Mobile cyber-assurance informed through knowledge graph construction: the OWASP threat of insecure communications
by Suzanna Schmeelk; Lixin Tao
International Journal of Internet of Things and Cyber-Assurance (IJITCA), Vol. 1, No. 3/4, 2020

Abstract: This research focuses on secure software development of mobile applications by developing knowledge graphs for threats reported by the Open Web Application Security Project (OWASP). OWASP maintains best practices on the current industry top ten security threats to mobile and web applications. We develop knowledge graphs based on the two most recent top ten OWASP threat reports. We, then, show how the knowledge graph relationships can be discovered in mobile application source code, specifically Android. From the developed knowledge graph, we analyse 200+ healthcare applications posted on GitHub to gain insights into the cyber-assurance of these mobile software. We specifically examine the source code for one of the OWASP top ten mobile threats, the threat of insecure communications. We find that many of the analysed applications are communicating with potential personal identifying information employing insecure methodologies leaving users exposed to higher risks.

Online publication date: Wed, 20-Jan-2021

The full text of this article is only available to individual subscribers or to users at subscribing institutions.

 
Existing subscribers:
Go to Inderscience Online Journals to access the Full Text of this article.

Pay per view:
If you are not a subscriber and you just want to read the full contents of this article, buy online access here.

Complimentary Subscribers, Editors or Members of the Editorial Board of the International Journal of Internet of Things and Cyber-Assurance (IJITCA):
Login with your Inderscience username and password:

    Username:        Password:         

Forgotten your password?


Want to subscribe?
A subscription gives you complete access to all articles in the current issue, as well as to all articles in the previous three years (where applicable). See our Orders page to subscribe.

If you still need assistance, please email subs@inderscience.com