This site is the archived OWASP Foundation Wiki and is no longer accepting Account Requests.
To view the new OWASP Foundation website, please visit https://owasp.org

Difference between revisions of "OWASP Mobile Security Project"

From OWASP
Jump to: navigation, search
(Mobile Tools: Uploaded the mindmap)
(About this list)
Line 110: Line 110:
 
In 2013, we polled the industry for new vulnerability statistics in the field of mobile applications. What you see here is a result of that data and a representation of the mobile application threat landscape.  
 
In 2013, we polled the industry for new vulnerability statistics in the field of mobile applications. What you see here is a result of that data and a representation of the mobile application threat landscape.  
  
 +
[[File:Mobile_Top_10_2014.png|right|640px]]
 +
Our goals for the 2014 list included the following:
  
Our goals for the 2014 list included the following:
 
[[File:2014-01-26 20-23-29.png|right|550px]]
 
 
* Updates to the wiki content; including cross-linking to testing guides, more visual exercises, etc;
 
* Updates to the wiki content; including cross-linking to testing guides, more visual exercises, etc;
 
* Generation of more data; and
 
* Generation of more data; and
Line 119: Line 119:
 
This list has been finalized after a 90-day feedback period from the community. Based on feedback, we intend on releasing a Mobile Top Ten 2015 list following a similar approach of collecting data, grouping the data in logical and consistent ways.
 
This list has been finalized after a 90-day feedback period from the community. Based on feedback, we intend on releasing a Mobile Top Ten 2015 list following a similar approach of collecting data, grouping the data in logical and consistent ways.
  
Feel free to visit [https://groups.google.com/a/owasp.org/forum/#!forum/owasp-mobile-top-10-risks the mailing list] as well!  
+
Feel free to visit [https://groups.google.com/a/owasp.org/forum/#!forum/owasp-mobile-top-10-risks the mailing list] as well!
  
 
== Call to Action for 2015 ==
 
== Call to Action for 2015 ==

Revision as of 21:10, 27 June 2015

Lab big.jpg

OWASP Mobile Security Project

The OWASP Mobile Security Project is a centralized resource intended to give developers and security teams the resources they need to build and maintain secure mobile applications. Through the project, our goal is to classify mobile security risks and provide developmental controls to reduce their impact or likelihood of exploitation.

Our primary focus is at the application layer. While we take into consideration the underlying mobile platform and carrier inherent risks when threat modeling and building controls, we are targeting the areas that the average developer can make a difference. Additionally, we focus not only on the mobile applications deployed to end user devices, but also on the broader server-side infrastructure which the mobile apps communicate with. We focus heavily on the integration between the mobile application, remote authentication services, and cloud platform-specific features.


We have a Google Doc where anyone who wants to be involved with the project can add their thoughts, suggestions, and take ownership of initiatives - Click here. There are various tasks that people have started over the past 6 months with varying levels of quality and completeness.

This project is still a work in progress. We are small group doing this work and could use more help! If you are interested, please contact one of the project leads or feel free to visit the mailing list as well!

Email List

Asvs-bulb.jpg Project Email List

Project Leaders

Mike Zusman @
Tony DeLaGrange @
Sarath Geethakumar @
Tom Eston @
Don Williams
Jason Haddix @

Contributors

Zach Lanier @
Jim Manico @
Ludovic Petit @
Swapnil Deshmukh @
Beau Woods @
Jonathan Carter @
David Martin Aaron @
Luca De Fulgentis @
Milan Singh Thakur @
Andrew Pannell @