Protection foundations
Scope, trust models and the layers of application protection.
Runtime protection: where RASP fits in an application
Application protection goes beyond obscuring compiled code. RASP evaluates signs of interference while a distributed application runs, providing the runtime layer of…
Read the guideFrom protection signal to transaction decision: the RASP flow
A security check and a security decision serve different purposes.
Read the guideApp shielding and RASP: understanding product scope
App shielding usually describes products that combine code hardening with runtime checks. RASP focuses on security decisions made while the application is running.
Read the guideThe difference between in-app protection and antivirus
Antivirus aims to identify malicious software on a device. Application protection focuses on the security of its own code, data and operations.
Read the guideWhat do mobile app protection and a WAF cover together?
A WAF evaluates web traffic reaching the server; in-app protection evaluates client execution. The two systems collect information at different observation points.
Read the guideHow SAST findings inform an application protection plan
SAST examines source code and data flows for issues that developers can fix during development. Runtime defenses operate at a different control point.
Read the guideCombining DAST with mobile protection testing
DAST observes a running service from outside. This perspective helps establish whether protection added to a mobile client changes API behavior.
Read the guideMobile Threat Defense and application protection
MTD broadens visibility into devices, networks and mobile threats. App protection applies controls directly to a particular application's code and operations.
Read the guideAn application protection threat model for Android and iOS
Prepare the threat model before assembling a product list. Identify the asset, the operation in which it needs protection and the capabilities of the attacker it must…
Read the guideDrawing trust boundaries in a mobile application
The device is under the user's control. Values produced by the application cannot all carry the same authority as trusted server data.
Read the guideShould the device or server make a protection decision?
Local decisions provide a quick response. Server decisions combine account details, history and transaction context.
Read the guideWhy root and jailbreak need distinct policies
Root concerns Android privileges; jailbreak concerns modifications to restrictions on Apple's platform.
Read the guideThe practical contribution of code obfuscation
Code obfuscation changes names, control flow or data representation to increase analysis cost. It does not make it safe to place server secrets in a client.
Read the guideAnti-tamper: detecting and stopping package modification
Anti-tamper checks look for departures from an application's expected integrity. Producing an alert and protecting a critical function require separate verification.
Read the guideHow to assess anti-debugging controls
Debugging is a normal part of development. Observing sensitive execution in a production application creates a different risk.
Read the guideAnti-hooking and the protection of critical functions
Hooking allows a function's behavior to be observed or changed at runtime. Anti-hooking controls aim to limit the effect of that interference on an application.
Read the guideApp attestation: establishing application identity
Attestation evaluates claims made by a client against an independent source of trust. Android and iOS do not use the same evidence format.
Read the guideHow false positives affect application protection
A false positive classifies legitimate use as risky. Its impact extends beyond support-ticket volume: it can interrupt payments, access and account recovery.
Read the guideAccess during failures: fail-open and fail-closed
A verification service that does not respond has not proved the application untrustworthy. A failure policy defines which operations can continue under uncertainty.
Read the guideMeasuring the performance cost of application protection
APK or IPA size alone does not measure protection overhead. Startup time, transaction latency, memory, battery use and error rates all affect the user experience.
Read the guideSDK, compiler and post-build protection options
Where protection enters the delivery pipeline affects maintenance cost. SDKs, compiler plugins and post-build processing create different integration requirements.
Read the guideWhat questions should protection telemetry answer?
Useful telemetry goes beyond recording that something happened. It connects the control, the policy and the resulting transaction outcome.
Read the guideWhich vulnerabilities does application protection leave open?
A hardened client does not make faulty authorization or account recovery safe. Understanding protection limits helps direct investment where it matters.
Read the guideDefining success in an app protection proof of concept
A proof of concept tests security and operational expectations in your own application, rather than simply demonstrating a product.
Read the guideA learning path for Android app protection and iOS app protection
Understanding a platform's trust model comes before memorizing tool names. Code, data, identity and server decisions are interconnected.
Read the guide