# How MobileAudit Maps Built-In SAST Patterns to CWE and OWASP Mobile Top 10

> Discover how MobileAudit maps built-in SAST patterns to CWE and OWASP Mobile Top 10 for automated security finding classification. Understand mobile app vulnerabilities efficiently.

- Repository: [Mónica Pastor/mobileaudit](https://github.com/mpast/mobileaudit)
- Tags: deep-dive
- Published: 2026-03-07

---

**MobileAudit automatically classifies every static analysis finding with both a CWE identifier and an OWASP Mobile Top 10 risk by storing these mappings inside the `Pattern` model and applying them at detection time.**

MobileAudit is an open-source Django application that performs static application security testing (SAST) on Android APKs. The tool ships with a built-in rule engine that uses regular-expression **SAST patterns** to detect vulnerable code snippets. Each pattern is permanently linked to a **CWE** (Common Weakness Enumeration) entry and an **OWASP Mobile Top 10** risk, ensuring that every finding inherits standardized taxonomies for reporting and prioritization.

## Understanding the Pattern Data Model

The core of MobileAudit’s SAST capability resides in the `Pattern` model defined in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py). This model acts as a database-backed rule repository where each row represents a single security check.

### Core Schema and Fields

The `Pattern` model contains the following essential fields (lines 12–113 in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py)):

- **`pattern`** – A regular-expression string that is compiled and executed against decompiled source files.
- **`default_cwe`** – Foreign key to the `Cwe` model (lines 101–103), storing the weakness classification (e.g., CWE-89 for SQL Injection).
- **`default_risk`** – Foreign key to the `Risk` model (lines 101–105), mapping the finding to an OWASP Mobile Top 10 entry (e.g., M1: Improper Platform Usage).
- **`default_name`**, **`default_description`**, **`default_severity`**, **`default_mitigation`** – Human-readable metadata attached to every finding generated by this rule.
- **`active`** – Boolean flag (lines 112–113) that allows administrators to enable or disable the rule without deleting it.

### Supporting Taxonomy Models

Two auxiliary models complete the mapping infrastructure:

1. **`Cwe`** ([`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py) lines 88–92) – Stores the CWE identifier (`cwe`) and description.
2. **`Risk`** ([`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py) lines 94–99) – Stores the Mobile Top 10 identifier (`risk`), description, and a reference URL linking to the official OWASP entry.

## How the SAST Engine Applies Patterns

The analysis workflow is implemented in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py). When a user uploads an APK, Celery workers decompile the binary and invoke the `find_patterns` function.

### Pattern Loading and Regex Compilation

The engine first retrieves all active rules:

```python
patterns = Pattern.objects.filter(active=True)

# app/analysis.py L273-L274

```

Each pattern’s regex is compiled with multiline support:

```python
re.compile(p.pattern, re.MULTILINE)

```

The compiled expression is then matched against every line of every decompiled source file.

### Automatic Taxonomy Mapping on Detection

When a match occurs, the engine instantiates a `Finding` object and copies the taxonomic data directly from the matched `Pattern`:

```python
finding = Finding(
    # ... file location and match details ...

    name=p.default_name,
    description=p.default_description,
    severity=p.default_severity,
    mitigation=p.default_mitigation,
    cwe=p.default_cwe,
    risk=p.default_risk,
    # ...

)

# app/analysis.py L333-L339

```

This design guarantees that every finding is automatically labeled with both a **CWE** and an **OWASP Mobile Top 10** risk at the moment of creation, without requiring manual classification by the analyst.

## Mapping to CWE and Mobile Top 10

MobileAudit’s dual-taxonomy approach bridges generic software weakness classification with mobile-specific threat modeling.

### CWE Integration

The `default_cwe` field links each pattern to the Common Weakness Enumeration. When findings are rendered in the UI ([`app/templates/finding.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/finding.html)), the CWE identifier is displayed as a hyperlink using the base URL defined in `settings.CWE_URL`:

```html
<a class="link" href="{{ settings.CWE_URL }}{{ finding.cwe.cwe }}.html">
    {{ finding.cwe.cwe }}
</a>
<!-- app/templates/finding.html L22-L23 -->

```

This allows security teams to pivot directly from a finding to the official CWE definition for detailed remediation guidance.

### OWASP Mobile Top 10 Risk Classification

The `default_risk` field maps patterns to the OWASP Mobile Top 10 (e.g., M1 through M10). The `Risk` model stores the risk number, description, and a reference URL to the official OWASP documentation.

In the pattern listing ([`app/templates/patterns.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/patterns.html)) and finding detail views, the risk is displayed with a link to the OWASP reference:

```html
<a class="link" href="{{ pattern.default_risk.reference }}">
    M{{ pattern.default_risk.risk }}
</a>
<!-- app/templates/finding.html -->

```

This mapping ensures that mobile developers and security auditors can prioritize issues based on the industry-standard mobile threat taxonomy.

## Managing SAST Patterns

MobileAudit provides two interfaces for rule management: the Django admin dashboard and programmatic APIs.

