Network security best practices  |  Android Open Source Project Skip to main content Docs What's new? Release notes Latest security bulletins Latest Compatibility Definition Document (CDD) Site updates Getting Started About Start Download Builds Test Create Contribute Community Tools, build, and related reference Security Overview Bulletins Features Testing Best Practices Core Topics Architecture Audio Camera Connectivity Data Display Fonts Graphics Interaction Media Performance Permissions Power Runtime Settings Storage Tests Updates Virtualization Compatibility Compatibility Definition Document (CDD) Compatibility Test Suite (CTS) Android Devices Cuttlefish Enterprise TV Automotive Overview Software Defined Vehicle In-vehicle Infotainment Release Details Reference HIDL HAL Trade Federation Security Test Suite Android Code Search / English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어 Sign in Documentation What's New? Getting Started Security Core Topics Compatibility Android Devices Automotive Reference Docs More What's New? Getting Started Security Core Topics Compatibility Android Devices Automotive Reference Android Code Search Overview Security overview Secure an Android device Kernel security App security Implement security Updates and resources ASPIRE Security reports Enhancements Acknowledgements Android Security Bulletins Bulletins home Overview 2026 bulletins July June May April March February January Android 17 2025 bulletins December November October September August July June May April March February January Android 16 Android 16 QPR2 2024 bulletins December November October September August July June May April March February January Android 15 2023 bulletins December November October September August July June May April March February January Android 14 Index 2022 bulletins December November October September August July June May April March Android 12L February January Android 13 Index 2021 bulletins December November October September August July June May April March February January Android 12 Index 2020 bulletins December November October September August July June May April March February January Android 11 Index 2019 bulletins December November October September August July June May April March February January Android 10 Index 2018 bulletins December November October September August July June May April March February January Index 2017 bulletins December November October September August July June May April March February January Index 2016 bulletins December November October September August July June May April March February January Index 2015 bulletins December November October September August Index Pixel/Nexus bulletins Overview 2026 bulletins July June May April March February January 2025 bulletins December November October September August July June May April March February January 2024 bulletins December November October September August July June May April March February January 2023 bulletins December November October September August July June May April March February January 2022 bulletins December November October September August July June May April March February January 2021 bulletins December November October September August July June May April March February January Index 2020 bulletins December November October September August July June May April March February January Index 2019 bulletins December November October September August July June May April March February January Index 2018 bulletins December November October September August July June May April March February January Index 2017 bulletins December November October Index Android Automotive Overview 2026 bulletins July June May April March February January 2025 bulletins December November October September August July June May April March February January 2024 bulletins December November October September August July June May April March February January 2023 bulletins December November October September August July June May April March February January 2022 bulletins December November October September August July June May April March February January 2021 bulletins December November October September August July June May April March February January Android XR Overview 2026 bulletins July June May April March February January Chromecast Overview 2025 bulletins December 2024 bulletins December September July March 2023 bulletins December September June April 2022 bulletins December October July Wear Overview 2026 bulletins July June May April March February January 2025 bulletins December November October September August July June May April March February January 2024 bulletins December November October September August July June May April March February January 2023 bulletins December November October September August Pixel Watch Overview 2026 bulletins June March 2025 bulletins December November October September August July June May April March February January 2024 bulletins December August July June May April March February January 2023 bulletins December September June Advisories Overview March 2016 Features Overview Application Sandbox OMAPI vendor stable interface App signing Overview APK signature scheme v2 APK signature scheme v3 APK signature scheme v3.1 APK signature scheme v4 Authentication Overview Gatekeeper Rate-limiting Weaver Biometrics Overview Measure biometric security Fingerprint HIDL Face authentication HIDL Android Protected Confirmation Overview Implementation UI design Accessibility DICE Overview Applications Encryption Overview File-based encryption Full-disk encryption Metadata encryption Enable Adiantum Hardware-wrapped keys Keystore Overview Features Key and ID attestation Version binding Authorization tags KeyMint