How MobileAudit Maps Built-In SAST Patterns to CWE and OWASP Mobile Top 10

MobileAudit automatically classifies every static analysis finding with both a CWE identifier and an OWASP Mobile Top 10 risk by storing these mappings inside the Pattern model and applying them at detection time.

MobileAudit is an open-source Django application that performs static application security testing (SAST) on Android APKs. The tool ships with a built-in rule engine that uses regular-expression SAST patterns to detect vulnerable code snippets. Each pattern is permanently linked to a CWE (Common Weakness Enumeration) entry and an OWASP Mobile Top 10 risk, ensuring that every finding inherits standardized taxonomies for reporting and prioritization.

Understanding the Pattern Data Model

The core of MobileAudit’s SAST capability resides in the Pattern model defined in app/models.py. This model acts as a database-backed rule repository where each row represents a single security check.

Core Schema and Fields

The Pattern model contains the following essential fields (lines 12–113 in app/models.py):

  • pattern – A regular-expression string that is compiled and executed against decompiled source files.
  • default_cwe – Foreign key to the Cwe model (lines 101–103), storing the weakness classification (e.g., CWE-89 for SQL Injection).
  • default_risk – Foreign key to the Risk model (lines 101–105), mapping the finding to an OWASP Mobile Top 10 entry (e.g., M1: Improper Platform Usage).
  • default_name, default_description, default_severity, default_mitigation – Human-readable metadata attached to every finding generated by this rule.
  • active – Boolean flag (lines 112–113) that allows administrators to enable or disable the rule without deleting it.

Supporting Taxonomy Models

Two auxiliary models complete the mapping infrastructure:

  1. Cwe (app/models.py lines 88–92) – Stores the CWE identifier (cwe) and description.
  2. Risk (app/models.py lines 94–99) – Stores the Mobile Top 10 identifier (risk), description, and a reference URL linking to the official OWASP entry.

How the SAST Engine Applies Patterns

The analysis workflow is implemented in app/analysis.py. When a user uploads an APK, Celery workers decompile the binary and invoke the find_patterns function.

Pattern Loading and Regex Compilation

The engine first retrieves all active rules:

patterns = Pattern.objects.filter(active=True)

# app/analysis.py L273-L274

Each pattern’s regex is compiled with multiline support:

re.compile(p.pattern, re.MULTILINE)

The compiled expression is then matched against every line of every decompiled source file.

Automatic Taxonomy Mapping on Detection

When a match occurs, the engine instantiates a Finding object and copies the taxonomic data directly from the matched Pattern:

finding = Finding(
    # ... file location and match details ...

    name=p.default_name,
    description=p.default_description,
    severity=p.default_severity,
    mitigation=p.default_mitigation,
    cwe=p.default_cwe,
    risk=p.default_risk,
    # ...

)

# app/analysis.py L333-L339

This design guarantees that every finding is automatically labeled with both a CWE and an OWASP Mobile Top 10 risk at the moment of creation, without requiring manual classification by the analyst.

Mapping to CWE and Mobile Top 10

MobileAudit’s dual-taxonomy approach bridges generic software weakness classification with mobile-specific threat modeling.

CWE Integration

The default_cwe field links each pattern to the Common Weakness Enumeration. When findings are rendered in the UI (app/templates/finding.html), the CWE identifier is displayed as a hyperlink using the base URL defined in settings.CWE_URL:

<a class="link" href="{{ settings.CWE_URL }}{{ finding.cwe.cwe }}.html">
    {{ finding.cwe.cwe }}
</a>
<!-- app/templates/finding.html L22-L23 -->

This allows security teams to pivot directly from a finding to the official CWE definition for detailed remediation guidance.

OWASP Mobile Top 10 Risk Classification

The default_risk field maps patterns to the OWASP Mobile Top 10 (e.g., M1 through M10). The Risk model stores the risk number, description, and a reference URL to the official OWASP documentation.

In the pattern listing (app/templates/patterns.html) and finding detail views, the risk is displayed with a link to the OWASP reference:

<a class="link" href="{{ pattern.default_risk.reference }}">
    M{{ pattern.default_risk.risk }}
</a>
<!-- app/templates/finding.html -->

This mapping ensures that mobile developers and security auditors can prioritize issues based on the industry-standard mobile threat taxonomy.

Managing SAST Patterns

MobileAudit provides two interfaces for rule management: the Django admin dashboard and programmatic APIs.

Via Django Admin Interface

Administrators can create, edit, or disable patterns without touching code:

  1. Navigate to /admin/app/pattern/.
  2. Click Add Pattern.
  3. Populate the fields:
    • Pattern: The regular expression (e.g., r"\brawQuery\([^)]*\)").
    • Default CWE: Select from existing CWE records or create a new one.
    • Default Risk: Select the OWASP Mobile Top 10 category.
    • Default Name, Description, Severity, Mitigation: Metadata for findings.
  4. Toggle the Active checkbox to enable the rule immediately.

