A privacy enforcing framework for Android applications

被引:15
|
作者
Neisse, Ricardo [1 ]
Steri, Gary [1 ]
Geneiatakis, Dimitris [2 ]
Fovino, Igor Nai [1 ]
机构
[1] European Commiss, Joint Res Ctr, Via E Fermi 2749, Ispra, Italy
[2] Aristotle Univ Thessaloniki, Elect & Comp Engn Dept, GR-54124 Thessaloniki, Greece
关键词
Android; App instrumentation; Permission control; Policy enforcement; Privacy;
D O I
10.1016/j.cose.2016.07.005
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The widespread adoption of the Android operating system in a variety type of devices ranging from smart phones to smart TVs, makes it an interesting target for developers of malicious applications. One of the main flaws exploited by these developers is the permissions granting mechanism, which does not allow users to easily understand the privacy implications of the granted permissions. In this paper, we propose an approach to enforce fine-grained usage control privacy policies that enable users to control the access of applications to sensitive resources through application instrumentation. The purpose of this work is to enhance user control on privacy, confidentiality and security of their mobile devices, with regards to application intrusive behaviours. Our approach relies on instrumentation techniques and includes a refinement step where high-level resource-centric abstract policies defined by users are automatically refined to enforceable concrete policies. The abstract policies consider the resources being used and not the specific multiple concrete API methods that may allow an app to access the specific sensitive resources. For example, access to the user location may be done using multiple API methods that should be instrumented and controlled according to the user selected privacy policies. We show how our approach can be applied in Android applications and discuss performance implications under different scenarios. (C) 2016 The Authors. Published by Elsevier Ltd. This is an open access article under the CC BY-NC-ND license.
引用
收藏
页码:257 / 277
页数:21
相关论文
共 50 条
  • [31] Privacy and contextual integrity: Framework and applications
    Barth, Adam
    Datta, Anupam
    Mitchell, John C.
    Nissenbaum, Helen
    2006 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, PROCEEDINGS, 2006, : 184 - +
  • [32] Enforcing Privacy in Cloud Databases
    Moghadam, Somayeh Sobati
    Darmont, Jerome
    Gavin, Gerald
    BIG DATA ANALYTICS AND KNOWLEDGE DISCOVERY, DAWAK 2017, 2017, 10440 : 53 - 73
  • [33] Framework for Assessing Privacy of Internet Applications
    Coleman, James P. H.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2015, 6 (10) : 1 - 6
  • [34] A Dynamic Online Protection Framework for Android Applications
    Xu, Junfeng
    Zhou, Linna
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2018, 33 (05): : 361 - 368
  • [35] A Dynamic Online Protection Framework for Android Applications
    Xu, Junfeng
    Zhou, Linna
    COMPUTER SYSTEMS SCIENCE AND ENGINEERING, 2018, 33 (02): : 149 - 156
  • [36] Research on Personal Privacy Security Detection Techniques for Android Applications
    Tian, Ye
    Dai, Xin
    Li, Zhijun
    Guo, Hong
    Mao, Xiao
    Li, Yan
    2024 9TH INTERNATIONAL CONFERENCE ON ELECTRONIC TECHNOLOGY AND INFORMATION SCIENCE, ICETIS 2024, 2024, : 375 - 379
  • [37] State of the art on Privacy Risk Estimation Related to Android Applications
    El May, Zied
    Ben Ayed, Hella Kaffel
    Machfar, Dorra
    2019 15TH INTERNATIONAL WIRELESS COMMUNICATIONS & MOBILE COMPUTING CONFERENCE (IWCMC), 2019, : 889 - 894
  • [38] Analyzing Security and Privacy Risks in Android Video Game Applications
    Phaenthong, Ratiros
    Ngamsuriyaroj, Sudsanguan
    ADVANCED INFORMATION NETWORKING AND APPLICATIONS, VOL 6, AINA 2024, 2024, 204 : 307 - 319
  • [39] PlusApps: Towards a Privacy Risk Analysis for Android Plus Applications
    Alzahrani, Abdullah J.
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2020, 11 (11) : 684 - 693
  • [40] Container-Based Privacy Preserving Scheme for Android Applications
    Cui, Haoliang
    Shao, Shuai
    Niu, Shaozhang
    Zhang, Wen
    Yuan, Yang
    CHINESE JOURNAL OF ELECTRONICS, 2020, 29 (04) : 731 - 737