Google now scanning Android apps for malware

 

Summary

New service scans apps for malicious code or behavior and bounces them if they are suspect.

Events

Echelon 2012
June 11 and 12, 2012

University Cultural Centre, National University of Singapore

Startup Asia Jakarta 2012
June 7 and 8, 2012

12th Floor, Annex Building, Wisma Nusantara Complex, Jl. M.H. Thamrin No. 59 Jakarta 10350, Indonesia

MMA Forum Singapore
April 23-25, 2012

Grand Hyatt Singapore

Google has added an automated scanning process that is designed to keep malicious apps out of the Android Market, the company announced on Thursday.

The new service, code-named "Bouncer", scans apps for known malware, spyware, and Trojans, and looks for suspicious behaviors and compares them against previously analyzed apps, Hiroshi Lockheimer, vice president of engineering on the Android team, said in an interview with ZDNet Asia's sister site, CNET, on Thursday.

Every app is then run on Google's cloud infrastructure to simulate how the software would operate on an Android device, he said. Existing apps are continuously analyzed, too.

"The system takes an app that's been uploaded and runs it in the cloud and monitors what the app is doing in a virtual environment, if you will," Lockheimer said.

If malicious code or behavior is detected, the app is flagged for manual confirmation that it is malware. The app could be blocked from being uploaded if it is blatantly malicious or will be removed quickly thereafter if it gets flagged by the scanning process. "It won't get uploaded at all if it is an instance of known malware," Lockheimer said.

Unlike Apple, which vets every iPhone app before it hits the iTunes Marketplace, Google does not require pre-approval for Android apps. Instead, it does the screening of the apps behind the scenes when the developers upload them to the Android Market.

Google also is analyzing new developer accounts to "prevent malicious and repeat-offending developers from coming back", the company says in a blog post today.

Google has been quietly testing Bouncer for a "number of months", long enough to see an impact, Lockheimer said. Between the first and second half of 2011 there was a 40 percent decline in the number of downloads of potentially malicious apps, the company said.

Lockheimer said he could not say how many malicious apps had been blocked or removed from the market as a result of the scanning.

Asked if Google created Bouncer in response to complaints about malicious apps on the Android Market, Lockheimer said no. "It's not like there is a rampant malware problem," he said. "Think of it as an insurance policy...to ensure that Android continues to be a safe place."

Mobile security firm Lookout found that there were about 1,000 malicious Android apps last year, but the vast majority were on unofficial, third-party sites where anything goes. But some malicious apps have made it to the Android Market, including about two dozen apps containing malware that Google yanked in May and nearly 60 malicious apps removed in March.

It's likely Bouncer will flag apps that may not technically be considered malware but are designed to perpetrate fraud against the consumer. This would include situations such as the nearly 30 fraud-related apps Google pulled from the market in December that were found to be charging premium SMS toll rates on European phones without the user's knowledge.

Asked to comment on this, a Google spokesman said: "We look for many things, this may be one of them."

The news was met with praise by security experts, including some who wondered why Android apps weren't scanned from the beginning.

"I think it is great that Google is taking steps to address the inevitability of malicious apps in their app store. What were they thinking at first?" said Chris Wysopal, CTO at application security provider Veracode, who had called on Google to scan Android apps in March of last year.

"Both Apple and Microsoft started their app stores with a validation process. Blocking known malware patterns is a no-brainer."

"I hope Google can keep up with published rootkit code and research on vulnerabilities and add these patterns to their scanners," he added. "The process should be proactive and not have a window of time when tens or hundreds of thousands of mobile users can be compromised before the malware is detected and removed."

Kevin Mahaffey, chief technology officer at Lookout, said Google's move was a "step in the right direction".

"We think it is great that Google is working with the Android community to provide an alternative to a manual curation process, allowing developers to innovate quickly while also increasing the baseline level of security for Android users," he said.

Talkback

Add your opinion

In order to post a comment, you need to be registered. (Sign In or register below)

Post your comment

ZDNet Asia Live

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/L4QzDq3H

Kodak loses patent ruling against Apple, RIM - ZDNet Asia http://t.co/O7P8U2Ya

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia http://t.co/WJCfhWLs

Kodak loses patent ruling against Apple, RIM. http://t.co/N1j7aZ6o

#radio Radio Serbia by EnjoyIT 1.0 http://t.co/nGQFvX2E

Rise in <b>Chinese</b>-funded acquisitions could trigger more hurdles http://t.co/0pXBS1HR

Rise in Chinese-funded acquisitions could trigger more hurdles: By Ellyne Phneah , ZDNet Asia on May 22, 2012 (6... http://t.co/W3SOdw2c

RT @zdnetasia: CFOs increasingly involved in IT investment decisions. http://t.co/8QrfwOSb

CFOs increasingly involved in IT investment decisions http://t.co/XD1LerFq via @zdnetasia #PrivateCloud #SC2012 #CAPEX

Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

RT @zdnetasia: Rise in Chinese-funded acquisitions could trigger more hurdles. http://t.co/VC3G3m3o

So much as we know , MTK6575 extremely integrated frequency1GHz ARM Cortex-A9 processor, the superiority of 3G / HSPA Modem, and help the...

1 hour ago by y15822137359 on 5 SaaS adoption speed bumps to avoid

Rise in Chinese-funded acquisitions could trigger more hurdles - ZDNet Asia: Rise in Chinese-funded acquisitions... http://t.co/bZaAQnRL

Rise in Chinese-funded acquisitions could trigger more hurdles http://t.co/mIsuZjnU http://t.co/erFX4aVv #arcavir

http://t.co/VNaZtseV Rise in Chinese-funded acquisitions could trigger more hurdles: "Cash r... http://t.co/N0gZZEdR http://t.co/wiqY9ktt

Rise in Chinese-funded acquisitions could trigger more regulatory clearance issues overseas http://t.co/cvLSpTwo #in

I reckon your view: "CRM is strategy, not software", if a company replicating the approach uses in ERP implementation into CRM, what they...

1 day ago by wykoong on Gartner: Mobile CRM gives better ROI than social

This video will teach you about the Excel fill handle but also provide you with a workook to download... http://www.youtube.com/watch?v=...

1 day ago by TradeBrother on A quick fill handle trick for Microsoft Excel

waiting...

3 days ago by eapete on What should count in a company's market value?

Boy, you've opened a can of worms now.

Wait for the rants & raves.

3 days ago by eapete on What should count in a company's market value?

I was puzzling before this whether to replicate the success formula we executed for a financial institute, and come out with a standard s...

4 days ago by wykoong on Drop the egos, copy ideas, then innovate