An evaluation of smartphone communication (in)security

The purpose of this study is to examine and evaluate the security of the data traffic sent to and from smartphone devices. Since smartphones are becoming more common, are highly connected, often use cloud based computation, and contain highly personal data, it is important that the communication is...

Full description

Bibliographic Details
Main Author: Brodd-Reijer, Christoffer
Format: Others
Language:English
Published: Uppsala universitet, Institutionen för informationsteknologi 2014
Online Access:http://urn.kb.se/resolve?urn=urn:nbn:se:uu:diva-219069
id ndltd-UPSALLA1-oai-DiVA.org-uu-219069
record_format oai_dc
spelling ndltd-UPSALLA1-oai-DiVA.org-uu-2190692014-02-21T04:44:45ZAn evaluation of smartphone communication (in)securityengBrodd-Reijer, ChristofferUppsala universitet, Institutionen för informationsteknologi2014The purpose of this study is to examine and evaluate the security of the data traffic sent to and from smartphone devices. Since smartphones are becoming more common, are highly connected, often use cloud based computation, and contain highly personal data, it is important that the communication is secure and safe. This paper examines the Android and iOS platforms and focuses on three key parts: platform, application, and user. The platforms are evaluated on the basis of their libraries, APIs, and documentation; applications are evaluated using static code analysis and manual traffic analysis; users are examined using a social experiment. Results show that about one in twenty applications leaks sensitive data, without any difference between platforms. While the platforms do a good job educating developers about security there are room for improvements. The paper also concludes that a non-insignificant share of users are inclined to bypass important security warnings which may expose their passwords to an attacker. Student thesisinfo:eu-repo/semantics/bachelorThesistexthttp://urn.kb.se/resolve?urn=urn:nbn:se:uu:diva-219069IT ; 14 014application/pdfinfo:eu-repo/semantics/openAccess
collection NDLTD
language English
format Others
sources NDLTD
description The purpose of this study is to examine and evaluate the security of the data traffic sent to and from smartphone devices. Since smartphones are becoming more common, are highly connected, often use cloud based computation, and contain highly personal data, it is important that the communication is secure and safe. This paper examines the Android and iOS platforms and focuses on three key parts: platform, application, and user. The platforms are evaluated on the basis of their libraries, APIs, and documentation; applications are evaluated using static code analysis and manual traffic analysis; users are examined using a social experiment. Results show that about one in twenty applications leaks sensitive data, without any difference between platforms. While the platforms do a good job educating developers about security there are room for improvements. The paper also concludes that a non-insignificant share of users are inclined to bypass important security warnings which may expose their passwords to an attacker.
author Brodd-Reijer, Christoffer
spellingShingle Brodd-Reijer, Christoffer
An evaluation of smartphone communication (in)security
author_facet Brodd-Reijer, Christoffer
author_sort Brodd-Reijer, Christoffer
title An evaluation of smartphone communication (in)security
title_short An evaluation of smartphone communication (in)security
title_full An evaluation of smartphone communication (in)security
title_fullStr An evaluation of smartphone communication (in)security
title_full_unstemmed An evaluation of smartphone communication (in)security
title_sort evaluation of smartphone communication (in)security
publisher Uppsala universitet, Institutionen för informationsteknologi
publishDate 2014
url http://urn.kb.se/resolve?urn=urn:nbn:se:uu:diva-219069
work_keys_str_mv AT broddreijerchristoffer anevaluationofsmartphonecommunicationinsecurity
AT broddreijerchristoffer evaluationofsmartphonecommunicationinsecurity
_version_ 1716648161008680960