Apple wants the jury to know that Samsung destroyed evidence
The U.S. Apple vs Samsung legal odyssey continues today with new developments in one of the most important patent-based cases in the world right now. Itâs not just a fight between titans, between business partners, between closed and open ecosystems, but also a battle that could have decisive consequences on the future of the mobile ecosystem.
The trial started on Monday with jury selection, and we saw yesterday the opening arguments from both Apple and Samsung. Each party is accusing the other of violating its patents, with Apple claiming Samsung has copied the look and feel of its iPhone and iPad and with Samsung saying that Apple is infringing various of its 3G patents.
The trial will last for at least four weeks, and weâre bound to see more interesting things emerge from this fight.
Earlier today, we showed you pieces of evidence from Samsungâs case, which were not allowed to be used in court. Therefore, Samsungâs legal counsel released them to the media, annoying the judge in the process. Consequently, Samsungâs attorneys had to formally explain why they leaked those documents, which they did earlier today.
Now we hear that Apple wants the jury in the case, formed by nine members that have to unanimously agree on each claim presented in the case, to know that Samsung destroyed evidence relevant to the case. According to Apple, this sort of thing happened not just once, but twice so far in Samsungâs legal war history.
   Magistrate Judge Paul Grewal agreed that Samsung wronged Apple when the company âcontinued throughout this case automatically to delete e-mails.â
   Grewal also wrote that Samsung âkept the shredder on long after it should have known about this litigation and simply trusted its custodial employees to save relevantâ e-mails.
   Grewal found that âSamsung âconsciously disregardedâ its obligation to preserve relevant evidence.â
The judge issued an âadverse inference jury instruction,â which Samsung is contesting. The Android device maker is asking Judge Lucy Koh, presiding over the U.S. Apple vs Samsung case, not to reveal the instruction to jurors.
But, apparently this isnât the first time Samsung was found to withhold evidence in such a manner. In a different patent case dating back to 2004, a district court in New Jersey âissued adverse inference instructions against Samsung because it never flipped the âoff switch on its⌠automatic computer e-mail policy [that] allowed e-mails to be deleted.â
Apple basically argues that Samsung failed to preserve emails from the files of Lee Min-hyuk, the main designer of Galaxy S handsets:
âRelevant e-mails once existed.â Appleâs lawyers say they know this because Samsung produced 75 of them dated after Lee received a document-retention notice and because other âcustodiansâ of the e-mails preserved them.
On that note, we close another small chapter in this complex battle, but weâll be back with more details in the following days.
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
â Live Streamingâ Interactive Chatâ Private Showsâ HD Qualityâ Free Actions
Free to watch ⢠No registration required ⢠HD streaming
SAN JOSE, Calif.--The first day of the patent infringement trial between Apple and Samsung wrapped up with a jury in hand.
After whittling down a pool of prospective jurors, the court now has its 10, which will hear testimony and decide the case.
On the way to that selection, potential jurors were asked myriad questions ranging from what gadgets they owned to whether they worked for either company. Such a question was an important one given where the trial is taking place. The U.S. District Court here in San Jose is just a few miles away from Apple's nearby Cupertino headquarters.
As it turned out, both a Google and Apple employee were in the pool of potential jurors, along with numerous former tech workers. Those two individuals did not make it into the final group, though a man who told the court that he had once been involved with a patent-related lawsuit made it on the final jury, which is made up of 7 men and 3 women.
Samsung's argument centers on the idea that Apple's suit against it threatens to "stifle" innovation among other device-makers if it's successful. Samsung also plans to argue that the iPhone could have never come to be without some of its technology, and those from other companies.
The trial now moves on to opening statements from both companies, which last week filed pre-trial briefs making those aforementioned arguments. Those statements were originally set for today, but were pushed back until tomorrow due to the extensive jury questioning, as well as a dispute between Apple and Samsung about the inclusion of testimony from former Apple employee Shin Nishibori. That testimony dealt with the alleged beginnings of the iPhone's design from a Sony product, something Samsung says is critical to defending itself from Apple's claims that copied Samsung's designs.
