Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Add MSTG-RESILIENCE-7 and MSTG-RESILIENCE-8 #1113

Open
commjoen opened this issue Jan 11, 2019 · 2 comments
Open

Add MSTG-RESILIENCE-7 and MSTG-RESILIENCE-8 #1113

commjoen opened this issue Jan 11, 2019 · 2 comments

Comments

@commjoen
Copy link
Collaborator

@commjoen commjoen commented Jan 11, 2019

Add 8.7 and 8.8 for android and ios: show how you can delay the attacker or report tampering to the backend as a response to a tamper detected
8.7: The app implements multiple mechanisms in each defense category (8.1 to 8.6). Note that resiliency scales with the amount, diversity of the originality of the mechanisms used.
8.8: The detection mechanisms trigger responses of different types, including delayed and stealthy responses.

@commjoen commjoen added this to the 1.2: Android and iOS updates milestone Jan 11, 2019
@commjoen commjoen added this to To do in OWASP MSTG via automation Jan 11, 2019
@sushi2k
Copy link
Collaborator

@sushi2k sushi2k commented Jan 23, 2019

I guess it would make sense to mention Safetynet for Android as one mechanism that could be used to achieve this (report tampering) https://developer.android.com/training/safetynet/

@commjoen
Copy link
Collaborator Author

@commjoen commjoen commented Jan 24, 2019

True :)

@cpholguera cpholguera changed the title Add 8.7 and 8.8 for android and ios: show how you can delay the attacker or report tampering to the backend Add MSTG-RESILIENCE-7 and MSTG-RESILIENCE-8 Apr 16, 2020
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Projects
OWASP MSTG
  
To do
Linked pull requests

Successfully merging a pull request may close this issue.

None yet
3 participants