Hyppää sisältöön
    • Suomeksi
    • In English
Trepo
  • Suomeksi
  • In English
  • Kirjaudu
Näytä viite 
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto (Limited access)
  • Näytä viite
  •   Etusivu
  • Trepo
  • Opinnäytteet - ylempi korkeakoulututkinto (Limited access)
  • Näytä viite
JavaScript is disabled for your browser. Some features of this site may not work without it.

Security Assessment of Plugit Mobile Application Utilizing OWASP MASVS

Ashraf, Rehan (2026)

 
Avaa tiedosto
AshrafRehan.pdf (430.1Kt)
Lataukset: 

Tekijä ei ole antanut lupaa avoimeen julkaisuun, aineisto on luettavissa vain Tampereen yliopiston kirjastojen opinnäytepisteillä. The author has not given permission to publish the thesis online. The thesis can be read at the thesis point at Tampere University Library.

Ashraf, Rehan
2026

Tietotekniikan DI-ohjelma - Master's Programme in Information Technology
Informaatioteknologian ja viestinnän tiedekunta - Faculty of Information Technology and Communication Sciences
Hyväksymispäivämäärä
2026-06-09
Näytä kaikki kuvailutiedot
Julkaisun pysyvä osoite on
https://urn.fi/URN:NBN:fi:tuni-202606097155
Tiivistelmä
Mobile applications are an integral part of our daily lives. They have turned phones into versatile digital platforms for entertainment, communication, and business services. As mobile applications evolve rapidly, cybercriminals increasingly target them, thus security is a serious concern. Applications typically store sensitive user data, such as financial records, health information, and personal communications, making them desirable targets for cyberattacks. Developers can mitigate these threats by following established security frameworks and adhering to secure coding practices to secure mobile applications.

This thesis assesses the security of mobile applications in practice by assessing a real-world mobile application that is actively used and accessible to many users. It uncovers possible security risks in the app and reveals areas to improve its security. The analysis primarily focuses on the Plugit mobile application, an Electric Vehicle (EV) charging application for Android and iOS. Furthermore, the review follows the Open Web Application Security Project (OWASP) Mobile Application Security Verification Standard (MASVS), a widely used framework for systematically determining and minimizing security threats on mobile platforms. By integrating manual analysis, automated inspection, and penetration testing, this work focuses on the most critical aspects of the application, including data storage, cryptography, authentication, and network communication.

The security assessment identified over ten observations across various MASVS controls. It found no critical vulnerabilities, confirming that the application maintains a strong security posture. However, the assessment highlights some areas that could be improved. Addressing these highlighted areas further strengthens the defenses of the application and enhances its resilience to evolving threats.

In addition to the Plugit app assessment, this thesis also includes security testing performed on AndroGoat, an open-source native Android application implemented using Kotlin and Android Software Development Kit (SDK) components. The assessment executed a selective set of MASVS-mapped test cases across four control groups: STORAGE, CRYPTO, NETWORK, and PLATFORM. The results showed that seven test cases failed to meet the defined security requirements, with most failures related to insecure data storage and network communication controls.

This study shows that systematic security frameworks work effectively when applied to real-world mobile applications. The findings offer practical steps to improve app security, promote better development practices, and build more robust mobile systems for the expanding EV infrastructure. By testing actual applications against established standards, this research goes beyond theory to deliver actionable improvements that developers can implement immediately.
Kokoelmat
  • Opinnäytteet - ylempi korkeakoulututkinto (Limited access) [4181]
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste
 

 

Selaa kokoelmaa

TekijätNimekkeetTiedekunta (2019 -)Tiedekunta (- 2018)Tutkinto-ohjelmat ja opintosuunnatAvainsanatJulkaisuajatKokoelmat

Omat tiedot

Kirjaudu sisäänRekisteröidy
Kalevantie 5
PL 617
33014 Tampereen yliopisto
oa[@]tuni.fi | Tietosuoja | Saavutettavuusseloste