IEICE Transactions on Information and Systems
Online ISSN : 1745-1361
Print ISSN : 0916-8532
Special Section on Security, Privacy, Anonymity and Trust in Cyberspace Computing and Communications
Study on the Vulnerabilities of Free and Paid Mobile Apps Associated with Software Library
Takuya WATANABEMitsuaki AKIYAMAFumihiro KANEIEitaro SHIOJIYuta TAKATABo SUNYuta ISHIIToshiki SHIBAHARATakeshi YAGITatsuya MORI
著者情報
ジャーナル フリー

2020 年 E103.D 巻 2 号 p. 276-291

詳細
抄録

This paper reports a large-scale study that aims to understand how mobile application (app) vulnerabilities are associated with software libraries. We analyze both free and paid apps. Studying paid apps was quite meaningful because it helped us understand how differences in app development/maintenance affect the vulnerabilities associated with libraries. We analyzed 30k free and paid apps collected from the official Android marketplace. Our extensive analyses revealed that approximately 70%/50% of vulnerabilities of free/paid apps stem from software libraries, particularly from third-party libraries. Somewhat paradoxically, we found that more expensive/popular paid apps tend to have more vulnerabilities. This comes from the fact that more expensive/popular paid apps tend to have more functionality, i.e., more code and libraries, which increases the probability of vulnerabilities. Based on our findings, we provide suggestions to stakeholders of mobile app distribution ecosystems.

著者関連情報
© 2020 The Institute of Electronics, Information and Communication Engineers
前の記事 次の記事
feedback
Top