An Empirical Study of Android Security Bulletins in Different Vendors

An Empirical Study of Android Security Bulletins in Different Vendors
复制标题

DOI:
10.1145/3366423.3380078
复制
发表时间:
2020-02
期刊:
Proceedings of The Web Conference 2020
影响因子:
--
通讯作者:
Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags
Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags
中科院分区:
其他
文献类型:
--
作者:
Sadegh Farhang;Mehmet Bahadir Kirdan;Aron Laszka;Jens Grossklags

文献摘要

被引文献

相似文献

移动的设备几乎侵占了我们生活的每一个部分,包括工作和休闲,并包含了丰富的个人和敏感信息。因此,这些设备必须坚持高安全标准。一个关键方面是底层操作系统的安全性。特别是,Android扮演着至关重要的角色,因为它是移动的生态系统中最占主导地位的平台,拥有超过10亿台活跃设备,并且由于其开放性,允许供应商采用和定制它。与其他平台类似,Android通过每月提供安全补丁并通过Android安全公告来维护安全。为了在整个Android生态系统中成功地吸收这些信息,需要许多不同供应商的完美协调。在本文中,我们对3,171个与Android相关的漏洞进行了全面研究,并研究了它们在Android安全公告以及三星,LG和华为三家领先供应商的安全公告中的反映程度。在我们的分析中,我们关注这些安全公告的元数据(例如,时间、受影响的层、严重性和CWE数据),以更好地了解供应商之间的相似性和差异。我们发现,(i)Android生态系统中的研究供应商采用了不同的漏洞报告结构,(ii)供应商不太可能对具有Android Git存储库引用的CVE延迟做出反应,(iii)供应商处理高通相关的CVE不同于其他外部层CVE。
Mobile devices encroach on almost every part of our lives, including work and leisure, and contain a wealth of personal and sensitive information. It is, therefore, imperative that these devices uphold high security standards. A key aspect is the security of the underlying operating system. In particular, Android plays a critical role due to being the most dominant platform in the mobile ecosystem with more than one billion active devices and due to its openness, which allows vendors to adopt and customize it. Similar to other platforms, Android maintains security by providing monthly security patches and announcing them via the Android security bulletin. To absorb this information successfully across the Android ecosystem, impeccable coordination by many different vendors is required. In this paper, we perform a comprehensive study of 3,171 Android-related vulnerabilities and study to which degree they are reflected in the Android security bulletin, as well as in the security bulletins of three leading vendors: Samsung, LG, and Huawei. In our analysis, we focus on the metadata of these security bulletins (e.g., timing, affected layers, severity, and CWE data) to better understand the similarities and differences among vendors. We find that (i) the studied vendors in the Android ecosystem have adopted different structures for vulnerability reporting, (ii) vendors are less likely to react with delay for CVEs with Android Git repository references, (iii) vendors handle Qualcomm-related CVEs different from the rest of external layer CVEs.