Article#2 Review
Victoria Asare
CYSE 201S
Diwakar Yalpi
11/10/2024.
Article Title – A Risk Estimation Study of Native Code Vulnerabilities in Android Applications”.
Article Citation – Silvia Lucia Sanna, Diego Soi, Davide Maiorca. A risk estimation study of native code vulnerabilities in Android applications, Journal of Cybersecurity, Volume 10, Issue 1, 2024,
https://academic.oup.com/cybersecurity/article/10/1/tyae015/7744932
- Describe how the topic relates to the principles of the Social Science
The topic “A Risk Estimation Study of Native Code Vulnerabilities in Android Applications,” plays a significant role in principles of social science, particularly technology studies, cybersecurity, and the sociology of technology. The research delves into the escalating security threats associated with mobile applications, particularly those on the Android platform. The research emphasizes that mobile apps, which are integral to modern living, pose risks to both individual users and broader societal structures. Grasping these risks is vital for sustaining trust in technology and safeguarding users from privacy violations or data breaches, which have extensive social implications. The study draws a connection between technical software vulnerabilities and their wider societal impacts, affecting everything from personal privacy to national security..
- Research Questions and Hypotheses
- The study aims to address three primary research questions:
- What is the extent of security risks in Android applications due to native code vulnerabilities?
- What factors contribute to these vulnerabilities, and how can they be assessed?
- How can the risks associated with these vulnerabilities be mitigated?
The hypothesis posits that vulnerabilities in native code, particularly those overlooked during the development stage, can lead to severe security breaches. The study proposes that structured risk estimation frameworks can enable developers and security professionals to identify and prioritize improvements in Android apps.
- Research Methods
Sanna employs a quantitative research design, utilizing risk estimation methods to assess vulnerabilities in native code within Android applications. The methodology includes analyzing the source code of Android apps to uncover potential security flaws. Tools such as static code analysis are used to detect issues in the native code, and a risk assessment framework estimates the severity and likelihood of these vulnerabilities being exploited.
- Data and Analysis
The study gathers quantitative data through a detailed analysis of Android applications and their interactions with native code. Automated security tools scan the source code to identify potential vulnerabilities. Once identified, a risk estimation model evaluates the potential impact of these vulnerabilities on user security. Statistical analysis methods help determine which vulnerabilities are most common, most dangerous, and easiest to mitigate.
- Concepts from PowerPoint Presentations
This study integrates concepts discussed in courses on cybersecurity, risk management, and software development. The focus on software vulnerabilities and risk estimation models ties into material commonly covered in cybersecurity and risk management training. The use of risk assessment frameworks and statistical analysis to identify and prioritize security risks aligns with standard risk analysis techniques taught in information security curricula.
- Relevance to Marginalized Groups
Android security is particularly crucial for marginalized groups who may be more susceptible to mobile application exploitation. These groups often depend on mobile technology for essential services such as banking, healthcare, and education but may lack the resources to ensure app security. Vulnerabilities in native code can disproportionately affect these users, exposing them to risks like identity theft or privacy violations, which can have significant consequences. Identifying and addressing these vulnerabilities can help reduce the digital divide and promote equitable access to secure technology. Marginalized groups, including low-income users or individuals from developing regions, are more likely to use free apps that may not undergo rigorous security testing. This research provides critical insights that could inform better policies and development practices to protect all users, regardless of their socioeconomic status.
- Contributions to Society
Sanna’s research significantly contributes to cybersecurity and broader societal issues. As mobile applications become increasingly essential to daily life, ensuring their security is crucial for protecting user data and privacy. The study highlights vulnerabilities related to native code in Android apps, identifying risks that could harm millions of users worldwide. The findings could guide developers in writing more secure code, improve existing security frameworks, and influence policies designed to protect end-users. Additionally, the emphasis on risk estimation offers a practical framework that could be applied to other areas of software development, benefiting the tech industry and society at large.
In summary, Sanna’s research is a timely contribution to the ongoing discussions about mobile application security. By offering insights into risk estimation techniques and highlighting the social implications of software vulnerabilities, the study aids in developing more secure software and ensures that vulnerable and marginalized groups are better protected in the digital age.
References
Silvia Lucia Sanna, Diego Soi, Davide Maiorca, Giorgio Fumera, Giorgio Giacinto, A risk estimation study of native code vulnerabilities in Android applications, Journal of Cybersecurity, Volume 10, Issue 1, 2024, tyae015,
https://doi.org/10.1093/cybsec/tyae015
https://academic.oup.com/cybersecurity/article/10/1/tyae015/7744932