Google, cybersecurity firms to scan Play store apps for malware

Google to scan Play store apps for malware
Image Source

Google has partnered with three cybersecurity firms to increase its security checks and scan apps on its Play store for malware.

According to Google, all new apps on the Play store will go through malware scanning tools from security firms Zimperium, Eset and Lookout, as well as its own in-house system. The tech company has expressed that it needed assistance in handling checks because the number of apps being uploaded was too large for it to handle alone.

ADVERTISEMENT

In June, the company found malicious code in apps that were downloaded 400 million times.

The four partners, which Google collectively calls the App Defense Alliance, will create a combined scanning system that will scrutinize apps as they pass through Google's pipeline until they become available for download to Android users via the Play store.

The scanning systems will search for trojans, adware, ransomware, banking malware and phishing attacks by using numerous databases of known malware, behavioral clues and machine-learning models of new threats.

ADVERTISEMENT

Dave Kleidermacher, Google's vice president of Android security, said: "On the malware side we haven't really had a way to scale as much as we've wanted to scale." He added that even achieving a "one percent incremental improvement" could make a difference due to the sheer number of apps being developed.

The new scanning system is only the latest in Google's efforts to improve the security of its Play store. In April, the company announced that it would implement more stringent checks on app developers to crackdown on "bad faith" developers.

These developers often create different accounts to avoid Google's checks, with some hijacking existing accounts to take advantage of the good reputation established developers have built upon.

ADVERTISEMENT

Sameer Samat, product manager for Android and Google Play, said the "more thorough" checks will be done on application creators who do not have a "track record" with the company.