Analysis of testing approaches to Android mobile application vulnerabilities

Mykhailo Antonishyn, Oleksii Misnik · 2020

In the first part of the article we discuss international, industrial and national standards and methodologies that describe the process of testing for ap- plication vulnerabilities, including mobile applications for Android OS. The fol- lowing standards and methodologies were taken for the study: ISO/IEC 27034. Information technology. Security techniques. Application Security, NIST 800- 163 Vetting the Security of Mobile application, National In-formation Assurance Partnership and Mobile application security verification standard. Also, we have compared methods it selves and methods of testing for vulnerabilities of mobile software applications for operating system Android. The analysis of the stages by which testing for vulnerabilities is carried out. The second part of the article presents statistics on vulnerabilities that were published by vendors – Google se- curity statistics and Quick Heal, as well as statistics, which were formed by the authors of the publication. For statistics, the test results were taken from an online store, two crypto exchanges and two crypto wallets. The conclusions to the article summarize the results of a study of standards and statistics for conducting subse- quent research on the subject of scientific work.

Read the paper · More papers on PaperTik