SlideShare a Scribd company logo
Debashis Banerjee (deba_ban@rediffmail.com)
Who are they and how are they
             changing our world?




Pic: Free Lib:
http://office.microsoft.com/en-us/images
Today’s Agenda
   What is Mobile Web
   What is Mobile App
   Mobile Web and App Ecosystem
   Inside the Mobile
   Security in Mobile Web
   Security in Mobile App
   The Pyramid of Safety
What is Mobile Web and Apps
   Mobile Web
   Mobile Apps
     Android

     iOS

     Windows   Mobile
On Premise or Off Premise   Physical Access (internal/third party)
Enterprise Security
Software


                                                                           Web Developers


                                                                      Web Servers
    App Stores                     The Network




 App Developers
                                                               On Premise or Off Premise
                                                               Enterprise Security
                                                               Software

                                                          Mobile Web And Mobile
 On device
                                                          App Ecosystem – The
 phone                                                    Security Perspective
 Security
 Software
                                    Phone User
Inside the Mobile
6


                                   Wireless
                                                    RF
                   Microphone                      (e.g.
                                                GSM,CDMA)


                                                         SIM Cards
            RAM



                                                            Browser or
           ROM OS                                          Native Apps



                                                    Calender
            Pictures
                                                   Phone Book
               Or
                                                    Mail, SMS
            Videos


                                              Keyboard
                  Speaker                      Access
                                Battery
                                 Power
                                Supply
Security in Mobile web
   Decide on Device Class
   What is stored where? – cookies, passwords?
   Encryption – Off and on wire, Data & meta data
   Multi Factor Auth
   Anti Virus
   Intrusion Detection /Prevention
   Web Threats …SQL Injection, Cross Site Forgery
Security in Mobile web - Continued
   PCI DSS
   Identity , Previlidge and Access
   Sign in vs Sign off
   Logical and Physical Security
   Trusted/Untrusted Access/URLs
   Impact of Non Standard OSs
Security in Mobile app
   Security and Hosting Guidelines per app platform
   Signed Apps
   Marketplace security
   App to desktop sync risks
   Who reviewed the app?
   Security Ratings
   Install and Run previlidges of apps
Security in Mobile app - continued
   Remote Clean
   Access to areas of the phone
   Second Factor Auth
   Sandboxes
   Physical Security
   Security as a Service
The Pyramid of Safety
11




                         Safe Internet
                         /App usage practices

                   Web Site Security/App Security


              Browser Security/Web App Store Security
              Network and on device Security (anti virus
              /Identity/Access/Privilege Management)

              Physical Security – device and server
In Summary
   Mobile Web and Apps are going to significantly
    impact our browsing experiences
   Know the ecosystem they work in
   Security aspects
   The pyramid of Safety
The changed world is here !!!!!




Pic: Free Lib:
http://office.microsoft.com/en-us/images

More Related Content

PPTX
Mobile security
PPT
ttv_1215410348
PPT
Srand005 message protection
PPT
Hacking JME platform by example / 0wned by MoMo
PPT
Sven Kirsimäe: "Hacking JME platform by example: 0wned by MoMo"
PPTX
5 Key Ways to Incorporate Security Protection into your Organization’s Mobile...
PPTX
NGSoft General Overview
PDF
New trends in Payments Security: NFC & Mobile
Mobile security
ttv_1215410348
Srand005 message protection
Hacking JME platform by example / 0wned by MoMo
Sven Kirsimäe: "Hacking JME platform by example: 0wned by MoMo"
5 Key Ways to Incorporate Security Protection into your Organization’s Mobile...
NGSoft General Overview
New trends in Payments Security: NFC & Mobile

What's hot (20)

