Understanding Mobile App Security Risks
Mobile devices present a significant security problem as they operate outside the security perimeter and beyond the visibility of the security team. While security teams may know what applications are installed on these devices, they rarely understand the components and dependencies that comprise those applications, nor the vulnerabilities buried within those components.
Jim Dolce, CEO at Lookout, highlights the example of WolfSSL, a small, fast, and portable SSL/TLS library written in ANSI C, designed mainly for devices with limited memory. WolfSSL exists on more than a billion devices and is likely used by banking apps on mobile devices for online banking. However, it has a serious vulnerability that can be exploited by bad actors to mimic the bank and steal banking credentials when users input their credentials.
The Importance of Visibility
Knowing an application's name and version reveals only a fraction of its risk profile. Security teams need visibility into the software components, dependencies, and vulnerabilities embedded beneath the surface. This is where Lookout's new Mobile Security Exposure Center (MSEC) comes in, providing full visibility into an organization's potentially vast mobile fleet.
MSEC examines every device in the fleet, identifies the apps present, and creates a proprietary software bill of materials (SBOM) from the binary for the different apps. From this SBOM, it learns every component within the app and correlates those components with vulnerability databases, such as the KEV list. The results are fed into the organization's CTEM to assist the security team in taking necessary remediation steps.
Identifying and Remedying Exposure
MSEC identifies which apps use WolfSSL, the version of that app, the user, and the device using that app, providing all the necessary information for remediation. This applies to all software components of all apps on all mobile devices. MSEC also complements Lookout's existing AI Visibility & Governance product, revealing the software composition and exposure profile of applications and providing a more complete view of application risk, security, and governance.
The result is a shift from reactive application management to proactive exposure management. However, there is a slight issue - MSEC correlates app components with known vulnerability databases, which may not include unknown vulnerabilities. Lookout is aware of this and plans to use frontier AI models defensively to find unknown vulnerabilities across the SBOM.
Using Frontier AI Models Defensively
Bad actors can use frontier AI models to find vulnerabilities and exploit them. Lookout can use the same models defensively to find unknown vulnerabilities and catalog them. This will be the next iteration of MSEC, taking the SBOM and using frontier AI models to find unknown vulnerabilities and provide a more comprehensive view of application risk.
The process starts with knowing the app inventory across the enterprise mobile fleet, creating an accurate SBOM for all apps in the fleet, and correlating app components against known vulnerability databases. The final step is finding unknown vulnerabilities using frontier AI models defensively, providing security teams with the necessary information to remediate exposure and protect their organizations from potential attacks.
- Related: Mobile Attack Surface Expands as Enterprises Lose Control
- Related: FBI Warns of Data Security Risks From China-Made Mobile Apps
- Related: Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm
- Related: Chinese Hackers Turn Smartphones Into a ‘Mobile Security Crisis’
Kevin Townsend is a Senior Contributor at SecurityWeek, specializing in information security for the last 15 years and publishing thousands of articles in various magazines and online platforms.
Knowing an application's name and version reveals only a fraction of its risk profile. - Lookout
Daily Briefing Newsletter: Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.
Source: SecurityWeek