Reducing Permission Requests in Mobile Apps

被引:16
|
作者
Peddinti, Sai Teja [1 ]
Bilogrevic, Igor [1 ]
Taft, Nina [1 ]
Pelikan, Martin [1 ]
Erlingsson, Ulfar [1 ]
Anthonysamy, Pauline [1 ]
Hogben, Giles [1 ]
机构
[1] Google Inc, Mountain View, CA 94043 USA
关键词
Mobile Apps; Permissions;
D O I
10.1145/3355369.3355584
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Users of mobile apps sometimes express discomfort or concerns with what they see as unnecessary or intrusive permission requests by certain apps. However encouraging mobile app developers to request fewer permissions is challenging because there are many reasons why permissions are requested; furthermore, prior work [25] has shown it is hard to disambiguate the purpose of a particular permission with high certainty. In this work we describe a novel, algorithmic mechanism intended to discourage mobile-app developers from asking for unnecessary permissions. Developers are incentivized by an automated alert, or "nudge", shown in the Google Play Console when their apps ask for permissions that are requested by very few functionally-similar apps-in other words, by their competition. Empirically, this incentive is effective, with significant developer response since its deployment. Permissions have been redacted by 59% of apps that were warned, and this attenuation has occurred broadly across both app categories and app popularity levels. Importantly, billions of users' app installs from the Google Play have benefited from these redactions.
引用
收藏
页码:259 / 266
页数:8
相关论文
共 50 条
  • [1] How do Apps Evolve in Their Permission Requests? A Preliminary Study
    Calciati, Paolo
    Gorla, Alessandra
    2017 IEEE/ACM 14TH INTERNATIONAL CONFERENCE ON MINING SOFTWARE REPOSITORIES (MSR 2017), 2017, : 37 - 41
  • [2] Understanding the Purpose of Permission Use in Mobile Apps
    Wang, Haoyu
    Li, Yuanchun
    Guo, Yao
    Agarwal, Yuvraj
    Hong, Jason I.
    ACM TRANSACTIONS ON INFORMATION SYSTEMS, 2017, 35 (04)
  • [3] Automatic permission inference for hybrid mobile apps
    Mao, Jian
    Ma, Hanjun
    Chen, Yue
    Jia, Yaoqi
    Liang, Zhenkai
    JOURNAL OF HIGH SPEED NETWORKS, 2016, 22 (01) : 55 - 64
  • [4] PerRec: A Permission Configuration Recommender System for Mobile Apps
    Cheng, Yanxiao
    Yan, Zheng
    ALGORITHMS AND ARCHITECTURES FOR PARALLEL PROCESSING, ICA3PP 2017, 2017, 10393 : 476 - 485
  • [5] 'Lean' Laboratory Requests: Mobile Apps for Immunohistochemistry and Molecular Test Requests
    Pilson, Keith
    Bennett, Michael
    McCarthy, Julie
    LABORATORY INVESTIGATION, 2015, 95 : 401A - 401A
  • [6] 'Lean' Laboratory Requests: Mobile Apps for Immunohistochemistry and Molecular Test Requests
    Pilson, Keith
    Bennett, Michael
    McCarthy, Julie
    MODERN PATHOLOGY, 2015, 28 : 401A - 401A
  • [7] You Are (not) Who Your Peers Are: Identification of Potentially Excessive Permission Requests in Android Apps
    Mallojula, Prashanthi
    Ahmad, Javaria
    Li, Fengjun
    Luo, Bo
    2021 IEEE 20TH INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2021), 2021, : 114 - 121
  • [8] Figment: Fine-grained Permission Management for Mobile Apps
    Gasparis, Ioannis
    Qian, Zhiyun
    Song, Chengyu
    Krishnamurthy, Srikanth V.
    Gupta, Rajiv
    Yu, Paul
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 1405 - 1413
  • [9] Intelligent mobile malware detection using permission requests and API calls
    Alazab, Moutaz
    Alazab, Mamoun
    Shalaginov, Andrii
    Mesleh, Abdelwadood
    Awajan, Albara
    FUTURE GENERATION COMPUTER SYSTEMS-THE INTERNATIONAL JOURNAL OF ESCIENCE, 2020, 107 : 509 - 521
  • [10] Mobile users' information privacy concerns and the role of app permission requests
    Degirmenci, Kenan
    INTERNATIONAL JOURNAL OF INFORMATION MANAGEMENT, 2020, 50 : 261 - 272