Potential jurors were also grilled by U.S. District Judge Lucy Koh, were asked if they knew any employees at either company, if they had read any books about Apple or Samsung, whether they had Apple or Samsung stock, and if they had strong feelings about the case based on what they have already heard through the media. Samsung attorney William Price later stressed that last point, comparing any kind of potential bias to watching two sports players collide where there was a referee call involved.
"If it's against your team you say 'that's ridiculous: I saw it clearly, it was a charge!'" Williams told would-be jurors. "Because you're already leaning one way, you see things differently."
Koh, who is presiding over the case, said that the evidence portion is slated to wrap up as soon as August 17, but more likely the 20 or 21. After that, the jury begins its deliberation.
Android drops to 56%, iOS rises to 33%, and Blackberry falls to 6.5% in Q2 2012 in U.S.
According to Strategy Analyticsâ latest research, smartphone sales in the U.S. dropped by 5 million, down to 24 million in the 2nd quarter of the year. Â The reasons for this sharp decline in smartphone sales include:
âA volatile economy, maturing penetration of smartphones among contract mobile subscribers, and major operators tightening their upgrade policies to enhance profits [...].â
It also seems iOS surged to 33% from 23% a year ago, by stealing an extra 10% from the others â half from Android, which dropped from 61% to 56% and half from Blackberry (now less than 7%) and âothersâ (WP7, etc).
Now that the iPhone is available from almost all American carriers, the iOS and Android market shares will probably tend towards becoming equal in the future, or perhaps weâll see Androidâs market share become only slightly bigger than iPhoneâs market share. But for now this still remains pretty unpredictable, as we donât know how people will react to the new iPhone. If they find it way too similar to the previous 2 generations, their interest might drop, and the iPhoneâs market share might stagnate or even drop.
RIM seems to be in a terrible position with Blackberry, which is now at 6.5% market share, and will probably continue to drop by the time the company even gets to launch its new BB10 operating system. Even my suggestions for them might not work anymore at that point.
This is why when you get disrupted by new technologies, you need to act years before they start affecting you financially, otherwise you get to a point where itâs too late to do anything about it. This is a lesson that both Nokia and RIM are learning the hard way because they refused to acknowledge for years the change in the market.
Android Jelly Bean 4.1 Galaxy Nexus and Nexus S factory images released
Being part of the Android reference device family has many perks. Besides being the first to receive the latest updates, Google also provides factory images for users to download. These factory images are used to return phones or tablets back to out-of-box or factory condition if the need should ever arise. The Nexus S (soju and sojua) and the Galaxy Nexus (yakju an takju) have joined the ranks of the Nexus 7 (nakasi) getting their factory images posted online by Google.
The average user wonât find these all too useful. However, if youâre into rooting, Â flashing various custom ROMs or kernels, you can now sleep a little bit easier at night knowing you can always go back to stock in an emergency. If for some odd reason you have not received your official OTA update, these images can also be used to upgrade to Android Jelly Bean 4.1.1. To download the factory images, just head on over to the official factory images for Nexus devices download page.
Sadly, theas well as the Sprint and Verizon Wireless variants of the Galaxy Nexus are still waiting to to be upgraded to Jelly Bean. There has been no word from Google nor their respective carriers on when they can expect to receive their official Jelly Bean update. Normally, the CDMA Nexus devices compared to their GSM counterparts take a bit longer to receive their updates due to having different radios. Keep your fingers crossed for timely updates.
The Interesting Android Games of 2012 London Olympics
It is well known to us all that the 2012 London Olympic Games will be hold on 27 July. The 2012 London Olympic Games marks the third time that the greatest sporting event of the world has been to London.This worldwide sports event is certainly going to be visual a feast to sports fans. We can not only enjoy the exciting Olympic sports games, but also can play the Android funny Games of 2012 London Olympics.The following list 5 popular Android funny Games of 2012 London Olympics.
