Mobile Application Hardening: Protecting Business Critical Apps

No ratings

Presented at SecuriTayDundee 2019 by

Mobile application security isn't always super exciting or challenging but when it comes to application hardening things get more interesting. These days, it is not uncommon for particular types of application to go out of their way to defend themselves at runtime. Such application types would include but are not limited to:- financial apps- multiplayer games- apps which feature DRM protected content- apps with intellectual property etc. It's often the case that such applications attempt to protect themselves via internally developed controls, as well as leveraging commercial products. During this talk we'll look at some of the typical controls that Android/iOS applications exhibit, how they work, how to spot them, and how to sidestep them. We’ll be demonstrating analysis and techniques using free open source tooling such as Radare, Frida, and for some parts we’ll also leverage IDA Pro. Since automation is the buzzword of the year too we’ll also be discussing how to automate some of these activities that typically take up most of the assessment window.