题名 |
行動App安全風險評估與防範措施之研究 |
并列篇名 |
A Study on Mobile App Security Risk Assessment and Preventive Measures |
作者 |
賴森堂 |
关键词 |
行動App ; 安全事證 ; MASRA ; 防範措施 ; 行動裝置 ; Mobile App ; Security certificate ; MASRA ; Preventive measures ; Mobile devices |
期刊名称 |
電腦稽核 |
卷期/出版年月 |
44期(2021 / 08 / 31) |
页次 |
28 - 42 |
内容语文 |
繁體中文 |
中文摘要 |
資訊與網路技術快速成長,各種網路應用環境普及且融入人們日常生活,透過行動App可以達到互動、溝通、支付及交易等行為,搭配行動裝置的便利性,行動App已成為網路應用必備的工具。行動App依應用可區分為三種類型:無須使用身分鑑別(純功能性)、須使用身分鑑別(具認證功能與連網行為)、具交易行為等。各類型行動App取得方便,只要提供相關資料即可在多項行動裝置下載、安裝與使用,不過,台灣地區每天有超過4000多部手機中毒或遭駭客入侵,嚴重者可能造成民眾個資外洩與財務損失。為了降低使用行動App帶來的安全風險,本文蒐集App多方面資訊,以行動App安全事證為基礎,設計一套行動App安全風險評估(MASRA)程序,適時評估App的安全風險,有效協助民眾篩選高安全性的App,及時提醒民眾採取安全防範措施,保護民眾個資隱私與財產安全,避免敏感性資料外洩與財務損失。 |
英文摘要 |
Information and network technologies are growing rapidly, and various network application environments are popularized and integrated into people's daily lives. Through mobile apps, interaction, communication, payment, and transactions can be achieved. With the convenience of mobile devices, mobile apps have become a necessary tool for network applications. Mobile apps can be divided into three types according to applications: purely functional, with authentication function and connection behavior, with financial transaction function, etc. All types of mobile apps are easy to get. People can download, install and use on multiple mobile devices as long as you provide relevant information. However, more than 4000 mobile phones are poisoned or hacked every day in Taiwan, and severe cases may cause personal information leakage and financial losses. In order to reduce the security risks caused by the use of mobile apps, this paper collects various information about the apps. Based on the security evidence of the mobile apps, designs a Mobile Apps Security Risk Assessment (MASRA) procedures to assess the security risks of the apps in a timely manner and effectively assist the people to select high-security apps. MASRA can also promptly remind the people to take security precautions to protect the privacy of personal information and property security and to avoid the leakage of sensitive information and financial losses. |
主题分类 |
基礎與應用科學 >
資訊科學 |
参考文献 |
|