Home

Android Anti-Malware Tests Show Big Detection Differences

Comments | Larry Seltzer, BYTE | March 06, 2012 04:00 AM

Category: Tablets, Smartphones, Freeware

Anti-malware test lab AV-Test has released results for 41 Android anti-malware packages that it tested for effectiveness. The results show vast differences in performance, but there are several important caveats to the tests.

More Insights

Webcasts

More >>

White Papers

More >>

Reports

More >>

The products tested ran the gamut, from free apps made by companies you've never heard of to pricey products from big-time security vendors. The only objective of the testing was to measure detection rates. Although detection might be the most important characteristic of an anti-malware product, it isn't the only one--so the report doesn't endorse or condemn any of the products tested.


Growth of Android malware threats identified by AV-Test since January 2011.

Malware finds a welcome mat in Android because of certain decisions Google made to ease the process of developing and distributing apps. The cost and qualifications for distributing apps through Google's Android Market are lower than those for Apple's App Store. Android also lets users allow software to be installed from other stores, whereas iOS users must "jailbreak" their phones to do so. Many of the third-party Android markets are not very picky about checking the apps they accept and often offer malware, but malware has been found in Google's market, too. As a result, Google has, in recent months, ratcheted up its automated scanning of submissions to the Market. The malware that AV-Test tested for included phishing and banking trojans, spyware, bots, root exploits, SMS fraud, premium dialers, and fake installers.

[ Larry Seltzer argues that whitelisting is the best way for enterprises to keep their Android devices safe. Read about one whitelisting solution..]

AV-Test doesn't provide exact detection rates--perhaps to discourage unjustified comparisons. Instead it split the products into five detection groups: >90%, >65%, >40%, >0% and 0%. Most of the products detected more than 40% but less than 65% of the malware threats. Six found none. Seven found more than 90%. They are:

  • avast! Mobile Security
  • Dr. Web anti-virus Light
  • F-Secure Mobile Security
  • IKARUS mobile Security LITE
  • Kaspersky Mobile Security (Lite)
  • Lookout Security & Antivirus
  • Zoner AntiVirus Free
The second-tier products might well be good choices, too--the failure to detect one type of malware might not matter in certain areas.

As for the packages that found nothing, it's not clear whether they weren't functioning properly or are just bad products. None detected the Eicar test file, which is a specific non-malicious file that all products are supposed to detect and thereby prove that they are running.

AV-Test made some trade-off decisions for the testing that one has to take into account when considering the test results. For instance, in order to make it possible to run a large number of tests, AV-Test chose to use the Android emulator that comes with Google's Android SDK, set for Gingerbread (Android 2.3, API level 10). The advantage of the emulator is that it lets testing scale much more easily than on a phone. On the other hand, because the emulator is not a phone--for instance, it doesn't have a phone number--it might cause malware to fail or behave differently. Some apps would not run it at all. For those apps, AV-Test used a Samsung Galaxy Tab running Android 2.2 (Froyo) and a Samsung Galaxy Nexus running Android 4.0 (Ice Cream Sandwich).

Another possible problem is that some Android malware still falls into a gray area that is not strictly defined as malware. If an app throws up annoying ads is it malware? Some products might not think so.

AV-Test did not consider the other features a product might have, such as backup or anti-theft protection.

You can make a case that by avoiding shady stores and using common sense, you can avoid Android malware without installing anti-malware software. However, AV-Test concludes that you should at least consider running one of them. There are attacks which could get past Google, at least for a while, and some of the products work well enough that some day you might be happy you took the trouble to install them.

Follow Larry Seltzer and BYTE on Twitter, Facebook, LinkedIn, and Google+:



Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

BYTE encourages readers to engage in spirited, healthy debate, including taking us to task. However, BYTE moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. BYTE further reserves the right to disable the profile of any commenter participating in said activities.

COMMENTS

Tune In to BYTE
Facebook Twitter LinkedIn Newsletter RSS
Whitepapers
whitepaper
In this paper you will learn the five trends shaping the future of enterprise mobility. Learn how the rise of social media as a business application, the lurring between work and home, the emergence of new mobile devices, the demand for tech savvy employees and changing expectations of corporate IT will fundamentally change the workplace.
whitepaper
In a survey of more than 1,700 information workers (iWorkers) in North America, notebooks, desktops, and smartphones were found to be “must-have” devices, while tablets, slates, and netbooks were relegated to “nice-to-have” status, according to a commissioned study conducted by Forrester Consulting on behalf of Dell and Intel.
Sponsored by: Dell
Upcoming Events