SlideShare a Scribd company logo
Secure Android ApplicationsThe OWASP WayJack ManninoCEO/Chief “Breaker”ISSA DC- June 21, 2011https://www.nvisiumsecurity.comhttp://twitter.com/jack_manninohttp://www.linkedin.com/pub/jack-mannino/7/2b7/562©2011 nVisium Security Inc.
OverviewWho I am/ What we do
OWASP Mobile Security Project
Mobile World Meets Security World
Android Crash Course
Threat Modeling Android Apps
Risks and Controls
Where Do We Go From here?
Q&A, ResourcesWho I Am/ What We Do/ Where We AreWho I am
Jack Mannino
Company co-founder
Co-leader of the OWASP Mobile Security Project
Has a lot of phones…..
What we do:
Mobile Application Security
Web Application Security
Penetration Testing
Secure Development Training
Where we are:
Northern VirginiaOWASP Mobile Security Project
OWASP Mobile Security ProjectBegan in 2010
Current state of mobile application security: bad
We are aiming to make it: good
How do we plan to achieve this?OWASP Mobile Security Project
DisclaimerWe support OWASP by contributing expertise to the security community
OWASP does not support or endorse our business and services
Why am I mentioning this?
https://www.owasp.org/index.php/OWASP_brand_usage_rulesMobile World Meets Security World
Mobile World Meets Security WorldOnce upon a time, all phones could do was make phone calls….
And then, the world changed
Today’s mobile devices do things like
Make phone calls
Send SMS messages
Browse the web
VPN into corporate assets
Video conferencing
Track our location
Tap our phones to pay for things (soon)
Is anyone making money?
Do people use these things and their “apps”?Mobile World Meets Security World- Show Me The Money!!“Gartner Forecasts Mobile App Store Revenues Will Hit $15 Billion in 2011” (http://techcrunch.com/2011/01/26/mobile-app-store-15-billion-2011/)“Industry first: Smartphones pass PCs in sales” (http://tech.fortune.cnn.com/2011/02/07/idc-smartphone-shipment-numbers-passed-pc-in-q4-2010/)
Android Crash Course
And Now…Android!Debuted in 2008
Most popular mobile platform aroundPeople Use Android….Now What?Huge market share + attack monetization = target
Android Market is OPEN (in a bad way)

More Related Content

PDF
Challenges in Testing Mobile App Security
Cygnet Infotech
 
PPTX
Mobile application security
Shubhneet Goel
 
PPTX
Web and Mobile Application Security
Prateek Jain
 
ODP
Mobile Apps Security Testing -1
Krisshhna Daasaarii
 
PPTX
Security testing of mobile applications
GTestClub
 
PDF
Mobile Application Security
cclark_isec
 
PPTX
Secure SDLC in mobile software development.
Mykhailo Antonishyn
 
PPTX
Android Security
Arqum Ahmad
 
Challenges in Testing Mobile App Security
Cygnet Infotech
 
Mobile application security
Shubhneet Goel
 
Web and Mobile Application Security
Prateek Jain
 
Mobile Apps Security Testing -1
Krisshhna Daasaarii
 
Security testing of mobile applications
GTestClub
 
Mobile Application Security
cclark_isec
 
Secure SDLC in mobile software development.
Mykhailo Antonishyn
 
Android Security
Arqum Ahmad
 

What's hot (20)

PDF
Mobile Application Security
Dirk Nicol
 
PDF
Mobile Threats and Trends Changing Mobile App Security
DevOps.com
 
PDF
Android Security & Penetration Testing
Subho Halder
 
PPTX
Android Device Hardening
anupriti
 
PPTX
[Wroclaw #1] Android Security Workshop
OWASP
 
PPTX
Allianz Global CISO october-2015-draft
Eoin Keary
 
PPT
Mobile Application Security – Effective methodology, efficient testing!
espheresecurity
 
PDF
Android Malware: Study and analysis of malware for privacy leak in ad-hoc net...
IOSR Journals
 
ODP
Mobile Apps Security Testing -3
Krisshhna Daasaarii
 
PDF
Oh, WASP! Security Essentials for Web Apps
TechWell
 
PPT
六合彩香港-六合彩
baoyin
 
PDF
Penetration Testing, Auditing & Standards Issue : 02_2012-1
Falgun Rathod
 
PDF
Sperasoft talks: Android Security Threats
Sperasoft
 
PDF
Deep Dive Into Android Security
Marakana Inc.
 
