Appdome combines API and bot protection
Appdome, which protects mobile businesses, has integrated its IDAnchor’s Customer Identity Protection suite into MobileBOT Defense, Appdome’s bot defense offering. This combination enables businesses to build a virtual mobile API gateway on top of any standard backend infrastructure.
“There’s no need for point products in bot defence and API protection any longer,” said Tom Tovar, CEO and co-creator of Appdome.
“Within one solution, IDAnchor can tell network security teams if an API request is coming from real users, apps, and devices and MobileBOT Defense can stop brute force bot attacks with ease.”
Powered by AI, Appdome’s MobileBOT Defense, with IDAnchor inside, provides an operating system (OS)-independent chain of trust consisting of:
- WorkspaceID: root identifier from the DevOps environment
- ReleaseID: intermediate identifier for each app release
- InstallID: leaf identifier for each app instance
- DeviceID: leaf identifier for each mobile device that uses an IDAnchor-enabled app.
During any API connection request, if any part of the chain is missing, altered, or replaced, the mobile brand or business knows the origin of API request is suspicious or malicious. If an attacker attempts to impersonate legitimate mobile users, applications, devices, locations, or uses automated programs to generate requests individually or via brute force methods, the connection can be dropped or routed for mitigation in the application. No external systems or software development kits (SDKs) are required.
“The Appdome platform lets mobile brands create the mobile API gateway or mobile application firewall of their choice,” said Chris Roeckl, Chief Product Officer at Appdome.
“Put simply, MobileBOT Defense and IDAnchor combined can offer deeper inspection, 400+ detection and defence options, to stop unauthorised access, API attacks, API abuse or bot attacks in one.”
Legacy mobile API and bot defense products use time-based cookies and tokens to determine session validity. They can be stored insecurely or transmitted in the clear, making them vulnerable to reuse by the attacker. Further, cookies and tokens do not provide any data on the mobile device, application, or installation making the API request. This means they cannot tell if the API request is coming from a good, bad, real, fake, compromised or uncompromised mobile user, app, install, or device.
In contrast, each IDAnchor fingerprint can be cryptographically bound to each user so that it is not reusable and persists across re-installs, OS updates, and factory resets.
“API attacks and abuse are a superset of bot defence, and you have to defend against both,” said Gil Hartman, Field CTO at Appdome.
“MobileBOT Defense with IDAnchor proves you can address both in one solution and retain full flexibility to customise where and how you enforce each defence, per app, per API, or per device.”
Comments
Post a Comment