Security metrics for the Android ecosystem
View / Open Files
Authors
Thomas, DR
Beresford, AR
Rice, A
Publication Date
2015-10-12Journal Title
SPSM 2015 - Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, co-located with: CCS 2015
Conference Name
5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices,
ISBN
9781450338196
Publisher
ACM
Pages
87-98
Type
Conference Object
This Version
AM
Metadata
Show full item recordCitation
Thomas, D., Beresford, A., & Rice, A. (2015). Security metrics for the Android ecosystem. SPSM 2015 - Proceedings of the 5th Annual ACM CCS Workshop on Security and Privacy in Smartphones and Mobile Devices, co-located with: CCS 2015, 87-98. https://doi.org/10.1145/2808117.2808118
Abstract
© 2015 ACM. The security of Android depends on the timely delivery of updates to fix critical vulnerabilities. In this paper we map the complex network of players in the Android ecosystem who must collaborate to provide updates, and determine that inaction by some manufacturers and network operators means many handsets are vulnerable to critical vulnerabil- ities. We define the FUM security metric to rank the per- formance of device manufacturers and network operators, based on their provision of updates and exposure to critical vulnerabilities. Using a corpus of 20 400 devices we show that there is significant variability in the timely delivery of security updates across different device manufacturers and network operators. This provides a comparison point for purchasers and regulators to determine which device man- ufacturers and network operators provide security updates and which do not. We find that on average 87.7% of An- droid devices are exposed to at least one of 11 known critical vulnerabilities and, across the ecosystem as a whole, assign a FUM security score of 2.87 out of 10. In our data, Nexus devices do considerably better than average with a score of 5.17; and LG is the best manufacturer with a score of 3.97.
Sponsorship
Engineering and Physical Sciences Research Council (EP/M020320/1)
EPSRC (1453439)
Identifiers
External DOI: https://doi.org/10.1145/2808117.2808118
This record's URL: https://www.repository.cam.ac.uk/handle/1810/279693
Rights
Licence:
http://www.rioxx.net/licenses/all-rights-reserved
Statistics
Total file downloads (since January 2020). For more information on metrics see the
IRUS guide.
Recommended or similar items
The current recommendation prototype on the Apollo Repository will be turned off on 03 February 2023. Although the pilot has been fruitful for both parties, the service provider IKVA is focusing on horizon scanning products and so the recommender service can no longer be supported. We recognise the importance of recommender services in supporting research discovery and are evaluating offerings from other service providers. If you would like to offer feedback on this decision please contact us on: support@repository.cam.ac.uk