Automating Static Application Security Testing for Android: Design and Implementation using Mobile Security Framework (MobSF)
Viertola, Vilja (2026)
Viertola, Vilja
2026
Tietotekniikan DI-ohjelma - Master's Programme in Information Technology
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
This publication is copyrighted. You may download, display and print it for Your own personal use. Commercial use is prohibited.
Hyväksymispäivämäärä
2026-05-28
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202605286491
https://urn.fi/URN:NBN:fi:tuni-202605286491
Tiivistelmä
Android is the most popular operating system for mobile devices. Also, the number of Android applications is increasing rapidly which increases security vulnerabilities. This thesis is written for Finnish mobile device company, HMD, which highly values secure software development. Therefore, the motivation for this thesis comes from the will to maintain secure software development and to improve the application whitelisting process. The thesis is implemented with the design science approach with entire process of design, implementation, evaluation and results.
To address this problem, the automated static application test for Android applications was implemented. It was clear from the beginning that each step needed to be automated to avoid manual work. The reading of the static application test report also needed to be optimized to save time and effort. The core tools for the implementation were Mobile Security Framework (MobSF), Docker, Jenkins and Python. In addition to implementation, the focus was to understand how well MobSF static analysis can detect the vulnerabilities and how the entire process can be automated while maintaining the performance.
For the evaluation, the MobSF static analysis was evaluated with the vulnerable APK where the vulnerabilities were known in advance. As a result, it was noted that MobSF static analysis is powerful in detecting vulnerabilities especially in Android manifest file which contains, for example, components and configuration settings. However, not all vulnerabilities were detected, which was expected given the inherent limitations of static analysis, particularly in identifying runtime vulnerabilities. Furthermore, MobSF did not detect all hardcoded secrets, indicating limited effectiveness compared to prior studies. Overall, the MobSF detected 10 vulnerabilities of 22, where 7 vulnerabilities were flagged directly.
The entire automation process was evaluated with four firmware to mirror the real scenario. As a result, it was noted that each build contained timeouted APKs. In addition, it was noted that the APK file size is not directly related to scanning time: according to evaluation and other studies, the APK file complexity might be the reason for timeouts. However, even the timeouts increase significantly the execution duration, it does not have significant impact since the builds will be executed only several times in a week. Overall, the process was automated successfully end-to-end, and it saves significantly time from the security team and offers relevant security information of APKs for software development. Android on mobiililaitteiden suosituin käyttöjärjestelmä. Myös Android-sovellusten määrä kasvaa nopeasti, mikä lisää tietoturvahaavoittuvuuksia. Tämä työ on kirjoitettu suomalaiselle matkapuhelinyhtiölle, HMD:lle, joka arvostaa turvallista mobiililaitteiden tietoturvakehitystä, minkä ansiosta tämän opinnäytetyön motivaatio syntyi halusta ylläpitää turvallista ohjelmistokehitystä ja parantaa sovellusten hyväksymisprosessia. Opinnäytetyö toteutetaan suunnittelututkimuksen lähestymistavalla, joka sisältää koko suunnittelu-, toteutus-, arviointi- ja tulosprosessin.
Ratkaisuksi on toteutettu Android-sovellusten automatisoitu staattinen sovellustesti. Alusta asti oli selvää, että koko prosessi oli automatisoitava manuaalisen työn välttämiseksi. Myös staattisen sovellustestin raportin lukeminen oli optimoitava ajan ja vaivan säästämiseksi. Keskeisiä työkaluja toteutukseen olivat Mobile Security Framework (MobSF), Docker, Jenkins ja Python. Toteutuksen lisäksi keskityttiin ymmärtämään, kuinka hyvin MobSF:n staattinen analyysi pystyy havaitsemaan haavoittuvuudet ja kuinka koko prosessi voidaan automatisoida suoritusta ylläpitäen.
Arviointia varten MobSF:n staattista analyysia arvioitiin haavoittuneella APK:lla, jossa haavoittuvuudet tiedettiin etukäteen. Tämän seurauksena todettiin, että MobSF staattinen analyysi on tehokas havaitsemaan haavoittuvuuksia erityisesti Android manifest -tiedostossa, joka sisältää mm. sovelluksen komponentit ja asetukset. Kaikkia haavoittuvuuksia ei kuitenkaan havaittu, mikä oli odotettavissa staattisen analyysin luontaisten rajoitteiden vuoksi, erityisesti ajonaikaisten haavoittuvuuksien tunnistamisessa. Lisäksi MobSF ei havainnut kaikkia kovakoodattuja salaisuuksia, mikä viittaa rajalliseen tehokkuuteen verrattaessa aiempiin tutkimuksiin. Kaiken kaikkiaan MobSF havaitsi 10 haavoittuvuutta 22:sta, joista 7 haavoittuvuutta oli merkitty raportissa suoraan.
Koko automaatioprosessia arvioitiin neljällä ohjelmistolla todellisen skenaarion peilaamiseksi. Tämän seurauksena todettiin, että jokainen ajo sisälsi keskeytyneitä APK-skannauksia. Lisäksi todettiin, että APK-tiedoston koko ei liity suoraan skannausaikaan: tulosten sekä muiden tutkimusten mukaan APK-tiedoston monimutkaisuus saattaa olla syynä keskeytyksiin. Kuitenkin vaikka keskeytykset lisäävät merkittävästi prosessin kestoa, sillä ei ole suurta vaikutusta, koska ajot toteutetaan vain muutamia kertoja viikossa. Kaiken kaikkiaan prosessi automatisoitiin onnistuneesti alusta loppuun, mikä säästää merkittävästi aikaa tietoturvatiimiltä ja tarjoaa asiaankuuluvat tietoturvatiedot APK:ista ohjelmistokehitykseen.
