Abstract

This research focuses on secure software development of mobile applications by developing knowledge graphs for threats reported by the Open Web Application Security Project (OWASP). OWASP maintains best practices on the current industry top ten security threats to mobile and web applications. We develop knowledge graphs based on the two most recent top ten OWASP threat reports. We, then, show how the knowledge graph relationships can be discovered in mobile application source code, specifically Android. From the developed knowledge graph, we analyse 200+ healthcare applications posted on GitHub to gain insights into the cyber-assurance of these mobile software. We specifically examine the source code for one of the OWASP top ten mobile threats, the threat of insecure communications. We find that many of the analysed applications are communicating with potential personal identifying information employing insecure methodologies leaving users exposed to higher risks.

Full Text
Paper version not known

Talk to us

Join us for a 30 min session where you can share your feedback and ask us any queries you have

Schedule a call

Disclaimer: All third-party content on this website/platform is and will remain the property of their respective owners and is provided on "as is" basis without any warranties, express or implied. Use of third-party content does not indicate any affiliation, sponsorship with or endorsement by them. Any references to third-party content is to identify the corresponding services and shall be considered fair use under The CopyrightLaw.