首页> 外文会议>IEEE International Conference on Big Data Science and Engineering >Trust4App: Automating Trustworthiness Assessment of Mobile Applications
【24h】

Trust4App: Automating Trustworthiness Assessment of Mobile Applications

机译:Trust4App:自动化移动应用的可信度评估

获取原文

摘要

Smartphones have become ubiquitous in our everyday lives, providing diverse functionalities via millions of applications (apps) that are readily available. To achieve these functionalities, apps need to access and utilize potentially sensitive data, stored in the user's device. This can pose a serious threat to users' security and privacy, when considering malicious or underskilled developers. While application marketplaces, like Google Play store and Apple App store, provide factors like ratings, user reviews, and number of downloads to distinguish benign from risky apps, studies have shown that these metrics are not adequately effective. The security and privacy health of an application should also be considered to generate a more reliable and transparent trustworthiness score. In order to automate the trustworthiness assessment of mobile applications, we introduce the Trust4App framework, which not only considers the publicly available factors mentioned above, but also takes into account the Security and Privacy (S&P) health of an application. Additionally, it considers the S&P posture of a user, and provides an holistic personalized trustworthiness score. While existing automatic trustworthiness frameworks only consider trustworthiness indicators (e.g. permission usage, privacy leaks) individually, Trust4App is, to the best of our knowledge, the first framework to combine these indicators. We also implement a proof-of-concept realization of our framework and demonstrate that Trust4App provides a more comprehensive, intuitive and actionable trustworthiness assessment compared to existing approaches.
机译:智能手机已经在我们的日常生活中无处不在,通过数以百万计的应用程序(应用程序)都是现成提供多样化的功能。为了实现这些功能,应用需要访问和利用潜在的敏感数据,存储在用户的设备。考虑到恶意或underskilled开发时,这可能会对用户的安全和隐私,造成严重威胁。虽然应用集市,像谷歌Play商店和苹果应用程序商店,提供收视率一样,用户评论,和下载次数因素,区分风险的应用程序是良性的,研究显示,这些指标都没有得到充分有效的。应用程序的安全性和保密性健康也应该被视为产生更可靠和透明的可信度得分。为了自动移动应用的可信性评估,我们引入Trust4App框架,它不仅考虑上面提到的公开可用的因素,同时也考虑到了安全性和保密性(S&P)的应用程序的健康。此外,它考虑了用户的S&P的姿势,并提供了一个整体的个性化的可信性得分。尽管现有的自动守信框架只考虑可信度指标(例如许可使用,隐私泄露)单独,Trust4App是,到我们所知,第一个框架,以这些指标结合起来。我们还实行验证的概念的实现我们的框架,并展示相比,现有的方法是Trust4App提供了更为全面,直观的和可操作的可信度评估。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号