Projects per year
Abstract
Android’s fast-paced development cycles and the large number of devices from different manufacturers do not allow for an easy comparison between different devices’ security and privacy postures. Manufacturers each adapt and update their respective firmware images. Furthermore, images published on OEM websites do not necessarily match those installed in the field. Relevant software security and privacy aspects do not remain static after initial device release, but need to be measured on live devices that receive these updates. There are various potential sources for collecting such attributes, including webscraping, crowdsourcing, and dedicated device farms. However, raw data alone is not helpful in making meaningful decisions on device security and privacy. We make available a website to access collected data. Our implementation focuses on reproducible requests and supports filtering by OEMs, devices, device models, and displayed attributes. To improve usability, we further propose a security score based on the list of attributes. Based on input from Android experts, including a focus group and eight individuals, we have created a method that derives attribute weights from the importance of attributes for mitigating threats on the Android platform. We derive weightings for general use cases and suggest possible examples for more specialist weightings for groups of confidentiality/privacy-sensitive users and integrity-sensitive users. Since there is no one-size-fits-all setting for Android devices, our website provides the possibility to adapt all parameters of the calculated security score to individual needs.
| Original language | English |
|---|---|
| Title of host publication | 2024 IEEE Conference on Communications and Network Security (CNS) |
| Place of Publication | Taipei, Taiwan |
| Publisher | IEEE |
| Number of pages | 9 |
| ISBN (Electronic) | 9798350375961 |
| DOIs | |
| Publication status | Published - Sept 2024 |
| Event | IEEE Conference on Communications and Network Security - Teipei, Taiwan, Province of China Duration: 30 Sept 2024 → 03 Oct 2024 https://cns2024.ieee-cns.org/ |
Conference
| Conference | IEEE Conference on Communications and Network Security |
|---|---|
| Abbreviated title | CNS 2024 |
| Country/Territory | Taiwan, Province of China |
| City | Teipei |
| Period | 30.09.2024 → 03.10.2024 |
| Internet address |
Fields of science
- 102 Computer Sciences
- 102016 IT security
- 102015 Information systems
JKU Focus areas
- Digital Transformation
- Sustainable Development: Responsible Technologies and Management
-
Christian Doppler Laboratory for Private Digital Authentication in the Physical World - Digidow
Mayrhofer, R. (PI)
01.01.2020 → 31.12.2026
Project: Funded research › CDG - Christian Doppler Forschungsgesellschaft
-
ONCE
Roland, M. (PI)
15.07.2021 → 14.07.2023
Project: Funded research › FFG - Austrian Research Promotion Agency