Yishay Yovel directs IBM Security

The Return of the Wild West: Securing Enterprise Mobile Applications Against Evolving Threats

To secure the mobile workforce at the age of BYOD, IT security professionals and line-of-business executives must consider how mobility impacts their business risk profile. The framework proposed in this document looks at the device, the data, the application and the transaction as components of single continuum that must be secured to minimize the business risk associated with mobility. The appropriate mobile security framework will enable enterprises to reap the productivity gains and enhance employee satisfaction while limiting the exposure to their critical information and business assets.

This trend, while positively impacting the user experience, can reduce the ability of the IT department to confidently secure access to data on enterprise systems.The Emerging Mobile Application “Wild West”

Mobile applications, available through online app marketplaces such as Apple’s App Store, Google’s Play Store and third-party marketplaces, are the dominant form of delivering value to users worldwide. Organizations have embraced mobile applications as a way to improve employees’ productivity and align with their new agile and mobile lifestyle.

At the same time, many companies are increasingly adopting Bring-Your-Own-Device (BYOD) policies to allow employees to meld their personal and professional lives into a single mobile experience. This trend, while positively impacting the user experience, can reduce the ability of the IT department to confidently secure access to data on enterprise systems.

Because of this, it is no longer possible to make assumptions about the underlying security of the mobile device, or the application mix being used on that device. This unknown territory, the so-called “Mobile Wild West,” makes securing the application and its execution an increasingly difficult task.

What follows is a framework to address the creation, deployment and execution of secure mobile applications – thus reducing the business exposure associated with enterprise mobility.

Secure the Code: Building a Secure Application

Mobile malware often taps vulnerabilities or bugs, in the design and coding of mobile applications they target. Once exploited, these vulnerabilities cause unintended behaviors which are used to take over and tamper with the application execution.

Even before vulnerability is exploited, attackers can obtain a public copy of an application and reverse engineer it. Popular applications are repackaged into “rogue apps” containing malicious code and are posted on third-party app stores to lure and trick unsuspecting users to install them and compromise their devices.

Enterprises should look for tools to aid their developers to detect and close security vulnerabilities and then harden their applications against reverse engineering and tampering. However, “consumer apps” still represent a threat as they may not undergo the appropriate hardening process. And as rogue applications, malware and enterprise apps share the same device, the threat is tangible.

Secure the Device: Detecting Compromised and Vulnerable Run-Time Environment

As secure the application is, its security relies on the underlying device security. Jailbroken or rooted devices, or the presence of rogue applications, can represent an execution risk that may be allowed for certain enterprise apps but not for others.

Enterprises should look into ways to dynamically gauge the security of the underlying device. First, the mobile app sandbox (that is prevalent in modern mobile operating system design) must be intact. Rooting or jailbreaking the device breaks the underlying security model and it is highly recommended to restrict these devices from accessing enterprise data. Furthermore, jailbreak technology is evolving rapidly to evade detection – coping with these mechanisms is essential to keeping up with these threats.

Mobile malware, though, doesn’t always rely on the device being jailbroken. Excessive use of permissions to the mobile applications (which are granted by the user, often by default) can provide malware and rogue applications access to basic services (i.e., SMS) used to facilitate fraudulent activities. 

Enterprises should consider up-to-date intelligence sources and application reputation services to track the tidal wave of applications - and their associated risk - as they enter mobile app stores on a daily basis. Using this data, application capabilities could be enabled or disabled based on the device risk profile.

Secure the Data:  Preventing Data Theft and Leakage

When mobile applications access enterprise data, documents and unstructured information are often stored on the device. If the device is lost, or when data is shared with non-enterprise applications, the potential for data loss is heightened.

Many enterprises are already looking into “remote wipe” capabilities to address stolen or lost devices. Mobile data encryption can be used to secure data within the application sandbox against malware and other forms of criminal access. To control application data sharing on the device, individual data elements should be encrypted and controlled. 

