Android Forensic and Security Assessment for Hospital and Stock-and-Trade Applications in Thailand

被引:0
|
作者
Phumkaew, Noppanat [1 ]
Visoottiviseth, Vasaka [1 ]
机构
[1] Mahidol Univ, Fac Informat & Commun Technol, Nakhon Pathom, Thailand
来源
2018 15TH INTERNATIONAL JOINT CONFERENCE ON COMPUTER SCIENCE AND SOFTWARE ENGINEERING (JCSSE) | 2018年
关键词
Android; Mobile Forensics; OWASP Mobile Top Ten Risks 2016; Vulnerability Assessment; Data Leak;
D O I
暂无
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Many hospitals and stock-and-trade mobile applications are developed in Thailand to fulfill business requirements. These applications normally handle user's sensitive data, such as the identification, financial data, and health records. Thus, the objective of this research is to investigate whether these applications can expose the sensitive data over the communication channel and whether the sensitive data can be retrieved from the lost or stolen mobile phones. We conduct the forensic investigation and security assessment toward these mobile applications by considering the OWASP Mobile Security Top Ten Risks 2016. In our experiment, Android forensics was conducted over three hospital applications in Thailand and five stock-and-trade applications. The analysis techniques include both static analysis and dynamic analysis. From our results, we found that each application has its own vulnerability reflecting to OWASP's risk, thus the user must use them with caution. Moreover, the Android application developers must take security awareness into their account.
引用
收藏
页码:56 / 61
页数:6
相关论文
共 2 条
  • [1] Breaking into the vault: Privacy, security and forensic analysis of Android vault applications
    Zhang, Xiaolu
    Baggili, Ibrahim
    Breitinger, Frank
    COMPUTERS & SECURITY, 2017, 70 : 516 - 531
  • [2] A SECURITY ASSESSMENT METHOD FOR ANDROID APPLICATIONS BASED ON PERMISSION MODEL
    Jiang, Danyang
    Fu, Xiangling
    Song, Maoqiang
    Cui, Yidong
    2012 IEEE 2nd International Conference on Cloud Computing and Intelligent Systems (CCIS) Vols 1-3, 2012, : 701 - 705