1.Baseball SuperstarsÂŽ 2012
The key features are as follows:
BASEBALL IN CRYSTAL-CLEAR HD
See more, play better â Enhanced details and clarity make an eye-opening ballgame optimized for HD and high-res displays on latest Android devices.
SMART CONTROLS & INTELLIGENT AI
New gesture and tilt controls allow intuitive pitching and batting. Smart AI teammates make exciting baseball plays, split-second catches and laser-precision throws.
TOTAL TEAM MANAGEMENT & CUSTOMIZATION
Customize your team logo, stadium, uniform and equipment. Recruit, combine and level up players to assemble the best team.
NETWORK MATCHES
Go up against other users' teams around the world in PVP matches.
COLLECT SUPER PLAYERS AND MORE
Meet the challenges of new super players to have them join your team. Go after the multiple story endings and player skill abilities.
2.Soccer Superstars 2012
Do you have what it takes to be the Soccer Superstar?
Play Soccer Superstars 2012, the most immersive and dynamic soccer game on App Store. Train your player and team with endless skill building and leveling options. Unlock special players and dominate the stadium against impressive AI or others players across the world. Soccer Superstars 2012 brings intensive team management and soccer game play to your device for endless hours of soccer fun.
The key features are as follows:
ENDLESS SOCCER IN 4 DIFFERENT MATCHES
Play in League Match, Village Cup, Event Match and Quick Match, as your team challenges intelligent AI and other users!
HANDS-ON CUSTOMIZATION AND MANAGEMENT
Manage your team with the most thorough customization features as you combine and upgrade players, draft players, unlock Super Players and manage your stadium tickets!
INTENSE TRAINING AND SKILL BUILDING
Learn new tricks and level up as you train your team to be the best in the league! Specialize your playerâs moves and skills!
CRISP GRAPHICS AND FUN ANIMATION
Shoot goals, make passes in clean and clear retina enhanced graphics for smartphones!
DOMINATE THE RANKING CHARTS
Set records and top scores in the global ranking charts against other players across the world!
3.Run Run Chicken 2012
The game is ridiculously simple and addictive. It has filled millions of those interstitial moments spent riding the bus, on a plane or in important work meetings, and it is or has been the number-one free app on iTunes in 139 countries.
And it's FREE! Go download itďźÂ
Who said chickens can't fly?! Make them flap their tiny wings! Journey through beautiful hills to help little chickens find their moms. Use the one-finger touch play to jump, until this annoying gravity brings you back down to earth.
- Incredibly simple and addictive gameplay.
- Dazzling hi-res graphics
- Acquire new "Power-Ups" to use special skills
Taking part into the exciting competitions in 2012 London Olympic Games is hard-won for professional athlete, but for us fans it could be only possible in Mobile Games. These funny Android games definitely offer great opportunities for ordinary people to join such great events. If you like these games, you can download them from the internet and then enjoy them, it will be a special and unforgettable experience. Just enjoy them.
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
â Live Streamingâ Interactive Chatâ Private Showsâ HD Qualityâ Free Actions
Free to watch ⢠No registration required ⢠HD streaming
CoPilot Live iOS and Android apps updated to help navigate London 2012 Olympics
As a long time athlete and sports fan, I am very excited for the start of the 2012 Olympics and yesterday posted about ways you can follow all the action from your mobile device. If you are lucky enough to actually be in the UK for the Olympics then you may also be interested in ways to get around London during this busy time. The folks at ALK Technologies informed me that European and UK versions of CoPilot Live have added new features to help you out.
If you are traveling by foot or Tube then you will see there is a new added category in CoPilot Live for Olympic game venue locations. Maps can be download directly to your smartphone so you won't need to pay high data roaming fees or rent a GPS device while visiting London. The CoPilot Live Premium UK version is priced at a one time cost of $26.99, but that includes lifetime navigation and is not a subscription price.
