Trust4App: Automating Trustworthiness Assessment of Mobile Applications

被引:5
|
作者
Habib, Sheikh Mahbub [1 ]
Alexopoulos, Nikolaos [1 ]
Islam, Md Monirul [1 ]
Heider, Jens [2 ]
Marsh, Stephen [3 ]
Muehlhaeuser, Max [1 ]
机构
[1] Tech Univ Darmstadt, Telecooperat Lab, Darmstadt, Germany
[2] Fraunhofer SIT, Darmstadt, Germany
[3] Univ Ontario Inst Technol, Oshawa, ON, Canada
基金
加拿大自然科学与工程研究理事会;
关键词
trust; trusworthiness; mobile security; security assessment;
D O I
10.1109/TrustCom/BigDataSE.2018.00029
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Smartphones have become ubiquitous in our everyday lives, providing diverse functionalities via millions of applications (apps) that are readily available. To achieve these functionalities, apps need to access and utilize potentially sensitive data, stored in the user's device. This can pose a serious threat to users' security and privacy, when considering malicious or underskilled developers. While application marketplaces, like Google Play store and Apple App store, provide factors like ratings, user reviews, and number of downloads to distinguish benign from risky apps, studies have shown that these metrics are not adequately effective. The security and privacy health of an application should also be considered to generate a more reliable and transparent trustworthiness score. In order to automate the trustworthiness assessment of mobile applications, we introduce the Trust4App framework, which not only considers the publicly available factors mentioned above, but also takes into account the Security and Privacy (S&P) health of an application. Additionally, it considers the S&P posture of a user, and provides an holistic personalized trustworthiness score. While existing automatic trustworthiness frameworks only consider trustworthiness indicators (e.g. permission usage, privacy leaks) individually, Trust4App is, to the best of our knowledge, the first framework to combine these indicators. We also implement a proof-of-concept realization of our framework and demonstrate that Trust4App provides a more comprehensive, intuitive and actionable trustworthiness assessment compared to existing approaches.
引用
收藏
页码:124 / 135
页数:12
相关论文
共 50 条
  • [1] The Mobile Health App Trustworthiness Checklist: Usability Assessment
    van Haasteren, Afua
    Vayena, Effy
    Powell, John
    [J]. JMIR MHEALTH AND UHEALTH, 2020, 8 (07):
  • [2] Automating trust assessment for configuration of temporary partnerships
    Msanjila, Simon Samwel
    Afsarmanesh, Hamideh
    [J]. INNOVATION IN MANUFACTURING NETWORKS, 2008, : 95 - 104
  • [3] A Mobile Usability Assessment of Carousell Mobile App
    Hussain, Azham
    Mkpojiogu, Emmanuel O. C.
    Yahaya, Nusaibah Binti
    Abu Bakar, Noor Zuraidah Binti
    [J]. PROCEEDINGS OF THE 3RD INTERNATIONAL CONFERENCE ON APPLIED SCIENCE AND TECHNOLOGY (ICAST'18), 2018, 2016
  • [4] No Risk, More Fun! Automating Breach of Confidentiality Risk Assessment for Android Mobile Health Applications
    Brueggemann, Thomas
    Dehling, Tobias
    Sunyaev, Ali
    [J]. PROCEEDINGS OF THE 52ND ANNUAL HAWAII INTERNATIONAL CONFERENCE ON SYSTEM SCIENCES, 2019, : 4266 - 4275
  • [5] Efficiently Predicting Trustworthiness of Mobile Services Based on Trust Propagation in Social Networks
    Saixia Lyu
    Jianxun Liu
    Mingdong Tang
    Yu Xu
    Jinjun Chen
    [J]. Mobile Networks and Applications, 2015, 20 : 840 - 852
  • [6] Efficiently Predicting Trustworthiness of Mobile Services Based on Trust Propagation in Social Networks
    Lyu, Saixia
    Liu, Jianxun
    Tang, Mingdong
    Xu, Yu
    Chen, Jinjun
    [J]. MOBILE NETWORKS & APPLICATIONS, 2015, 20 (06): : 840 - 852
  • [7] Data Trustworthiness Evaluation in Mobile Crowdsensing Systems with Users' Trust Dispositions' Consideration
    Zupancic, Eva
    Zalik, Borut
    [J]. SENSORS, 2019, 19 (06)
  • [8] 'You have to put a lot of trust in me': autonomy, trust, and trustworthiness in the context of mobile apps for mental health
    Mueller, Regina
    Primc, Nadia
    Kuhn, Eva
    [J]. MEDICINE HEALTH CARE AND PHILOSOPHY, 2023, 26 (03) : 313 - 324
  • [9] 'You have to put a lot of trust in me': autonomy, trust, and trustworthiness in the context of mobile apps for mental health
    Regina Müller
    Nadia Primc
    Eva Kuhn
    [J]. Medicine, Health Care and Philosophy, 2023, 26 : 313 - 324
  • [10] Mobile App Distribution Transparency (MADT): Design and Evaluation of a System to Mitigate Necessary Trust in Mobile App Distribution Systems
    Lins, Mario
    Mayrhofer, Rene
    Roland, Michael
    Beresford, Alastair R.
    [J]. SECURE IT SYSTEMS, NORDSEC 2023, 2024, 14324 : 185 - 203