DocumentCode
3730238
Title
Experience report: A field analysis of user-defined security configurations of Android devices
Author
Daniel Vecchiato;Eliane Martins
Author_Institution
Institute of Computing, University of Campinas / Federal University of Mato Grosso, Campinas. Brazil. 13083-852
fYear
2015
Firstpage
314
Lastpage
323
Abstract
The wide spreading of mobile devices, such as smart phones and tablets, and their always-advancing capabilities, ranging from taking photos to accessing banking accounts, makes them an attractive target for attackers. This, together with the fact that users frequently store critical personal information in such devices and that many organizations currently allow employees to use their personal devices to access the enterprise information infrastructure and applications, turns assessing the security of mobile devices into a key issue. In order to understand the common misconfiguration problems, this practical experience report presents a held analysis of 41 user-defined security settings of more than 500 Android devices. Findings suggest that most users neglect basic security configurations such as login mechanisms and (bat manufacturers should rethink their policies in terms of the security settings that can be modified by the users. The paper also proposes concrete security countermeasures to mitigate some of the identified misconfigurations.
Keywords
"Mobile communication","Google","Androids","Humanoid robots","Benchmark testing","Operating systems","Security"
Publisher
ieee
Conference_Titel
Software Reliability Engineering (ISSRE), 2015 IEEE 26th International Symposium on
Type
conf
DOI
10.1109/ISSRE.2015.7381824
Filename
7381824
Link To Document