Security evaluation of ten Swedish mobile applications
2022 (English)Independent thesis Basic level (degree of Bachelor), 10 credits / 15 HE credits
Student thesis
Abstract [en]
The widespread usage of smartphones and mobile applications in Sweden exposes the users to potential risks if not adequate security standards are implemented. An insecure application that is exploited by an adversary could potentially compromise the users private data and integrity. As such, this report aims to examine and evaluate the security of ten commonly used mobile applications in Sweden. Using the OWASP Mobile Security Testing Guide (MSTG) and conducting penetration testing, the applications were assessed in regards of strengths and weaknesses. The results presents nine potential vulnerabilities of which three were successfully exploited with the use of brute-force and session hijack attacks. Even though all examined applications adopt industry security standards of various degrees, our findings shows that a few applications are susceptible to vulnerabilities.
Abstract [sv]
Det breda användadet av smarta telefoner och mobila applikationer i Sverige utsätter användare för potentiella risker om inte tillräckliga nivåer av säkerhetsstandarder implementeras. En osäker applikation som utnyttjas av en person med onda avsikter skulle kunna leda till dataintrång hos en användare. Därav siktar denna rapport på att utvärdera säkerheten hos tio vanligt förekommande mobila applikationer i Sverige. Med hjälp av OWASP Mobile Security Testing Guide (MSTG) och utförandet av penetrationstester så har applikationernas styrkor och svagheter utvärderats. Resultatet som presenteras visar på nio potentiella sårbarheter varav tre kunde verifieras genom lyckade brute-force och session hijack attacker. Även om de utvärderade applikationerna implementerar en viss nivå av säkerhetsstandarder, så visar vårt resultat att vissa av applikationerna är utsatta för sårbarheter.
Place, publisher, year, edition, pages
2022. , p. 81
Series
TRITA-EECS-EX ; 2022:287
Keywords [en]
Black-box testing, Penetration testing, Mobile applications, Android, Exploit, Vulnerability Evaluation, OWASP, MSTG
Keywords [sv]
Black-box testning, Penetrations testning, Mobila applikationer, Android, Exploatering, Sårbarhetsutvärdering, OWASP, MSTG
National Category
Computer and Information Sciences
Identifiers
URN: urn:nbn:se:kth:diva-319794OAI: oai:DiVA.org:kth-319794DiVA, id: diva2:1701868
Subject / course
Information Technology
Educational program
Master of Science in Engineering - Information and Communication Technology
Supervisors
Examiners
2022-10-102022-10-072022-10-10Bibliographically approved