Press Release

New report: App-store security– the 'five lines of defence'

The Agency today publishes a new report on app-store security where it advocates for a baseline set of ‘five lines of defence ‘ against malware.

Published on September 13, 2011

de fr fr

The booming smartphone industry has a special way of delivering software to end-users: app-stores. Popular app-stores have hundreds of thousands of apps for anything from online banking to mosquito repellent, and the most popular stores (e.g. Apple App-store, Google Android market) claim billions of app downloads.


But app-stores have not escaped the attention of cyber attackers. Over the course of 2011 numerous malicious apps were found, targeting a variety of smartphone models. Dr Marnix Dekker and Dr Giles Hogben, authors of the report say: “Using malicious apps, attackers can easily tap into the vast amount of private data processed on smartphones such as confidential business emails, location data, phone calls, SMS messages and so on. Consumers are hardly aware of this.


“Five lines of defence” to secure app-stores

Starting from a threat model for app-stores, the paper identifies what it calls “the five lines of defence” that must be in place to secure app stores from malware: app review, reputation, kill-switches, device security and jails. “This report provides a very practical and technical analysis of malware threats for app-stores in under 20 pages. The Agency has made an excellent choice of security techniques, and the recommendations are ready-to-use,” says Raoul Chiesa, an Italian ethical hacker and cybersecurity expert.


Without overlooking the differences between the various smartphone models and app-stores, ENISA recommends an industry-wide approach to addressing insecure and malicious apps. “The number of malware attacks direct at smartphones still pales in comparison to PCs. This paper is a blueprint for how to maintain this head-start and address security across app-stores." says Professor Udo Helmbrecht, Executive Director of ENISA.

For full report:

Background: Malware in app-stores is not the only risk for smartphone users; ENISA recently published a full overview of smartphone risks.

For interviews: Ulf Bergstrom, Spokesman, ENISA, [email protected], Mobile: + 30 6948 460 143 or Dr. Marnix Dekker, Expert, ENISA [email protected]

Stay updated - subscribe to RSS feeds of both ENISA news items & press releases!

News items;


This site uses cookies to offer you a better browsing experience.
Aside from essential cookies we also use tracking cookies for analytics.
Find out more on how we use cookies.

Accept all cookies Accept only essential cookies