{"id":51165,"date":"2017-11-08T05:28:25","date_gmt":"2017-11-08T05:28:25","guid":{"rendered":"https:\/\/www.biphoo.com\/bipnews\/?p=51165"},"modified":"2017-11-08T05:28:25","modified_gmt":"2017-11-08T05:28:25","slug":"when-google-play-protect-fails","status":"publish","type":"post","link":"https:\/\/www.biphoo.com\/bipnews\/technology\/security\/when-google-play-protect-fails.html","title":{"rendered":"When Google Play Protect fails"},"content":{"rendered":"<h2 style=\"text-align: justify\"><span style=\"font-size: 18pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">When Google Play Protect fails<\/span><\/strong><\/span><\/h2>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">When Google Play Protect fails:- I&#8217;ve written a lot about Android security over the years \u2014 and more often than not, it&#8217;s the same ol&#8217; story time and time again:<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">A company that sells mobile security software finds some theoretical threat \u2014 something that (a) hasn&#8217;t affected any actual users in the real world and (b) couldn&#8217;t affect any actual users in the real world, outside of a highly improbable scenario in which all native security measures are disabled and the user goes out of his way to download a questionable-looking app from some shady porn forum.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Those critical points then become footnotes in a fear-inducing narrative, complete with a carefully crafted memorable name for the Big, Bad Virus\u2122 and a strongly worded reminder about how only such-and-such security software can possibly keep you safe.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">It&#8217;s an effective form of marketing \u2014 that&#8217;s for damn sure. But it&#8217;s also about as sensational as can be.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">If you&#8217;ve read this column for long, you know about the long-standing realities of Android security and why these sorts of highly publicized hype campaigns are generally best taken with a grain of salt. Lately, though, we&#8217;ve seen a handful of genuine malware situations that don&#8217;t fall into that same category of silliness \u2014 things like the headline-making WireX botnet, in which a few hundred internet-traffic-generating-apps made their way into the Play Store and onto users&#8217; devices, or the more recent phony WhatsApp incident, in which an app pretended to be WhatsApp and then just served up ads to anyone who installed it.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">Those were both the real deal, and the native Google Play Protect security system absolutely failed to recognize the breaches and stop them before they affected a fair number of Android device owners. Even if the level of direct harm to end-users was ultimately pretty minimal \u2014 basically just having their devices send out web traffic or show some stupid ads, behaviors that&#8217;d stop as soon as the offending app was uninstalled \u2014 these types of programs clearly have no place in the Play Store and shouldn&#8217;t be getting past Google&#8217;s gates.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">You know what, though? There&#8217;s still no reason to panic. And, as I wrote for CSO.com this week, you still don&#8217;t need a third-party security app to stay safe. There&#8217;s a strong argument, in fact, that installing one is pointless at best \u2014 and at worst, could actually be counterproductive to your personal and\/or company-oriented interests.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">I&#8217;ll direct you to CSO for the full context on that point, because there are quite a few layers to it. Here, I want to delve a bit more deeply into what actually happens in a situation like WireX, when Google Play Protect fails, and how such missteps can take place on a practical level \u2014 all directly from the perspective of the company that controls the platform.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">I had the chance to ask Google&#8217;s director of Android security, Adrian Ludwig, about this very area. And while the discussion proved to be a bit superfluous to my main story, I thought it made for an interesting little sidebar that&#8217;d be worth sharing here.<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Here&#8217;s what Ludwig had to say:<\/span><\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">On how these types of apps get through the gates and go undetected for as long as they occasionally do, given the layers of protection in place:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;The challenge that all detection technology runs into, inclusive of Google Play Protect, is when we see a completely new family coming from a different environment \u2014 especially if [the apps] are on the borderline of behavior that might be considered to be potentially harmful and not quite potentially harmful.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">On the success vs. failure rate:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;Most of the time when we see those variations, our automated systems are able to detect them and take action on them very quickly. In fact, the improvements that we&#8217;ve been making in machine learning over the past six months to a year have been primarily focused on \u2014 and very effective at \u2014 finding new variations on existing families.