PDF
SecuSUITE for Enterprise Brochure
PDF
Ambient Intelligence - Parham Beheshti
PDF
Tips and Tricks for Building Secure Mobile Apps
PDF
Challenges in Testing Mobile App Security
PPT
How BYOD Will Shape Wireless Network Security in 2012
PPTX
Mobilination Ntymoshyk Personal Mobile Security Final Public
PDF
Motorola Cell Phone Accessories
PDF
Biometric Technology
PPTX
Mobile security
PDF
SYPHERSAFE
PDF
CTO Cybersecurity Forum 2013 David Turahi
PDF
Ca partner day - cloud e mobile security - milano
PPTX
PPTX
Cyber security
PPTX
ANDROID SECURITY
PDF
Eventure mobile app
PDF
Cloud based Anti-Theft Application for Android Devices: A Literature Review
ODP
Mobile Apps Security Testing -1
PDF
Viruses on mobile platforms why we don't/don't we have viruses on android_
PDF
Biometrics - The Future of Authentication in the Banking Industry
SecuSUITE for Enterprise Brochure
Ambient Intelligence - Parham Beheshti
Tips and Tricks for Building Secure Mobile Apps
Challenges in Testing Mobile App Security
How BYOD Will Shape Wireless Network Security in 2012
Mobilination Ntymoshyk Personal Mobile Security Final Public
Motorola Cell Phone Accessories
Biometric Technology
Mobile security
SYPHERSAFE
CTO Cybersecurity Forum 2013 David Turahi
Ca partner day - cloud e mobile security - milano
Cyber security
ANDROID SECURITY
Eventure mobile app
Cloud based Anti-Theft Application for Android Devices: A Literature Review
Mobile Apps Security Testing -1
Viruses on mobile platforms why we don't/don't we have viruses on android_
Biometrics - The Future of Authentication in the Banking Industry
Ad

Viewers also liked (13)

PPT
Changing trends in sw development
DOC
1102700 laporan jobsheet 1 - vegi laten haju embulni sanyus
DOC
atul_resume
PPT
Transaction unit1 topic 2
PDF
Debashis banerjee cloud_is_as_secure
PPTX
Is there a Golden Ratio? Test Specialist to Developer in an Agile team
PPT
Section 3 resistive circuit analysis ii
PPT
Locks with updt nowait
PPT
Normalization
PPT
Overview of query evaluation
PPT
Multivalued dependency
PPT
Sequences
PPT
Locking unit 1 topic 3
Changing trends in sw development
1102700 laporan jobsheet 1 - vegi laten haju embulni sanyus
atul_resume
Transaction unit1 topic 2
Debashis banerjee cloud_is_as_secure
Is there a Golden Ratio? Test Specialist to Developer in an Agile team
Section 3 resistive circuit analysis ii
Locks with updt nowait
Normalization
Overview of query evaluation
Multivalued dependency
Sequences
Locking unit 1 topic 3
Ad

Similar to Debashis banerjee mobile_webappintrosecurity (20)

PPTX
Securing mobile population for White Hats
PPTX
Enterprise Mobile Security
PDF
Be A Mobile Design Hero: Transform Your Web Design Knowledge Into Mobile Desi...
PPT
Udløs potentialet i Enterprise Mobility, Vijay Dheap, IBM US
PDF
Securing Mobile Apps: New Approaches for the BYOD World
PDF
Mobile Application Security
PPTX
SMART PHONE
PDF
Pharma times mobile[2]
PDF
C0c0n 2011 mobile security presentation v1.2
PDF
35602787 mobile-application-testing
PDF
การสร้างเกราะป้องกันภัยคุกคาม ต่อข้อมูลความเป็นส่วนบุคคลในองค์กร
PDF
Lotusphere 2012 - Harnessing the Power of Enterprise Mobility
PDF
All about apps
PDF
Online information conference 2011
PPT
Mobile Apps Security
PDF
The Enterprise Goes Mobile
PPTX
Mobile – Adoption and Adaption in 2012
PDF
Palm Pre User Guide
PDF
Mobile Apps for Business Productivity The Circuit
PDF
How to scale enterprise mobility and improve roi
Securing mobile population for White Hats
Enterprise Mobile Security
Be A Mobile Design Hero: Transform Your Web Design Knowledge Into Mobile Desi...
Udløs potentialet i Enterprise Mobility, Vijay Dheap, IBM US
Securing Mobile Apps: New Approaches for the BYOD World
Mobile Application Security
SMART PHONE
Pharma times mobile[2]
C0c0n 2011 mobile security presentation v1.2
35602787 mobile-application-testing
การสร้างเกราะป้องกันภัยคุกคาม ต่อข้อมูลความเป็นส่วนบุคคลในองค์กร
Lotusphere 2012 - Harnessing the Power of Enterprise Mobility
All about apps
Online information conference 2011
Mobile Apps Security
The Enterprise Goes Mobile
Mobile – Adoption and Adaption in 2012
Palm Pre User Guide
Mobile Apps for Business Productivity The Circuit
How to scale enterprise mobility and improve roi