Speaking of using public transportation in London for the Olympics, I recommend you check out this handy site that lets you check mass transit status at various time and days throughout the Olympic and Paralympic Games in August and September.
Warning: New Android malware tricks users with real Opera Mini
As you can see above, two sets of "Permission to Install" pages are displayed during installation. The first (above in the middle), comes from the malware itself: it asks for read and modify rights to all SMS and MMS messages, read rights to all contacts stored on the smartphone, modify or delete rights to the SD card, and so on. The second (above on the right) one appears once users agree to install the first, which is simply the permissions required for the legitimate Opera Mini browser.
This particular threat is interesting because it shows that OpFake is evolving. Instead of trying to mimic a popular app, OpFake now simply installs the real version. As a result, the user is less suspicious that something is wrong. "More than likely, users will not be aware that something might have infiltrated their phones until the bill arrives," a GFI spokesperson said in a statement.
The devil is in the details: in the background, the malicious app sends expensive international text messages to earn its creators revenue. The malicious app does the dirty work to incur costs on the victim. More specifically, here's what this particular threat does:
It sends one SMS message to a premium-rate number before it installs the legitimate Opera Mini. A command and control (C&C) server controls the message sent and the number where it is sent.
It also connects to the C&C server to retrieve data.
It reads the following stored information: Country location, Operator name, OS version, Phone type, and Device ID (IMEI).
Android lets you download and install apps from anywhere. If you want the official version of an app, however, get it from the official Google Play store.
Samsung Galaxy Note 10.1 gets unboxed, 2GB of RAM onboard
Itâs been hinted to come on August 15 and weâve seen its first ever commercial being released â now if only thereâs some lucky soul out there who can get a hold of the Samsung Galaxy Note 10.1 and do the requisite unboxing. And just like that, our prayer is answered, thanks to The Brave Post all the way from South Korea.
Feast your eyes on the white Samsung Galaxy Note 10.1 and all of its S Pen glory. While the accompanying texts on the website are in Korean, itâs nothing that a little Google Translate canât fix.
Those who were expecting to see a higher resolution display are in for a disappointment, as thereâs no change to the 1,280 x 800 resolution of the Galaxy Note 10.1. Other features to be found include a quad-core 1.4GHz Exynos 4412 processor, 5MP rear camera with Full HD Playback and HD recording, HSPA+ connectivity, 7,000mAh battery, and Android 4.0 Ice Cream Sandwich.
Having launched an all-out blitz on the high-end of US smartphones, Samsung must be eager to conquer the mid-range as well. A Verizon rebate list finding its way to Droid-Life has the previously unknown Galaxy Stellar showing up amongst the carrier's more budget-minded smartphones for a $50 discount sometime between now and an August 19th expiry date.
There's little we can definitively attach to that starry-eyed name so far, although we have our hunches: first and foremost is that it's the Jasper, the Snapdragon S4-touting spiritual successor to the Droid Charge. It might alternately be the even more mysterious SCH-i415, which just showed up at the FCC this weekend and could be a world-roaming sequel to the Stratosphere (SCH-i405) with CDMA, LTE and GSM all rolled into one.
Whether the Galaxy Stellar is one of these two devices or something entirely off of the map, there's a strong indication between this, Sprint's mystery SPH-L300 and the slightly more tangible Galaxy Reverb that Samsung will leave no CDMA corner unturned in the near future.
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
â Live Streamingâ Interactive Chatâ Private Showsâ HD Qualityâ Free Actions
Free to watch ⢠No registration required ⢠HD streaming
Android face-off: ZTE Grand X vs Intel Orange San Diego
ZTE's Grand X smartphone, launched on Wednesday, will arrive running the Ice Cream Sandwich (ICS) version of Android and at a price below ÂŁ200.
ZTE showed off the dual-core Tegra 2 device at a press event in London on Wednesday. Its launch marks a renewed push by the Chinese company to become a household name in the European smartphone market.
At the event, the company highlighted the "fast download speeds" and video processing delivered by the Nvidia Tegra 2 processor.
