STATIC SECURITY ANALYSER FOR ANDROID APPLICATION

Nowadays smartphone is part of our daily life. We use applications every day, from social media, communication, banking, etc. Each application usually uses our personal data such as name, birthday, address, etc. That information is our private dataandmustonlybeknownbyus...

Full description

Saved in:
Bibliographic Details
Main Author: ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS
Format: Final Project
Language:Indonesia
Online Access:https://digilib.itb.ac.id/gdl/view/26668
Tags: Add Tag
No Tags, Be the first to tag this record!
Institution: Institut Teknologi Bandung
Language: Indonesia
id id-itb.:26668
spelling id-itb.:266682018-10-01T08:58:20ZSTATIC SECURITY ANALYSER FOR ANDROID APPLICATION ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS Indonesia Final Project INSTITUT TEKNOLOGI BANDUNG https://digilib.itb.ac.id/gdl/view/26668 Nowadays smartphone is part of our daily life. We use applications every day, from social media, communication, banking, etc. Each application usually uses our personal data such as name, birthday, address, etc. That information is our private dataandmustonlybeknownbyus and the service provider. However, the development of mobile application itself does not consider the security aspect. There willbepossibilityofdatatheftandsecuritybreachasaresult of not considering security aspect on development of mobile application. To address this issue, there are several solutions that can be used, such as implementing the secure software development process, testing the security aspect, conducting code review or code analysis, both dynamic testing and static analysis. <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> In this paper, the solution proposed is test the security aspect by using staticanalysistechnique. Static analysis is part of code review in software development process. This solution is good enough, because it is done in early process of application development, so that can prevent common bad practice occur. But, the solution is not enough to make a completely secure application. This solution is one of many solutions in developing secure mobile application. In this paper we create tool for helping code review for security aspect using static analysis techniques. The toolwillbeintegratedwiththeofficialIDEfordevelopingAndroidApplication, Android Studio.ThetoolisdevelopedbyextendingtheCodeInspectiontoolsonAndroidStudio for checking security aspect, specifically for Insecure Data Storage aspect, Insecure Communication aspect, and insufficient Cryptography aspect.Thetoolisdesignedtoeasilyadd, update, or delete rules, so that the tool can still detect latest vulnerabilities or bad practices. text
institution Institut Teknologi Bandung
building Institut Teknologi Bandung Library
continent Asia
country Indonesia
Indonesia
content_provider Institut Teknologi Bandung
collection Digital ITB
language Indonesia
description Nowadays smartphone is part of our daily life. We use applications every day, from social media, communication, banking, etc. Each application usually uses our personal data such as name, birthday, address, etc. That information is our private dataandmustonlybeknownbyus and the service provider. However, the development of mobile application itself does not consider the security aspect. There willbepossibilityofdatatheftandsecuritybreachasaresult of not considering security aspect on development of mobile application. To address this issue, there are several solutions that can be used, such as implementing the secure software development process, testing the security aspect, conducting code review or code analysis, both dynamic testing and static analysis. <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> <br /> In this paper, the solution proposed is test the security aspect by using staticanalysistechnique. Static analysis is part of code review in software development process. This solution is good enough, because it is done in early process of application development, so that can prevent common bad practice occur. But, the solution is not enough to make a completely secure application. This solution is one of many solutions in developing secure mobile application. In this paper we create tool for helping code review for security aspect using static analysis techniques. The toolwillbeintegratedwiththeofficialIDEfordevelopingAndroidApplication, Android Studio.ThetoolisdevelopedbyextendingtheCodeInspectiontoolsonAndroidStudio for checking security aspect, specifically for Insecure Data Storage aspect, Insecure Communication aspect, and insufficient Cryptography aspect.Thetoolisdesignedtoeasilyadd, update, or delete rules, so that the tool can still detect latest vulnerabilities or bad practices.
format Final Project
author ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS
spellingShingle ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS
STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
author_facet ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS
author_sort ARIE GINARTA SITORUS - NIM : 13513083 , DIMPOS
title STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
title_short STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
title_full STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
title_fullStr STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
title_full_unstemmed STATIC SECURITY ANALYSER FOR ANDROID APPLICATION
title_sort static security analyser for android application
url https://digilib.itb.ac.id/gdl/view/26668
_version_ 1822021079688806400