iOS App Integrity: Enhancing Security with Encrypted Code Modules

iOS App Integrity: Enhancing Security with Encrypted Code Modules

OWASP Foundation via YouTube Direct link

Introduction

1 of 29

1 of 29

Introduction

Class Central Classrooms beta

YouTube videos curated by Class Central.

Classroom Contents

iOS App Integrity: Enhancing Security with Encrypted Code Modules

Automatically move to the next video in the Classroom when playback concludes

  1. 1 Introduction
  2. 2 iOS Mobile App Security (MAS) Elevator Pitch
  3. 3 Hacking and Jailbreaking ios Attacks and weaknesses are well documented
  4. 4 Recent iOS App Coding and OS Reported Vulnerabilities
  5. 5 Standard iOS Application Today
  6. 6 Research Idea: IMAS Secure Application Framework
  7. 7 iOS Security Architecture
  8. 8 IMAS App Security "trade-space" Comparison Mar 2014
  9. 9 IMAS - Security Controls Device Access
  10. 10 Github: project-imas.github.io 13 Controls
  11. 11 IMAS - Encrypted Core Data (ECD) em
  12. 12 Encrypted Core Data Additional iMAS Support
  13. 13 Multi-compiler Based on work out of UC Irvine by Michael Franz and Per Larsen . Produces different binaries each compile • Static analysis and ROP exploits must account for variations
  14. 14 System Monitor - Monitor all device processes and network calls at the kernel level - Filtering tools to find and react to developer defined system events -IMAS provides direct programmatic app integ…
  15. 15 Memory Security Allows encryption, wiping, and checksums of objects in memory - Provides function address space validation Application Start
  16. 16 File Shredding
  17. 17 IMAS Sentry Application Add to existing Apple deployed devices • Jailbreak and Debugger Detection
  18. 18 Prior Research Focus - modifying ELF structures
  19. 19 iOS Static App Attacks
  20. 20 Static App Attacks Process
  21. 21 Code Injection and Binary Patching
  22. 22 Consequences of Static Attacks
  23. 23 Encrypted Code Modules (ECM) WHAT?
  24. 24 IMAS Encrypted Code Modules (ECM) Summary
  25. 25 ECM - Encrypted Code Modules Concept 2/3
  26. 26 Build Summary
  27. 27 App Startup
  28. 28 Validating Integrity
  29. 29 ECM Advantages

Never Stop Learning.

Get personalized course recommendations, track subjects and courses with reminders, and more.

Someone learning on their laptop while sitting on the floor.