【24h】

Trust4App: Automating Trustworthiness Assessment of Mobile Applications

机译:Trust4App:移动应用程序的自动化可信度评估

获取原文
获取原文并翻译 | 示例

摘要

Smartphones have become ubiquitous in our everyday lives, providing diverse functionalities via millions of applications (apps) that are readily available. To achieve these functionalities, apps need to access and utilize potentially sensitive data, stored in the user's device. This can pose a serious threat to users' security and privacy, when considering malicious or underskilled developers. While application marketplaces, like Google Play store and Apple App store, provide factors like ratings, user reviews, and number of downloads to distinguish benign from risky apps, studies have shown that these metrics are not adequately effective. The security and privacy health of an application should also be considered to generate a more reliable and transparent trustworthiness score. In order to automate the trustworthiness assessment of mobile applications, we introduce the Trust4App framework, which not only considers the publicly available factors mentioned above, but also takes into account the Security and Privacy (S&P) health of an application. Additionally, it considers the S&P posture of a user, and provides an holistic personalized trustworthiness score. While existing automatic trustworthiness frameworks only consider trustworthiness indicators (e.g. permission usage, privacy leaks) individually, Trust4App is, to the best of our knowledge, the first framework to combine these indicators. We also implement a proof-of-concept realization of our framework and demonstrate that Trust4App provides a more comprehensive, intuitive and actionable trustworthiness assessment compared to existing approaches.
机译:智能手机已经在我们的日常生活中变得无处不在,它通过数百万个随时可用的应用程序提供各种功能。为了实现这些功能,应用程序需要访问和利用存储在用户设备中的潜在敏感数据。在考虑恶意或技能不足的开发人员时,这可能对用户的安全和隐私构成严重威胁。虽然Google Play商店和Apple App商店等应用程序市场会提供评分,用户评论和下载次数等因素,以区分良性和风险应用程序,但研究表明这些指标不够有效。还应考虑应用程序的安全性和隐私状况,以生成更可靠和透明的可信度评分。为了使移动应用程序的可信度评估自动化,我们引入了Trust4App框架,该框架不仅考虑了上述公共可用因素,而且还考虑了应用程序的安全性和隐私(S&P)健康状况。另外,它考虑了用户的S&P姿势,并提供了整体的个性化可信度评分。虽然现有的自动信任框架仅考虑信任度指标(例如权限使用,隐私泄露),但就我们所知,Trust4App是第一个结合这些指标的框架。我们还实现了我们框架的概念验证实现,并证明与现有方法相比,Trust4App提供了更全面,直观和可操作的可信度评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号