Secure Mobile Apps

Learning objectives

Get to know the most important security risks (OWASP Mobile Top 10) of mobile apps with the aid of intentionally vulnerable mobile apps for iPhone and Android. After an introduction into the security architecture of Android and iOS, you will be guided through various application vulnerabilities and the corresponding countermeasures. After the course you will be in a position to apply what you have learned to your company's mobile application projects and will gain the competence for secure development and evaluation (self-assessment) of mobile apps

Demarcation: The seminar is differentiated from the subject of MDM (Mobile Device Management) and focuses on the (in-)secure development of apps.

Highlights

  • Introduction to the subject of  Secure Mobile Coding
    • OWASP Mobile Security Top 10
    • Introduction to the laboratory environment
  • Overview of security architecture
    • Android Security
    • iOS Security Framework
  • Secure transmission of app data
    • Network analysis, Man-in-the-Middle
    • SSL Trust with expanded validation
  • Secure storage of sensitive app data
    • Encryption of data
    • Pitfalls when saving data
    • Encryption management
  • Secure Programming
    • User input, indexing, field completion
    • Efficient data encryption
    • Backup & Restore
    • Logging & Auditing & Memory Management
  • Malware & Jailbreak, Rooting
    • Jailbreak & Jailbreak detection
    • Effective protection against malware
  • Advanced App Analysis
    • Reverse engineering
    • Static and dynamic analysis
    • Source code analysis
    • Code obfuscation

 

The exercises will be done on www.hacking-lab.com.

Target group

Developers of iPhone and Android applications and those who are responsible for security and want to learn the current mobile threats.

Prerequisite

  • Knowledge of programming not necessary
  • Good understanding of mobile devices advantageous
  • Ability to read and understand source code

CALENDAR

Basel Economic Forum 2019

The Basel Economic Forum is the economic forum for the trinational metropolitan region of Basel and northwestern Switzerland. The 6th event will take... Read more

New: Compass-Training "Internal Network and System Security" in Bern

In the 2-day seminar (in German) from February 11/12, 2020, you will get to know the most important basic concepts of IT security, attack tools and... Read more

KMU Swiss Forum 2020

The association «KMU Swiss» promotes the interaction between companies and specialists. He organises the annual KMU Swiss Forum. The next years motto... Read more

ALL DATES

NEWS

Vulnerability in totemodata

Fabio Poloni identified an XSS vulnerability in totemodata®. Read more

Gesundheitswesen: Ein leichtes Ziel für Hacker

«Heime & Spitäler» ist das Fachmedium für Entscheidungsträger von Schweizer Heimen und Spitäler. In der aktuellen Ausgabe beschreibt Compass Security... Read more

Vulnerablitity in VeloCloud™

Silas Bärtsch identified a vulnerability in VeloCloud™ (VMware), that allows a VeloCloud standard admin user to access user information of other... Read more

ARCHIVES

Compass Security Blog

Hacking Tools Cheat Sheet

Everyone knows: cheat sheets are cool! They are very useful if you already know the basics about a topic but you have to look up details when you are not sure about something. mehr

Introducing Web Vulnerabilities into Native Apps

Mobile applications nowadays make heavy use of WebViews in order to render their user interfaces. Frameworks such as PhoneGap / Apache Cordova are even used to implement most of the application's... mehr

ZUM BLOG