undefined

Investigation of Security-related Commits in Android Apps

Year of publication

2023

Authors

Das, Teerath; Ali, Adam; Mikkonen, Tommi

Abstract

The exponential increase in smartphone usage has fueled the rapid growth of Android applications (apps). Unfortunately, this growth has also resulted in an alarming rise in security vulnerabilities, posing a significant challenge for developers of smartphone apps. In this paper, we conducted a quantitative and qualitative study to analyze security-related issues in open-source Android apps available on GitHub. Our study included a total set of 689 security-related commits identified from 111,224 commits distributed over 2,187 apps. We proposed a taxonomy of ten distinct categories of security issues, which we identified using the card-sorting technique. Our findings showed that Permission issues were the most prevalent in our dataset (370, 53.7%), followed by Login issues (160, 23.22%). Issues such as Privacy (5, 0.72%) and Framework (3, 0.43%) were rare in our dataset. These preliminary findings serve as an initial step towards comprehending the primary security concerns from the perspective of both developers and researchers.
Show more

Organizations and authors

University of Jyväskylä

Das Teerath

Mikkonen Tommi Orcid -palvelun logo

Publication type

Publication format

Article

Parent publication type

Conference

Article type

Other article

Audience

Scientific

Peer-reviewed

Peer-Reviewed

MINEDU's publication type classification code

A4 Article in conference proceedings

Publication channel information

Open access

Open access in the publisher’s service

No

Self-archived

No

Other information

Fields of science

Computer and information sciences

Keywords

[object Object],[object Object],[object Object]

Publication country

United States

Internationality of the publisher

International

Language

English

International co-publication

Yes

Co-publication with a company

No

DOI

10.1145/3593434.3593437

The publication is included in the Ministry of Education and Culture’s Publication data collection

Yes