A privacy enforcing framework for Android applications

被引:15
|
作者
Neisse, Ricardo [1 ]
Steri, Gary [1 ]
Geneiatakis, Dimitris [2 ]
Fovino, Igor Nai [1 ]
机构
[1] European Commiss, Joint Res Ctr, Via E Fermi 2749, Ispra, Italy
[2] Aristotle Univ Thessaloniki, Elect & Comp Engn Dept, GR-54124 Thessaloniki, Greece
关键词
Android; App instrumentation; Permission control; Policy enforcement; Privacy;
D O I
10.1016/j.cose.2016.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The widespread adoption of the Android operating system in a variety type of devices ranging from smart phones to smart TVs, makes it an interesting target for developers of malicious applications. One of the main flaws exploited by these developers is the permissions granting mechanism, which does not allow users to easily understand the privacy implications of the granted permissions. In this paper, we propose an approach to enforce fine-grained usage control privacy policies that enable users to control the access of applications to sensitive resources through application instrumentation. The purpose of this work is to enhance user control on privacy, confidentiality and security of their mobile devices, with regards to application intrusive behaviours. Our approach relies on instrumentation techniques and includes a refinement step where high-level resource-centric abstract policies defined by users are automatically refined to enforceable concrete policies. The abstract policies consider the resources being used and not the specific multiple concrete API methods that may allow an app to access the specific sensitive resources. For example, access to the user location may be done using multiple API methods that should be instrumented and controlled according to the user selected privacy policies. We show how our approach can be applied in Android applications and discuss performance implications under different scenarios. (C) 2016 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license.
引用
收藏
页码:257 / 277
页数:21
相关论文
共 50 条
  • [1] An Analysis Framework for Information Loss and Privacy Leakage on Android Applications
    Yeh, Kuo-Hui
    Lo, Nai-Wei
    Fan, Chuan-Yen
    2014 IEEE 3RD GLOBAL CONFERENCE ON CONSUMER ELECTRONICS (GCCE), 2014, : 216 - 218
  • [2] A Framework for Major Stakeholders in Android Application Industry to Manage Privacy Policies of Android Applications
    Cha, Shi-Cho
    Shiung, Chuang-Ming
    Liu, Tzu-Ching
    Syu, Sih-Cing
    Chien, Li-Da
    Tsai, Tsung-Ying
    PRIVACY TECHNOLOGIES AND POLICY, APF 2016, 2016, 9857 : 153 - 170
  • [3] Privacy Protection Framework for Android
    Mishra, Bharavi
    Agarwal, Aastha
    Goel, Ayush
    Ansari, Aman Ahmad
    Gaur, Pramod
    Singh, Dilbag
    Lee, Heung-No
    IEEE ACCESS, 2022, 10 : 7973 - 7988
  • [4] A Privacy Enforcing Framework for Data Streams on the Edge
    Sedlak, Boris
    Murturi, Ilir
    Donta, Praveen Kumar
    Dustdar, Schahram
    IEEE TRANSACTIONS ON EMERGING TOPICS IN COMPUTING, 2024, 12 (03) : 852 - 863
  • [5] A Framework for Privacy Information Protection on Android
    Jia, Peng
    He, Xiang
    Liu, Liang
    Gu, Binjie
    Fang, Yong
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 1127 - 1131
  • [6] Privacy Consistency Analyzer for Android Applications
    Maitra, Sayan
    Suh, Bohyun
    Ghanavati, Sepideh
    2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 28 - 33
  • [7] A Privacy Enhanced Security Framework for Android Users
    Singh, Shirish Kumar
    Mishra, Bharavi
    Gera, Poonam
    2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,
  • [8] A Framework for Expressing and Enforcing Purpose-Based Privacy Policies
    Jafari, Mohammad
    Safavi-Naini, Reihaneh
    Fong, Philip W. L.
    Barker, Ken
    ACM TRANSACTIONS ON INFORMATION AND SYSTEM SECURITY, 2014, 17 (01)
  • [9] Examining the Privacy Vulnerability Level of Android Applications
    Kapitsaki, Georgia M.
    Ioannou, Modestos
    WEBIST: PROCEEDINGS OF THE 15TH INTERNATIONAL CONFERENCE ON WEB INFORMATION SYSTEMS AND TECHNOLOGIES, 2019, : 34 - 45
  • [10] PRADroid: Privacy Risk Assessment for Android Applications
    Yang, Yang
    Du, Xuehui
    Yang, Zhi
    2021 IEEE 5TH INTERNATIONAL CONFERENCE ON CRYPTOGRAPHY, SECURITY AND PRIVACY (ICCSP), 2021, : 90 - 95