Security Smells Pervade Mobile App Servers


연구 분야: Infrastructure



학회: ESEM '21: Proceedings of the 15th ACM / IEEE International Symposium on Empirical Software Engineering and Measurement (ESEM)


초록

[Background] Web communication is universal in cyberspace, and security risks in this domain are devastating. [Aims] We analyzed the prevalence of six security smells in mobile app servers, and we investigated the consequence of these smells from a security perspective. [Method] We used an existing dataset that includes 9 714 distinct URLs used in 3 376 Android mobile apps. We exercised these URLs twice within 14 months and investigated the HTTP headers and bodies. [Results] We found that more than 69% of tested apps suffer from three kinds of security smells, and that unprotected communication and misconfigurations are very common in servers. Moreover, source-code and version leaks, or the lack of update policies expose app servers to security risks. [Conclusions] Poor app server maintenance greatly hampers security.


Author Profile
Pascal Gadient

Software Composition Group University of Bern Bern Switzerland

Switzerland
Author Profile
Marc Andrea Tarnutzer

Software Composition Group University of Bern Bern Switzerland

Switzerland
Author Profile
Oscar Nierstrasz

Software Composition Group University of Bern Bern Switzerland

Switzerland

📄 논문 정보

발행 연도 2021년
인용수 3
출판 국가 New Zealand, Switzerland
사이트 ACM
좋아요 수 0

연관 논문 목록 (39건)