论文标题
用户应该信任他们的Android设备吗?评估预装应用程序的安全性和隐私风险的评分系统
Should Users Trust Their Android Devices? A Scoring System for Assessing Security and Privacy Risks of Pre-Installed Applications
论文作者
论文摘要
Android设备配备了许多预安装的应用程序,具有跟踪和监视用户的能力。尽管预先安装的应用程序对用户安全和隐私构成了极大的危险,但迄今为止,在该领域的研究人员中,他们几乎没有受到关注。在这项研究中,我们收集了一个包括此类应用程序的数据集并使其公开可用。使用此数据集,我们分析了跟踪器SDK,清单文件和云服务的使用,并报告我们的结果。我们还进行了一项用户调查,以了解用户的关注和看法。最后但并非最不重要的一点是,我们提出了一个风险评分系统,该系统分配了智能手机的分数,以基于精心加权的标准巩固我们的发现。通过此评分系统,用户可以根据有关在其Android设备上预先安装的应用程序的安全性和隐私影响的可用简洁信息做出自己的信任决策。
Android devices are equipped with many pre-installed applications which have the capability of tracking and monitoring users. Although applications coming pre-installed pose a great danger to user security and privacy, they have received little attention so far among researchers in the field. In this study, we collect a dataset comprising such applications and make it publicly available. Using this dataset, we analyze tracker SDKs, manifest files and the use of cloud services and report our results. We also conduct a user survey to understand concerns and perceptions of users. Last but not least, we present a risk scoring system which assigns scores for smart phones consolidating our findings based on carefully weighted criteria. With this scoring system, users could give their own trust decisions based on the available concise information about the security and privacy impacts of applications pre-installed on their Android devices.