Connect with us

Hi, what are you looking for?

SecurityWeekSecurityWeek

Mobile & Wireless

What’s Hiding in Your Mobile Apps? Lookout MSEC Aims to Find Out

The new Mobile Security Exposure Center creates SBOMs for enterprise mobile apps to uncover vulnerable components, dependencies and hidden risks.

Mobile Attack Surface

Mobile devices present a serious security problem: they operate outside the security perimeter and beyond the visibility of the security team. While security may know what applications live on those devices, they rarely understand the components and dependencies that comprise those applications; nor what vulnerabilities are buried within those components.

Jim Dolce, CEO at Lookout, gave an example: WolfSSL. It’s a small, fast, and portable SSL/TLS library written in ANSI C, designed mainly for devices with limited memory – and it exists on more than a billion devices. “If you have a banking app on a mobile device for online banking, that app is likely using WolfSSL. It has a very serious vulnerability. If exploited by a bad actor, it can mimic your bank, and when you put in your credentials, it will steal your banking credentials.” 

The Mythos Glasswing project found and publicized this WolfSSL vulnerability. So, the bad guys know the banking app may be vulnerable, but does the security team know that employees are using it?

“Knowing an application’s name and version reveals only a fraction of its risk profile,” explains Lookout. “Security teams need visibility into the software components, dependencies, and vulnerabilities embedded beneath the surface.”

This is what the firm’s new Mobile Security Exposure Center (MSEC) provides: full visibility into (rather simply ‘about’) an organization’s potentially vast mobile fleet. In a nutshell, MSEC examines every device in the fleet, so it knows what apps are present. It then creates its own proprietary software bill of materials (SBOM) from the binary for the different apps.

From this SBOM it learns every component within the app and correlates those components with the vulnerability databases (such as the KEV list) that exist. The results are fed into the organization’s CTEM to assist the security team to take any necessary remediation steps.

Advertisement. Scroll to continue reading.

“The system will identify which apps use WolfSSL, the version of that app, the user and the device that is using that app, and all of that information then can be used to remediate the exposure. So MSEC basically identifies the exposure and provides that information,” continued Dolce. This applies to all the software components of all the apps on all the mobile devices.

MSEC also complements Lookout’s existing AI Visibility & Governance product. “While AI Visibility & Governance helps organizations understand AI adoption and usage across the enterprise,” says Lookout, “MSEC reveals the software composition and exposure profile of those applications. Together, they provide a more complete view of application risk, security, and governance.”

The result, it continues, is “A shift from reactive application management to proactive exposure management.”

However, there is a slight issue here. MSEC correlates the app components it unearths in its SBOM creation with the vulnerability databases that exist. We’ve mentioned one – the KEV list, or the Known Exploited Vulnerabilities Catalog produced by CISA. The clue to the issue is in the name, known vulnerabilities. No vulnerability database can include unknown vulnerabilities. So, while MSEC can help remediate known vulnerabilities, there is always the possibility that a new frontier AI model will unearth new vulnerabilities.

Lookout is obviously aware of this, and has it covered. 

“Bad actors can use frontier AI models, Mythos as an example, in order to find vulnerabilities and exploit them,” agreed Dolce. “That’s the offensive use of a frontier AI model. Well, Lookout can use that same model defensively. We can go beyond KEV and the other vulnerability databases by using the frontier models ourselves to find unknown vulnerabilities across the SBOM. That will be the next iteration of MSEC.” 

He continued, “We will take our SBOM and use the frontier AI models defensively to go and find unknown vulnerabilities for ourselves, and catalog those as well.” 

But it all starts with knowing the app inventory across the enterprise mobile fleet, creating the accurate SBOM for all the apps in the fleet, and then correlating the app components against known vulnerability databases, and then, he added, “The last step is find unknown vulnerabilities using the same frontier AI models defensively that the bad guys are using offensively.”

Related: Mobile Attack Surface Expands as Enterprises Lose Control

Related: FBI Warns of Data Security Risks From China-Made Mobile Apps

Related: Mobile Security: Verizon Says Attacks Soar, AI-Powered Threats Raise Alarm

Related: Chinese Hackers Turn Smartphones Into a ‘Mobile Security Crisis’

Written By

Kevin Townsend is a Senior Contributor at SecurityWeek. He has been writing about high tech issues since before the birth of Microsoft. For the last 15 years he has specialized in information security; and has had many thousands of articles published in dozens of different magazines – from The Times and the Financial Times to current and long-gone computer magazines.

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing for the latest cybersecurity threats, trends, and expert insights.

Trending

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest threats, trends, and technology, along with insightful columns from industry experts.

Join this live webinar as we explore why exploitation is outpacing remediation, where risk is growing fastest, and what security leaders can do to close the gap before attackers take advantage.

Register

CodeSecCon bridges the gap between dev and security. Discover best practices for secure coding, innovative risk-reduction tools, and safe AI integration to cultivate a true DevSecOps culture. Safely secure your apps!

Register

People on the Move

Barry Childe has joined data sciences tech company Datavault AI as Chief Information Security Officer.

John DeSimone, the former CEO of Nightwing, has been named Chief Operating Officer at Everfox.

Sectigo has appointed Prem Hareesh as Corporate Chief Technology Officer.

More People On The Move

Expert Insights

Daily Briefing Newsletter

Subscribe to the SecurityWeek Email Briefing to stay informed on the latest cybersecurity news, threats, and expert insights. Unsubscribe at any time.