首页> 外文会议>IEEE International Symposium on Software Reliability Engineering >Risk Assessment of User-Defined Security Configurations for Android Devices
【24h】

Risk Assessment of User-Defined Security Configurations for Android Devices

机译:用户定义的Android设备安全配置的风险评估

获取原文

摘要

The wide spreading of mobile devices, such as smartphones and tablets, and their advancing capabilities, ranging from taking photos to accessing banking accounts, make them an attractive target for attackers. This, together with the fact that users frequently store critical information in such devices and that many organizations allow employees to use their personal devices to access the enterprise information infrastructure and applications, makes security assessment a key need. This paper proposes an approach for assessing the security risk posed by user-defined configurations in Android devices. The approach is based on the analysis of the risk (impact and likelihood) of user misconfiguration to harm the device or the user. The impact and likelihood values are defined based on a Multiple-Criteria Decision Analysis (MCDA) performed on the inputs provided by a set of security experts. A case study considering the user-defined configurations of 561 Android devices is presented, showing that the majority of the users neglect important and basic security configurations and that the proposed approach can be used in practice to characterize the security risk level of such devices.
机译:智能手机和平板电脑等移动设备的广泛普及以及先进的功能(从拍照到访问银行帐户),使其成为攻击者的诱人目标。加上用户经常在此类设备中存储关键信息,并且许多组织允许员工使用其个人设备来访问企业信息基础结构和应用程序,这一事实使安全评估成为关键需求。本文提出了一种方法,用于评估Android设备中用户定义的配置所带来的安全风险。该方法基于对用户错误配置以损害设备或用户的风险(影响和可能性)的分析。影响和可能性值是基于对一组安全专家提供的输入执行的多标准决策分析(MCDA)定义的。提出了一个案例研究,其中考虑了561个Android设备的用户定义配置,表明大多数用户忽略了重要的基本安全配置,并且所建议的方法可在实践中用于表征此类设备的安全风险等级。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号