Conference archive

IoT Dev+Test 2016 - Security Testing

Tuesday, April 19

TC

Testing Web Services and the APIs behind Mobile Apps

Tuesday, April 19, 2016 - 8:30am to 4:30pm

“There’s an app for that” is frequently heard today. The data (content) being presented by an app is delivered from a web service by an API (Application Programming Interface), the communication framework between applications and back-end systems. Marc van’t Veer explores functional and nonfunctional risks with APIs and explains step-by-step how to test them. Testing web services and APIs is more than just checking the features of applications. An API and the services it calls must meet requirements like response time, security, stability, performance, and scalability. In defining the test...

Bryan Batty
Coveros
TE

Security Testing Mobile Applications

Tuesday, April 19, 2016 - 8:30am to 12:00pm

The sensitive nature of personal information stored on smart devices makes security testing vital when building mobile applications. Cliff Berg explores the unique characteristics of mobile devices—how they store data, the fluid trust boundaries between applications, and the unique aspects of device security models. Learn about the many different threat types and use cases that make security testing mobile applications so challenging. Cliff offers hints and tips for comprehensive security testing of mobile applications during the development process, sharing when and where in that process...

Jon_Hagar
Grand Software Testing
TK

Test Attack Patterns for Mobile, IoT, and Embedded Software

Tuesday, April 19, 2016 - 1:00pm to 4:30pm
Mobile/IoT/embedded software teams are looking for ways to speed up development, testing, and deployment of products that wow users but don’t blow up in their faces. In the tradition of James Whittaker’s book series How to Break Software, Jon Hagar applies the “attack” pattern concept to identify and test for potential failures in these types of systems. Jon defines the environments of mobile, IoT, and embedded software, and examines common software failures found in hardware/software systems. He shares a set of patterns you can apply during pre-production testing or in a...

Wednesday, April 20

W1

Usability vs. Security: Find the Right Balance in Mobile Apps

Wednesday, April 20, 2016 - 10:00am to 10:45am

Successful mobile apps have two key features: a great user experience and the ability to protect users’ data. Balancing user experience and security—a key aspect of product design and engineering—requires a multidisciplinary approach. According to Levent Gurses, a well-balanced app is designed through a series of informed decisions, meaningful compromises, and research that supports core user behaviors. Based on lessons learned from designing winning mobile apps and securing front- and back-end infrastructure, Levent shares his method for scientifically discovering the most critical...