A Proactive Approach toward Privacy Risk Assessment for Android Apps Permissions

被引:0
|
作者
Hamed, Asma [1 ,2 ]
Kaffel-Ben Ayed, Hella [1 ,3 ]
Machfar, Dorra [3 ]
机构
[1] Univ Manouba, Natl Sch Comp Sci, CRISTAL Lab, Manouba, Tunisia
[2] Esprit Sch Engn, Tunis, Tunisia
[3] Univ Tunis El Manar, Fac Sci Tunis, Tunis, Tunisia
关键词
risk assessment; Android applications; Android permissions; privacy;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile devices store users' personal data. When mobile applications have access to this data they may leak it to third parties without users' consent. Google's Android platforms include a permission model that restricts applications' access to users' personal data. However, users are not aware of how their personal data would be used once applications are installed and permissions granted. This raises a potential privacy concern. In this paper we propose a proactive approach towards users' awareness of the privacy risk involved with granting permissions to Android applications. We present a dynamic privacy risk assessment model that assesses the risk to users' privacy associated to an application which requires a set of permissions. The parameters of this model are the severity and the relative importance of permissions and their interactions. Severity is evaluated according to a standard severity assessment method. The relative importance is estimated according to an analytic method. An experimental study to validate our proactive approach has been conducted. The originality of this works lies in that the privacy risk for a given device owned by an individual varies dynamically based on its different uses applications and related permissions.
引用
收藏
页码:1465 / 1470
页数:6
相关论文
共 50 条
  • [11] Quantitative Security Risk Assessment of Android Permissions and Applications
    Wang, Yang
    Zheng, Jun
    Sun, Chen
    Mukkamala, Srinivas
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXVII, 2013, 7964 : 226 - 241
  • [12] Privacy Assessment in Android Apps: A Systematic Mapping Study
    Del Alamo, Jose M.
    Guaman, Danny
    Balmori, Belen
    Diez, Ana
    ELECTRONICS, 2021, 10 (16)
  • [13] Runtime Permissions for Privacy in Proactive Intelligent Assistants
    Malkin, Nathan
    Wagner, David
    Egelman, Serge
    PROCEEDINGS OF THE EIGHTEENTH SYMPOSIUM ON USABLE PRIVACY AND SECURITY, SOUPS 2022, 2022, : 633 - 651
  • [14] Towards Improving Privacy Awareness Regarding Apps' Permissions
    Momen, Nurul
    Piekarska, Marta
    ICDS 2017: THE ELEVENTH INTERNATIONAL CONFERENCE ON DIGITAL SOCIETY, 2017, : 18 - 23
  • [15] FCDP: Fidelity Calculation for Description-to-Permissions in Android Apps
    Wu, Zhiqiang
    Chen, Xin
    Lee, Scott Uk-Jin
    IEEE ACCESS, 2021, 9 : 1062 - 1075
  • [16] Identifying malicious Android apps using permissions and system events
    Han, Hongmu
    Li, Ruixuan
    Gu, Xiwu
    INTERNATIONAL JOURNAL OF EMBEDDED SYSTEMS, 2016, 8 (01) : 46 - 58
  • [17] Privacy issues of android application permissions: A literature review
    Shrivastava, Gulshan
    Kumar, Prabhat
    Gupta, Deepak
    Rodrigues, Joel J. P. C.
    TRANSACTIONS ON EMERGING TELECOMMUNICATIONS TECHNOLOGIES, 2020, 31 (12):
  • [18] How Privacy Invasive Android Apps are?
    Kesswani, Nishtha
    Lin, Frank
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 3731 - 3734
  • [19] MOBILE APPS - USER AWARENESS ON PERMISSIONS, INFORMATION PRIVACY AND SECURITY
    Tutunea, Mihaela Filofteia
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY (IE 2017): EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2017, : 70 - 77
  • [20] Automated Detection and Repair of Incompatible Uses of Runtime Permissions in Android Apps
    Dilhara, Malinda
    Cai, Haipeng
    Jenkins, John
    2018 IEEE/ACM 5TH INTERNATIONAL CONFERENCE ON MOBILE SOFTWARE ENGINEERING AND SYSTEMS (MOBILESOFT), 2018, : 67 - 71