Uraniborg's device preloaded app risks scoring metrics
Lau, Billy and Zhang, Jiexin and Beresford, Alastair R. and Thomas, Daniel R. and Mayrhofer, René (2020) Uraniborg's device preloaded app risks scoring metrics. Institute of Networks and Security, Linz, Austria. (https://pure.strath.ac.uk/admin/files/temp/perm-te...)
Full text not available in this repository.Request a copyAbstract
The security of Android devices depends on a wide range of factors. In this paper we focus on quantifying the risks associated with one important factor: the security and privacy posture of preloaded apps. Such applications deserve particular attention since they are installed by the manufacturer on all devices of a particular make and model, individual apps may have elevated privileges beyond those available to apps installed via the Google Play Store, and typically cannot be removed by the user. In order to measure the risk presented by preloaded apps in a quantifiable way, we adopt a numerical approach and derive a single overall score for a given handset and therefore support the relative comparison of risks posed by different handsets. Due to the difficulty in computing the security and privacy risk, we approximate the actual risk by estimating the attack surface 1 presented by this layer of software. We therefore present an extensible mathematical software framework that allows us to define, compute, and analyze various aspects of security and privacy risks of preloaded Android apps in a systematic manner.
ORCID iDs
Lau, Billy, Zhang, Jiexin, Beresford, Alastair R., Thomas, Daniel R. ORCID: https://orcid.org/0000-0001-8936-0683 and Mayrhofer, René;-
-
Item type: Report ID code: 81605 Dates: DateEvent31 August 2020Published1 August 2020AcceptedSubjects: Science > Mathematics > Electronic computers. Computer science Department: Faculty of Science > Computer and Information Sciences Depositing user: Pure Administrator Date deposited: 27 Jul 2022 15:46 Last modified: 11 Nov 2024 15:55 Related URLs: URI: https://strathprints.strath.ac.uk/id/eprint/81605