"This [Grand X] will be a milestone in establishing ZTE in the UK," said He Shiyou, global head of the company's Terminals division.
In general, the Grand X pairs middle-of-the-road specs with a mid-tier price point. Here, we put it up against the Orange San Diego, the first smartphone in the UK to use the Intel Atom processor â a good example of the mid-tier Android phones the Grand X will compete with.
Android has a bigger U.S. market share than all other mobile operating systems combined, according to a new report by Nielsen.
Nielsenâs research shows that 51.8% of smartphone owners in the U.S. use an Android handset. Appleâs iOS has a 34.3% market share, and the rest is divided between RIMâs BlackBerry (8.1%) and Microsoftâs Windows Mobile and Windows Phone 7 platforms (4.3%).
Symbian and Palm OS both have less than one percent market share: 0.9% and 0.6%, respectively.
Nielsenâs numbers from recent smartphone acquirers (last three months) paint an even rosier picture for Android and iOS, with their respective market shares jumping to 54.6% and 36.3%, at the expense of everyone else.
Digging a little bit deeper into those numbers reveals Appleâs dominance on the market, as it is by far the biggest manufacturer out there with its 34.3% share. Samsung is number two with a 17% share, followed by HTC, Motorola and RIM. Itâs also interesting to note that overall, Nokia is bested by both Samsung and HTC even when it comes to Windows 7 handsets.
Weâll see how these numbers will change after two extremely important devices hit the market: Samsungâs Galaxy S III and Appleâs upcoming iPhone, probably due to be launched this fall.
Acer officially released the Android 4.0 phone: AT390 and AK330
On July 18, 2012, Acer announced its roadmap for mobile terminals. It indicates that although Acer is not a dedicated phone manufacturer, but it will be fully engaged and builds a mobile terminal, and it is very optimistic about the domestic market. In addition, Acer has released two Android 4.0 phone: Acer AK330 and Acer AT390.
Acer AK330 is a phone that is loved by young people, this mobile phone has a 4.3 inches screen with a resolution of 960 Ă 540 pixels, high resolution can be said to be a feature of the Acer AK330. Mobile phone equipped with a 5 million pixel camera with auto-focus and built-in flash. Acer adopts the Android 4.0 versionâs operating system and a 1GHz Cortex A9 processor, with 4GB of ROM and 1GB of RAM. In other aspects, the phone also has a 1500mAH battery, GPS and the function of Wi-Fi.
Acer AT390 is popular in business market, it is a dual sim dual standby mobile phone that support TD-SCDMA network. It uses the touch screen of 4.3 inches and the resolution is 800 Ă 480 pixels. Acer AT390 has a 5 million pixel camera; it can support autofocus and 720p video recording. The phone supports Android 4.0 operating system, equipped with a 1GHz processor and 4GB ROM and 512MB RAM.
Acer AK330 and AT390 are not only configured to mainstream level, the price also reflects their advantages, the former is priced at 1599 yuan; the price of the AT390 is only 1499 yuan.
Apple Must Advertise That Apple Didnât Copy the iPad
Today a UK judged ordered that Apple must issue a notice stating that Samsung did not copy its design for the iPad.
Appleâs statement must be published on its UK website for six months and be distributed throughout several British magazines and newspapers, Bloomberg reports.
Judge Colin Birss mandated that the notice must detail the July 9 ruling in which he dismissed Appleâs lawsuit over Samsungâs Galaxy Tab. According to Birss, the design for the Galaxy tablets doesnât infringe on that of Appleâs product. He even went as far to say the Samsung designs werenât as distinctively âcoolâ as the iPad.
â[The Galaxy tablets] do not have the same understated and extreme simplicity which is possessed by the Apple design. They are not as cool,â Birss said.
The order means that Apple will essentially have to run advertisement for Samsung in the UK, a move that may be inherently bad for business. âNo company likes to refer to a rival on its website,â Apple lawyer Richard Hacon told the court.
