<?xml version="1.0" encoding="ISO-8859-1"?><article xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance">
<front>
<journal-meta>
<journal-id>0121-1129</journal-id>
<journal-title><![CDATA[Revista Facultad de Ingeniería]]></journal-title>
<abbrev-journal-title><![CDATA[Rev. Fac. ing.]]></abbrev-journal-title>
<issn>0121-1129</issn>
<publisher>
<publisher-name><![CDATA[Universidad Pedagógica y Tecnológica de Colombia]]></publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id>S0121-11292022000100201</article-id>
<article-id pub-id-type="doi">10.19053/01211129.v31.n59.2022.13957</article-id>
<title-group>
<article-title xml:lang="en"><![CDATA[Information Management Security Vulnerabilities in Smartphones Used by University Students: A Case Study in the Southwest of Colombia]]></article-title>
<article-title xml:lang="es"><![CDATA[Vulnerabilidades de seguridad en la gestión de la información en teléfonos inteligentes utilizados por estudiantes universitarios: Un estudio de caso en el suroeste de Colombia]]></article-title>
<article-title xml:lang="pt"><![CDATA[Vulnerabilidades de segurança na gestão da informação em smartphones usados por estudantes universitários: Um estudo de caso no sudoeste da Colômbia]]></article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Ordoñez-Quintero]]></surname>
<given-names><![CDATA[Cristian-Camilo]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Ordoñez-Eraso]]></surname>
<given-names><![CDATA[Hugo-Armando]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
<contrib contrib-type="author">
<name>
<surname><![CDATA[Ordoñez-Córdoba]]></surname>
<given-names><![CDATA[Jose-Armando]]></given-names>
</name>
<xref ref-type="aff" rid="Aff"/>
</contrib>
</contrib-group>
<aff id="Af1">
<institution><![CDATA[,Fundación Universitaria de Popayán  ]]></institution>
<addr-line><![CDATA[Popayán Cauca]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af2">
<institution><![CDATA[,Universidad del Cauca  ]]></institution>
<addr-line><![CDATA[Popayán Cauca]]></addr-line>
<country>Colombia</country>
</aff>
<aff id="Af3">
<institution><![CDATA[,Universidad del Cauca  ]]></institution>
<addr-line><![CDATA[Popayán Cauca]]></addr-line>
<country>Colombia</country>
</aff>
<pub-date pub-type="pub">
<day>00</day>
<month>03</month>
<year>2022</year>
</pub-date>
<pub-date pub-type="epub">
<day>00</day>
<month>03</month>
<year>2022</year>
</pub-date>
<volume>31</volume>
<numero>59</numero>
<copyright-statement/>
<copyright-year/>
<self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_arttext&amp;pid=S0121-11292022000100201&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_abstract&amp;pid=S0121-11292022000100201&amp;lng=en&amp;nrm=iso"></self-uri><self-uri xlink:href="http://www.scielo.org.co/scielo.php?script=sci_pdf&amp;pid=S0121-11292022000100201&amp;lng=en&amp;nrm=iso"></self-uri><abstract abstract-type="short" xml:lang="en"><p><![CDATA[Abstract Currently, students who use smartphones are affected by theft and information leakage, to address this problem, this research aims to identify security vulnerabilities in these devices. In addition, an application to prevent phishing and information leakage was implemented. Effectiveness and performance tests were carried out to identify vulnerabilities and to alert users about them. The threats identified in Android smartphones used by university students in the southwest of Colombia were based on various techniques (phishing, DNS poisoning, identity theft, Man in the middle, foot-printing, spyware). To reach this result, we defined the problem, then we made a literature review, after that we defined the study population, methods, and instruments; finally, we collected the information and analyzed the results. An application was launched to show the security vulnerabilities of malicious software installation, which extracts information from student&#8217;s devices and makes the security of our mobile phones a priority nowadays; and to achieve greater security on Android smartphones. However, it is essential to be aware of the importance of self-care.]]></p></abstract>
