The rapid growth of mobile health (mHealth) applications has revolutionized healthcare delivery, offering innovative solutions to address various healthcare challenges. However, this has raised concerns regarding the security and privacy of these applications, particularly those developed by solo or small team developers. This research paper analyzes mHealth apps for security vulnerabilities due to solo or small team development using the Open Web Application Security Project (OWASP)’s Top 10 vulnerabilities guidance and Quick Android Review Kit (QARK). By synthesizing insights from previous studies, the research highlights the critical importance of security in mHealth app development and the need for comprehensive security measures to protect user data and ensure the integrity of these applications. The analysis reveals that vulnerabilities in mHealth apps are primarily attributed to weak authentication and authorization, inadequate server-side control, lack of encryption, insecure communication, inadequate user input validation, and unprotected API usage. Future research will focus on strategies for enhancing the solo or small team developers’ security knowledge, resources availability, and supporting the integration of robust security practices throughout the development lifecycle to enhance the resilience of mHealth applications against cyber-threats and ensure the confidentiality and integrity of sensitive health data.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

An OWASP-Based Security Vulnerabilities Evaluation of Solo and Small Team Developed mHealth Applications

  • Ranganai Turugare,
  • Fungai Bhunu Shava,
  • Mercy Chitauro

摘要

The rapid growth of mobile health (mHealth) applications has revolutionized healthcare delivery, offering innovative solutions to address various healthcare challenges. However, this has raised concerns regarding the security and privacy of these applications, particularly those developed by solo or small team developers. This research paper analyzes mHealth apps for security vulnerabilities due to solo or small team development using the Open Web Application Security Project (OWASP)’s Top 10 vulnerabilities guidance and Quick Android Review Kit (QARK). By synthesizing insights from previous studies, the research highlights the critical importance of security in mHealth app development and the need for comprehensive security measures to protect user data and ensure the integrity of these applications. The analysis reveals that vulnerabilities in mHealth apps are primarily attributed to weak authentication and authorization, inadequate server-side control, lack of encryption, insecure communication, inadequate user input validation, and unprotected API usage. Future research will focus on strategies for enhancing the solo or small team developers’ security knowledge, resources availability, and supporting the integration of robust security practices throughout the development lifecycle to enhance the resilience of mHealth applications against cyber-threats and ensure the confidentiality and integrity of sensitive health data.