An Analysis of Pre-installed Android Software

05/07/2019
by   Julien Gamba, et al.
0

The open-source nature of the Android OS makes it possible for manufacturers to ship custom versions of the OS along with a set of pre-installed apps, often for product differentiation. Some device vendors have recently come under scrutiny for potentially invasive private data collection practices and other potentially harmful or unwanted behavior of the pre-installed apps on their devices. Yet, the landscape of pre-installed software in Android has largely remained unexplored, particularly in terms of the security and privacy implications of such customizations. In this paper, we present the first large-scale study of pre-installed software on Android devices from more than 200 vendors. Our work relies on a large dataset of real-world Android firmware acquired worldwide using crowd-sourcing methods. This allows us to answer questions related to the stakeholders involved in the supply chain, from device manufacturers and mobile network operators to third-party organizations like advertising and tracking services, and social network platforms. Our study allows us to also uncover relationships between these actors, which seem to revolve primarily around advertising and data-driven services. Overall, the supply chain around Android's open source model lacks transparency and has facilitated potentially harmful behaviors and backdoored access to sensitive data and services without user consent or awareness. We conclude the paper with recommendations to improve transparency, attribution, and accountability in the Android ecosystem.

READ FULL TEXT

page 7

page 8

research
12/13/2021

FirmwareDroid: Security Analysis of the Android Firmware EcoSystem

The Android Open Source Project (AOSP) is probably the most used and cus...
research
06/24/2019

Mapping System Level Behaviors with Android APIs via System Call Dependence Graphs

Due to Android's open source feature and low barriers to entry for devel...
research
02/20/2013

Capturing Information Flows inside Android and Qemu Environments

The smartphone market has grown so wide that it assumed a strategic rele...
research
12/21/2017

An Economic Study of the Effect of Android Platform Fragmentation on Security Updates

Vendors in the Android ecosystem typically customize their devices by mo...
research
09/08/2021

A Case Study of Intra-library Privacy Issues on Android GPS Navigation Apps

The Android unrestricted application market, being of open source nature...
research
09/26/2022

Device Tracking via Linux's New TCP Source Port Selection Algorithm (Extended Version)

We describe a tracking technique for Linux devices, exploiting a new TCP...
research
09/21/2022

Android Private Compute Core Architecture

Android's Private Compute Core (PCC) is a secure, isolated environment w...

Please sign up or login with your details

Forgot password? Click here to reset