“The good, the bad and the ugly” is a well-known expression, but when it comes to mobile phishing, I suggest shifting the order. Let’s talk about the bad, the ugly and the good.
Phishing is one of the most dominant attack techniques in cyber security. Phishing has a very low barrier of entry, attacks can be set up in minutes and are challenging to detect at scale as sites are taken down or moved just as quickly.
Phishing attacks are increasing in alarming numbers. A recent Kaspersky Lab analysis revealed that in 2018, there were 482.5 million attempted phishing attacks, which is more than double the attacks in 2017. The 2018 Verizon Data Breach Investigations report found that 90% of cyber attacks begin with phishing.
Because email is the most common communication vector for phishing attacks, most organizations have attempted to stop phishing via email or web gateways or next gen firewalls. Even with this form of protection in place, a recent study has found there’s still a lot of room for improvement. Additionally, corporate solutions do not address half of email based threats: those that occur in users’ personal email solutions.
But email isn’t the sole phishing mechanism anymore… mobile devices open up novel vectors for phishing attacks. Hackers phish mobile device users in two primary ways:
While anti-phishing solutions (those trying to prevent access to phishing sites) like email gateways protect traditional endpoints, there hasn’t been a comprehensive and effective mobile anti-phishing solution. There are many unique challenges around mobile devices that complicate the requirements for an effective mobile anti-phishing solution, e.g.,
Having taken all of the “bad” and “ugly” into consideration, Zimperium zIPS is once again leading the industry by providing the “good” – – the first and only on-device, machine learning-based mobile phishing detection solution.
Solving for all of the mobile phishing challenges, zIPS meets all the following requirements:
Zimperium secures mobile devices through on-device detection, rather than requiring remote servers which can violate user’s privacy and can be undermined when attackers control the network. By combining the new phishing detection with our industry leading detections for the other major attack vectors, Zimperium zIPS is now the only solution that has on-device, machine learning-based detections of both phishing sites and phishing apps, e.g.:
Zimperium zIPS is the only on-device, machine learning-based phishing solution for mobile devices. Backed by zLabs research and millions of mobile endpoints, Zimperium provides complete protection for the 60% of your endpoints that are currently exposed and introducing risk to your organization. For more information contact us here.
Madhav brings more than 25 years of experience building and delivering enterprise cyber security products for companies. As Chief Product Officer at Zimperium, Madhav leads all aspects of Zimperium’s products, including product management, engineering and IT/Devops operations.