Security Evaluation of Android Mobile Healthcare and Fitness Applications
Suzan Anwar, dalya abdullah anwar, Shereen Abdulla · 2020 International Conference on Electrical, Communication, and Computer Engineering (ICECCE) · 2020
The biggest risk to the privacy of data and personal information of Android users that have mobile fitness and healthcare applications is the unencrypted connection between the application and an internet server. Another risk is the potential security threats, brought about because users often skip the alert message at install time. In this paper, both the applications and network communication processes are evaluated. The security part of the application takes place during downloading and using the applications, then determining what personal information the applications save in the local storage inside these devices, comes after. The security part of network communication includes analyzing the WIFI communication between the instead application and the Internet. We try to help Android health and fitness applications users to easily understand how trustworthy an application is by proposing a new security evaluation method based on both multi-criteria evaluations and privacy risks of an application. Out of the 110 apps found in different markets which were tested, 51 apps were trusted, 31 apps were untrusted, and 18 gave a short report to help the user to make a decision about installing the application or not.