首页> 外文会议>IEEE Symposium on Security and Privacy >Demystifying Hidden Privacy Settings in Mobile Apps
【24h】

Demystifying Hidden Privacy Settings in Mobile Apps

机译:揭秘移动应用中的隐藏隐私设置

获取原文

摘要

Mobile apps include privacy settings that allow their users to configure how their data should be shared. These settings, however, are often hard to locate and hard to understand by the users, even in popular apps, such as Facebook. More seriously, they are often set to share user data by default, exposing her privacy without proper consent. In this paper, we report the first systematic study on the problem, which is made possible through an in-depth analysis of user perception of the privacy settings. More specifically, we first conduct two user studies (involving nearly one thousand users) to understand privacy settings from the user's perspective, and identify these hard-to-find settings. Then we select 14 features that uniquely characterize such hidden privacy settings and utilize a novel technique called semantics- based UI tracing to extract them from a given app. On top of these features, a classifier is trained to automatically discover the hidden privacy settings, which together with other innovations, has been implemented into a tool called Hound. Over our labeled data set, the tool achieves an accuracy of 93.54%. Further running it on 100,000 latest apps from both Google Play and third-party markets, we find that over a third (36.29%) of the privacy settings identified from these apps are “hidden”. Looking into these settings, we observe that they become hard to discover and hard to understand primarily due to the problematic categorization on the apps' user interfaces and/or confusing descriptions. Further importantly, though more privacy options have been offered to the user over time, also discovered is the persistence of their usability issue, which becomes even more serious, e.g., originally easy-to-find settings now harder to locate. And among all such hidden privacy settings, 82.16% are set to leak user privacy by default. We provide suggestions for improving the usability of these privacy settings at the end of our study.
机译:移动应用程序包括隐私设置,允许其用户配置应如何共享其数据。但是,即使在流行的应用程序(例如Facebook)中,这些设置通常也很难被用户找到和理解。更严重的是,默认情况下,他们通常设置为共享用户数据,未经适当同意就暴露了她的隐私。在本文中,我们报告了对该问题的首次系统研究,这是通过对用户对隐私设置的感知进行深入分析而实现的。更具体地说,我们首先进行两项用户研究(涉及近千名用户),以从用户的角度了解隐私设置,并识别这些难以找到的设置。然后,我们选择14种独特地表征这种隐藏隐私设置的功能,并利用一种称为基于语义的UI跟踪的新颖技术从给定的应用程序中提取它们。除了这些功能外,还训练了分类器来自动发现隐藏的隐私设置,并将其与其他创新技术一起实施到称为“猎犬”的工具中。在我们标记的数据集上,该工具的准确性达到93.54%。进一步在来自Google Play和第三方市场的100,000个最新应用上运行它,我们发现从这些应用中识别出的隐私设置中有超过三分之一(36.29%)被“隐藏”了。查看这些设置,我们发现它们主要是由于应用程序用户界面上的分类问题和/或令人困惑的描述而变得难以发现和难以理解。更重要的是,尽管随着时间的流逝向用户提供了更多的隐私选项,但是还发现了其可用性问题的持续性,这变得更加严重,例如,原来较容易找到的设置现在变得更难定位。并且在所有这些隐藏的隐私设置中,默认情况下将82.16%设置为泄漏用户隐私。在研究结束时,我们提供了改善这些隐私设置可用性的建议。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号