android安全开发者必看文章

无意中看到一篇CompTIA Mobile App Security+ Certification Exam

This exam will certify that the successful candidate has the knowledge and skills required
to securely create a native Android mobile application, while also ensuring secure
network communications and backend Web services.

以后支付行业的安全工程师也得测评,认证通过方可上岗。要不然就不出这么多问题了。

这篇文章只是提供一个框架,还需要细化到具体。依托这个框架,可以定义Android安全开发指引,以便指导安全工程师开发程序。

要求工程师具备:

The successful candidate should have the knowledge and skills to:
Describe fundamental principles of application security
Describe the security model of Android devices
Describe common threats to mobile application security
Develop moderately complex applications using the Android SDK
Describe Web services security model and vulnerabilities
Properly implement SSL/TLS for Web communications
Utilize the security features of the Android operating system and APIs
Properly implement secure coding techniques
Avoid insecure retention of data in memory
Describe common implementations of cryptography such as PKI
Leverage encryption for storage and/or communications
Understand access control and file permissions
Harden an application against attack to levels appropriate for the risk model of theapplication

 

这个认证里面列出了知识点,

 

 

 

  • 0
    点赞
  • 1
    收藏
    觉得还不错? 一键收藏
  • 0
    评论

“相关推荐”对你有帮助么?

  • 非常没帮助
  • 没帮助
  • 一般
  • 有帮助
  • 非常有帮助
提交
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值