Changes take effect for all subsequent scans without requiring a server restart.

Programmatic Pattern Creation

Security teams can seed custom rules via Django shell or migration scripts:

from app.models import Pattern, Cwe, Risk

# Ensure taxonomies exist

cwe, _ = Cwe.objects.get_or_create(
    cwe=89,
    defaults={"description": "SQL Injection"}
)

risk, _ = Risk.objects.get_or_create(
    risk=1,
    defaults={
        "description": "Improper Platform Usage",
        "reference": "https://owasp.org/www-project-mobile-top-10/"
    }
)

# Create the SAST pattern

Pattern.objects.create(
    pattern=r"\brawQuery\([^)]*\)",
    default_cwe=cwe,
    default_risk=risk,
    default_name="Raw SQLite Query Usage",
    default_description="Detects rawQuery calls that may lead to SQL injection.",
    default_severity="HI",
    default_mitigation="Use parameterized queries with ? placeholders.",
    active=True
)

This approach is ideal for importing large rule sets from external sources or synchronizing with corporate security policies.

Querying Findings with Taxonomy Data

Analysts can extract findings complete with their CWE and Mobile Top 10 classifications for reporting:

from app.models import Finding

for finding in Finding.objects.select_related('cwe', 'risk'):
    print(f"[{finding.severity}] {finding.name}")
    print(f"  CWE-{finding.cwe.cwe}: {finding.cwe.description}")
    print(f"  Mobile Top 10: M{finding.risk.risk} - {finding.risk.description}")
    print(f"  Reference: {finding.risk.reference}\n")

This query uses select_related to efficiently join the Cwe and Risk tables, producing exportable data for compliance reports or SIEM integration.

Summary

  • Pattern Model: MobileAudit stores SAST rules as database records in app/models.py, where each Pattern contains a regex, metadata, and foreign keys to CWE and Risk taxonomies.
  • Automatic Classification: When find_patterns in app/analysis.py detects a match, it creates a Finding that automatically inherits the default_cwe and default_risk from the triggered pattern.
  • Dual Taxonomy: Every finding is simultaneously mapped to the Common Weakness Enumeration (generic software weaknesses) and the OWASP Mobile Top 10 (mobile-specific threats).
  • Flexible Management: Rules can be added or modified via the Django admin interface at /admin/app/pattern/ or programmatically using Django ORM calls, with no code deployment required.

Frequently Asked Questions

How are SAST patterns stored in MobileAudit?

SAST patterns are stored as records in the Django Pattern model defined in app/models.py. Each record contains a regular expression string in the pattern field, along with metadata fields such as default_name, default_description, and default_severity. Crucially, each pattern includes foreign keys (default_cwe and default_risk) that link the rule to specific CWE and OWASP Mobile Top 10 entries.

Can I add custom SAST patterns without modifying the source code?

Yes. MobileAudit provides a Django admin interface accessible at /admin/app/pattern/ where administrators can create new patterns, define their regular expressions, and select the appropriate CWE and Mobile Top 10 mappings from dropdown menus. You can also disable existing patterns by unchecking the active field. For bulk operations, you can use the Django shell or write migration scripts using the Pattern model API.

How does MobileAudit ensure every finding has both a CWE and Mobile Top 10 classification?

The enforcement happens at the database and application logic levels. The Pattern model requires foreign keys to both Cwe and Risk models. When the find_patterns function in app/analysis.py detects a regex match, it instantiates a Finding object and explicitly copies the default_cwe and default_risk from the matched pattern into the finding's cwe and risk fields. This design guarantees that findings inherit their classifications directly from the rules that triggered them.

Where can I view the CWE and Mobile Top 10 mappings in the UI?

The mappings are visible in multiple views within the MobileAudit web interface. The patterns list page (app/templates/patterns.html) displays columns for both the CWE ID and the Mobile Top 10 risk associated with each rule. When viewing an individual finding (app/templates/finding.html), the detail page renders the CWE as a hyperlink to the official CWE definition (using settings.CWE_URL) and displays the Mobile Top 10 risk with a link to the OWASP reference URL stored in the Risk model.

Have a question about this repo?

These articles cover the highlights, but your codebase questions are specific. Give your agent direct access to the source. Share this with your agent to get started:

Share the following with your agent to get started:
curl -s "https://instagit.com/install.md"

Works with
Claude Codex Cursor VS Code OpenClaw Any MCP Client

Maintain an open-source project? Get it listed too →