Secure the Transaction: Controlling the Execution of High Risk Mobile Transactions

Because mobile applications enable users to transact with enterprise services on the go, the risk tolerance for transactions will vary. For example, reading HR-related content may be deemed low-risk vs. the approval of a large payment to a new supplier.

Organizations should adapt an approach of risk-aware transaction execution that restricts client-side functionality based on policies that consider mobile risk factors such as device security attributes, user location, the security of the network connection, and so on. 

Even when client-side transactions are allowed, enterprise applications can leverage an enterprise mobile risk engine to correlate risk factors such as IP velocity (access to the same account from two locations that are far apart, over a short period of time), user access patterns and data access profile. This approach extends the enterprise’s ability to detect and respond to complex attacks that can span multiple interaction channels and seemingly unrelated security events.

Conclusion

To secure the mobile workforce at the age of BYOD, IT security professionals and line-of-business executives must consider how mobility impacts their business risk profile. The framework proposed in this document looks at the device, the data, the application and the transaction as components of single continuum that must be secured to minimize the business risk associated with mobility. The appropriate mobile security framework will enable enterprises to reap the productivity gains and enhance employee satisfaction while limiting the exposure to their critical information and business assets. 

Featured

  • Allegion, Comfort Technologies Implement Mobile Credentials at the Artisan Apartment Homes in Florida

    Artisan Apartment Homes, a luxury apartment complex in Dunedin, Florida, recently transitioned from mechanical keys to electronic locks and centralized system software with support from Allegion US, a leading provider of security solutions, technology and services, and Florida-based Comfort Technologies, which specializes in deploying multifamily access control, IoT devices and software management solutions. Read Now

  • Mall of America Deploys AI-Powered Analytics to Enhance Parking Intelligence

    Mall of America®, the largest shopping and entertainment complex in North America, announced an expansion of its ongoing partnership with Axis Communications to deploy cutting-edge car-counting video analytics across more than a dozen locations. With this expansion, Mall of America (MOA) has boosted operational efficiency, improved safety and security, and enabled more informed decision-making around employee scheduling and streamlining transportation for large events. Read Now

  • Security Industry Association Launches New “askSIA” AI Tool

    The Security Industry Association (SIA) has unveiled a brand-new SIA member benefit – askSIA, a conversational AI agent designed to help users get the most out of their SIA membership, easily access SIA resources and find the latest information on SIA’s training and courses, reports and publications, events, certification offerings and more. SIA members can easily find askSIA by visiting the SIA homepage or looking for the askSIA icon in the top left of webpages. Read Now

    • Industry Events
  • Industry Embraces Mobile Access, Biometrics and AI

    A combination of evolving workplace dynamics, technology innovation and new user expectations is changing how people enter and interact with physical spaces. Access control is at the heart of these changes. Combined with biometrics and AI, mobile access control has become increasingly crucial for deploying entry solutions that are seamless, secure and adaptive to user needs. Read Now

  • Sustainable Video Solution Delivered for Landmark City of London Office Development

    An advanced, end-to-end video solution from IDIS, with a focus on reducing waste and costs, has helped a major office development in the City of London align its security with sustainability objectives. Read Now

New Products

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols.

  • PE80 Series

    PE80 Series by SARGENT / ED4000/PED5000 Series by Corbin Russwin

    ASSA ABLOY, a global leader in access solutions, has announced the launch of two next generation exit devices from long-standing leaders in the premium exit device market: the PE80 Series by SARGENT and the PED4000/PED5000 Series by Corbin Russwin. These new exit devices boast industry-first features that are specifically designed to provide enhanced safety, security and convenience, setting new standards for exit solutions. The SARGENT PE80 and Corbin Russwin PED4000/PED5000 Series exit devices are engineered to meet the ever-evolving needs of modern buildings. Featuring the high strength, security and durability that ASSA ABLOY is known for, the new exit devices deliver several innovative, industry-first features in addition to elegant design finishes for every opening.