To address this problem, the automated static application test for Android applications was implemented. It was clear from the beginning that each step needed to be automated to avoid manual work. The reading of the static application test report also needed to be optimized to save time and effort. The core tools for the implementation were Mobile Security Framework (MobSF), Docker, Jenkins and Python. In addition to implementation, the focus was to understand how well MobSF static analysis can detect the vulnerabilities and how the entire process can be automated while maintaining the performance.
For the evaluation, the MobSF static analysis was evaluated with the vulnerable APK where the vulnerabilities were known in advance. As a result, it was noted that MobSF static analysis is powerful in detecting vulnerabilities especially in Android manifest file which contains, for example, components and configuration settings. However, not all vulnerabilities were detected, which was expected given the inherent limitations of static analysis, particularly in identifying runtime vulnerabilities. Furthermore, MobSF did not detect all hardcoded secrets, indicating limited effectiveness compared to prior studies. Overall, the MobSF detected 10 vulnerabilities of 22, where 7 vulnerabilities were flagged directly.
The entire automation process was evaluated with four firmware to mirror the real scenario. As a result, it was noted that each build contained timeouted APKs. In addition, it was noted that the APK file size is not directly related to scanning time: according to evaluation and other studies, the APK file complexity might be the reason for timeouts. However, even the timeouts increase significantly the execution duration, it does not have significant impact since the builds will be executed only several times in a week. Overall, the process was automated successfully end-to-end, and it saves significantly time from the security team and offers relevant security information of APKs for software development.
Ratkaisuksi on toteutettu Android-sovellusten automatisoitu staattinen sovellustesti. Alusta asti oli selvää, että koko prosessi oli automatisoitava manuaalisen työn välttämiseksi. Myös staattisen sovellustestin raportin lukeminen oli optimoitava ajan ja vaivan säästämiseksi. Keskeisiä työkaluja toteutukseen olivat Mobile Security Framework (MobSF), Docker, Jenkins ja Python. Toteutuksen lisäksi keskityttiin ymmärtämään, kuinka hyvin MobSF:n staattinen analyysi pystyy havaitsemaan haavoittuvuudet ja kuinka koko prosessi voidaan automatisoida suoritusta ylläpitäen.
Arviointia varten MobSF:n staattista analyysia arvioitiin haavoittuneella APK:lla, jossa haavoittuvuudet tiedettiin etukäteen. Tämän seurauksena todettiin, että MobSF staattinen analyysi on tehokas havaitsemaan haavoittuvuuksia erityisesti Android manifest -tiedostossa, joka sisältää mm. sovelluksen komponentit ja asetukset. Kaikkia haavoittuvuuksia ei kuitenkaan havaittu, mikä oli odotettavissa staattisen analyysin luontaisten rajoitteiden vuoksi, erityisesti ajonaikaisten haavoittuvuuksien tunnistamisessa. Lisäksi MobSF ei havainnut kaikkia kovakoodattuja salaisuuksia, mikä viittaa rajalliseen tehokkuuteen verrattaessa aiempiin tutkimuksiin. Kaiken kaikkiaan MobSF havaitsi 10 haavoittuvuutta 22:sta, joista 7 haavoittuvuutta oli merkitty raportissa suoraan.
Koko automaatioprosessia arvioitiin neljällä ohjelmistolla todellisen skenaarion peilaamiseksi. Tämän seurauksena todettiin, että jokainen ajo sisälsi keskeytyneitä APK-skannauksia. Lisäksi todettiin, että APK-tiedoston koko ei liity suoraan skannausaikaan: tulosten sekä muiden tutkimusten mukaan APK-tiedoston monimutkaisuus saattaa olla syynä keskeytyksiin. Kuitenkin vaikka keskeytykset lisäävät merkittävästi prosessin kestoa, sillä ei ole suurta vaikutusta, koska ajot toteutetaan vain muutamia kertoja viikossa. Kaiken kaikkiaan prosessi automatisoitiin onnistuneesti alusta loppuun, mikä säästää merkittävästi aikaa tietoturvatiimiltä ja tarjoaa asiaankuuluvat tietoturvatiedot APK:ista ohjelmistokehitykseen.
Kokoelmat
Samankaltainen aineisto
Näytetään aineisto, joilla on samankaltaisia nimekkeitä, tekijöitä tai asiasanoja.
-
From maintaining stability to securing change : Expert perceptions on how the Civilian Security Sector contributes to resilience in Ukraine.
Karjalainen, Tyyne (2020)
Pro gradu -tutkielmaSix years after the Euromaidan, Ukraine has taken significant steps in order to reform its civilian security provision, namely the rule of law and law enforcement, to become more aligned with the standards demanded by the ... -
The Change in the Concept of Security after the Cold War. The case of environmental security problem of Sosnovyi Bor Nuclear Power Plant.
ERKKILÄ, HANNA-MARI (1996)
Pro gradu -tutkielma -
Security through integration? : the role of security in the enlargements of the European Union
Palosaari, Teemu
TAPRI Net Series : 7 (Tampere University Press, 2009)
book


