limits Threat Detection

TL;DR

Stronger Android and iOS protections can reduce attack surface while also depriving defenders of the privileged access, telemetry, backups, and historical evidence needed to detect compromises. Because attackers may still obtain root access or exploit unpatched flaws, incident responders must work with limited snapshots and increasingly depend on Apple and Google for platform-level security.

Transcript

Morning. Thanks. Um, my name's Andrew Hoog, and today I'm gonna talk about, um, Android and iOS and how the platforms themselves are making security enhancements, but ultimately that impacts our ability as defenders to protect our systems. Um, my background is computer science. Um, I co-founded and am CEO of NowSecure. Um, but in general, I'm very ... Read More

Key Insights

  • Mobile attacks are already occurring across several threat categories, including financially motivated crime, information exposure, ransomware, malware, and targeted attacks. The examples show that defenders must consider mobile devices genuine endpoints for both broad criminal campaigns and attacks aimed at particular individuals.
  • Mobile applications account for about two-thirds of all time spent on the internet, according to the presentation. Desktop usage has not declined substantially, but overall online activity has expanded, making mobile applications a major channel for transactions, shared content, sensitive information, and potential attacks.
  • Neither Android nor iOS is bulletproof because current releases still contain flaws that may be known and exploitable. Release notes regularly document patches for privilege escalation, security bypasses, corruption, and code execution, showing that substantial platform investment cannot eliminate every vulnerability.
  • Mobile security visibility is shrinking because sandboxed architectures and increasingly restrictive APIs limit accessible telemetry. Information that defenders previously obtained, such as installed application lists and network connections, has become less available with successive releases, reducing the evidence available for security decisions.
  • The race to root favors whichever party gains privileged access first. Platform restrictions keep defenders and ordinary security applications away from system-level data, yet attackers who successfully escalate privileges can operate with broader access while defenders remain unable to inspect the same underlying state.
  • Restrictions on security applications have meaningful benefits because privileged security tools may contain exploitable vulnerabilities or collect telemetry that can be abused. They also push Apple and Google to build protections directly into their operating systems instead of relying on a separate antivirus and integrity-monitoring ecosystem.
  • The absence of continuous mobile monitoring makes subtle compromises harder to identify. Security telemetry represents a device at one point in time, so effective detection requires comparison across time, but mobile platforms largely prevent background applications from collecting relevant system information on a semi-continuous basis.
  • Restricted backups reduce attack surface and the amount of extractable personal data, but they also weaken incident response. Investigators receive fewer logs, applications, integrity measurements, and forensic artifacts, which makes it easier for attackers to conceal activity without performing sophisticated cleanup.

Install to Summarize YouTube Videos and Get Transcripts

Explore YouTube Video Summarizer or Get YouTube Transcript Extractor

Questions & Answers

Q: Why do mobile security enhancements complicate threat detection?

Mobile security enhancements complicate detection because sandboxing, restricted privileges, limited APIs, constrained background activity, and reduced backup content also restrict legitimate defenders. These controls can prevent unauthorized access and protect privacy, but they leave incident responders with fewer logs, less telemetry, and weaker forensic evidence. Attackers who obtain privileged access can therefore gain an asymmetric advantage over defenders who must obey platform restrictions.

Q: How does restricted root access affect mobile incident response?

Restricted root access prevents defenders from inspecting the complete state of an Android or iOS device. Traditional tools such as antivirus software and integrity monitors need privileged system access to examine files, libraries, and changes over time. If an attacker exploits a vulnerability and gains root access first, the attacker can operate deeply within the system while authorized responders remain limited by the platform sandbox.

Q: Why can limiting mobile security applications improve security?

Limiting security applications can improve security because privileged defensive software may introduce vulnerabilities of its own. The presentation cites Project Zero research that found numerous flaws in antivirus programs running on personal computers. Restrictions also reduce the collection of security telemetry that could be abused and encourage operating-system providers such as Apple and Google to build more protection directly into their platforms.

Q: What visibility do defenders lose on Android and iOS?

Defenders lose access to system-level information that would help them determine whether a device has been compromised. The presentation specifically identifies installed application lists, network connections, logs, library integrity information, and other telemetry as restricted or increasingly unavailable. Without those sources, defenders cannot easily establish a baseline, observe changes, or investigate subtle signs of malicious activity over time.

Q: Why are mobile backups important for forensic investigations?

Mobile backups can provide investigators with evidence that would ordinarily be collected immediately after an incident, including logs, application data, system details, and material useful for reconstructing events. As platforms restrict backup content, responders receive progressively less information. The presentation notes that the move from iOS 9 to iOS 10 removed the ability to back up the specific installed IPA application file.

Q: Are current Android and iOS versions free from exploitable flaws?

Current Android and iOS versions are not free from flaws, according to the presentation. Even the newest and most secure releases receive patches for multiple vulnerabilities, including privilege escalation, security bypasses, corruption, and code execution. Some people may already know about remaining defects, and determined attackers may exploit them despite the substantial security investments made by the platform providers.

Q: Why is historical mobile telemetry necessary for detecting attacks?

Historical telemetry is necessary because a single security scan only shows the device at one point in time. Subtle evidence of compromise may become apparent only when defenders compare current system state with earlier observations. Mobile restrictions make that comparison difficult by limiting background monitoring and access to system data, preventing security tools from collecting relevant information on a regular, semi-continuous basis.

Q: What types of mobile attacks does the presentation describe?

The presentation describes financially motivated attacks, sensitive-information exposure, malware, ransomware, and targeted exploitation. It mentions unauthorized credit card charges associated with vulnerabilities in the Starbucks app, the release of HIPAA information through a Quest Diagnostics mobile app issue, and an attack in which a foreign government reportedly purchased zero-day exploits to target a dissident from the UAE.

Summary & Key Takeaways

  • Mobile attacks include financially motivated crime, privacy breaches, and targeted exploitation. Examples discussed include unauthorized credit card charges involving the Starbucks app, exposure of HIPAA information through a Quest Diagnostics mobile app issue, and a foreign government reportedly purchasing zero-day exploits to target a dissident from the UAE.

  • Apple and Google have invested heavily in platform security, but neither Android nor iOS is bulletproof. Their releases continue to patch vulnerabilities involving privilege escalation, security bypasses, corruption, and code execution. Determined attackers can exploit remaining flaws, while mobile architecture prevents defenders from using many tools available on desktops and servers.

  • Five platform enhancement areas are introduced, with the transcript detailing restricted root access, limitations on security software, and shrinking backup access. These measures improve sandboxing, privacy, and attack-surface reduction, but they also limit continuous monitoring, forensic imaging, log collection, application extraction, integrity checking, and comparison of device state over time.


Read in Other Languages (beta)

Share This Summary 📚

Explore More Summaries from RSAC Cybersecurity 📚