{"id":53353,"date":"2019-02-02T08:22:39","date_gmt":"2019-02-02T05:22:39","guid":{"rendered":"https:\/\/www.checkmarx.com\/?post_type=glossary&#038;p=3004"},"modified":"2024-08-15T14:21:16","modified_gmt":"2024-08-15T14:21:16","slug":"mobile-application-security-android-ios","status":"publish","type":"glossary","link":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/","title":{"rendered":"Mobile Application Security (Android\/iOS)"},"content":{"rendered":"<p style=\"text-align: justify;\">Mobile application security for Android and iOS doesn\u2019t always receive the attention it deserves. Because smartphones have become more affordable and internet access improves, software development teams are increasing mobile application development. Mobile internet traffic today accounts for 61% of total web traffic in Asia, and 57% of total web traffic in Africa. <a href=\"https:\/\/www.statista.com\/statistics\/306528\/share-of-mobile-internet-traffic-in-global-regions\/\" target=\"_blank\" rel=\"noopener\">According to statista<\/a>, 48% of the total web traffic globally is mobile internet traffic.<\/p>\n<p><span style=\"color: #333333;\"><!--more--><\/span><\/p>\n<h2 style=\"text-align: justify;\" class=\"article-anchor\" id=\"article-anchor-1\">Mobile Application Security (Android\/iOS) \u2013 An Overview<\/h2>\n<p style=\"text-align: justify;\">There is a level of trust that the ordinary user places in technology. They assume that it is difficult to be hacked and that viruses, malware, and other security issues are not prevalent. The truth is that mobile application security for Android and iOS should be a high priority. These platforms face the same threats as other platforms. Malicious actors still want to steal data, for financial gain or more esoteric purposes.<\/p>\n<p style=\"text-align: justify;\">The Trustwave 2018 Global Security Report showed retail, finance and insurance industry, and hospitality suffered the most breach incidences. Trustwave found all web applications to be vulnerable, and that web attacks are becoming more targeted. Nearly half of global web traffic is via mobile, making it essential to deploy secure mobile applications.<\/p>\n<h2 style=\"text-align: justify;\" class=\"article-anchor\" id=\"article-anchor-2\">Mobile Application Security (Android\/iOS) \u2013 Attack Points<\/h2>\n<p style=\"text-align: justify;\">Malware creators use various points of attack for smartphone applications. These attack points include:<\/p>\n<ul>\n<li style=\"text-align: justify;\">Data storage areas: key stores, file systems, databases, config files;<\/li>\n<li style=\"text-align: justify;\">Binary attacks: reverse engineering, exploitation of vulnerabilities, embedding false credentials;<\/li>\n<li style=\"text-align: justify;\">Platform: function hooking, installing malware, developing botnets on smartphones, targeting specific architecture requirements of a platform.<\/li>\n<\/ul>\n<h2 style=\"text-align: justify;\" class=\"article-anchor\" id=\"article-anchor-3\">Mobile Application Security (Android\/iOS) \u2013 Advice for Developers<\/h2>\n<p style=\"text-align: justify;\">Mobile application development teams need to focus on security. It\u2019s vital to understand the mobile platform and how the operating system (OS) functions. This allows developers to understand the possible threats to mobile application security and take action to prevent or minimize these threats. They should know how the code libraries for their application link to the OS itself and examine threats that emerge as part of that process.<\/p>\n<p style=\"text-align: justify;\">Software development teams must be confident that they know the contents of the final compiled version of the application and how an attacker might read that compiled code. Mobile application security (Android or iOS) can be enhanced by fully understanding where every piece of data is stored (cache, database, configuration information), then examining how that data can be better secured against attack.<\/p>\n<p style=\"text-align: justify;\">How can Checkmarx help with mobile application security? <a href=\"https:\/\/checkmarx.com\/cxsast-source-code-scanning\/\" target=\"_blank\" rel=\"noopener\">CxSAST<\/a> analyzes iOS and Android app code and identifies flaws often missed in traditional testing environments. The product helps you track down areas that may be vulnerable to code injection, session fixation, password inadequacy, among other issues. This fully automated process allows your developers to concentrate on fixing problems rather than finding them.<\/p>\n<div align=\"center\">\n<!--HubSpot Call-to-Action Code --><span class=\"hs-cta-wrapper\"><span class=\"hs-cta-wrapper\"><span class=\"hs-cta-node hs-cta-3e9bb362-9f66-4467-ae2d-a69cde52e9fa\"><!-- [if lte IE 8]&gt;--><\/span><\/span><\/span>\n<div id=\"hs-cta-ie-element\"><\/div>\n<p><a href=\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/05\/Tolly-Report-Checkmarx-Comparative-App-Security.pdf\" target=\"_blank\" rel=\"noopener\"><img decoding=\"async\" id=\"hs-cta-img-3e9bb362-9f66-4467-ae2d-a69cde52e9fa\" class=\"hs-cta-img alignnone\" style=\"border-width: 0px;\" src=\"https:\/\/no-cache.hubspot.com\/cta\/default\/146169\/3e9bb362-9f66-4467-ae2d-a69cde52e9fa.png\" alt=\"Secure your code from the very beginning with CxSAST\" width=\"600\" height=\"200\"><\/a><\/p>\n<p><!-- end HubSpot Call-to-Action Code --><\/p>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>Mobile application security for Android and iOS doesn\u2019t always receive the attention it deserves. Because smartphones have become more affordable and internet access improves, software development teams are increasing mobile application development. Mobile internet traffic today accounts for 61% of total web traffic in Asia, and 57% of total web traffic in Africa. According to [&hellip;]<\/p>\n","protected":false},"author":11,"featured_media":3005,"template":"","glossary-tags":[],"class_list":["post-53353","glossary","type-glossary","status-publish","has-post-thumbnail","hentry"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v27.1.