The UK lawsuit isnât the only legal battle the Cupertino, Calif.-based company is fighting. Similar disputes between Apple and Samsung are still unsettled in Germany, the Netherlands and the U.S. Also this month, Apple paid a cool $60 million for the âiPadâ name in China.
Charlie Miller: 'Difficult to write exploits' for Android 4.1
The latest version of Google's mobile operating system, Android 4.1 (Jelly Bean), significantly beefs up the platform's security. Jelly Bean includes several new exploit mitigations as well as full implementation of Address Space Layout Randomization (ASLR) and Data Execution Prevention (DEP). At least one famous hacker thinks this will finally make Android much harder to attack.
"As long as there's anything that's not randomized, then it (ASLR) doesn't work, because as long as the attacker knows something is in the same spot, they can use that to break out of everything else," Charlie Miller, a security researcher famous for publicly hacking Apple products, told Ars Technica. "Jelly Bean is going to be the first version of Android that has full ASLR and DEP, so it's going to be pretty difficult to write exploits for that."
ASLR randomizes the memory locations of key data areas, including the base of the executable and position of libraries, heap, and stack, in a process's address space. DEP prevents an application or service from executing code from a non-executable memory region. The goal is to stop hackers who exploit memory corruption bugs. Since they don't know in advance where their malicious payloads will be loaded, they cannot be so easily executed, and since other parts of the memory can't be leveraged, exploits that store code via a buffer overflow can also be blocked.
Google first included ASLR support in Android 4.0 (Ice Cream Sandwich), but only partially. The ASLR support in Android 4.0 only randomized certain key locations, leaving other key parts of the Android operating system memory space as a predictable space to attackers.
Security researcher Jon Oberheide was the first to note the change between Android 4.0 and Android 4.1 over on The Duo Bulletin:
As we mentioned in our previous post on Android ASLR, the executable mapping in the process address space was not randomized in Ice Cream Sandwich, making ROP-style attacks possible using the whole executable as a source of gadgets. In Jelly Bean, most binaries are now compiled/linked with the PIE flag (commits for the linker, ARM and x86), which means the executable mapping will be properly randomized when executed.
The custom Android linker was the last piece of the ASLR puzzle that was not randomized in Ice Cream Sandwich. In Jelly Bean, the linker is now randomized in the process address space. This means that the deficiencies in ICS pointed out in our previous blog post have all been addressed in Jelly Bean, giving it full stack, heap/brk, lib/mmap, linker, and executable ASLR.
All in all, this is great news, but it comes with one massive gotcha. Google still hasn't shown any desire to get its massive userbase onto the latest version of Android. As such, until most Android users are running Jelly Bean or later, this won't be a new feature that most people will be able to enjoy.
Anya is live and ready to show you everything. Watch her strip, dance, and perform exclusive shows just for you. Interact in real-time and make your fantasies come true.
â Live Streamingâ Interactive Chatâ Private Showsâ HD Qualityâ Free Actions
Free to watch ⢠No registration required ⢠HD streaming
Earlier this month I wrote about how Microsoft engineer Terry Zink said he discovered spam was being sent from compromised Yahoo accounts via what looked like an international Android spam botnet. Sophos, as well as other security researchers, backed up his claim, saying everything pointed to such a development, though nobody had found clear-cut evidence for it. Google quickly got in touch with me and denied Microsoft's claim by saying spammers are probably using infected computers and a fake mobile signature to make it appear as if the e-mails were coming from Android devices. Now there is further proof that Microsoft may have been right, although the botnet in question has still yet to be found.
One way spammers could be sending such large quantities of e-mail that appears as if it's being sent from Yahoo accounts used on Android devices is to exploit a Yahoo Android app vulnerability. In fact, Trend Micro says it recently uncovered a vulnerability in the Yahoo Android mail client, which can let an attacker do just that by gaining access to a user's Yahoo Mail cookie.
