Smartphone Application Assessment

mobile-security-check

Thorough verification: Manual diagnostics vs. tools.
Eliminate security risks before release and during operation Smartphone Application Diagnostics

We thoroughly diagnose and visualize risks specific to smart devices, such as fraudulent activities resulting from unauthorized device use (modification), theft of communication data, and unauthorized access to in-app data.

Identify Unknown Risks Through “Hybrid Diagnostics” Combining Tool-Based Scans and Manual Inspection

We perform a combination of our proprietary diagnostic tools and manual diagnostics by experienced engineers on apps installed on smart devices.
For areas where tool-based diagnostics alone are fundamentally impossible, or where engineers determine that deeper verification is necessary, we manually inspect physical devices and emulators to prevent attacks by malicious users and data leaks before they occur.

Supports Both Black-Box and
White-Box Testing

We thoroughly verify not only the behavior of installed apps (black-box testing) but also the encryption status of stored data and communications within the apps, checking security from every angle.

Combining the
Strengths of Manual and Automated Tools

We combine the comprehensiveness of scans using our proprietary diagnostic tools with in-depth, case-by-case verification performed by engineers who manually tamper with requests from an attacker’s perspective.

Addressing Risks Unique to Smart Devices

We specialize in risks unique to smartphone apps, such as malicious activities targeting apps resulting from unauthorized device use (modifications, rooting, jailbreaking, etc.), the theft of data transmitted between servers and devices, and unauthorized access to in-app data.

[SERVICE IMAGE & APPROACHES]

SERVICE IMAGE & APPROACHES

Detailed inspection items compliant with the OWASP Mobile Top 10 (2024)

We conduct rigorous verification of apps installed primarily on smart devices based on the following criteria.

Test Items OWASP Mobile
Top 10 (2024) Comparison
Verification Items Verification Items
App Settings, Backups, and Logs M6, M8, M9 Configuration Files Verify backup and debug settings
Log OutputVerify whether confidential information is logged
Authentication Information and Device Data M1, M6, M9, M10 Embedding of confidential information Verify presence of authentication information, encryption keys, etc.
Stored FilesVerify confidential information, storage location, permissions, and retention status
Encryption of Stored DataVerify presence and method of encryption
Communication Security M5 Encrypted Communication Verify whether plaintext communication is used
Certificate Verification and Communication DestinationVerify the certificate verification process and communication destination
Authentication Process on the Application Side M3 Authentication Process Verify authentication using device-specific information
WebView and External Integration Features M4, M8 WebView Verify settings and handling of external content
External Integration FeaturesVerify Deep Link and cross-app integration settings
Binary Analysis and Reverse Engineering Resistance M7 Decompilation and Obfuscation Verify analyzability and the state of obfuscation
Unnecessary Information in the BinaryVerify the presence of debug information and internal data
OWASP Mobile Top 10 2024 Japanese Translation
M1: Improper Credential UsageImproper Use of Credentials
M2: Inadequate Supply Chain SecurityInadequate Supply Chain Security
M3: Insecure Authentication/AuthorizationInsecure Authentication and Authorization
M4: Insufficient Input/Output ValidationInsufficient Input/Output Validation
M5: Insecure CommunicationInsecure Communication
M6: Inadequate Privacy ControlsInadequate Privacy Controls
M7: Insufficient Binary ProtectionsInsufficient Binary Protections
M8: Security MisconfigurationSecurity Misconfiguration
M9: Insecure Data StorageInsecure Data Storage
M10: Insufficient CryptographyInsufficient Cryptography

“List of Deliverables”—a quick and detailed summary of the diagnostic results

Upon completion of the diagnosis, we will deliver the following set of deliverables tailored to your environment.

① Results Report Scheduled Deliverables: ✔︎

A detailed report compiled by our engineers that clearly explains the severity of detected vulnerabilities, their specific locations, and recommended remediation procedures.

② Preliminary Diagnosis Report Scheduled Deliverables: ✔︎

First-notification service that immediately contacts the customer if a critical vulnerability is discovered during the assessment to minimize damage.

③ Various Analysis and Matching Data Scheduled Deliverables: ✔︎

We will provide you with a complete set of practical analysis data, including decompilation results, keyword matching results, and screenshots of verification screens.

You can download a sample vulnerability assessment report from our website.
We will submit the assessment report within approximately 5 business days after the assessment is complete (*We also offer an optional debriefing session).

Sample Image of Mobile App Vulnerability Assessment Report

Steps from Start to Completion of the Assessment

1

STEP 1: Site Review

We will review the app to be assessed and conduct a consultation.
*Please provide the relevant “Interview Sheet” and issue a test account.

2

STEP 2: Scope Confirmation

We will create a list of screen transitions and URLs to be assessed.
*We may request that you provide test data, etc.

3

STEP 3: Proposal

We will submit a proposal and a quote based on the scope and details of the assessment. We will also coordinate the assessment schedule.

4

STEP 4: Application

Please fill out the required information and submit the order form.
*Before the assessment begins, we may ask you to prepare test data or make configuration changes (such as allowing access from the assessment IP address) to your firewall (FW) or other systems.

5

STEP 5: Assessment

We will perform the assessment using proprietary tools and manual review by our engineers.
*If a critical vulnerability is discovered during the diagnosis, we will immediately notify you via an urgent alert.

6

STEP 6: Report

Upon completion of the assessment, we will submit a detailed “Assessment Report” within approximately 5 business days.
*We also offer optional briefing sessions.

Preconditions and Factors Affecting the Assessment

Conditions for Commencing the Diagnosis

  • The client and contractor must have reached an agreement to provide the pre-release app to a third-party diagnostic company (our company).
  • The client must provide the latest version of the target app (e.g., an APK file that can be run on an emulator).

Impact of Running the Diagnostic and Safety Measures

  • During the diagnostic process, the system’s processing load may increase, which could result in reduced system performance (such as slower response times).
  • A large amount of junk data may be registered in the test database, or a large number of emails regarding inquiries, etc., may be sent to administrators and relevant parties.
[Our Security Measures]
We do not generate or send requests intended to intentionally damage or disrupt databases or services.
[Notes on Backend Integration]
While we restrict simulated attacks on third-party sites, please inform us in advance if requests are sent from the backend of the app under testing to “external systems we are not aware of” (we will configure settings to avoid specific variables or URLs).

Smartphone Application Diagnosis Pricing Plans

Diagnostic Category Details Unit Cost (excluding tax)
Basic Application Diagnosis Basic Diagnosis (Tool-Based & Manual Diagnosis) 1 file ¥500,000~
Report Preparation Preparation of a detailed diagnostic results report 1 set ¥100,000+
Remediation Verification Re-verify security after remediation of detected vulnerabilities Included in the initial fee

We’ll start by providing a preliminary estimate based on your app’s specifications and the number of screens

Whether you want to “verify the security of a mobile app before release” or “have a thorough manual diagnostic performed,” please feel free to contact us with any questions.
One of our dedicated security engineers will assist you with care.