User-aware privacy control via extended static-information-flow analysis

被引:0
|
作者
Xusheng Xiao
Nikolai Tillmann
Manuel Fahndrich
Jonathan de Halleux
Michal Moskal
Tao Xie
机构
[1] NEC Laboratories America,Department of Computer Science
[2] Microsoft Research,undefined
[3] University of Illinois at Urbana-Champaign,undefined
来源
关键词
Mobile Application; Privacy Control; Information Flow Analysis; Static Analysis;
D O I
暂无
中图分类号
学科分类号
摘要
Applications in mobile marketplaces may leak private user information without notification. Existing mobile platforms provide little information on how applications use private user data, making it difficult for experts to validate applications and for users to grant applications access to their private data. We propose a user-aware-privacy-control approach, which reveals how private information is used inside applications. We compute static information flows and classify them as safe/unsafe based on a tamper analysis that tracks whether private data is obscured before escaping through output channels. This flow information enables platforms to provide default settings that expose private data for only safe flows, thereby preserving privacy and minimizing decisions required from users. We build our approach into TouchDevelop, an application-creation environment that allows users to write scripts on mobile devices and install scripts published by other users. We evaluate our approach by studying 546 scripts published by 194 users, and the results show that our approach effectively reduces the need to make access-granting choices to only 10.1 % (54) of all scripts. We also conduct a user survey that involves 50 TouchDevelop users to assess the effectiveness and usability of our approach. The results show that 90 % of the users consider our approach useful in protecting their privacy, and 54 % prefer our approach over other privacy-control approaches.
引用
收藏
页码:333 / 366
页数:33
相关论文
共 50 条
  • [1] User-Aware Privacy Control via Extended Static-Information-Flow Analysis
    Xiao, Xusheng
    Tillmann, Nikolai
    Fahndrich, Manuel
    de Halleux, Jonathan
    Moskal, Michal
    2012 PROCEEDINGS OF THE 27TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING (ASE), 2012, : 80 - 89
  • [2] User-aware privacy control via extended static-information-flow analysis
    Xiao, Xusheng
    Tillmann, Nikolai
    Fahndrich, Manuel
    de Halleux, J.
    Moskal, Michal
    Xie, Tao
    AUTOMATED SOFTWARE ENGINEERING, 2015, 22 (03) : 333 - 366
  • [3] User-Aware Image Tag Refinement via Ternary Semantic Analysis
    Sang, Jitao
    Xu, Changsheng
    Liu, Jing
    IEEE TRANSACTIONS ON MULTIMEDIA, 2012, 14 (03) : 883 - 895
  • [4] User-aware videoconference session control using software agents
    Botía, JA
    Ruiz, P
    Gómez-Skarmeta, AF
    IEEE/WIC/ACM INTERNATIONAL CONFERENCE ON INTELLIGENT AGENT TECHNOLOGY, PROCEEDINGS, 2004, : 349 - 352
  • [5] Towards Personalized Review Summarization via User-Aware Sequence Network
    Li, Junjie
    Li, Haoran
    Zong, Chengqing
    THIRTY-THIRD AAAI CONFERENCE ON ARTIFICIAL INTELLIGENCE / THIRTY-FIRST INNOVATIVE APPLICATIONS OF ARTIFICIAL INTELLIGENCE CONFERENCE / NINTH AAAI SYMPOSIUM ON EDUCATIONAL ADVANCES IN ARTIFICIAL INTELLIGENCE, 2019, : 6690 - 6697
  • [6] Static Analysis Method of Secure Privacy Information Flow for Service Composition
    Peng H.-F.
    Huang Z.-Q.
    Liu L.-Y.
    Li Y.
    Ke C.-B.
    Huang, Zhi-Qiu (zqhuang@nuaa.edu.cn), 1739, Chinese Academy of Sciences (29): : 1739 - 1755
  • [7] User-aware rate adaptive control for IEEE 802.11-based ad hoc networks
    Zhu, YF
    Niu, ZS
    GLOBECOM '05: IEEE GLOBAL TELECOMMUNICATIONS CONFERENCE, VOLS 1-6: DISCOVERY PAST AND FUTURE, 2005, : 2605 - 2609
  • [8] Towards the creation of a profile of the information privacy aware user through a systematic literature review of information privacy awareness
    Soumelidou, Aikaterini
    Tsohou, Aggeliki
    TELEMATICS AND INFORMATICS, 2021, 61
  • [9] Static analysis for efficient hybrid information-flow control
    Moore, Scott
    Chong, Stephen
    2011 IEEE 24TH COMPUTER SECURITY FOUNDATIONS SYMPOSIUM (CSF), 2011, : 146 - 160
  • [10] Privacy-Aware Remote Information Retrieval User Experiments Logging Tool
    Li, Hanyu
    Lu, Hongyu
    Huang, Songhao
    Ma, Weizhi
    Zhang, Min
    Liu, Yiqun
    Ma, Shaoping
    SIGIR '21 - PROCEEDINGS OF THE 44TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, 2021, : 2615 - 2619