Security boffins slip past Google Bouncer

Powered by SC Magazine
 

New app store security checkpoint misses malicious app.

Researchers have slipped malware past the new Android app store security control, and mapped its environment.

Google revealed the Bouncer control in February as a means of scanning the Android market for malicious software, without requiring developers to go through an Apple-like application approval process.

Uploaded apps would be analysed for known malware and malicious behaviour via a sandbox on Google’s cloud infrastructure.

Bouncer would also evict developers known as repeat offenders.

But security boffins Jon Oberheide and Charlie Miller have demonstrated how malicious code could be obfuscated within an application to skirt Bouncer and be uploaded to the Google Play Store.

The demonstration, to be presented at the US SummerCon event this week, also mapped out and fingerprinted the Bouncer infrastructure environment after it ran dynamic analysis of the booby-trapped app and granted an interactive remote shell.

Oberheide and Miller obtained Bouncer’s kernel version, the guts of its filesystem, and data on emulated devices run within its environment.

“So this is just one technique to fingerprint the Bouncer environment, allowing a malicious app to appear benign when run within Bouncer, and yet still perform malicious activities when run on a real user’s device,” Oberheide said.

Last year, Android device activations grew 250 percent while app store downloads topped 11 billion. But the bypass wasn’t a death knell for Bouncer.

“While Bouncer may be unable to catch sophisticated malware from knowledgeable adversaries currently, we’re confident that Google will continue to improve and evolve its capabilities,” Oberheide said.

Android engineering cheif Hiroshi Lockheimer said of Bouncer that "no security approach is foolproof, and added scrutiny can often lead to important improvements."

"Our systems are getting better at detecting and eliminating malware every day, and we continue to invite the community to work with us to keep Android safe."

The researchers had advised Google of the bypass and were assisting the Android security team to develop a fix.

Copyright © SC Magazine, Australia


Security boffins slip past Google Bouncer
 
 
 
Top Stories
First look: Microsoft Outlook for iOS
[Update] Office productivity suite for iOS completed with Outlook.
 
NewSat defaults on $26m in overdue Lockheed payments
Jabiru-1 satellite build hits further hurdles.
 
IBM denies plans to cut 112k jobs
But admits to further restructuring.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest articles on BIT Latest Articles from BIT
Microsoft Outlook is now on iPhone and iPad: why could this be useful?
Jan 30, 2015
Microsoft today released Office for Android and Outlook for iOS - complementing the other Office ...
Franchisees, here's something you should know about
Jan 23, 2015
You need to know the Code if you are a franchisee or franchisor as the penalties are significant.
Xero users rejoice! Quoting has finally arrived
Jan 23, 2015
It has taken years, but Xero has at last added integrated quoting to its online accounting software.
You can now get a no-contract wi-fi tablet from Telstra
Jan 17, 2015
Telstra has began selling wi-fi tablets out of contract without paying extra for cellular ...
Get your business ready for 2015: mobile payments
Jan 2, 2015
These handy apps from MYOB, Xero and others can reduce your administrative load and improve ...
Latest Comments
Polls
Who do you trust most to protect your private data?







   |   View results
Your bank
  36%
 
Your insurance company
  5%
 
A technology company (Google, Facebook et al)
  9%
 
Your telco, ISP or utility
  8%
 
A retailer (Coles, Woolworths et al)
  4%
 
A Federal Government agency (ATO, Centrelink etc)
  18%
 
An Australian law enforcement agency (AFP, ASIO et al)
  14%
 
A State Government agency (Health dept, etc)
  7%
TOTAL VOTES: 3093

Vote
Do you support the abolition of the Office of the Information Commissioner?

   |   View results
I support shutting down the OAIC.
  27%
 
I DON'T support shutting the OAIC.
  73%
TOTAL VOTES: 985

Vote