Gartner: Mobile Apps Open to Security Exploitation

Between device loss or theft, idle malware introduced via smartphone update requests, rogue hotspots and poorly-coded apps, IT leaders in education need to start girding themselves for an onslaught of security threats related to the mobile devices carried by students and staff. According to Gartner, over the next year and through the end of 2015, more than three-quarters of mobile apps will fail "basic security tests."

Tablets are only adding to the potential wreckage. The analyst firm predicted that by 2017, the focus of endpoint breaches will shift to tablets and smartphones. Already, the company noted in a statement, there are three attacks to mobile devices for every attack to a desktop.

The bulk of mobile data breaches will be a result of "mobile application misconfigurations," not "deeply technical attacks." As an example, a user may misuse personal cloud services through apps they run on their mobile devices, which can lead to undetected data leaks of enterprise data.

A basic problem is that developers creating mobile apps don't concern themselves much with app security testing, the IT firm noted. "Most enterprises are inexperienced in mobile application security," said Principal Research Analyst Dionisio Zumerle. "Even when application security testing is undertaken, it is often done casually by developers who are mostly concerned with the functionality of applications, not their security."

Over the last six to eight years, Gartner reported, most app-related testing has taken the traditional form of SAST and DAST, static and dynamic application security testing. The static form of testing, also known as "white-box" testing, analyzes a non-running application's source code and binaries for signs of security vulnerabilities, such as back doors or coding flaws. The dynamic form, also called "penetration" or "black box" testing, looks for clues to security problems in a running application, from the outside in. Most DAST testing examines code for Web-enabled applications.

Now a new kind of testing has surfaced specifically for mobile applications. "Behavioral analysis" monitors a running application to look for signs of "malicious and/or risky behavior" that might be going on in the background. For example, as a user is playing music through an audio player app, the app may also be getting into a user's contact list or geolocation and relaying that data to some external IP address.

Testing needs to take place at both the client layer — what the user interacts with — as well as the server layer, Zumerle said. Most of that testing will be done by vendors that specialize in running security tests.

"Today, more than 90 percent of enterprises use third-party commercial applications for their mobile BYOD strategies, and this is where current major application security testing efforts should be applied," he explained. "App stores are filled with applications that mostly prove their advertised usefulness. Nevertheless, enterprises and individuals should not use them without paying attention to their security. They should download and use only those applications that have successfully passed security tests conducted by specialized application security testing vendors."

IT also needs to broaden its understanding about mobile security and add a security focus to the work they do in evaluating and developing new applications for deployment that have a mobile component.

Zumerle and other Gartner experts will be discussing security issues during this week's Security & Risk Management Summit, taking place in Dubai.

About the Author

Dian Schaffhauser is a former senior contributing editor for 1105 Media's education publications THE Journal, Campus Technology and Spaces4Learning.

Featured

  • artificial intelligence on laptop

    OpenAI to Combine AI Products into Desktop 'Superapp'

    OpenAI is reportedly developing a desktop application that would combine several of its emerging AI products into a single platform, according to reports, marking the latest step in the company's effort to transform ChatGPT from a standalone chatbot into a broader productivity and automation environment.

  • woman surrounded by virtual hologram icons

    Beyond AI Adoption: Designing Learning for an Age of Abundant Intelligence

    Higher education was designed for a world in which access to knowledge, expertise, feedback, mentorship, and authentic learning experiences were inherently scarce. By making many forms of intelligence increasingly abundant, AI is inherently redefining the existing paradigm.

  • digital brain with network connections

    Microsoft Moving to Internally Developed AI Models in Office Apps

    Microsoft is reportedly using its own in-house artificial intelligence models to handle some workloads in Excel and Outlook, offering new evidence that the company is moving its AI strategy beyond model development and into large-scale cost reduction.

  • Profile silhouette of a person thoughtfully touching their chin, overlaid with transparent data visualizations and digital interface elements suggesting artificial intelligence and analytics.

    The Institutional Knowledge Shift Is Reshaping Higher Ed IT

    Higher education IT leaders are navigating a quiet but consequential transition: Experienced team members are retiring or leaving for private-sector roles, and the teams replacing them are smaller, newer, and often stretched thin. The result is a structural shift in how technology decisions are made, executed, and sustained.