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>Mobile Application Security (Android\/iOS)<\/title>\n<meta name=\"description\" content=\"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Mobile Application Security (Android\/iOS)\" \/>\n<meta property=\"og:description\" content=\"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/\" \/>\n<meta property=\"og:site_name\" content=\"Checkmarx\" \/>\n<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\" \/>\n<meta property=\"article:modified_time\" content=\"2024-08-15T14:21:16+00:00\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:site\" content=\"@checkmarx\" \/>\n<meta name=\"twitter:label1\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data1\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/\",\"url\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/\",\"name\":\"Mobile Application Security (Android\/iOS)\",\"isPartOf\":{\"@id\":\"https:\/\/checkmarx.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage\"},\"thumbnailUrl\":\"\",\"datePublished\":\"2019-02-02T05:22:39+00:00\",\"dateModified\":\"2024-08-15T14:21:16+00:00\",\"description\":\"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.\",\"breadcrumb\":{\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage\",\"url\":\"\",\"contentUrl\":\"\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Glossary\",\"item\":\"https:\/\/checkmarx.com\/glossary\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Mobile Application Security (Android\/iOS)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/checkmarx.com\/#website\",\"url\":\"https:\/\/checkmarx.com\/\",\"name\":\"Checkmarx\",\"description\":\"The world runs on code. We secure it.\",\"publisher\":{\"@id\":\"https:\/\/checkmarx.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/checkmarx.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/checkmarx.com\/#organization\",\"name\":\"Checkmarx\",\"url\":\"https:\/\/checkmarx.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"contentUrl\":\"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg\",\"width\":1,\"height\":1,\"caption\":\"Checkmarx\"},\"image\":{\"@id\":\"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/\"},\"sameAs\":[\"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis\",\"https:\/\/x.com\/checkmarx\",\"https:\/\/www.youtube.com\/user\/CheckmarxResearchLab\",\"https:\/\/www.linkedin.com\/company\/checkmarx\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Mobile Application Security (Android\/iOS)","description":"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/","og_locale":"en_US","og_type":"article","og_title":"Mobile Application Security (Android\/iOS)","og_description":"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.","og_url":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/","og_site_name":"Checkmarx","article_publisher":"https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","article_modified_time":"2024-08-15T14:21:16+00:00","twitter_card":"summary_large_image","twitter_site":"@checkmarx","twitter_misc":{"Est. reading time":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/","url":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/","name":"Mobile Application Security (Android\/iOS)","isPartOf":{"@id":"https:\/\/checkmarx.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage"},"image":{"@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage"},"thumbnailUrl":"","datePublished":"2019-02-02T05:22:39+00:00","dateModified":"2024-08-15T14:21:16+00:00","description":"Smartphones have become more affordable and mobile bandwidth (and Wi-Fi) access has improved, which is why mobile application security is essential.","breadcrumb":{"@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#primaryimage","url":"","contentUrl":""},{"@type":"BreadcrumbList","@id":"https:\/\/checkmarx.com\/glossary\/mobile-application-security-android-ios\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Glossary","item":"https:\/\/checkmarx.com\/glossary\/"},{"@type":"ListItem","position":2,"name":"Mobile Application Security (Android\/iOS)"}]},{"@type":"WebSite","@id":"https:\/\/checkmarx.com\/#website","url":"https:\/\/checkmarx.com\/","name":"Checkmarx","description":"The world runs on code. We secure it.","publisher":{"@id":"https:\/\/checkmarx.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/checkmarx.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/checkmarx.com\/#organization","name":"Checkmarx","url":"https:\/\/checkmarx.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/","url":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","contentUrl":"https:\/\/checkmarx.com\/wp-content\/uploads\/2024\/02\/logo-dark.svg","width":1,"height":1,"caption":"Checkmarx"},"image":{"@id":"https:\/\/checkmarx.com\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/www.facebook.com\/Checkmarx.Source.Code.Analysis","https:\/\/x.com\/checkmarx","https:\/\/www.youtube.com\/user\/CheckmarxResearchLab","https:\/\/www.linkedin.com\/company\/checkmarx"]}]}},"_links":{"self":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53353","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary"}],"about":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/types\/glossary"}],"author":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/users\/11"}],"version-history":[{"count":0,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary\/53353\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/"}],"wp:attachment":[{"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/media?parent=53353"}],"wp:term":[{"taxonomy":"glossary-tags","embeddable":true,"href":"https:\/\/checkmarx.com\/wp-json\/wp\/v2\/glossary-tags?post=53353"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}