ENGLISH

Bulletproof Android: Practical Advice for Building Secure Apps

Book information

Publisher
Addison-Wesley Professional
Year
2014
ISBN
0133993329, 9780133993325
Language
english
Format
CHM
Filesize
19 MB (20112195 bytes)
Edition
Paperback
Pages
240\0
Topic
Computers Security
Time added
2019-03-14 22:02:55

Description

Battle-Tested Best Practices for Securing Android Apps throughout the Development LifecycleAndroid's immense popularity has made it today's #1 target for attack: high-profile victims include eHarmony, Facebook, and Delta Airlines, just to name a few. Today, every Android app needs to resist aggressive attacks and protect data, and inBulletproof Android(TM),Godfrey Nolan shows you how. Unlike "black hat/gray hat" books, which focus on breaking code, this guide brings together complete best practices for hardening code throughout the entire development lifecycle. Using detailed examples from hundreds of apps he has personally audited, Nolan identifies common "anti-patterns" that expose apps to attack, and then demonstrates more secure solutions. Nolan covers authentication, networking, databases, server attacks, libraries, hardware, and more. He illuminates each technique with code examples, offering expert advice on implementation and trade-offs. Each topic is supported with a complete sample app, which demonstrates real security problems and solutions. Learn how to Apply core practices for securing the platform Protect code, algorithms, and business rules from reverse engineering Eliminate hardcoding of keys, APIs, and other static data Eradicate extraneous data from production APKs Overcome the unique challenges of mobile authentication and login Transmit information securely using SSL Prevent man-in-the-middle attacks Safely store data in SQLite databases Prevent attacks against web servers and services Avoid side-channel data leakage through third-party libraries Secure APKs running on diverse devices and Android versions Achieve HIPAA or FIPS compliance Harden devices with encryption, SELinux, Knox, and MDM Preview emerging attacks and countermeasuresThis guide is a perfect complement to Nolan'sAndroid(TM) Security Essentials LiveLessons(video training; ISBN-13: 978-0-13-382904-4) and reflects new risks that have been identified since the LiveLessons were released. Preface Acknowledgments About the Author 1 Android Security Issues Why Android? Decompiling an APK Art for Art’s Sake Guidelines PCI Mobile Payment Acceptance Security Guidelines Google Security HIPAA Secure OWASP Top 10 Mobile Risks (2014) Forrester Research’s Top 10 Nontechnical Security Issues in Mobile App Development Securing the Device SEAndroid Federal Information Processing Standard (FIPS) Conclusion 2 Protecting Your Code Looking into the classes.dex File Obfuscation Best Practices No Obfuscation ProGuard DexGuard Security Through Obscurity Testing Smali Helloworld Remove App Store Check Hiding Business Rules in the NDK Conclusion 3 Authentication Secure Logins Understanding Best Practices for User Authentication and Account Validation Take 1 Take 2 Take 3 Take 4 Application Licensing with LVL OAuth OAuth with Facebook Web and Mobile Session Management Vulnerability User Behavior Two (or More) Factor Authentication Conclusion 4 Network Communication HTTP(S) Connection Symmetric Keys Asymmetric Keys Ineffective SSL Man-in-the-Middle Demo Root Your Phone Charles Proxy Test Conclusion 5 Android Databases Android Database Security Issues SQLite Backing Up the Database Using adb Disabling Backup SQLCipher Finding the Key Hiding the Key Ask Each Time Shared Preferences In the Code In the NDK Web Services SQL Injection Conclusion 6 Web Server Attacks Web Services OWASP Web Services Cheat Sheet Replay Attacks Cross Platform WebView Attacks SQL Injection XSS Cloud OWASP Web Top 10 Risks OWASP Cloud Top 10 Risks HIPAA Web Server Compliance Conclusion 7 Third-Party Library Integration Transferring the Risk Permissions Installing Third-Party Apps Installing Crittercism Installing Crashlytics Trust but Verify Decompiling SDKs Man in the Middle Conclusion 8 Device Security Wiping Your Device Fragmentation adb Backup Logs Device Encryption SEAndroid FIPS 140-2 Mobile Device Management Conclusion 9 The Future More Sophisticated Attacks Internet of Things Android Wearables Ford Sync AppID Audits and Compliance Tools Drozer OWASP Mobile Top 10 Risks Lint Conclusion Index

Similar books