<abstract abstract-type="short" xml:lang="es"><p><![CDATA[Resumen Actualmente, los estudiantes que utilizan teléfonos inteligentes se ven afectados por el robo y la fuga de información, para abordar este problema, esta investigación tiene como objetivo identificar las vulnerabilidades de seguridad en estos dispositivos. Además, se implementó una aplicación para prevenir el phishing y la fuga de información. Se realizaron pruebas de efectividad y rendimiento para identificar vulnerabilidades y alertar a los usuarios sobre las mismas. Las amenazas identificadas en los teléfonos inteligentes Android utilizados por estudiantes universitarios del suroeste de Colombia se basaron en diversas técnicas (phishing, envenenamiento de DNS, robo de identidad, Man in the middle, foot-printing, spyware). Para llegar a este resultado, definimos el problema, luego hicimos una revisión de la literatura, luego definimos la población de estudio, métodos e instrumentos; finalmente, recolectamos la información y analizamos los resultados. Se lanzó una aplicación para mostrar las vulnerabilidades de seguridad de la instalación de software malicioso, que extrae información de los dispositivos de los estudiantes y hace que la seguridad de nuestros teléfonos móviles sea una prioridad en la actualidad; y para conseguir una mayor seguridad en los smartphones Android. Sin embargo, es fundamental ser conscientes de la importancia del autocuidado.]]></p></abstract>
<abstract abstract-type="short" xml:lang="pt"><p><![CDATA[Resumo Atualmente, os alunos que utilizam smartphones são acometidos por furtos e vazamento de informações, para solucionar esse problema, esta pesquisa tem como objetivo identificar vulnerabilidades de segurança nesses dispositivos. Além disso, foi implementado um aplicativo para evitar phishing e vazamento de informações. Foram realizados testes de eficácia e desempenho para identificar vulnerabilidades e alertar os usuários sobre elas. As ameaças identificadas em smartphones Android usados &#8203;&#8203;por estudantes universitários no sudoeste da Colômbia foram baseadas em várias técnicas (phishing, envenenamento de DNS, roubo de identidade, Man in the middle, foot-printing, spyware). Para chegar a esse resultado, definimos o problema, em seguida fizemos uma revisão de literatura, em seguida definimos a população do estudo, métodos e instrumentos; finalmente, coletamos as informações e analisamos os resultados. Foi lançado um aplicativo para mostrar as vulnerabilidades de segurança da instalação de software malicioso, que extrai informações dos dispositivos dos alunos e torna a segurança de nossos celulares uma prioridade nos dias de hoje; e para obter maior segurança em smartphones Android. No entanto, é fundamental ter consciência da importância do autocuidado.]]></p></abstract>
<kwd-group>
<kwd lng="en"><![CDATA[android]]></kwd>
<kwd lng="en"><![CDATA[information leak]]></kwd>
<kwd lng="en"><![CDATA[mobile devices]]></kwd>
<kwd lng="en"><![CDATA[phishing]]></kwd>
<kwd lng="en"><![CDATA[vulnerabilities]]></kwd>
<kwd lng="es"><![CDATA[androide]]></kwd>
<kwd lng="es"><![CDATA[dispositivos móviles]]></kwd>
<kwd lng="es"><![CDATA[fuga de información]]></kwd>
<kwd lng="es"><![CDATA[suplantación de identidad]]></kwd>
<kwd lng="es"><![CDATA[vulnerabilidades]]></kwd>
<kwd lng="pt"><![CDATA[andróide]]></kwd>
<kwd lng="pt"><![CDATA[dispositivos móveis]]></kwd>
<kwd lng="pt"><![CDATA[phishing]]></kwd>
<kwd lng="pt"><![CDATA[vazamento de informações]]></kwd>
<kwd lng="pt"><![CDATA[vulnerabilidades]]></kwd>
</kwd-group>
</article-meta>
</front><back>
<ref-list>
<ref id="B1">
<label>[1]</label><nlm-citation citation-type="book">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Valero]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
</person-group>
<source><![CDATA[Consumo móvil en Colombia]]></source>
<year>2018</year>
<publisher-name><![CDATA[Deloitte]]></publisher-name>
</nlm-citation>
</ref>
<ref id="B2">
<label>[2]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Álzate]]></surname>
<given-names><![CDATA[W. C.]]></given-names>
