Abstract

This research focuses on secure software development of mobile applications by developing knowledge graphs for threats reported by the Open Web Application Security Project (OWASP). OWASP maintains best practices on the current industry top ten security threats to mobile and web applications. We develop knowledge graphs based on the two most recent top ten OWASP threat reports. We, then, show how the knowledge graph relationships can be discovered in mobile application source code, specifically Android. From the developed knowledge graph, we analyse 200+ healthcare applications posted on GitHub to gain insights into the cyber-assurance of these mobile software. We specifically examine the source code for one of the OWASP top ten mobile threats, the threat of insecure communications. We find that many of the analysed applications are communicating with potential personal identifying information employing insecure methodologies leaving users exposed to higher risks.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call