Deploying Android Security Updates: an Extensive Study Involving Manufacturers, Carriers, and End Users

Deploying Android Security Updates: an Extensive Study Involving Manufacturers, Carriers, and End Users
复制标题

DOI:
10.1145/3372297.3423346
复制
发表时间:
2020-10
期刊:
Proceedings of the 2020 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas
Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas
中科院分区:
其他
文献类型:
--
作者:
Kailani R. Jones;T. Yen;S. C. Sundaramurthy;Alexandru G. Bardas

文献摘要

被引文献

相似文献

Android分散的生态系统使得安全更新和操作系统升级的交付变得繁琐和复杂。虽然谷歌发起了各种项目,如Android One,Project Treble和Project Mainline来解决这个问题,但其他相关实体(例如,芯片组供应商、制造商、运营商)不断地努力改进他们的过程,但是仍然不清楚这些努力在向所支持的最终用户设备交付更新方面的有效性。在本文中,我们进行了广泛的定量研究(2015年8月至2019年12月),以衡量Android安全更新和操作系统升级的推出过程。我们的研究利用了多个数据源:Android开源项目(AOSP)、设备制造商和美国四大运营商(AT&T、Verizon、T-Mobile和Sprint)。此外,我们分析了2019年从美国捕获的最终用户数据集(与910万唯一用户标识符相关联的1.52亿匿名HTTP请求)。基于社交网络。我们的研究结果包括独特的测量,由于分散和不一致的生态系统,以前很难执行。例如,制造商和运营商在推出安全更新之前引入了24天的中位延迟,在终端设备更新之前还增加了11天的中位延迟。我们发现,这些值改变每个运营商制造商的关系,但不改变很大的模型的年龄。我们的研究结果还深入研究了当前Android项目的有效性。例如,Treble设备的安全更新比非Treble设备平均快7天。虽然这是一个改进,但Treble设备的安全更新延迟仍然平均为19天。
Android's fragmented ecosystem makes the delivery of security updates and OS upgrades cumbersome and complex. While Google initiated various projects such as Android One, Project Treble, and Project Mainline to address this problem, and other involved entities (e.g., chipset vendors, manufacturers, carriers) continuously strive to improve their processes, it is still unclear how effective these efforts are on the delivery of updates to supported end-user devices. In this paper, we perform an extensive quantitative study (Aug. 2015 to Dec. 2019) to measure the Android security updates and OS upgrades rollout process. Our study leverages multiple data sources: the Android Open Source Project (AOSP), device manufacturers, and the top four U.S. carriers (AT&T, Verizon, T-Mobile, and Sprint). Furthermore, we analyze an end-user dataset captured in 2019 (152M anonymized HTTP requests associated with 9.1M unique user identifiers) from a U.S.-based social network. Our findings include unique measurements that, due to the fragmented and inconsistent ecosystem, were previously challenging to perform. For example, manufacturers and carriers introduce a median latency of 24 days before rolling out security updates, with an additional median delay of 11 days before end devices update. We show that these values alter per carrier-manufacturer relationship, yet do not alter greatly based on a model's age. Our results also delve into the effectiveness of current Android projects. For instance, security updates for Treble devices are available on average 7 days faster than for non-Treble devices. While this constitutes an improvement, the security update delay for Treble devices still averages 19 days.