A Security Configuration Assessment for Android Devices

被引:6
作者
Vecchiato, Daniel [1 ]
Vieira, Marco [2 ]
Martins, Eliane [3 ]
机构
[1] Univ Estadual Campinas, Inst Comp, UFMT, Cuiaba Campinas, Brazil
[2] Univ Coimbra, CISUC, Dept Informat Engn, Coimbra, Portugal
[3] Univ Estadual Campinas, Inst Comp, Campinas, Brazil
来源
30TH ANNUAL ACM SYMPOSIUM ON APPLIED COMPUTING, VOLS I AND II | 2015年
关键词
security assessment; mobile device; Android security;
D O I
10.1145/2695664.2695679
中图分类号
TP39 [计算机的应用];
学科分类号
081203 ; 0835 ;
摘要
The wide spreading of mobile devices, such as smartphones and tablets, and their always-advancing capabilities makes them an attractive target for attackers. This, together with the fact that users frequently store critical personal information in such devices and that many organizations currently allow employees to use their personal devices to access the enterprise information infrastructure and applications, makes the assessment of the security of mobile devices a key issue. This paper proposes an approach supported by a tool that allows assessing the security of Android devices based on the user-defined settings, which are known to be a key source of security vulnerabilities. The tool automatically extracts 41 settings from the mobile devices under testing, 14 of which defined and proposed in this work and the remaining adapted from the well-known CIS benchmarks. The paper discusses the settings that are analyzed, describes the overall architecture of the tool, and presents a preliminary evaluation that demonstrates the importance of this type of tools as a foundation towards the assessment of the security of mobile devices.
引用
收藏
页码:2299 / 2304
页数:6
相关论文
共 14 条
  • [1] [Anonymous], 2011, USENIX SECURITY S
  • [2] [Anonymous], 2010, P ACSAC 10 AUST TX U, DOI DOI 10.1145/1920261.1920313
  • [3] [Anonymous], 2014, Communications of the ACM, DOI DOI 10.1145/2494522
  • [4] Ben-Asher N., P 13 INT C HUMAN COM, P465, DOI DOI 10.1145/2037373.2037442
  • [5] Chin F., 2012, P 8 S US PRIV SEC SO
  • [6] deARAUJO Allyson Carvalho, 2012, THESIS
  • [7] Gartner, GARTNER SAYS ANN SMA
  • [8] Gartner I., 2011, Gartner Says Worldwide Application Infrastructure and Middleware Market Revenue Increased 7.3 Percent in 2010
  • [9] Halpert B., 2004, P 1 ANN C INFORM SEC, P99, DOI DOI 10.1145/1059524.1059545
  • [10] A Survey on Security for Mobile Devices
    La Polla, Mariantonietta
    Martinelli, Fabio
    Sgandurra, Daniele
    [J]. IEEE COMMUNICATIONS SURVEYS AND TUTORIALS, 2013, 15 (01): : 446 - 471