A Large-Scale Data Collection and Evaluation Framework for Android Device Security Attributes

Research output: Chapter in Book/Report/Conference proceedingConference proceedingspeer-review

Abstract

Android’s fast-lived development cycles and increasing amounts of manufacturers and device models make a comparison of relevant security attributes, in addition to the already difficult comparison of features, more challenging. Most smartphone reviews only consider offered features in their analysis. Smartphone manufacturers include their own software on top of the Android Open Source Project (AOSP) to improve user experience, to add their own pre-installed apps or apps from third-party sponsors, and to distinguish themselves from their competitors. These changes affect the security of smartphones. It is insufficient to validate device security state only based on measured data from real devices for a complete assessment. Promised major version releases, security updates, security update schedules of devices, and correct claims on security and privacy of pre-installed software are some aspects, which need statistically significant amounts of data to evaluate. Lack of software and security updates is a common reason for shorter lifespans of electronics, especially for smartphones. Validating the claims of manufacturers and publishing the results creates incentives towards more sustainable maintenance and longevity of smartphones. We present a novel scalable data collection and evaluation framework, which includes multiple sources of data like dedicated device farms, crowdsourcing, and webscraping. Our solution improves the comparability of devices based on their security attributes by providing measurements from real devices.
Original languageEnglish
Title of host publicationIDIMT-2023: New Challenges for ICT and Management
EditorsPetr Doucek, Michael Sonntag, Lea Nedomova
Place of PublicationHradec Králové, Czech Republic
PublisherVerlag Trauner
Pages63-71
Number of pages9
ISBN (Electronic)9783991511762
DOIs
Publication statusPublished - Sept 2023
EventIDIMT-2023 New Challenges for ICT and Managment, 31st Interdisciplinary Information Management Talks - Hradec Králové, Czech Republic
Duration: 06 Sept 202308 Sept 2023

Other

OtherIDIMT-2023 New Challenges for ICT and Managment, 31st Interdisciplinary Information Management Talks
Country/TerritoryCzech Republic
Period06.09.202308.09.2023

Fields of science

  • 102 Computer Sciences
  • 102016 IT security
  • 102015 Information systems

JKU Focus areas

  • Digital Transformation
  • ONCE

    Roland, M. (PI)

    15.07.202114.07.2023

    Project: Funded researchFFG - Austrian Research Promotion Agency

Cite this