Reducing Permission Requests in Mobile Apps

被引:16
|
作者
Peddinti, Sai Teja [1 ]
Bilogrevic, Igor [1 ]
Taft, Nina [1 ]
Pelikan, Martin [1 ]
Erlingsson, Ulfar [1 ]
Anthonysamy, Pauline [1 ]
Hogben, Giles [1 ]
机构
[1] Google Inc, Mountain View, CA 94043 USA
关键词
Mobile Apps; Permissions;
D O I
10.1145/3355369.3355584
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Users of mobile apps sometimes express discomfort or concerns with what they see as unnecessary or intrusive permission requests by certain apps. However encouraging mobile app developers to request fewer permissions is challenging because there are many reasons why permissions are requested; furthermore, prior work [25] has shown it is hard to disambiguate the purpose of a particular permission with high certainty. In this work we describe a novel, algorithmic mechanism intended to discourage mobile-app developers from asking for unnecessary permissions. Developers are incentivized by an automated alert, or "nudge", shown in the Google Play Console when their apps ask for permissions that are requested by very few functionally-similar apps-in other words, by their competition. Empirically, this incentive is effective, with significant developer response since its deployment. Permissions have been redacted by 59% of apps that were warned, and this attenuation has occurred broadly across both app categories and app popularity levels. Importantly, billions of users' app installs from the Google Play have benefited from these redactions.
引用
收藏
页码:259 / 266
页数:8
相关论文
共 50 条
  • [21] An Investigation of Comic-Based Permission Requests
    Watson, Katie
    Just, Mike
    Berg, Tessa
    SECURE IT SYSTEMS, NORDSEC 2020, 2021, 12556 : 246 - 261
  • [22] SecuRank: Starving Permission-Hungry Apps Using Contextual Permission Analysis
    Taylor, Vincent F.
    Martinovic, Ivan
    PROCEEDINGS OF THE 6TH WORKSHOP ON SECURITY AND PRIVACY IN SMARTPHONES AND MOBILE DEVICES (SPSM'16), 2016, : 43 - 52
  • [23] Permission Abusing by Ad Libraries of Smartphone Apps
    Su, Ming-Yang
    Chen, Sheng-Sheng
    Wu, Tsung-Ren
    Chang, Hao-Sen
    Liu, You-Liang
    2019 ELEVENTH INTERNATIONAL CONFERENCE ON UBIQUITOUS AND FUTURE NETWORKS (ICUFN 2019), 2019, : 475 - 477
  • [24] When Privacy Meets Usability: Unobtrusive Privacy Permission Recommendation System for Mobile Apps Based on Crowdsourcing
    Liu, Rui
    Cao, Jiannong
    Zhang, Kehuan
    Gao, Wenyu
    Liang, Junbin
    Yang, Lei
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2018, 11 (05) : 864 - 878
  • [25] On Understanding Permission Usage Contextuality in Android Apps
    Hossen, Md Zakir
    Mannan, Mohammad
    DATA AND APPLICATIONS SECURITY AND PRIVACY XXXII, DBSEC 2018, 2018, 10980 : 232 - 242
  • [26] Enhancement on Privacy Permission Management for Android Apps
    Shinde, Supriya S.
    Sambare, Santosh S.
    2015 GLOBAL CONFERENCE ON COMMUNICATION TECHNOLOGIES (GCCT), 2015, : 819 - 823
  • [27] Student Research Abstract: "Hard to Understand, Easy to Ignore": An Automated Approach to Predict Mobile App Permission Requests
    Hatamian, Majid
    SAC '19: PROCEEDINGS OF THE 34TH ACM/SIGAPP SYMPOSIUM ON APPLIED COMPUTING, 2019, : 1979 - 1982
  • [28] A Knowledge Graph based Approach for Apps Permission Recommendation
    Zhang, Huwei
    Feng, Zhiyong
    Xiao, Jianmao
    Ye, Zhixiong
    Fan, Guodong
    Chen, Shizhan
    Xue, Xiao
    2022 IEEE INTERNATIONAL CONFERENCE ON WEB SERVICES (IEEE ICWS 2022), 2022, : 176 - 181
  • [29] Studying Permission Related Issues in Android Wearable Apps
    Mujahid, Suhaib
    Abdalkareem, Rabe
    Shihab, Emad
    PROCEEDINGS 2018 IEEE INTERNATIONAL CONFERENCE ON SOFTWARE MAINTENANCE AND EVOLUTION (ICSME), 2018, : 345 - 356
  • [30] Android Apps:Static Analysis Based on Permission Classification
    Zhenjiang Dong
    Hui Ye
    Yan Wu
    Shaoyin Cheng
    Fan Jiang
    ZTECommunications, 2013, 11 (01) : 62 - 66