Digitala Vetenskapliga Arkivet

Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Towards Measuring Apps' Privacy-Friendliness
Karlstad University, Faculty of Health, Science and Technology (starting 2013), Department of Mathematics and Computer Science (from 2013). (PriSec)ORCID iD: 0000-0002-5235-5335
2018 (English)Licentiate thesis, comprehensive summary (Other academic)
Abstract [en]

Today's phone could be described as a charismatic tool that has the ability to keep human beings captivated for a considerable amount of their precious time. Users remain in the illusory wonderland with free services, while their data becomes the subject to monetizing by a genie called big data. In other words, users pay with their personal data but the price is in a way invisible. Poor means to observe and to assess the consequences of data disclosure causes hindrance for the user to be aware of and to take preventive measures.

Mobile operating systems use permission-based access control mechanism to guard system resources and sensors. Depending on the type, apps require explicit consent from the user in order to avail access to those permissions. Nonetheless, it does not put any constraint on access frequency. Granted privileges allow apps to access to users' personal information for indefinite period of time until being revoked explicitly. Available control tools lack monitoring facility which undermines the performance of access control model. It has the ability to create privacy risks and nontransparent handling of personal information for the data subject.

This thesis argues that app behavior analysis yields information which has the potential to increase transparency, to enhance privacy protection, to raise awareness regarding consequences of data disclosure, and to assist the user in informed decision making while selecting apps or services. It introduces models and methods, and demonstrates the risks with experiment results. It also takes the risks into account and makes an effort to determine apps' privacy-friendliness based on empirical data from app-behavior analysis.

Abstract [en]

Today's phone could be described as a charismatic tool that has the ability to keep human beings captivated for a considerable amount of their precious time. Users remain in the illusory wonderland with free services, while their data becomes the subject to monetizing by a genie called big data. In other words, users pay with their personal data but the price is in a way invisible. They face hindrance to be aware of and to take preventive measures because of poor means to observe and to assess consequences of data disclosure. Available control tools lack monitoring properties that do not allow the user to comprehend the magnitude of personal data access. Such circumstances can create privacy risks, erode intervenability of access control mechanism and lead to opaque handling of personal information for the data subject.

This thesis argues that app behavior analysis yields information which has the potential to increase transparency, to enhance privacy protection, to raise awareness regarding consequences of data disclosure, and to assist the user in informed decision making while selecting apps or services. It introduces models and methods, and demonstrates the data disclosure risks with experimental results. It also takes the risks into account and makes an effort to determine apps' privacy-friendliness based on empirical data from app-behavior analysis.

Place, publisher, year, edition, pages
Karlstad: Karlstads universitet, 2018. , p. 27
Series
Karlstad University Studies, ISSN 1403-8099 ; 2018:31
Keywords [en]
Mobile OS, Apps, User data, Transparency, Privacy
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
URN: urn:nbn:se:kau:diva-68569ISBN: 978-91-7063-864-0 (print)ISBN: 978-91-7063-959-3 (print)OAI: oai:DiVA.org:kau-68569DiVA, id: diva2:1234134
Presentation
2018-09-07, 1D 222, Universitetsgatan 2, Karlstad, 10:15 (English)
Opponent
Supervisors
Available from: 2018-08-17 Created: 2018-07-23 Last updated: 2026-02-12Bibliographically approved
List of papers
1. Towards Improving Privacy Awareness Regarding Apps' Permissions
Open this publication in new window or tab >>Towards Improving Privacy Awareness Regarding Apps' Permissions
2017 (English)In: ICDS 2017: THE ELEVENTH INTERNATIONAL CONFERENCE ON DIGITAL SOCIETY / [ed] Berntzen, L; GersbeckSchierholz, B, International Academy, Research and Industry Association (IARIA), 2017, p. 18-23Conference paper, Published paper (Other academic)
Abstract [en]

Empirical studies show that the flow of personal information through mobile apps made devices vulnerable in terms of privacy. Cumbersome and inconvenient representation of privacy notice encourages the user to ignore it and disclose sensitive private information unintentionally. Hence, summarized permissions are presented on mobile devices and users tend to overlook them as well. Rigid structure for using a service and inherited behavior from desktop applications to accept everything are the reasons behind compelling the user to proceed without paying any attention. Complex permission based structure is also a major impediment for consumers that makes it difficult to perceive appropriate consequences of their decisions. We argue that as privacy strongly depends on individual perception, the key to educate and empower users is to providing them with transparency of what is happening on their smartphones. In consequence we suggest a convenient, transparent and proactive approach to help in understanding and deciding upon privacy implications of apps. We propose a scale that has scalability within itself. We implement this method within a tool, named Aware, that presents the summary of what applications are installed on a smartphone, which resources they access, and what are the reasons for that. Moreover, the tool is capable of nudging the user when certain sensitive data is accessed.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2017
Keywords
Mobile Operating Systems; Mobile Phone Privacy; Control and Management of Privacy
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
urn:nbn:se:kau:diva-66716 (URN)000426494400005 ()978-1-61208-537-1 (ISBN)
Conference
11th International Conference on Digital Society (ICDS, Nice,France, March 19-23, 2017
Available from: 2018-03-15 Created: 2018-03-15 Last updated: 2026-02-12Bibliographically approved
2. How much Privilege does an App Need? Investigating Resource Usage of Android Apps
Open this publication in new window or tab >>How much Privilege does an App Need? Investigating Resource Usage of Android Apps
2017 (English)In: Proceedings of the Fifteenth International Conference on Privacy, Security and Trust – PST 2017 (IEEE proceedings pendings), IEEE, 2017Conference paper, Published paper (Refereed)
Abstract [en]

Arguably, one of the default solutions to many of today’s everyday errands is to install an app. In order to deliver a variety of convenient and user-centric services, apps need to access different types of information stored in mobile devices, much of which is personal information. In principle, access to such privacy sensitive data should be kept to a minimum. In this study, we focus on privilege utilization patterns by apps installed on Android devices. Though explicit consent is required prior to first time access to the resource, the unavailability of usage information makes it unclear when trying to reassess the users initial decision. On the other hand, if granted privilege with little or no usage, it would suggest the likely violation of the principle of least privilege. Our findings illustrate a plausible requirement for visualising resource usage to aid the user in their decision- making and finer access control mechanisms. 