The bug reportedly stems from the communication between the Yahoo mail server and the Yahoo Android mail client, according to the security firm. Once the attacker has the cookie, he or she can use the compromised Yahoo Mail account to send specially-crafted messages, not to mention access the user's inbox and messages.
Zink first deduced the spam e-mails were being sent from compromised Yahoo accounts on Android devices by looking at the e-mails' header information as well as noting the "Sent from Yahoo! Mail on Android" signature. The Microsoft engineer speculated a cybercriminal had developed a new piece of malware that can access Yahoo Mail accounts on Android devices, send spam messages from them, and had linked them together to create a spam botnet.
The other option (this is what Google is pushing) is that compromised PCs connected to Yahoo Mail are inserting the message-ID and overriding Yahoo's own Message-IDs and adding the "Yahoo Mail for Android" tagline at the bottom of the message. The goal here would be to make it look like the spam was coming from Android devices.
Since Yahoo provides the originating IP address for its e-mails, it is possible to see where the spam is being sent from: Asia, Eastern Europe, the Middle East, and South America. The e-mails Zink got his hands on came from Chile, Indonesia, Lebanon, Oman, Philippines, Russia, Saudi Arabia, Thailand, Ukraine, and Venezuela. Samples analyzed by Sophos originated from Argentina, Ukraine, Pakistan, Jordan, and Russia. Trend Micro did not detail where it saw its spam e-mails coming from.
Even if you are not in any of these countries, please be careful. Android lets you download and install apps from anywhere. Please only install apps from Google Play unless you are absolutely certain you know who wrote the software you want to install.
I have contacted both Google and Yahoo about Trend Micro's findings and will update you if I hear back.
Android malware's dirty secret: Repackaging of legit apps
Security researchers from North Carolina State University are warning that the majority of Android malware are repackaging other legitimate (popular) apps to get past the mobile platform's rudimentary security barriers.
After analyzing more than 1,200 Android malware families, the reserachers -- Yajin Zhou and Xuxian Jiang -- found that  86.0% repackaged legitimate apps to include malicious payloads and argued that the theats can be effectively mitigated by policing existing Android Markets for repackaging detection.
The pair, working within the Android Malware Genome Project, calleed for a a joint effort involving all parties in the Android ecosystem to spot and discourage repackaged apps.  "The challenges lie in the large volume of new apps created on a daily basis as well as the accuracy needed for repackaging detection," the group said in a paper [PDF] to be delivered at the upcoming IEEE Privacy and Security Symposium,Â
"Our characterization of existing Android malware and an evolution-based study of representative ones clearly reveal a serious threat we are facing today. Unfortunately, existing popular mobile security software still lag behind and it becomes imperative to explore possible solutions to make a difference," Zhou and Jiang said.
The researchers also found that more than one-third (36.7%) of Android malware enclose platform-level exploits to escalate privileges.  "Unfortunately, the open Android platform has the well-known âfragmentationâ problem, which leads to a long vulnerable time window of current mobile devices before a patch can be actually deployed," according to the paper.
Worse, researchers bemoaned the fact that current Android platform still lacks many desirable security features. Â Anti-exploit mitigations like Address Space Layout Randomization (ASLR) was not added until very recently in Android 4.0 and other security features such as TrustZone and eXecute-Never need to be gradually rolled out to raise the bar for exploitation.
The analysis also revealed that  the dynamic loading ability of both native code and Dalvik code are being "actively abused" by existing Android malware families.  It also found that about 45% of existing malware subscribe to premium-rate services with background SMS messages to generate spoils for cyber-criminals.
The researches recommend that the coarse-grained Android permission model be expanded to include additional context information to better facilitate users to make sound and informed decisions.
The research project also pitted Android malware against four mobile security products and found the results to be poor.
"The detection results of existing mobile security software are rather disappointing, which does raise a challenging question on the best model for mobile malware detection. SpeciďŹcally, the unique runtime environments with limited resources and battery could preclude the deployment of sophisticated detection techniques. Also, the traditional content-signature-based approaches have been demonstrated not promising at all," Zhou and Jiang added.