Android處境兇險(xiǎn),,威脅并非蘋果
????移動(dòng)惡意軟件的威脅正日益增長(zhǎng),,但同時(shí)也給手機(jī)殺毒軟件生產(chǎn)廠商,,特別是針對(duì)Android設(shè)備的廠商帶來(lái)巨大商機(jī)。 ????位于舊金山的新創(chuàng)企業(yè)Lookout移動(dòng)安全公司最近發(fā)布報(bào)告指出,,今年,,30%的Android手機(jī)用戶將會(huì)遭遇網(wǎng)絡(luò)安全威脅。報(bào)告同時(shí)指出,,目前Android用戶遭遇惡意軟件的幾率是6個(gè)月前的2.5倍之多,。據(jù)估計(jì),2011年上半年,,大約50萬(wàn)到100萬(wàn)Android用戶遭遇惡意軟件襲擊。 ????Lookout聯(lián)合創(chuàng)始人兼首席技術(shù)官凱文?馬哈菲稱:“在PC平臺(tái),,黑客入侵必須破解他人的賬號(hào),,或是設(shè)法取得他們的信用證書。而在移動(dòng)平臺(tái),,犯罪分子攫取錢財(cái)?shù)碾y度要低得多,。他們可以直接從用戶的手機(jī)話費(fèi)中非法獲利?!?Lookout的主要業(yè)務(wù)是出售安全應(yīng)用程序,,它能在用戶手機(jī)丟失或被盜竊的情況下保護(hù)手機(jī),,還能防御釣魚網(wǎng)站和惡意網(wǎng)站的侵襲。 ????當(dāng)然,,Android并不是唯一一款成為犯罪分子目標(biāo)的移動(dòng)操作系統(tǒng),,而瞄準(zhǔn)手機(jī)安全領(lǐng)域滾滾商機(jī)的也并非只有Lookout一家公司。蘋果(Apple)的iOS以及其它平臺(tái)同樣受到惡意軟件困擾,,不過(guò)Lookout等公司指出,,針對(duì)谷歌Android系統(tǒng)的惡意軟件最為常見(jiàn)。Android是一款流行的操作系統(tǒng),,谷歌(Google)宣稱已占據(jù)全球智能手機(jī)市場(chǎng)的幾乎半壁江山,。Lookout稱,今年上半年,,Android惡意應(yīng)用程序數(shù)量從80激增到400,。上周,企業(yè)軟件供應(yīng)商CA Technologies的研究人員稱,,他們發(fā)現(xiàn)一種新的Android惡意軟件能對(duì)感染手機(jī)的通話直接錄音,。 ????美國(guó)電話電報(bào)公司(AT&T)首席安全官愛(ài)德華?阿莫魯索說(shuō):“蘋果是封閉的生態(tài)系統(tǒng),但谷歌不一樣,。谷歌向市場(chǎng)開(kāi)放Android系統(tǒng),,而一旦選擇開(kāi)放,面臨的安全威脅也會(huì)隨之大增,?!?/p> ????那么解決移動(dòng)安全問(wèn)題的有效途徑是什么呢?答案并不意外,,美國(guó)電話電報(bào)公司稱,,解決該問(wèn)題的有效途徑是從網(wǎng)絡(luò)入手。在曼哈頓,,阿莫魯索帶領(lǐng)著一個(gè)由40名研究人員組成的實(shí)驗(yàn)室,,他們正在開(kāi)發(fā)一款移動(dòng)安全產(chǎn)品,美國(guó)電話電報(bào)公司希望能將其銷售給企業(yè)和個(gè)人用戶,。 ????阿莫魯索表示:“在移動(dòng)領(lǐng)域,,設(shè)備只占據(jù)(用戶)體驗(yàn)的很小部分,網(wǎng)絡(luò)則占據(jù)了(用戶)體驗(yàn)的大部分,。壞處是,,一旦體驗(yàn)不佳,我們就成了眾矢之的,;好處是,,它使我們有機(jī)會(huì)提高設(shè)備的安全性?!?/p> ????當(dāng)然,,美國(guó)電話電報(bào)公司并非惟一進(jìn)軍移動(dòng)安全市場(chǎng)的運(yùn)營(yíng)商,。在最近舉辦的《財(cái)富》科技頭腦風(fēng)暴大會(huì)上(Fortune Brainstorm TECH conference),威瑞森無(wú)線(Verizon Wireless)宣布將與Lookout合作,,檢測(cè)旗下V Cast應(yīng)用程序商店的惡意移動(dòng)應(yīng)用,。與此同時(shí),邁克菲(McAfee)和賽門鐵克(Symantec)等知名公司也紛紛推出了手機(jī)安全應(yīng)用,,這些公司在上世紀(jì)90年代都曾在PC機(jī)領(lǐng)域殺毒軟件領(lǐng)域創(chuàng)造過(guò)佳績(jī),。 ????接下來(lái)是谷歌,該公司表示為了將“Android平臺(tái)的安全威脅降到最低”,,已花費(fèi)大量精力對(duì)層出不窮的應(yīng)用程序掃描惡意軟件,。谷歌還與硬件廠商和運(yùn)營(yíng)商積極合作,一旦確定安卓市場(chǎng)(Android Market)出現(xiàn)惡意軟件,,他們將及時(shí)發(fā)布安全補(bǔ)丁,。 ????去年3月,,在安卓市場(chǎng)出現(xiàn)多款惡意應(yīng)用程序之后,,谷歌在博客上發(fā)文稱:“安全是Android團(tuán)隊(duì)的首要任務(wù)。我們將致力于開(kāi)發(fā)新的防護(hù)措施,,以避免將來(lái)再遭遇類似攻擊,。” ????與此同時(shí),,Lookout的報(bào)告還指出,,攻擊者正在使用“惡意廣告”等新技術(shù),而且他們的破壞力也在不斷升級(jí),,他們能控制用戶的手機(jī),、個(gè)人數(shù)據(jù)和資金。馬哈菲表示:“解決安全問(wèn)題沒(méi)有萬(wàn)全之策,。惡意軟件問(wèn)題非常嚴(yán)峻,,整個(gè)生態(tài)系統(tǒng)中的所有人都必須參與其中?!?/p> ????恐怕更可能出現(xiàn)的局面是生態(tài)系統(tǒng)中的所有人都會(huì)加入競(jìng)爭(zhēng),,但無(wú)論如何,移動(dòng)安全軟件現(xiàn)在才剛剛起步,。 ????譯者:項(xiàng)航 |
????Mobile malware is on the rise, and so is the market for companies that develop anti-virus software for cell phones -- particularly Android devices. ????According to a recent report from San Francisco-based startup Lookout Mobile Security, three out of 10 Android phone users will encounter a web-based threat on their device this year. The report also says that Android users are 2.5 times more likely to encounter malware today than they were six months ago. An estimated half million to one million people were affected by Android malware in the first half of 2011. ????"On the PC, you have to hack someone's account or get access to their credentials," says