首页> 外文会议>IEEE International Symposium on Software Reliability Engineering >Experience report: A field analysis of user-defined security configurations of Android devices
【24h】

Experience report: A field analysis of user-defined security configurations of Android devices

机译:体验报告:对Android设备用户定义的安全配置的现场分析

获取原文
获取外文期刊封面目录资料

摘要

The wide spreading of mobile devices, such as smart phones and tablets, and their always-advancing capabilities, ranging from taking photos to accessing banking accounts, makes them an attractive target for attackers. This, together with the fact that users frequently store critical personal information in such devices and that many organizations currently allow employees to use their personal devices to access the enterprise information infrastructure and applications, turns assessing the security of mobile devices into a key issue. In order to understand the common misconfiguration problems, this practical experience report presents a held analysis of 41 user-defined security settings of more than 500 Android devices. Findings suggest that most users neglect basic security configurations such as login mechanisms and (bat manufacturers should rethink their policies in terms of the security settings that can be modified by the users. The paper also proposes concrete security countermeasures to mitigate some of the identified misconfigurations.
机译:智能手机和平板电脑等移动设备的广泛普及,以及从拍照到访问银行帐户的不断发展的能力,使它们成为攻击者的诱人目标。这与用户经常在此类设备中存储重要的个人信息以及许多组织当前允许员工使用其个人设备访问企业信息基础结构和应用程序这一事实一起,将评估移动设备的安全性变成了关键问题。为了了解常见的配置错误问题,本实践经验报告对500多种Android设备的41种用户定义的安全设置进行了分析。研究结果表明,大多数用户忽略了基本的安全配置,例如登录机制和(蝙蝠制造商应根据用户可以修改的安全设置来重新考虑其策略。本文还提出了具体的安全对策,以减轻某些已识别的错误配置。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号