Place, publisher, year, edition, pages
IEEE, 2017
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
urn:nbn:se:kau:diva-65605 (URN)10.1109/PST.2017.00039 (DOI)000447643500028 ()978-1-5386-2487-6 (ISBN)978-1-5386-2488-3 (ISBN)
Conference
The Fifteenth International Conference on Privacy, Security and Trust – PST 2017. August 28-30, 2017 Calgary, Alberta, Canada
Available from: 2018-01-15 Created: 2018-01-15 Last updated: 2026-02-12Bibliographically approved
3. Derived Partial Identities Generated from App Permissions
Open this publication in new window or tab >>Derived Partial Identities Generated from App Permissions
2017 (English)In: Open Identity Summit 2017: Proceedings / [ed] Lothar Fritsch, Heiko Roßnagel, Detlef Hühnlein, Bonn: Gesellschaft für Informatik, 2017, p. 117-130Conference paper, Published paper (Refereed)
Abstract [en]

This article presents a model of partial identities derived from app permissions that is based on Pfitzmann and Hansen’s terminology for privacy [PH10]. The article first shows how app permissions accommodate the accumulation of identity attributes for partial digital identities by building a model for identity attribute retrieval through permissions. Then, it presents an experimental survey of partial identity access for selected app groups. By applying the identity attribute retrieval model on the permission access log from the experiment, we show how apps’ permission usage is providing to identity profiling.

Place, publisher, year, edition, pages
Bonn: Gesellschaft für Informatik, 2017
Series
Lecture Notes in Informatics (LNI), ISSN 1617-5468 ; 277
Keywords
identity management, Partial Identity, Access Control, Apps, Permissions, Privacy, Data
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
urn:nbn:se:kau:diva-63724 (URN)978-3-88579-671-8 (ISBN)
Conference
Open Identity Summit (OID) 2017, 5-6 october 2017, Karlstad, Sweden.
Available from: 2017-09-15 Created: 2017-09-15 Last updated: 2026-02-12Bibliographically approved
4. Turning the Table Around: Monitoring App Behavior
Open this publication in new window or tab >>Turning the Table Around: Monitoring App Behavior
2018 (English)In: Sicherheit 2018 / [ed] H. Langweg, M. Meier, B. C. Witt, D. Reinhardt, Bonn: Gesellschaft für Informatik, 2018, p. 279-284Conference paper, Published paper (Refereed)
Abstract [en]

Since Android apps receive white-card access through permissions, users struggle to understand the actual magnitude of app access to their personal data. Due to unavailability of statistical or other tools that would provide an overview of data access or privilege use, users can hardly assess privacy risks or identify app misbehavior. This is a problem for data subjects. The presented PhD research project aims at creating a transparency-enhancing technology that helps users to assess the magnitude of data access of installed apps by monitoring the Android permission access control system. This article will present how apps exercise their permissions, based on a pilot study with an app monitoring tool. It then presents a prototypical implementation of a networked laboratory for crowd-sourcing app behavior data. Finally, the article presents and discusses a model that will use the collected data to calculate and visualize risk signals based on individual risk preferences and measured app data access efforts.

Place, publisher, year, edition, pages
Bonn: Gesellschaft für Informatik, 2018
Series
Lecture Notes in Informatics (LNI) - Proceedings, ISSN 1617-5468 ; P-281
Keywords
App Behavior, Privacy Preservation, Transparency.
National Category
Computer Sciences
Research subject
Computer Science
Identifiers
urn:nbn:se:kau:diva-68568 (URN)10.18420/sicherheit2018_25 (DOI)978-3-88579-675-6 (ISBN)
Conference
Sicherheit 2018, 25-27 April, Konstanz, Germany
Note

Licens: CC-BY-SA-4.0

Available from: 2018-07-13 Created: 2018-07-13 Last updated: 2026-02-12Bibliographically approved

Open Access in DiVA

fulltext(1047 kB)916 downloads
File information
File name FULLTEXT02.pdfFile size 1047 kBChecksum SHA-512
5c6d171bfe998eeaaeed7a65e0ff91f42d3e45fccc0bddcbd65e63b54ba43094fadc5964c2abaf52de6390c064fd6b719704a13ffea4f96848d59800ce60d9e9
Type fulltextMimetype application/pdf
audio(38004 kB)105 downloads
File information
File name AUDIO01.mp3File size 38004 kBChecksum SHA-512
e1e4c69e74d947ec630e44d8a88844e58f3d7a07d14db822ff450b805d6f48542b27d038e8d87bd0d8b0621887820c011a981886f0cced13db092b83b571d342
Type audioMimetype audio/mpeg

Search in DiVA

By author/editor
Momen, Nurul
By organisation
Department of Mathematics and Computer Science (from 2013)
Computer Sciences

Search outside of DiVA

GoogleGoogle Scholar
Total: 917 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

isbn
urn-nbn

Altmetric score

isbn
urn-nbn
Total: 2335 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf