Privacy vulnerability analysis for Android Applications: A practical approach

Argudo Alejandro, Gabriel R. López, Franklin L. Sanchez · 2017

This investigation proposes a methodology with a practical approach for privacy vulnerability analysis on Android Applications. The methodology combines the controls of the OWASP Mobile Security Project [1], Open Android Security Assessment Methodology [2], and good practices from the current state of the art. The proposed assessment is composed of the following stages: collection of information, logon and encryption, data transfer between dispositive, and development of android applications. Next, it is presented the practical approach of the assessment using a variety of tools for the vulnerability analysis. The tests were performed using mobile applications from public institutions of the Republic of Ecuador. Although Android makes the necessary efforts to prevent security issues in mobile applications, security will be always a shared responsibility with the developers, since after the performed analysis, critical vulnerabilities were found, which are related to the application development.

Read the paper · More papers on PaperTik