</name>
<name>
<surname><![CDATA[Romaña]]></surname>
<given-names><![CDATA[C. S.]]></given-names>
</name>
<name>
<surname><![CDATA[Barco]]></surname>
<given-names><![CDATA[Y. Q.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Factores y causas de la fuga de información sensibles en el sector empresarial]]></article-title>
<source><![CDATA[Cuaderno Activa]]></source>
<year>2016</year>
<volume>7</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>67-73</page-range></nlm-citation>
</ref>
<ref id="B3">
<label>[3]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Maya]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[El cibercrimen y sus efectos en la teoría de la tipicidad: de una realidad física a una realidad virtual]]></article-title>
<source><![CDATA[Nuevo Foro Penal]]></source>
<year>2017</year>
<volume>13</volume>
<page-range>72-112</page-range></nlm-citation>
</ref>
<ref id="B4">
<label>[4]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Calpa]]></surname>
<given-names><![CDATA[A. C. Silva]]></given-names>
</name>
<name>
<surname><![CDATA[Delgado]]></surname>
<given-names><![CDATA[D. G. Martínez]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Influencia del Smartphone en los procesos de aprendizaje y enseñanza]]></article-title>
<source><![CDATA[Suma Negocios]]></source>
<year>2017</year>
<volume>8</volume>
<numero>17</numero>
<issue>17</issue>
<page-range>11-8</page-range></nlm-citation>
</ref>
<ref id="B5">
<label>[5]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Razgallah]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Khoury]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Hallé]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Khanmohammadi]]></surname>
<given-names><![CDATA[K]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A survey of malware detection in Android apps: Recommendations and perspectives for future research]]></article-title>
<source><![CDATA[Computer Science Review]]></source>
<year>2021</year>
<volume>39</volume>
</nlm-citation>
</ref>
<ref id="B6">
<label>[6]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Gao]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
<name>
<surname><![CDATA[Cheng]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[Zhang]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[GDroid: Android malware detection and classification with graph convolutional network]]></article-title>
<source><![CDATA[Computers &amp; Security]]></source>
<year>2021</year>
<volume>106</volume>
</nlm-citation>
</ref>
<ref id="B7">
<label>[7]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Zhang]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
<name>
<surname><![CDATA[Tan]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Yang]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Li]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Deep learning feature exploration for Android malware detection]]></article-title>
<source><![CDATA[Applied Soft Computing]]></source>
<year>2021</year>
<volume>102</volume>
<page-range>107069</page-range></nlm-citation>
</ref>
<ref id="B8">
<label>[8]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Kinkead]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
<name>
<surname><![CDATA[Millar]]></surname>
<given-names><![CDATA[S]]></given-names>
</name>
<name>
<surname><![CDATA[McLaughlin]]></surname>
<given-names><![CDATA[N]]></given-names>
</name>
<name>
<surname><![CDATA[O&#8217;Kane]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Towards Explainable CNNs for Android Malware Detection]]></article-title>
<source><![CDATA[Procedia Computer Science]]></source>
<year>2021</year>
<volume>184</volume>
<page-range>959-65</page-range></nlm-citation>
</ref>
<ref id="B9">
<label>[9]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Igarashi]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[DREBIN: Effective and Explainable Detection of Android Malware in Your Pocket]]></article-title>
<source><![CDATA[The Journal of Japanese Studies]]></source>
<year>2009</year>
<volume>36</volume>
<numero>1</numero>
