Connect with us

Hi, what are you looking for?

HEADLINES

Appdome empowers mobile brands to build their own mobile API gateway with AI

“There’s no need for point products in Bot Defense and API Protection any longer,” said Tom Tovar, CEO and co-creator of Appdome. “Within one solution, IDAnchor can tell network security teams if an API request is coming from real users, apps, and devices and MobileBOT Defense can stop brute force bot attacks with ease.”

Appdome, the leader in protecting mobile businesses, announced its IDAnchor’s Customer Identity Protection suite into MobileBOT Defense, Appdome’s bot defense offering. This powerful combination enables mobile brands and businesses to build a virtual Mobile API Gateway on top of any standard backend infrastructure, preventing unauthorized API access, stopping brute-force bot attacks, and eliminating point products for API Protection and Bot Defense.

“There’s no need for point products in Bot Defense and API Protection any longer,” said Tom Tovar, CEO and co-creator of Appdome. “Within one solution, IDAnchor can tell network security teams if an API request is coming from real users, apps, and devices and MobileBOT Defense can stop brute force bot attacks with ease.”

Build Your Own Mobile API Gateway

Powered by AI, Appdome’s MobileBOT Defense, with IDAnchor inside, enables mobile teams to create a virtual Mobile API Gateway that sits on top of any standard backend infrastructure. Together, they provide an OS-independent chain of trust consisting of:

  • WorkspaceID – root identifier from the DevOps environment
  • ReleaseID – intermediate identifier for each App Release
  • InstallID – leaf identifier for each App instance
  • DeviceID – leaf identifier for each mobile Device that uses an IDAnchor enabled app
  • True Device Attributes – OS-independent device attributes
  • Threat Signals – for identity, OS, Application and Device Threats
  • During any API connection request, if any part of the chain is missing, altered, or replaced, the mobile brand or business knows the origin of API request is suspicious or malicious. If an attacker attempts to impersonate legitimate mobile users, applications, devices, locations, or uses automated programs to generate requests individually or via brute force methods, the connection can be dropped or routed for mitigation in the application. No external systems or SDKs are required.

    “The Appdome platform lets mobile brands create the Mobile API Gateway or Mobile Application Firewall of their choice,” said Chris Roeckl, Chief Product Officer at Appdome. “Put simply, MobileBOT™ Defense and IDAnchor™ combined can offer deeper inspection, 400+ detection and defense options, to stop Unauthorized Access, API Attacks, API Abuse or Bot Attacks in one.”

    Advertisement. Scroll to continue reading.

    Immutable Mobile Identity vs. Cookies and Tokens

    Legacy mobile API and bot defense products use time-based cookies and tokens to determine session validity. They can be stored insecurely or transmitted in the clear, making them vulnerable to reuse by the attacker. Cookies and tokens do not provide any data on the mobile device, application, or installation making the API request. In short, cookies and tokens cannot tell if the API request is coming from a good, bad, real, fake, compromised or uncompromised mobile user, app, install, or device.

    In contrast, each IDAnchor fingerprint can be cryptographically bound to each user so that it is not reusable and persists across re-installs, OS updates, and factory resets. This fully addresses these top challenges in legacy bot protection strategies:

    Fake Users & Devices: Fake users and fake, emulated, or spoofed devices cannot present a valid IDAnchor identity, making it easy to block spoofed or impersonated sources.

    Bot Attack Masking & Evasion Techniques: Any attempted reuse or manipulation of the device, application, or OS attributes will result in an IDAnchor mismatch, revealing the attacker.

    Advertisement. Scroll to continue reading.
  • Stolen Credentials or Identities: Stolen identities using separate devices, synthetic identity or AI generated deepfakes, vishing, or session hijacks.
  • Install and attribution fraud: Fraud attempts conducted by emulator farms, malware-controlled apps, or fake devices.
  • KYC-fraud: Fake signups, fake account creation, and usage performed by bots or automated tools designed to spoof real behavior.
  • Weaponized Mobile Apps: Malware-controlled or modified apps will change the IDAnchor fingerprint, revealing the weaponized mobile app.
  • Brute force credential stuffing: Attacks that use automated programs or stolen credentials with fake or spoofed mobile applications and devices.
  • Bot Source Triangulation: A bot detected from App A can be blocked or flagged in App B—without needing to sync external intelligence.
  • Risk Scoring for API Connection Requests: Each match or mismatch of IDAnchor values is represented as a percentage and can be used as a proxy for connection risk or used to influence risk scoring methods for such purpose.
  • “API attacks and abuse are a superset of bot defense, and you have to defend against both,” said Gil Hartman, Field CTO at Appdome. “MobileBOT™ Defense with IDAnchor™ proves you can address both in one solution and retain full flexibility to customize where and how you enforce each defense, per App, per API, or per Device.”

    Advertisement
    Advertisement
    Advertisement

    Like Us On Facebook

    You May Also Like

    HEADLINES

    The need for resilience is becoming more urgent as Philippine enterprises modernize across sectors such as banking, healthcare, retail, business process outsourcing, government, and...

    HEADLINES

    Maya has already integrated National ID eVerify, the Philippine Statistics Authority’s identity-verification service, into its onboarding process. Since early this year, eligible customers have been...

    HEADLINES

    The new architecture is designed to scale into the modular, shared, and ultra-cold system required to link hundreds of quantum chips into a more...

    HEADLINES

    MCWD will use Cisco’s networking and industrial edge technologies to reduce non-revenue water (NRW) – treated water that is lost before it reaches the...

    HEADLINES

    IBM expects its scalable cryogenic modules to help speed its pace of innovation. For example, three essential components of IBM Quantum System Two’s environment...

    HEADLINES

    As more Filipino households look for dependable internet for work, school, entertainment, and daily connectivity, Globe AT HOME is continuing to invest in the...

    HEADLINES

    The Presidential Task Force on Media Security (PTFOMS), in partnership with the European Union, International Media Support (IMS), PLDT, and Smart equipped more than...

    HEADLINES

    Set for September 7–11, 2026 in Clark, the competition will bring together Filipino talent in Technical-Vocational Education and Training (TVET), allowing them to showcase...

    Advertisement