MENLO PARK, Calif., April 16, 2015 (GLOBE NEWSWIRE) -- Enterprises face a greater threat from the millions of apps their employees casually use each day than from mobile malware. Through 2017, 75 percent of all mobile security breaches will be through apps, not through deep technical attacks on the OS, according to Gartner1. Called 'riskware,' these seemingly harmless apps expose enterprise users to data leakage, credential theft and the exfiltration of private information used to target employees in precise, advanced attacks. Attackers can also use mobile apps to target enterprise users, gain valuable information about corporate networks, employees and directories, and socially engineer passwords.
Marble Security has found that in an average enterprise with 2,000 users of BYOD Android and iOS devices:
Enter Marble Security's AppHawk, the just-announced enterprise mobile threat intelligence and defense service that determines which iOS and Android apps send personal and corporate data beyond the enterprise, what data is transmitted and where that data is sent, and assesses the risk to the enterprise. AppHawk, which is tightly integrated with leading mobile device management (MDM) and enterprise mobility management (EMM) solutions including MobileIron, provides dynamic app threat detection and protection while ensuring employee privacy. AppHawk offers automated controls for malicious apps that leak sensitive corporate data, dynamically assesses threat levels and where data is sent, and assures safety of BYOD program rollouts.
AppHawk is powered by Marble Security's app analysis engine and database of more than 3 million analyzed apps from 500,000 publishers. Each app is scored against more than 1,000 potentially malicious and privacy-leaking behaviors to determine whether it is risky or safe. The locations that apps communicate to are evaluated against threat intelligence of tens of millions of malicious locations.
"Risky apps frequently lead to advanced persistent threats (APTs), spear phishing attacks on employees and leaked corporate data," said Dave Jevans, CEO, chairman and CTO of Marble Security. "Without considering the potentially negative effects on their personal identities and workplaces, enterprise users nonchalantly give riskware apps sweeping permissions, not realizing that their data may be sent to remote servers and advertising networks all over the world, where it can be mined by cybercriminals and hostile governments seeking access to corporate networks. AppHawk uses deep analysis to identify risks and dynamically assess threats to the enterprise."
To combat these often overlooked dangers, AppHawk's automated workflow identifies a dangerous app on the employee's device, prompting an alert to remove it. If the employee fails to do so in time, AppHawk quarantines the device. Once the app is deleted, corporate services are reinstated.
The service's optional mobile client educates employees by showing if they've downloaded dangerous apps at a glance, advising on deletion and graphically mapping where in the world an app is sending their data.
The easily configurable AppHawk administrative console uses a dashboard to show the overall state of app security in mobile deployments. Enterprise controls include:
Risky apps that violate users' privacy may:
To learn more, visit Marble's website or read the AppHawk datasheet.
Recent Mobile Threat Stats from Marble Labs
Here are some highlights from Marble's February 2015 Mobile Threat Report:
Resources
About Marble Security
Marble Security is the leading provider of mobile threat intelligence and defense. Marble Labs, the company's research and response team of analysts, developers and cybercrime specialists, has analyzed millions of Android and iOS apps, detecting apps with malicious and privacy-leaking behaviors that frequently lead to advanced persistent threats (APTs), spear phishing attacks on employees and other information security risks.
Marble's security apps and services deliver comprehensive, correlated threat intelligence for Android and iOS devices. Marble integrates directly with mobile device management (MDM) or enterprise mobility management (EMM) solutions, providing granular risk control for bring-your-own-device (BYOD) programs. Marble Security is a Security, Reputation and Risk Management partner with MobileIron (Nasdaq:MOBL). www.marblesecurity.com
1 Gartner, 2014, http://www.gartner.com/newsroom/id/2846017