A Framework for Major Stakeholders in Android Application Industry to Manage Privacy Policies of Android Applications

被引:1
|
作者
Cha, Shi-Cho [1 ]
Shiung, Chuang-Ming [2 ]
Liu, Tzu-Ching [1 ]
Syu, Sih-Cing [1 ]
Chien, Li-Da [1 ]
Tsai, Tsung-Ying [1 ]
机构
[1] Natl Taiwan Univ Sci & Technol, Dept Informat Management, Taipei, Taiwan
[2] Criminal Invest Bur, Taipei, Taiwan
来源
关键词
D O I
10.1007/978-3-319-44760-5_10
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
As Android's permission-based system cannot fulfill the requirements of personal data protection, several countries around the world are requesting application developers to provide privacy policies for their applications. To address the issue, this study proposes a framework to Manage Privacy Policies of Android Applications (MaPPA). MaPPA provides standard format for application providers to present privacy policies in machine processable format and to embed the policies into applications. Application verifiers or marketplace providers can then verify whether an application complies with embedded privacy policies and envelop verification reports in the application. Therefore, users can extract privacy policies and verification reports from applications directly. Compared to providing URL links to privacy policies in marketplaces, the proposed framework can reduce the cost for application developers to maintain additional servers to provide privacy policies. Moreover, application users can obtain verification reports in an application to comfirm the consistency between privacy policies and application behavior. In light of this, the study can hopefully solve current problems of privacy policy notification for Android applications.
引用
收藏
页码:153 / 170
页数:18
相关论文
共 50 条
  • [1] A privacy enforcing framework for Android applications
    Neisse, Ricardo
    Steri, Gary
    Geneiatakis, Dimitris
    Fovino, Igor Nai
    COMPUTERS & SECURITY, 2016, 62 : 257 - 277
  • [2] Longitudinal Compliance Analysis of Android Applications with Privacy Policies
    Hashmi, Saad Sajid
    Waheed, Nazar
    Tangari, Gioacchino
    Ikram, Muhammad
    Smith, Stephen
    MOBILE AND UBIQUITOUS SYSTEMS: COMPUTING, NETWORKING AND SERVICES, 2022, 419 : 280 - 305
  • [3] Privacy Protection Framework for Android
    Mishra, Bharavi
    Agarwal, Aastha
    Goel, Ayush
    Ansari, Aman Ahmad
    Gaur, Pramod
    Singh, Dilbag
    Lee, Heung-No
    IEEE ACCESS, 2022, 10 : 7973 - 7988
  • [4] An Analysis Framework for Information Loss and Privacy Leakage on Android Applications
    Yeh, Kuo-Hui
    Lo, Nai-Wei
    Fan, Chuan-Yen
    2014 IEEE 3RD GLOBAL CONFERENCE ON CONSUMER ELECTRONICS (GCCE), 2014, : 216 - 218
  • [5] Exposing Android social applications: linking data leakage to privacy policies
    Krych, Daniel E.
    McDaniel, Patrick
    Journal of Cyber Security Technology, 2021, 5 (3-4) : 139 - 190
  • [6] A Framework for Privacy Information Protection on Android
    Jia, Peng
    He, Xiang
    Liu, Liang
    Gu, Binjie
    Fang, Yong
    2015 INTERNATIONAL CONFERENCE ON COMPUTING, NETWORKING AND COMMUNICATIONS (ICNC), 2015, : 1127 - 1131
  • [7] On the (Un)Reliability of Privacy Policies in Android Apps
    Verderame, Luca
    Caputo, Davide
    Romdhana, Andrea
    Merlo, Alessio
    2020 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2020,
  • [8] Privacy Consistency Analyzer for Android Applications
    Maitra, Sayan
    Suh, Bohyun
    Ghanavati, Sepideh
    2018 IEEE 5TH INTERNATIONAL WORKSHOP ON EVOLVING SECURITY & PRIVACY REQUIREMENTS ENGINEERING (ESPRE 2018), 2018, : 28 - 33
  • [9] Toward a Framework for Detecting Privacy Policy Violations in Android Application Code
    Slavin, Rocky
    Wang, Xiaoyin
    Hosseini, Mitra Bokaei
    Hester, James
    Krishnan, Ram
    Bhatia, Jaspreet
    Breaux, Travis D.
    Niu, Jianwei
    2016 IEEE/ACM 38TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING (ICSE), 2016, : 25 - 36
  • [10] A Privacy Enhanced Security Framework for Android Users
    Singh, Shirish Kumar
    Mishra, Bharavi
    Gera, Poonam
    2015 5TH INTERNATIONAL CONFERENCE ON IT CONVERGENCE AND SECURITY (ICITCS), 2015,