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">And on the perception of successes vs. failures:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;We have an extraordinarily high bar in terms of the expectations of what [our] protections will provide, which is being able to scan all the applications, being able to discover every potential bad behavior, and never making a mistake \u2014 and we come very, very close to that. Our goal is to get to a point where there&#8217;s fewer than one in a million apps that make it through Google Play Protect that represent a risk to the user. We&#8217;re not there yet, but we&#8217;re well above 99.9% in terms of our ability to detect things, and we&#8217;re continuing to get stronger.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">On the challenges of detecting patterns that don&#8217;t immediately raise red flags:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;It&#8217;s not necessarily a type of app we&#8217;ve seen in the past. It might [involve] relatively low-risk abusive ads, for example, or [something that] makes network connections that are not obviously harmful but that on further inspection, we&#8217;re able to track down and see that there&#8217;s an issue.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">And how working with partners, as in the WireX investigation, can be crucial to the discovery process:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;They have visibility a lot of times to what&#8217;s happening on the server side of some of these malware networks, and so sometimes it&#8217;s only in partnership with the data they have through their installations in those environments that the actual bad behavior is visible. On the Android side, there&#8217;s [sometimes] nothing about the traffic that is obviously harmful to the user.&#8221;<\/span><\/p>\n<p style=\"text-align: justify\"><span style=\"font-size: 14pt\"><strong><span style=\"font-family: Arial, Helvetica, sans-serif;color: #000000\">Finally, on the curious timing of Android malware publicity campaigns:<\/span><\/strong><\/span><\/p>\n<p style=\"text-align: justify\">\n<span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 14pt;color: #000000\">&#8220;Certainly by the time there&#8217;s publicity around one of these [malware] families, it&#8217;s already gonna have been cleaned up \u2014 so the publicity around the families tends to be a way to draw attention to security vendors and the products that they make available. By the time something becomes public, Google Play Protect already has rolled out its protections, [and] the applications have been taken down and removed.&#8221;<\/span><\/p>\n<p><span style=\"font-family: Arial, Helvetica, sans-serif;font-size: 8pt\">Source:-\u00a0https:\/\/www.computerworld.com\/article\/3236194\/android\/google-play-protect.html<\/span><\/p>\n<div class=\"fb-background-color\">\n\t\t\t  <div \n\t\t\t  \tclass = \"fb-comments\" \n\t\t\t  \tdata-href = \"https:\/\/www.biphoo.com\/bipnews\/technology\/security\/when-google-play-protect-fails.html\"\n\t\t\t  \tdata-numposts = \"10\"\n\t\t\t  \tdata-lazy = \"true\"\n\t\t\t\tdata-colorscheme = \"light\"\n\t\t\t\tdata-order-by = \"social\"\n\t\t\t\tdata-mobile=true>\n\t\t\t  <\/div><\/div>\n\t\t  <style>\n\t\t    .fb-background-color {\n\t\t\t\tbackground: #ffffff !important;\n\t\t\t}\n\t\t\t.fb_iframe_widget_fluid_desktop iframe {\n\t\t\t    width: 630px !important;\n\t\t\t}\n\t\t  <\/style>\n\t\t  ","protected":false},"excerpt":{"rendered":"<p>When Google Play Protect fails When Google Play Protect fails:- I&#8217;ve written a lot about Android security over the years \u2014 and more often than not, it&#8217;s the same ol&#8217; story time and time again: A company that sells mobile security software finds some theoretical threat \u2014 something that (a) [&hellip;]<\/p>\n","protected":false},"author":12,"featured_media":51174,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[974],"tags":[95399,95400,95403,85873,95402,95401],"class_list":["post-51165","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-security","tag-android-malware-publicity-campaigns","tag-android-security","tag-few-hundred-internet-traffic-generating-apps","tag-google-play-protect","tag-headline-making-wirex-botnet","tag-highly-improbable-scenario"],"_links":{"self":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/51165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/users\/12"}],"replies":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/comments?post=51165"}],"version-history":[{"count":0,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/posts\/51165\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media\/51174"}],"wp:attachment":[{"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/media?parent=51165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/categories?post=51165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.biphoo.com\/bipnews\/wp-json\/wp\/v2\/tags?post=51165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}