Q. Does the Nexus 7 tablet need a security app like Norton or McAfee on it? If so, what apps do you recommend?
Debbie, Amelia Island, Fla.
A. The Nexus 7, which runs the Android operating system, is part of a booming ecosystem of mobile devices that can certainly fall prey to malicious hackers.
But despite the very real threat, recommending a security solution for your portable gadget is a little more difficult than for your desktop.
When it comes to the latter, there’s a common refrain I hear from my go-to geeks. Keep your system updated. Use shrink-wrapped antivirus software. Avoid downloading things from unfamiliar sources.
These tips don’t exactly correlate to tablets and smartphones.
System updates are often out of users’ hands, antivirus software is only available through centralized app markets and with so many quality startups making apps, the “unfamiliar source” rule isn’t a terribly good guiding principle for mobile.
There’s also evidence that antivirus apps, in general, are having an incredibly hard time keeping up with the rapid pace of mobile malware evolution.
Apps put to the test
Researchers with N.C. State’s Android Malware Genome Project collected and analyzed 1,200 samples of malicious mobile software that hit the market between August 2010 and October 2011. Their research showed the number of new malware families in July 2011 – just one month – beat out everything they had collected in all of 2010.
With their samples in hand, the N.C. State team also tested the effectiveness of four mobile antivirus apps: AVG (free to $14.99), Lookout (free to $2.99/month), Norton (free) and TrendMicro (free).
In a paper presented in May 2012, NCSU computer scientists Yajin Zhou and Xuxian Jiang reported that Lookout and TrendMicro detected the highest percentage of threats at 80 and 77 percent, while AVG trailed at about 55 percent. Norton, their findings showed, only detected about 20 percent of the malware.
It’s worth noting for comparison’s sake that other security researchers found different results with a similar testing technique.
The AV-TEST Institute out of Germany, for example, released a report in March 2012 ranking 41 antivirus apps. Its malware sample was smaller – 20 virus families as opposed to N.C. State’s 49 –yet it too ranked Lookout among the highest performing at more than 90 percent (a rate McAfee also scored). AVG, Norton and Trend Micro landed in an upper tier, with a detection rate of between 65 and 90 percent (see the rest of the findings here: http://www.av-test.org/en/tests/mobile-devices/android/).
Security depends on use
Surely these apps have been updated in the past year, so their performance may have changed. And they certainly won’t hurt your ability to detect and protect against malicious software. But outside the Android arms race between developers and malicious hackers, many of these apps have other useful features to help in cases where threats don’t come from code.
“If someone steals your tablet, it won’t matter which operating system it was running,” Jeff Crume, IBM IT security architect and author of the blog Inside Internet Security, said in an email. “You still could benefit from tracking and remote device-wiping tools since most people have passwords saved in apps on these devices that can access their email, banking and other accounts conveniently.”
In the end, Crume said your mobile security strategy depends on how you’re using your device. So at least in that respect, it can be a lot like protecting your desktop.
“As with all things security, the answer lies in what tolerance for risk you have,” Crume said. “If you were going to be putting sensitive corporate or personal information on the tablet, then the need for protection is clearly greater.”
Send technology questions to email@example.com. Please include your name, city and daytime phone number. Sorry, we can’t answer every question.