
Signed, sealed, delivered
By Tom Espiner
Published: 20 July 2009 10:34 GMT
The Symbian Foundation has acknowledged that its process for keeping malicious applications off Symbian OS-based phones needs improvement, after a Trojan horse program passed a security test.
The botnet-building Trojan, which calls itself Sexy Space, passed through the group's digital signing process, Symbian's chief security technologist Craig Heath said on Thursday. Heath said the group is working on improving its security auditing procedure.
"When software is submitted, we do try to filter out the bad eggs," Heath told silicon.com's sister site ZDNet UK. "When apps are submitted, they are scanned. We are looking at how they could be scanned better."
Developers must submit the mobile applications they build to the Symbian Foundation for checking in order for the applications to be accepted by handsets with the Symbian operating system. Once the submission has been accepted, the applications are digitally signed by Symbian. Digital signatures, which are cryptographic security features, are designed to provide an amount of assurance that software for download comes from a trusted source.
The first stage of Symbian's signing process, antivirus scanning, is done automatically using an antivirus engine. Once an application has been submitted and scanned, random samples are then submitted for human audit.
In the case of the low-risk Sexy Space Trojan, which was disguised as a legitimate application called ACSServer.exe, the Trojan had not been subjected to human scrutiny, said Heath.
The Symbian Foundation became aware that Sexy Space was a Trojan two weeks ago, and the signature was revoked then, Heath said. However, an error on Symbian's servers meant the application was available for download until this week.
On the Symbian Signed website, the group's antivirus-scanning provider is identified as Finnish company F-Secure. Mikko Hyppönen, F-Secure's chief research officer, told ZDNet UK on Friday that the malware authors had probably tested their Trojan against the F-Secure antivirus engine to circumvent security measures.
"Virus writers scan their malware, and keep modifying it until it passes the filters," said Hypponen. "Obviously, the signing process can be and has been circumvented."
Symbian uses graded signing processes for mobile applications, according to Hyppönen. The Sexy Space malware went through its express signing process, which is designed for freeware. "It shows the express signing process is not foolproof, but it's still much better than the apps not being signed at all," said Hypponen.
Symbian is in the process of upgrading its automated scanning processes, Heath said, adding that human auditing is also going to be improved. However, human auditing will probably not be expanded, as this introduces cost and time delays into the process, he said.
The group is looking to automate more of the work involved in publishing applications. "Today, most of the processes behind [Symbian] require manual tasks," said the organisation in a blog post on the launch of its new Symbian Horizon programme. "Our goal for the near future is to develop a system that will automate this work allowing us to scale the program to include as many apps as possible."
The Symbian Horizon programme intends to select applications submitted by developers and then support them through their development and submission to mobile app stores. Symbian said that one of the aims of Horizon was to automate the publication of apps as far as possible.
Original article: Symbian admits Trojan slip-up from ZDNet UK
Your details, as submitted by you, will only be used in conjunction with this vacancy. Experience using MS SQL Server 2000/ 2005/ 2008 - Backup ...
Your details, as submitted by you, will only be used in conjunction with this vacancy. By submitting your CV and cover letter to us, you give express ...
Your details, as submitted by you, will only be used in conjunction with this vacancy. By submitting your CV and cover letter to us, you give express ...
Agenda Setters 2009
Welcome to the ninth annual Agenda Setters poll – silicon.com's list of the top 50 most influential individuals in the technology and IT industries, from techies and CIOs to entrepreneurs and business leaders. Find out more in our latest special report.
Stories from the web...
Copyright © 2008 CBS Interactive Limited. All rights reserved. Top of page
Tim Ferguson Exclusive: Former MySQL boss Marten Mickos talks open source Why Microsoft could become one of the "biggest friends of open source" and why Oracle getting its hands on MySQL could be "one of the biggest open source coups ever"...
Naked CIO Naked CIO: Cloud computing more expensive than we thought? Smart IT leaders will examine the impact of how they pay for tech