Reducing Attack Surface on Cordova-based Hybrid Mobile Apps

Mohamed Elemam Shehab, Abeer AlJarrah · 2014

Hybrid mobile application development is increasingly being adopted by the mobile development community since it provides the answer to the challenge of having the right mix of accessibility to mobile native features at an affordable development cost. Apache Cordova library is an example of a middle-ware that enables developers of different mobile operating systems to access mobile native features through web frameworks, such as HTML and JavaScript, which at the same time introduces several security challenges. In this paper, we highlight current security setting limitations of hybrid mobile frameworks and propose a policy based approach to provide limited access to the different pages/states of the app to mitigate the effect of possible attacks. In addition, we downloaded and analyzed 622 real hybrid apps, and presented settings and security statistics.

Read the paper · More papers on PaperTik