AN INVESTIGATION INTO KNOWLEDGE LEVELS OF USERS ON MOBILE SECURITY
By Ongezwa Mtshikilo
Student No: 207097410
Research article submitted in partial fulfilment of the requirements for the degree
Bachelor of Technology
In
Information Technology
in the Faculty of Informatics & Design
at the Cape Peninsula University of Technology
Supervisor: Dr. A. de la Harpe
Cape Town
October 2014
Page | 1
Abstract
The invention of mobile devices was received with much enthusiasm by the global population.
Since then, its use has grown very tremendously with sensitive tasks such as monetary
transactions, storage and transfer of valuable data being performed on these mobile devices.
Unfortunately, this invention has lately come under increasing attacks by cyber criminals
especially on Android OS. There is no adequate data on user’s knowledge on mobile security
and it is unclear whether users are aware of the security risks and possible prevention
measures.
The aim was to determine mobile user understanding of the security threats affecting their
mobile devices.
This was a qualitative cross sectional survey in which 30 participants were randomly selected
from the Cape Town larger population. A questionnaire with mostly structured questions was
used to obtain data from participants. Data was captured on an excel spreadsheet, coded and
categorized into themes for analysis.
Our data shows that even though a majority of mobile users are aware of risks targeting the
mobile devices, the range of activities to which they put their devices raises their security risk
since most users don’t use appropriate protective measures.
Keywords: Mobile Security, Mobile attacks, security awareness, mobile society, anti-virus,
mobile connectivity.
Introduction
Mobile technology is the technology used for cellular communication. It is almost half
a century since the introduction of this technology, initially as basic form of
communication using first generation devices. Motorola is known to have made the
first mobile telephone. However, the first call made from handheld subscriber
equipment was in the 1970s (Wakefield et al., 2012; Goodwin, 2013). This
technology was received with great excitement and its use has increased
tremendously. The technology has further evolved to include other handheld devices
such as laptops and iPads. The basic nature of the original devices at the time did
not subject them to current mobile security risk.
The evolution of mobile technology has since then been prone to invasion from
criminal activities commonly referred to as cyber-crime. Cyber-crime has been
associated with the nature of sophistication with which the devices are made. These
devices today have been made to perform a wide range of activities including storage
of sensitive information as well performing financial transactions. Such information
has been a centre of attraction of criminals to illegally gain access into people’s
mobile devices or systems.
On one hand, due to the increasing security risk on mobile devices, manufacturers
are trying to institute risk reduction measures such as use of anti-virus, anti-malware,
activation of firewalls on devices. Furthermore, individual device owners have been
encouraged to use passwords to access their devices as well as encrypting data so
that it cannot be illegally consumed. On the other hand, criminals are also coming up
with sophisticated techniques in order to beat manufacturers’ security measures.
Page | 2
Because of the very significant roles these devices play, their use has increased
amongst the global population. However, the mobile security knowledge level of
mobile device owners is questionable.
Background to Research Problem
The invention of mobile devices was received with much enthusiasm by the global
population (Safavi et al, 2013). This is because of the ease of performing tasks which
would have otherwise posed a challenge without mobile technology. Since then, its
use worldwide has grown very fast. Sensitive tasks including monetary transactions,
storage and transfer of valuable data are all conducted using these devices over a
network (Tu & Yuan, 2012). Unfortunately, this invention has lately come under
increasing attacks by cyber criminals especially on Android as compared to Apple’s
IOS devices (Saidi & Gehani, 2013). A study conducted by Gendro (2014) further
shows that android devices are the most affected and targeted devices. Data from
various sources shows that companies both locally and internationally are fighting a
battle as these cyber criminals seem to keep pace with current technology (Herhalt,
2011; KPMG International Cooperative, 2013; The Institute for Security Studies
(ISS), 2014).
There is not adequate available data on user’s knowledge on mobile security, hence,
it is unclear whether users are aware of the security risks faced by this important
technology and the possible prevention modalities. Mobile security can be improved
if users (individuals and organizations) exercise caution of safe guarding device(s) by
means of implementing security control to prevent hackers from tempering with their
personal and sensitive data in cases where user accesses network applications such
as social application, online banking services and in case the device gets lost or
stolen. Evidence has shown that a majority of mobile users are not aware of the
security risks facing these applications and hence some share passwords as well as
logging into insecure sites (Mylonas et al., 2013). This increases the risk of
unauthorized access to their private information by cyber criminals (Mylonas et al.,
2013).
Research Problem
Mobile users are not aware that their mobile devices are susceptible to many security
threats that can cause various types of damages. This damage can range from minor
functional errors to significant destruction of databases and computer centres.
Research objective
The aim of this study was to explore the mobile user understanding of the security
threats affecting their mobile devices so that preventative measures against mobile
attacks could be suggest. This study will benefit mobile device owners, it will serve as
an eye opener to those that are not aware of the security risks their mobile device(s)
are prone to.
Underlying the above aim are the following objectives:
1. To assess mobile user awareness of common security risks.
2. To assess frequently performed activities on the mobile user’s device(s).
3. To identify common security risks faced by mobile device users.
4. To determine the type of data stored on the user’s mobile device(s).
5. To suggest preventative measures against mobile attacks.
Research Question
Numerous factors are associated with increased mobile security risk. The risk
vulnerability is further heightened by the level to which the devices are put. Hence
questions in this study have been formulated in such a way that they gather data on
user knowledge on mobile security risk. The questions are as follows:
Research Question 1: What is the knowledge level of mobile device users about
security risks?
Research Sub Question 1.1: What are some of the security risks faced by
mobile users?
Research Sub Question 1.2: What kind of information is stored on user’s
devices?
Research Sub Question 1.3 What user factors contribute to mobile attacks?
Research Question 2: How can mobile users protect information on their
mobile devices?