Application Security for the Android Platform: Processes, Permissions, and Other Safeguards
Book information
Description
This book will educate readers on the need for application security and secure coding practices when designing any app. No prior knowledge of security or secure programming techniques is assumed. The book will discuss the need for such practices, how the Android environment is structured with respect to security considerations, what services and techniques are available on the platform to protect data, and how developers can build and code applications that address the risk to their applications and the data processed by them. This text is especially important now, as Android is fast becoming the mobile platform target of choice for attackers attempting to steal data from mobile devices. Table of Contents file://www.ebooksave.comPreface Organization of the Book Conventions Used in This Book Using Code Examples Safari® Books Online How to Contact Us Acknowledgments Chapter 1. Introduction Application Security: Why You Should Care The Current State of Mobile Application Security on Android Security: Risk = Vulnerability + Threat + Consequences Evolution of Information Security: Why Applications Matter the Most Your Role: Protect the Data Secure Software Development Techniques Unique Characteristics of Android Moving On Chapter 2. Android Architecture Introduction to the Android Architecture The Linux Security Model The Resulting Android Security Model Application Signing, Attribution, and Attestation Process Design Android Filesystem Isolation Android Preferences and Database Isolation Moving up the Layers to System API and Component Permissions Chapter 3. Application Permissions Android Permission Basics Using Restricted System APIs and the User Experience Custom Permissions Chapter 4. Component Security and Permissions The Types of Android Components Intercomponent Signaling Using Intents Public and Private Components Imposing Restrictions on Access to Components Securing Activities Securing Services Securing Content Providers Securing Broadcast Intents Putting It All Together: Securing Communications in a Multi-Tier App Chapter 5. Protecting Stored Data The Threats and Vulnerabilities Against Stored Data Vulnerabilities of Stored Data Threats to, and Mitigations for, Stored Data Protection Principles Cryptography Primer: Encryption Symmetric Encryption Asymmetric Key Encryption Cryptography Primer: Hashing Cryptographic Practicalities Computational Infeasibility Algorithm Choice and Key Size Cipher Operation Modes, Initialization Vectors, and Salt Public Keys and Their Management Key Derivation and Management Motivation Key Derivation Encryption Without User-Supplied Key Derivation Practical Cryptography: Applying a Technique Against a Threat Chapter 6. Securing Server Interactions Confidentiality and Authentication SSL/TLS: The Industry Standard Authentication of the Entities Encryption of Data Protecting Data En Route to Public Services Introducing the Android SSL/TLS Environment Server Verification Handling SSL/TLS Connection Errors Protecting Data En Route to Private Services Using Only Specific Certificates for SSL/TLS One Step Further: Using Client-Side Authentication SSL/TLS Threats Against Devices Using Data in Transit Input Validation: The Central Tenant of Application Security Reject-Known-Bad Accept-Known-Good Wrapping It Up: Input Validation Preventing Command Injection Chapter 7. Summary Key Themes It’s All About Risk The Principle of Least Privilege Use the Permissions System Android Is an Open Architecture Get the Cryptography Right Never Trust User Input Wrapping It Up
Similar books
Application Security for the Android Platform: Processes, Permissions, and Other Safeguards
2011 · PDF
Application Security for the Android Platform: Processes, Permissions, and Other Safeguards
2011 · EPUB
Application Security for the Android Platform: Processes, Permissions, and Other Safeguards
2011 · PDF
MySQL® Notes for Professionals book
2018 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
MrExcel 2022: Boosting Excel
2022 · PDF
Session C11: Ancient Cultural Landscapes in South Europe – their Ecological Setting and Evolution, Session C22: Gardeners from South America, Session S04: Agro-Pastoralism and Early Metallurgy Sessions, Session WS29: The Idea of Enclosure in Recent Iberian Prehistory, Session C88: Rhytmes et causalites des dynamiques de l'anthropisation en Europe entre 6500 ET 500 BC: Hypotheses socio-culturelles et/ou climatiques: Proceedings of the XV UISPP World Congress (Lisbon 4-9 September 2006) / Actes du XV Congrès Mondial (Lisbonne 4-9 Septembre 2006) Vol.36
2010 · PDF
THE BRITISH ARMY IN INDIA: ITS PRESERVATION BY AN APPROPRIATE CLOTHING, HOUSING, LOCATING, RECREATIVE EMPLOYMENT, AND HOPEFUL ENCOURAGEMENT OF THE TROOPS. with AN APPENDIX ON INDIA : THE CLIMATE OP ITS HILLS ; THE DEVELOPMENT OF ITS RESODRCBS, INDUSTRY, AND ARTS ; THE ADMINISTRATION OF JUSTICE ; THE BLACK ACT ; THE PROGRESS OF CHRISTIANITY ; THE TRAFFIC IN OPIUM ; THE VALUE OF INDIA ; PERMANENT CAUSES OF DISAFFECTION, AND OF THE RECENT REBELLION ; THE TRADITIONARY POLICY; MISGOVERNMENT BY NATIVE RULERS ; ANNEXATIONS OF THEIR TERRITORY, ETC.
1858 · PDF