Recently uploaded (20)

PDF
Spectral efficient network and resource selection model in 5G networks
PDF
Dropbox Q2 2025 Financial Results & Investor Presentation
PDF
Electronic commerce courselecture one. Pdf
PDF
Empathic Computing: Creating Shared Understanding
PDF
Review of recent advances in non-invasive hemoglobin estimation
PDF
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
DOCX
The AUB Centre for AI in Media Proposal.docx
PPTX
Cloud computing and distributed systems.
PDF
Approach and Philosophy of On baking technology
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
Diabetes mellitus diagnosis method based random forest with bat algorithm
PPTX
Big Data Technologies - Introduction.pptx
PPTX
20250228 LYD VKU AI Blended-Learning.pptx
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Network Security Unit 5.pdf for BCA BBA.
Spectral efficient network and resource selection model in 5G networks
Dropbox Q2 2025 Financial Results & Investor Presentation
Electronic commerce courselecture one. Pdf
Empathic Computing: Creating Shared Understanding
Review of recent advances in non-invasive hemoglobin estimation
Architecting across the Boundaries of two Complex Domains - Healthcare & Tech...
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
Unlocking AI with Model Context Protocol (MCP)
The AUB Centre for AI in Media Proposal.docx
Cloud computing and distributed systems.
Approach and Philosophy of On baking technology
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Encapsulation_ Review paper, used for researhc scholars
Mobile App Security Testing_ A Comprehensive Guide.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Diabetes mellitus diagnosis method based random forest with bat algorithm
Big Data Technologies - Introduction.pptx
20250228 LYD VKU AI Blended-Learning.pptx
Per capita expenditure prediction using model stacking based on satellite ima...
Network Security Unit 5.pdf for BCA BBA.

Debashis banerjee mobile_webappintrosecurity

  • 2. Who are they and how are they changing our world? Pic: Free Lib: http://office.microsoft.com/en-us/images
  • 3. Today’s Agenda  What is Mobile Web  What is Mobile App  Mobile Web and App Ecosystem  Inside the Mobile  Security in Mobile Web  Security in Mobile App  The Pyramid of Safety
  • 4. What is Mobile Web and Apps  Mobile Web  Mobile Apps  Android  iOS  Windows Mobile
  • 5. On Premise or Off Premise Physical Access (internal/third party) Enterprise Security Software Web Developers Web Servers App Stores The Network App Developers On Premise or Off Premise Enterprise Security Software Mobile Web And Mobile On device App Ecosystem – The phone Security Perspective Security Software Phone User
  • 6. Inside the Mobile 6 Wireless RF Microphone (e.g. GSM,CDMA) SIM Cards RAM Browser or ROM OS Native Apps Calender Pictures Phone Book Or Mail, SMS Videos Keyboard Speaker Access Battery Power Supply
  • 7. Security in Mobile web  Decide on Device Class  What is stored where? – cookies, passwords?  Encryption – Off and on wire, Data & meta data  Multi Factor Auth  Anti Virus  Intrusion Detection /Prevention  Web Threats …SQL Injection, Cross Site Forgery
  • 8. Security in Mobile web - Continued  PCI DSS  Identity , Previlidge and Access  Sign in vs Sign off  Logical and Physical Security  Trusted/Untrusted Access/URLs  Impact of Non Standard OSs
  • 9. Security in Mobile app  Security and Hosting Guidelines per app platform  Signed Apps  Marketplace security  App to desktop sync risks  Who reviewed the app?  Security Ratings  Install and Run previlidges of apps
  • 10. Security in Mobile app - continued  Remote Clean  Access to areas of the phone  Second Factor Auth  Sandboxes  Physical Security  Security as a Service
  • 11. The Pyramid of Safety 11 Safe Internet /App usage practices Web Site Security/App Security Browser Security/Web App Store Security Network and on device Security (anti virus /Identity/Access/Privilege Management) Physical Security – device and server
  • 12. In Summary  Mobile Web and Apps are going to significantly impact our browsing experiences  Know the ecosystem they work in  Security aspects  The pyramid of Safety
  • 13. The changed world is here !!!!! Pic: Free Lib: http://office.microsoft.com/en-us/images