首页> 外文会议>IEEE Symposium on Security and Privacy >Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security Privacy
【24h】

Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security Privacy

机译:简短的文字,大的影响:衡量用户评论对Android App安全性和隐私的影响

获取原文

摘要

Application markets streamline the end-users' task of finding and installing applications. They also form an immediate communication channel between app developers and their end-users in form of app reviews, which allow users to provide developers feedback on their apps. However, it is unclear to which extent users employ this channel to point out their security and privacy concerns about apps, about which aspects of apps users express concerns, and how developers react to such security- and privacy-related reviews. In this paper, we present the first study of the relationship between end-user reviews and security- & privacy-related changes in apps. Using natural language processing on 4.5M user reviews for the top 2,583 apps in Google Play, we identified 5,527 security and privacy relevant reviews (SPR). For each app version mentioned in the SPR, we use static code analysis to extract permission-protected features mentioned in the reviews. We successfully mapped SPRs to privacy-related changes in app updates in 60.77% of all cases. Using exploratory data analysis and regression analysis we are able to show that preceding SPR are a significant factor for predicting privacy-related app updates, indicating that user reviews in fact lead to privacy improvements of apps. Our results further show that apps that adopt runtime permissions receive a significantly higher number of SPR, showing that runtime permissions put privacy-jeopardizing actions better into users' minds. Further, we can attribute about half of all privacy-relevant app changes exclusively to third-party library code. This hints at larger problems for app developers to adhere to users' privacy expectations and markets' privacy regulations. Our results make a call for action to make app behavior more transparent to users in order to leverage their reviews in creating incentives for developers to adhere to security and privacy best practices, while our results call at the same time for better tools to support app developers in this endeavor.
机译:应用程序市场简化了最终用户查找和安装应用程序的任务。它们还以应用程序评论的形式在应用程序开发人员与最终用户之间形成直接的沟通渠道,使用户可以向开发人员提供有关其应用程序的反馈。但是,尚不清楚用户在多大程度上使用此渠道来指出他们对应用程序的安全性和隐私权的关注,有关应用程序用户表达哪些方面的担忧以及开发人员如何对此类与安全性和隐私权相关的评论做出反应。在本文中,我们对终端用户评论与应用程序中与安全性和隐私相关的更改之间的关系进行了首次研究。使用自然语言处理450万个用户评论中的Google Play前2583个应用程序,我们确定了5,527个与安全和隐私相关的评论(SPR)。对于SPR中提到的每个应用版本,我们使用静态代码分析来提取评论中提到的受权限保护的功能。我们成功地将SPR映射到应用程序更新中与隐私相关的更改,占所有案例的60.77%。使用探索性数据分析和回归分析,我们可以证明之前的SPR是预测与隐私相关的应用更新的重要因素,这表明用户查看实际上可以改善应用的隐私。我们的结果进一步表明,采用运行时权限的应用程序会收到大量SPR,这表明运行时权限使危害隐私的操作更好地进入了用户的脑海。此外,我们可以将所有与隐私相关的应用更改中的大约一半归因于第三方库代码。这为应用程序开发人员遵守用户的隐私期望和市场的隐私法规提出了更大的问题。我们的结果呼吁采取行动,使用户对应用程序的行为更加透明,以便利用他们的评论来激励开发人员遵守安全性和隐私最佳做法,而我们的结果同时需要更好的工具来支持应用程序开发人员在这一努力中。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号