An Economic Study of the Effect of Android Platform Fragmentation on Security Updates

12/21/2017
by   Sadegh Farhang, et al.
0

Vendors in the Android ecosystem typically customize their devices by modifying Android Open Source Project (AOSP) code, adding in-house developed proprietary software, and pre-installing third-party applications. However, research has documented how various security problems are associated with this customization process. We develop a model of the Android ecosystem utilizing the concepts of game theory and product differentiation to capture the competition involving two vendors customizing the AOSP platform. We show how the vendors are incentivized to differentiate their products from AOSP and from each other, and how prices are shaped through this differentiation process. We also consider two types of consumers: security-conscious consumers who understand and care about security, and naïve consumers who lack the ability to correctly evaluate security properties of vendor-supplied Android products or simply ignore security. It is evident that vendors shirk on security investments in the latter case. Regulators such as the U.S. Federal Trade Commission have sanctioned Android vendors for underinvestment in security, but the exact effects of these sanctions are difficult to disentangle with empirical data. Here, we model the impact of a regulator-imposed fine that incentivizes vendors to match a minimum security standard. Interestingly, we show how product prices will decrease for the same cost of customization in the presence of a fine, or a higher level of regulator-imposed minimum security.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
02/22/2020

An Empirical Study of Android Security Bulletins in Different Vendors

Mobile devices encroach on almost every part of our lives, including wor...
research
06/24/2019

Mapping System Level Behaviors with Android APIs via System Call Dependence Graphs

Due to Android's open source feature and low barriers to entry for devel...
research
05/07/2019

An Analysis of Pre-installed Android Software

The open-source nature of the Android OS makes it possible for manufactu...
research
09/04/2012

Security Issues in the Android Cross-Layer Architecture

The security of Android has been recently challenged by the discovery of...
research
06/03/2019

Evolutionary Fuzzing of Android OS Vendor System Services

Android devices are shipped in several flavors by more than 100 manufact...
research
04/11/2019

The Android Platform Security Model

Android is the most widely deployed end-user focused operating system. W...
research
10/11/2021

Towards a Principled Approach for Dynamic Analysis of Android's Middleware

The Android middleware, in particular the so-called systemserver, is a c...

Please sign up or login with your details

Forgot password? Click here to reset