Kevin Mahaffey, co-founder and CTO of Lookout, which sells a security app that protects your phone if it's lost or stolen and blocks phishing and malware sites. "On mobile it's much easier for the bad guys to make money. They can directly monetize by charging to a user's phone bill." ????Of course, Android is not the only mobile operating system that the "bad guys" are targeting, and Lookout isn't the only company trying to capitalize on the growing security threats on cell phones. Apple's (AAPL) iOS and other platforms are not immune to malware, though reports like Lookout's suggest malicious applications have been most common on Google's (GOOG) popular Android OS. It now claims almost 50% of the worldwide smartphone market. According to Lookout, the number of Android apps infected with malware rose from 80 to 400 in the first half of this year. Just this week, researchers at enterprise software vendor CA Technologies said they uncovered new Android malware that can actually record conversations on infected phones. ????"Apple is a closed ecosystem, but Google's different," says Ed Amoroso, chief security officer at AT&T (T). "Google opened up the marketplace and once you open things up the security threat increases significantly." ????So what's the right approach to mobile security? Not surprisingly, AT&T says the answer to the security problem is in the network. Amoroso heads up a Manhattan-based lab of about 40 researchers who are working on a mobile security product that AT&T hopes to sell to both enterprise customers and consumers. ????"With mobility, the device is a small part of the experience and the network is a big part of the experience," says Amoroso. "That's bad in the sense that when the experience is lagging we take it on the chin, but it's also great because it gives us the opportunity to enhance the security." ????Naturally, AT&T's not the only carrier hoping to get into the mobile security market. At the recent Fortune Brainstorm TECH conference, Verizon Wireless (VZ) announced it would partner with Lookout to detect mobile threats on its V Cast App Store. Big-name security companies like McAfee and Symantec—who made their mark selling antivirus software for PCs in the 90s—have also come out with security features for phones. ????And then there's Google, which says it has made significant efforts to "minimize the security risks on Android" by scanning incoming applications for malware. It also works with its hardware and carrier partners to push security patches when a malicious app does make it into the Android Market. ????"Security is a priority for the Android team," Google said in a blog post last March, after a number of malicious apps became available in the Android Market. "And we're committed to building new safeguards to help prevent these kinds of attacks from happening in the future." ????In the meantime, Lookout's recent report says attackers are using new techniques like "malvertising" and upgrade attacks to take control of users' phones, personal data, and money. "There's no silver bullet in security," says Lookout's Mahaffey. "The malware problem is so hard, that it will take participation from everyone in the ecosystem." ????Competition from everyone in the ecosystem may be more like it, but either way it's still early days for mobile security software. |