Mobile Runtime Application Self-Protection (RASP)
How Your App is Being Exploited On-Device
Use screen overlay attacks to steal credentials
Man-in-the-middle attacks to eavesdrop and redirect sensitive data
Abusing app permissions to record all keystrokes
Abusing inter-app communication to exfiltrate PII
Fake devices/emulators to impersonate real users
Use compromised devices to divert traffic to malicious destinations
How zDefend Secures Mobile Apps
Zimperium zDefend offers an outside-in approach to mobile in-app protection. It’s an SDK that enables the host application to detect and proactively protect itself by taking actions on the end user’s device, even without network connectivity. The SDK leverages z9, Zimperium’s patented machine learning-based threat detection engine. The on-device actions are configured within the application. They can be updated in real-time without publishing a new version making it practical and scalable across large install bases. zDefend’s mobile RASP capabilities allow continuous monitoring, protection, and effective threat modeling within the mobile DevSecOps life cycle.
Key Detections to Prevent Runtime Exploitation
Malware
Unsafe Networks
Emulators
Compromised Devices
Rooting Detection Evasion
Hooking Frameworks
App Tampering
System Tampering
Privilege Escalation Detection
Device Security Disabled
What zDefend Protects Mobile Apps Against
Platforms Supported
Why Zimperium for RASP Mobile Security?
Advanced machine learning-based
behavior detections
Restrict access & disable
features when risk is unacceptable
Update in-app protection
policies in real time
SDK optimized for size and
performance
Minimal app permissions to
preserve privacy
No PII data taken off the
device
Softpay Secures Mobile Payments for Retailers with Zimperium MAPS
Softpay made headlines when their solution helped 7-Eleven circumvent a cyberattack. Find out how Softpay’s due diligence and their existing partnership with Zimperium helped thwart the attack on 7-Eleven and prevented the closure of all their Danish stores for weeks.
Learn how our customers are leveraging zDefend to proactively prevent fraud and theft
Anti-Malware To Prevent Account Takeover Fraud
A Fortune 500 bank was looking to protect their customers and bankers from malware-driven fraud on their mobile devices. Existing traditional fraud platforms were siloed and provided little threat visibility and protection against fraud attempts via the mobile app. Within the first six months of embedding zDefend in their digital banking apps, they realized that their app was running on 18,000 devices with malware, 120,000 compromised machines, and 2 million risky devices. They are deploying zDefend’s on-device actions to prevent users from accessing and conducting high-risk transactions in untrusted environments to minimize fraud risk and exposure.
Prevent Mobile Banking Fraud With Compliance Grade Security
A Fortune 200 bank in Europe was concerned that their current mobile applications security posture was insufficient. Banking regulations mandated anti-malware protection, and they realized signature-based protections were impractical. The enterprise began by embedding zDefend into iOS applications that serve over 5 million customers. In the first six months, they gained visibility into 500+ app tampering attempts, 30,000+ malware infected devices, and 25,000+ risky devices running their apps. They are employing zDefend to embrace compliance-grade security and systematically reduce risk.
“Through 2022, mobile application security failures will be the biggest mobile threat for enterprises.”
– The Gartner “Avoid Mobile Application Security Pitfalls” Report
(Refreshed 27 January 2022, Published 27 July 2020; Dionisio Zumerle)