undefined

Investigation of Security-related Commits in Android Apps

Publiceringsår

2023

Upphovspersoner

Das, Teerath; Ali, Adam; Mikkonen, Tommi

Abstrakt

The exponential increase in smartphone usage has fueled the rapid growth of Android applications (apps). Unfortunately, this growth has also resulted in an alarming rise in security vulnerabilities, posing a significant challenge for developers of smartphone apps. In this paper, we conducted a quantitative and qualitative study to analyze security-related issues in open-source Android apps available on GitHub. Our study included a total set of 689 security-related commits identified from 111,224 commits distributed over 2,187 apps. We proposed a taxonomy of ten distinct categories of security issues, which we identified using the card-sorting technique. Our findings showed that Permission issues were the most prevalent in our dataset (370, 53.7%), followed by Login issues (160, 23.22%). Issues such as Privacy (5, 0.72%) and Framework (3, 0.43%) were rare in our dataset. These preliminary findings serve as an initial step towards comprehending the primary security concerns from the perspective of both developers and researchers.
Visa mer

Organisationer och upphovspersoner

Jyväskylä universitet

Das Teerath

Mikkonen Tommi Orcid -palvelun logo

Publikationstyp

Publikationsform

Artikel

Moderpublikationens typ

Konferens

Artikelstyp

Annan artikel

Målgrupp

Vetenskaplig

Kollegialt utvärderad

Kollegialt utvärderad

UKM:s publikationstyp

A4 Artikel i en konferenspublikation

Publikationskanalens uppgifter

Öppen tillgång

Öppen tillgänglighet i förläggarens tjänst

Nej

Parallellsparad

Nej

Övriga uppgifter

Vetenskapsområden

Data- och informationsvetenskap

Nyckelord

[object Object],[object Object],[object Object]

Publiceringsland

Förenta staterna (USA)

Förlagets internationalitet

Internationell

Språk

engelska

Internationell sampublikation

Ja

Sampublikation med ett företag

Nej

DOI

10.1145/3593434.3593437

Publikationen ingår i undervisnings- och kulturministeriets datainsamling

Ja