A Proactive Approach toward Privacy Risk Assessment for Android Apps Permissions

被引:0
|
作者
Hamed, Asma [1 ,2 ]
Kaffel-Ben Ayed, Hella [1 ,3 ]
Machfar, Dorra [3 ]
机构
[1] Univ Manouba, Natl Sch Comp Sci, CRISTAL Lab, Manouba, Tunisia
[2] Esprit Sch Engn, Tunis, Tunisia
[3] Univ Tunis El Manar, Fac Sci Tunis, Tunis, Tunisia
关键词
risk assessment; Android applications; Android permissions; privacy;
D O I
暂无
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile devices store users' personal data. When mobile applications have access to this data they may leak it to third parties without users' consent. Google's Android platforms include a permission model that restricts applications' access to users' personal data. However, users are not aware of how their personal data would be used once applications are installed and permissions granted. This raises a potential privacy concern. In this paper we propose a proactive approach towards users' awareness of the privacy risk involved with granting permissions to Android applications. We present a dynamic privacy risk assessment model that assesses the risk to users' privacy associated to an application which requires a set of permissions. The parameters of this model are the severity and the relative importance of permissions and their interactions. Severity is evaluated according to a standard severity assessment method. The relative importance is estimated according to an analytic method. An experimental study to validate our proactive approach has been conducted. The originality of this works lies in that the privacy risk for a given device owned by an individual varies dynamically based on its different uses applications and related permissions.
引用
收藏
页码:1465 / 1470
页数:6
相关论文
共 50 条
  • [21] Analyzing Unnecessary Permissions Requested by Android Apps Based on Users' Opinions
    Kang, Jina
    Kim, Daehyun
    Kim, Hyoungshick
    Huh, Jun Ho
    INFORMATION SECURITY APPLICATIONS, WISA 2014, 2015, 8909 : 68 - 79
  • [22] Analysis of Security Permissions on Android and iOS from a Privacy Perspective
    Luna, Carlos
    Galuppo, Raul Ignacio
    2024 L LATIN AMERICAN COMPUTER CONFERENCE, CLEI 2024, 2024,
  • [23] PRADroid: Privacy Risk Assessment for Android Applications
    Yang, Yang
    Du, Xuehui
    Yang, Zhi
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 90 - 95
  • [24] Proactive Libraries: Enforcing Correct Behaviors in Android Apps
    Riganelli, Oliviero
    Fagadau, Ionut Daniel
    Micucci, Daniela
    Mariani, Leonardo
    2022 ACM/IEEE 44TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING: COMPANION PROCEEDINGS (ICSE-COMPANION 2022), 2022, : 159 - 163
  • [25] Enhancing Fidelity of Description in Android Apps With Category-Based Common Permissions
    Wu, Zhiqiang
    Chen, Xin
    Khan, Muhammad Umair
    Lee, Scott Uk-Jin
    IEEE ACCESS, 2021, 9 : 105493 - 105505
  • [26] Privacy Assurance for Android Augmented Reality Apps
    Zhang, Xueling
    Slavin, Rocky
    Wang, Xiaoyin
    Niu, Jianwei
    2019 IEEE 24TH PACIFIC RIM INTERNATIONAL SYMPOSIUM ON DEPENDABLE COMPUTING (PRDC 2019), 2019, : 114 - 115
  • [27] Enhancement on Privacy Permission Management for Android Apps
    Shinde, Supriya S.
    Sambare, Santosh S.
    2015 GLOBAL CONFERENCE ON COMMUNICATION TECHNOLOGIES (GCCT), 2015, : 819 - 823
  • [28] On the (Un)Reliability of Privacy Policies in Android Apps
    Verderame, Luca
    Caputo, Davide
    Romdhana, Andrea
    Merlo, Alessio
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [29] Privacy Risk Assessment for Web Tracking A user-oriented approach toward privacy risk assessment for Web tracking
    Hamed, Asma
    Ben Ayed, Hella Kaffel
    2016 IEEE CANADIAN CONFERENCE ON ELECTRICAL AND COMPUTER ENGINEERING (CCECE), 2016,
  • [30] Detecting over-claim permissions and recognising dangerous permission in Android apps
    Shah, Monika
    INTERNATIONAL JOURNAL OF INFORMATION AND COMPUTER SECURITY, 2022, 17 (1-2) : 204 - 218