Security analysis of a mHealth app in Android: Problems and solutions
Isabel de la Torre Díez, Bruno Olivar Trinchet, Joel J. P. C. Rodrigues, Miguel López-Coronado · 2017
In recent years, medicine has seen how technology was going day by day more present to become necessary. At the same time, security became a critical aspect, since private patient medical data are handled. In this field in which gather mobile technologies with medicine, security has great importance. Therefore, it is essential to conduct security audits to mobile applications which deal with private information and confidential patient data. The main objective of this paper is to carry out an audit of security of an mHealth Android application. Taking HeartKeeper application to self-manage cardiac patients, a series of tests and modifications are conducted to check its strengths and weaknesses. The methodology consists in attempting to decompile the application HeartKeeper. Applying to the source code techniques of reverse engineering, we will try to perform an analysis that allows us to carry out the security check of the Android application HeartKeeper. It can be applied to audit security on any other Android application. In this way, it provides developers a tool that allows them to check the security of any Android app. Among these vulnerabilities found, the most relevant is that which allows us to inject code to steal some private information. This information should only be accessible from the application itself and only once the user is authenticated. As solutions, we propose different protections. These are: protection against decompilation, against code analysis, and against modified applications. It is very important to carry out a comprehensive review of the mobile applications' strength, since they are increasingly present in our lives and they manage sensitive and protected data. It is highly recommended to install applications from trusty sources, as they are the official app stores like Google Play Store in Android and iOS App Store.