PDF
Anomaly Detection using String Analysis for Android Malware Detection - CISIS...
Carlos Laorden
 
PDF
Threat Modeling for the Internet of Things
Eric Vétillard
 
PPTX
Android security
Mobile Rtpl
 
PPTX
Android sandbox
Anusha Chavan
 
PDF
VSEC Sourcecode Review Service Profile
Vietnamese Network Security J.S.C
 
PPTX
[CB16] Security in the IoT World: Analyzing the Security of Mobile Apps for A...
CODE BLUE
 
Mobile Application Security
Dirk Nicol
 
Mobile Threats and Trends Changing Mobile App Security
DevOps.com
 
Android Security & Penetration Testing
Subho Halder
 
Android Device Hardening
anupriti
 
[Wroclaw #1] Android Security Workshop
OWASP
 
Allianz Global CISO october-2015-draft
Eoin Keary
 
Mobile Application Security – Effective methodology, efficient testing!
espheresecurity
 
Android Malware: Study and analysis of malware for privacy leak in ad-hoc net...
IOSR Journals
 
Mobile Apps Security Testing -3
Krisshhna Daasaarii
 
Oh, WASP! Security Essentials for Web Apps
TechWell
 
六合彩香港-六合彩
baoyin
 
Penetration Testing, Auditing & Standards Issue : 02_2012-1
Falgun Rathod
 
Sperasoft talks: Android Security Threats
Sperasoft
 
Deep Dive Into Android Security
Marakana Inc.
 
Anomaly Detection using String Analysis for Android Malware Detection - CISIS...
Carlos Laorden
 
Threat Modeling for the Internet of Things
Eric Vétillard
 
Android security
Mobile Rtpl
 
Android sandbox
Anusha Chavan
 
VSEC Sourcecode Review Service Profile
Vietnamese Network Security J.S.C
 
[CB16] Security in the IoT World: Analyzing the Security of Mobile Apps for A...
CODE BLUE
 
Ad

Similar to Secure Android Apps- nVisium Security (20)

PDF
Unicom Conference - Mobile Application Security
Subho Halder
 
PDF
Securing Mobile Apps - Appfest Version
Subho Halder
 
PPTX
Android Application Security Awareness Talk, OWASP MEETUP Q3, 2015
Sina Manavi
 
PPTX
Building a Mobile Security Program
Denim Group
 
PDF
Android Application Security from consumer and developer perspectives
Ayoma Wijethunga
 
PDF
Introduction to Android Application Security Testing - 2nd Sep 2017
Satheesh Kumar V
 
PDF
Android App Hacking - Erez Metula, AppSec
DroidConTLV
 
PPT
Security Testing for Mobile and Web Apps
DrKaramHatim
 
PPT
Analysis and research of system security based on android
Ravishankar Kumar
 
PPTX
Mobile security
Stefaan
 
PPTX
OWASP Mobile TOP 10 2014
Islam Azeddine Mennouchi
 
PPTX
Appsecurity, win or loose
Bjørn Sloth
 
PDF
85% of App Store Apps Fail OWASP Mobile Top 10: Are you exposed?
NowSecure
 
PDF
DataMindsConnect2018_SECDEVOPS
Tobias Koprowski
 
PPTX
Android security
Midhun P Gopi
 
PPTX
Mobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Nikola Milosevic
 
PDF
OWASP Day - OWASP Day - Lets secure!
Prathan Phongthiproek
 
PDF
The fundamentals of Android and iOS app security
NowSecure
 
PPTX
Webdays blida mobile top 10 risks
Islam Azeddine Mennouchi
 
Unicom Conference - Mobile Application Security
Subho Halder
 
Securing Mobile Apps - Appfest Version
Subho Halder
 
Android Application Security Awareness Talk, OWASP MEETUP Q3, 2015
Sina Manavi
 
Building a Mobile Security Program
Denim Group
 
Android Application Security from consumer and developer perspectives
Ayoma Wijethunga
 
Introduction to Android Application Security Testing - 2nd Sep 2017
Satheesh Kumar V
 
Android App Hacking - Erez Metula, AppSec
DroidConTLV
 
Security Testing for Mobile and Web Apps
DrKaramHatim
 
Analysis and research of system security based on android
Ravishankar Kumar
 
Mobile security
Stefaan
 
OWASP Mobile TOP 10 2014
Islam Azeddine Mennouchi
 
Appsecurity, win or loose
Bjørn Sloth
 
85% of App Store Apps Fail OWASP Mobile Top 10: Are you exposed?
NowSecure
 
DataMindsConnect2018_SECDEVOPS
Tobias Koprowski
 
Android security
Midhun P Gopi
 
Mobile security, OWASP Mobile Top 10, OWASP Seraphimdroid
Nikola Milosevic
 
OWASP Day - OWASP Day - Lets secure!
Prathan Phongthiproek
 
The fundamentals of Android and iOS app security
NowSecure
 
Webdays blida mobile top 10 risks
Islam Azeddine Mennouchi
 
Ad

Secure Android Apps- nVisium Security