functions Identity Credential APIs Overview SELinux Overview Concepts Implementation Customization Build sepolicy Policy compatibility Validation Write policy Vendor init Trusty TEE Overview Download and build Trusty API reference Verified Boot Overview Device state Use Verified Boot Boot flow Implement dm-verity Verify system_other partition Reference implementation On-device signing Safety Center Overview Cellular security Overview Disable 2G 2G connectivity toggle Mobile network security Private space GPU syscall filtering Testing Overview Memory safety Arm Memory Tagging Extension Overview MTE bootloader support Understand MTE reports MTE configuration Sanitizers Overview AddressSanitizer Kernel AddressSanitizer Hardware-assisted AddressSanitizer Understand HWASan reports UndefinedBehaviorSanitizer Other topics Control flow integrity Control flow integrity in the kernel Execute-only memory Fuzz with libFuzzer GWP-ASan and KFENCE Android Security AutoRepro Scudo ShadowCallStack Tagged pointers Zero initialized memory Best practices Overview Organizational and operational security System security App security Network security Hardware security Privacy security What's new? Release notes Latest security bulletins Latest Compatibility Definition Document (CDD) Site updates Getting Started About Start Download Builds Test Create Contribute Community Tools, build, and related reference Security Overview Bulletins Features Testing Best Practices Core Topics Architecture Audio Camera Connectivity Data Display Fonts Graphics Interaction Media Performance Permissions Power Runtime Settings Storage Tests Updates Virtualization Compatibility Compatibility Definition Document (CDD) Compatibility Test Suite (CTS) Android Devices Cuttlefish Enterprise TV Automotive Overview Software Defined Vehicle In-vehicle Infotainment Release Details Reference HIDL HAL Trade Federation Security Test Suite Effective in 2026, to align with our trunk stable development model and ensure platform stability for the ecosystem, we will publish source code to AOSP in Q2 and Q4. For building and contributing to AOSP, use android-latest-release. The android-latest-release manifest branch will always reference the most recent release pushed to AOSP. For more information, see Changes to AOSP. AOSP Docs Security Network security best practices Stay organized with collections Save and categorize content based on your preferences. This section contains recommendations to ensure the security of network communications from Android devices. Secure listening sockets Use listening sockets with caution. There should generally not be any open listening sockets on devices as these provide a vector for a remote attacker to gain access to the device. Android devices should minimize the number of internet listening sockets they expose, especially on boot or by default. No socket should be listening on the internet at boot by default. Root processes and processes owned by the system unique identifier (UID) shouldn't expose any listening sockets. Listening sockets must be able to be disabled without an OTA update. This can be performed using either a server or user-device configuration change. For local IPC-using sockets, apps must use a UNIX domain socket with access limited to a group. Create a file descriptor for the IPC and make it +RW for a specific UNIX group. Any client apps must be within that UNIX group. Some devices with multiple processors (for example, a radio/modem separate from the app processor) use network sockets to communicate between processors. In such instances, the network socket used for inter-processor communication must use an isolated network interface to prevent access by unauthorized apps on the device (i.e. use iptables to prevent access by other apps on the device). Daemons that handle listening ports must be robust against malformed data. You should conduct fuzz-testing against the port using an unauthorized client, and, where possible, authorized client. File bugs to follow up on crashes. The Android Compatibility Test Suite (CTS) includes tests that check for the presence of open listening ports. Disable adb Android Debug Bridge (adb) is a valuable development and debugging tool, but is designed for use in a controlled, secure environment and shouldn't be enabled for general use. Ensure that adb is disabled by default. Ensure that adb requires the user to turn it on before accepting connections. Content and code samples on this page are subject to the licenses described in the Content License. Java and OpenJDK are trademarks or registered trademarks of Oracle and/or its affiliates. Last updated 2024-09-24 UTC. [[["Easy to understand","easyToUnderstand","thumb-up"],["Solved my problem","solvedMyProblem","thumb-up"],["Other","otherUp","thumb-up"]],[["Missing the information I need","missingTheInformationINeed","thumb-down"],["Too complicated / too many steps","tooComplicatedTooManySteps","thumb-down"],["Out of date","outOfDate","thumb-down"],["Samples / code issue","samplesCodeIssue","thumb-down"],["Other","otherDown","thumb-down"]],["Last updated 2024-09-24 UTC."],[],[]] Build Android repository Requirements Downloading Preview binaries Factory images Driver binaries Connect @Android on X @AndroidDev on X Android Blog Google Security Blog Platform on Google Groups Building on Google Groups Porting on Google Groups Get help Android Help Center Pixel Help Center www.android.com Google Mobile Services Stack Overflow Issue Tracker About Android Community Legal License Privacy Site feedback Manage cookies English Deutsch Español – América Latina Français Indonesia Italiano Polski Português – Brasil Tiếng Việt Türkçe Русский עברית العربيّة فارسی हिंदी বাংলা ภาษาไทย 中文 – 简体 中文 – 繁體 日本語 한국어