<issue>1</issue>
<page-range>165-9</page-range></nlm-citation>
</ref>
<ref id="B10">
<label>[10]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Wang]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
<name>
<surname><![CDATA[Xu]]></surname>
<given-names><![CDATA[G]]></given-names>
</name>
<name>
<surname><![CDATA[Liu]]></surname>
<given-names><![CDATA[X]]></given-names>
</name>
<name>
<surname><![CDATA[Mao]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
<name>
<surname><![CDATA[Si]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Pedrycz]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
<name>
<surname><![CDATA[Wang]]></surname>
<given-names><![CDATA[W]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Identifying vulnerabilities of SSL/TLS certificate verification in Android apps with static and dynamic analysis]]></article-title>
<source><![CDATA[Journal of Systems and Software]]></source>
<year>2020</year>
<volume>167</volume>
</nlm-citation>
</ref>
<ref id="B11">
<label>[11]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Runeson]]></surname>
<given-names><![CDATA[P]]></given-names>
</name>
<name>
<surname><![CDATA[Höst]]></surname>
<given-names><![CDATA[M]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Guidelines for conducting and reporting case study research in software engineering]]></article-title>
<source><![CDATA[Empirical Software Engineering]]></source>
<year>2009</year>
<volume>14</volume>
<numero>2</numero>
<issue>2</issue>
</nlm-citation>
</ref>
<ref id="B12">
<label>[12]</label><nlm-citation citation-type="">
<collab>NIST</collab>
<source><![CDATA[Marco de Ciberseguridad del NIST]]></source>
<year>2019</year>
<page-range>1-9</page-range></nlm-citation>
</ref>
<ref id="B13">
<label>[13]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Alquraan]]></surname>
<given-names><![CDATA[R]]></given-names>
</name>
<name>
<surname><![CDATA[Hadi]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Atoum]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Al-Zewairi]]></surname>
<given-names><![CDATA[M.]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[Ultrasurf Traffic Classification: Detection and Prevention]]></article-title>
<source><![CDATA[International Journal of Communications, Network and System Sciences]]></source>
<year>2015</year>
<volume>8</volume>
<page-range>304-11</page-range></nlm-citation>
</ref>
<ref id="B14">
<label>[14]</label><nlm-citation citation-type="">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Howe]]></surname>
<given-names><![CDATA[D]]></given-names>
</name>
<name>
<surname><![CDATA[Nissenbaum]]></surname>
<given-names><![CDATA[H]]></given-names>
</name>
</person-group>
<source><![CDATA[Engineering Privacy and Protest: A Case Study of Ad Nauseam]]></source>
<year>2017</year>
</nlm-citation>
</ref>
<ref id="B15">
<label>[15]</label><nlm-citation citation-type="confpro">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Skendzic]]></surname>
<given-names><![CDATA[A]]></given-names>
</name>
<name>
<surname><![CDATA[Kova&#269;i&#263;]]></surname>
<given-names><![CDATA[B]]></given-names>
</name>
</person-group>
<source><![CDATA[Open source system OpenVPN in a function of Virtual Private Network]]></source>
<year>2017</year>
<volume>200</volume>
<conf-name><![CDATA[ IOP Conference Series: Materials Science and Engineering]]></conf-name>
<conf-loc> </conf-loc>
</nlm-citation>
</ref>
<ref id="B16">
<label>[16]</label><nlm-citation citation-type="journal">
<person-group person-group-type="author">
<name>
<surname><![CDATA[Dai]]></surname>
<given-names><![CDATA[J]]></given-names>
</name>
<name>
<surname><![CDATA[Chen]]></surname>
<given-names><![CDATA[C]]></given-names>
</name>
<name>
<surname><![CDATA[Li]]></surname>
<given-names><![CDATA[Y]]></given-names>
</name>
</person-group>
<article-title xml:lang=""><![CDATA[A Backdoor Attack Against LSTM-Based Text Classification Systems]]></article-title>
<source><![CDATA[IEEE Access]]></source>
<year>2019</year>
<volume>7</volume>
<page-range>138872-8</page-range></nlm-citation>
</ref>
</ref-list>
</back>
</article>
