• DocumentCode
    3730238
  • Title

    Experience report: A field analysis of user-defined security configurations of Android devices

  • Author

    Daniel Vecchiato;Eliane Martins

  • Author_Institution
    Institute of Computing, University of Campinas / Federal University of Mato Grosso, Campinas. Brazil. 13083-852
  • fYear
    2015
  • Firstpage
    314
  • Lastpage
    323
  • Abstract
    The wide spreading of mobile devices, such as smart phones and tablets, and their always-advancing capabilities, ranging from taking photos to accessing banking accounts, makes them an attractive target for attackers. This, together with the fact that users frequently store critical personal information in such devices and that many organizations currently allow employees to use their personal devices to access the enterprise information infrastructure and applications, turns assessing the security of mobile devices into a key issue. In order to understand the common misconfiguration problems, this practical experience report presents a held analysis of 41 user-defined security settings of more than 500 Android devices. Findings suggest that most users neglect basic security configurations such as login mechanisms and (bat manufacturers should rethink their policies in terms of the security settings that can be modified by the users. The paper also proposes concrete security countermeasures to mitigate some of the identified misconfigurations.
  • Keywords
    "Mobile communication","Google","Androids","Humanoid robots","Benchmark testing","Operating systems","Security"
  • Publisher
    ieee
  • Conference_Titel
    Software Reliability Engineering (ISSRE), 2015 IEEE 26th International Symposium on
  • Type

    conf

  • DOI
    10.1109/ISSRE.2015.7381824
  • Filename
    7381824