iOS Application Defense - iMAS

Thursday, November 21 • 10:00 am - 10:50 am

iOS application security can be *much* stronger and easy for developers to find, understand and use.  iMAS (iOS Mobile Application Security) - is a secure, open source  iOS application framework research project focused on reducing iOS application vulnerabilities and information loss.  Today, iOS meets the enterprise security needs of customers, however many security experts cite critical vulnerabilities and have demonstrated exploits, which in turn pushes enterprises to augment iOS deployments with commercial solutions.  The iMAS intent is to protect iOS applications and data beyond the Apple provided security model and reduce the adversary’s ability and efficiency to perform recon, exploitation, control and execution on iOS mobile applications.  iMAS has released five security controls (researching many more)  for developers to download and use within iOS applications.  This talk will walk through various iOS application vulnerabilities, iMAS security controls, OWASP Mobile top10 and CWE vulnerabilities addressed, and demonstrate the iMAS App Password control integrated into an application.
Speaker:
Gregg Ganley

23+ software development and management experience Education: MSCS, BSEE Active research and development in iOS security and development, Ruby on Rails web apps, project leadership and agile SW development methodologies, Linux, Java Android Mobile Application Development and Android system internals and security, relational/NoSQL databases, Objective-C, Java, Ruby, HTML, JavaScript, HTML5, CSS, MVC architecture, REST, Sinatra, git, and C/Linux kernel SW development, Scrum Master Certified

Gregg Ganley is a mobile security researcher at the MITRE Corp and is currently the Principal Investigator on the iOS Mobile App Security (iMAS) research project. Gregg has been working in the mobile field for the past 6 years which has included iOS security, forensics and app development, Java Android mobile application security development and forensic expertise. Gregg also develops Ruby / Rails web applications and prototypes for various government agencies. http://project-imas.github.com