### Via Django Admin Interface

Administrators can create, edit, or disable patterns without touching code:

1. Navigate to `/admin/app/pattern/`.
2. Click **Add Pattern**.
3. Populate the fields:
   - **Pattern**: The regular expression (e.g., `r"\brawQuery\([^)]*\)"`).
   - **Default CWE**: Select from existing CWE records or create a new one.
   - **Default Risk**: Select the OWASP Mobile Top 10 category.
   - **Default Name**, **Description**, **Severity**, **Mitigation**: Metadata for findings.
4. Toggle the **Active** checkbox to enable the rule immediately.

Changes take effect for all subsequent scans without requiring a server restart.

### Programmatic Pattern Creation

Security teams can seed custom rules via Django shell or migration scripts:

```python
from app.models import Pattern, Cwe, Risk

# Ensure taxonomies exist

cwe, _ = Cwe.objects.get_or_create(
    cwe=89,
    defaults={"description": "SQL Injection"}
)

risk, _ = Risk.objects.get_or_create(
    risk=1,
    defaults={
        "description": "Improper Platform Usage",
        "reference": "https://owasp.org/www-project-mobile-top-10/"
    }
)

# Create the SAST pattern

Pattern.objects.create(
    pattern=r"\brawQuery\([^)]*\)",
    default_cwe=cwe,
    default_risk=risk,
    default_name="Raw SQLite Query Usage",
    default_description="Detects rawQuery calls that may lead to SQL injection.",
    default_severity="HI",
    default_mitigation="Use parameterized queries with ? placeholders.",
    active=True
)

```

This approach is ideal for importing large rule sets from external sources or synchronizing with corporate security policies.

## Querying Findings with Taxonomy Data

Analysts can extract findings complete with their CWE and Mobile Top 10 classifications for reporting:

```python
from app.models import Finding

for finding in Finding.objects.select_related('cwe', 'risk'):
    print(f"[{finding.severity}] {finding.name}")
    print(f"  CWE-{finding.cwe.cwe}: {finding.cwe.description}")
    print(f"  Mobile Top 10: M{finding.risk.risk} - {finding.risk.description}")
    print(f"  Reference: {finding.risk.reference}\n")

```

This query uses `select_related` to efficiently join the `Cwe` and `Risk` tables, producing exportable data for compliance reports or SIEM integration.

## Summary

- **Pattern Model**: MobileAudit stores SAST rules as database records in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py), where each `Pattern` contains a regex, metadata, and foreign keys to CWE and Risk taxonomies.
- **Automatic Classification**: When `find_patterns` in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py) detects a match, it creates a `Finding` that automatically inherits the `default_cwe` and `default_risk` from the triggered pattern.
- **Dual Taxonomy**: Every finding is simultaneously mapped to the **Common Weakness Enumeration** (generic software weaknesses) and the **OWASP Mobile Top 10** (mobile-specific threats).
- **Flexible Management**: Rules can be added or modified via the Django admin interface at `/admin/app/pattern/` or programmatically using Django ORM calls, with no code deployment required.

## Frequently Asked Questions

### How are SAST patterns stored in MobileAudit?

SAST patterns are stored as records in the Django `Pattern` model defined in [`app/models.py`](https://github.com/mpast/mobileaudit/blob/main/app/models.py). Each record contains a regular expression string in the `pattern` field, along with metadata fields such as `default_name`, `default_description`, and `default_severity`. Crucially, each pattern includes foreign keys (`default_cwe` and `default_risk`) that link the rule to specific CWE and OWASP Mobile Top 10 entries.

### Can I add custom SAST patterns without modifying the source code?

Yes. MobileAudit provides a Django admin interface accessible at `/admin/app/pattern/` where administrators can create new patterns, define their regular expressions, and select the appropriate CWE and Mobile Top 10 mappings from dropdown menus. You can also disable existing patterns by unchecking the `active` field. For bulk operations, you can use the Django shell or write migration scripts using the `Pattern` model API.

### How does MobileAudit ensure every finding has both a CWE and Mobile Top 10 classification?

The enforcement happens at the database and application logic levels. The `Pattern` model requires foreign keys to both `Cwe` and `Risk` models. When the `find_patterns` function in [`app/analysis.py`](https://github.com/mpast/mobileaudit/blob/main/app/analysis.py) detects a regex match, it instantiates a `Finding` object and explicitly copies the `default_cwe` and `default_risk` from the matched pattern into the finding's `cwe` and `risk` fields. This design guarantees that findings inherit their classifications directly from the rules that triggered them.

### Where can I view the CWE and Mobile Top 10 mappings in the UI?

The mappings are visible in multiple views within the MobileAudit web interface. The patterns list page ([`app/templates/patterns.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/patterns.html)) displays columns for both the CWE ID and the Mobile Top 10 risk associated with each rule. When viewing an individual finding ([`app/templates/finding.html`](https://github.com/mpast/mobileaudit/blob/main/app/templates/finding.html)), the detail page renders the CWE as a hyperlink to the official CWE definition (using `settings.CWE_URL`) and displays the Mobile Top 10 risk with a link to the OWASP reference URL stored in the `Risk` model.