...
首页> 外文期刊>ACM Transactions on Information Systems >Understanding the Purpose of Permission Use in Mobile Apps
【24h】

Understanding the Purpose of Permission Use in Mobile Apps

机译:了解移动应用中权限使用的目的

获取原文
获取原文并翻译 | 示例
           

摘要

Mobile apps frequently request access to sensitive data, such as location and contacts. Understanding the purpose of why sensitive data is accessed could help improve privacy as well as enable new kinds of access control. In this article, we propose a text mining based method to infer the purpose of sensitive data access by Android apps. The key idea we propose is to extract multiple features from app code and then use those features to train a machine learning classifier for purpose inference. We present the design, implementation, and evaluation of two complementary approaches to infer the purpose of permission use, first using purely static analysis, and then using primarily dynamic analysis. We also discuss the pros and cons of both approaches and the trade-offs involved.
机译:移动应用程序经常请求访问敏感数据,例如位置和联系人。了解为什么访问敏感数据的目的可以帮助改善隐私性并实现新的访问控制。在本文中,我们提出了一种基于文本挖掘的方法来推断Android应用程序敏感数据访问的目的。我们提出的关键思想是从应用程序代码中提取多个功能,然后使用这些功能来训练机器学习分类器以进行目的推断。我们介绍了两种补充方法的设计,实现和评估,以推断权限使用的目的,首先使用纯静态分析,然后主要使用动态分析。我们还将讨论两种方法的利弊以及所涉及的取舍。

著录项

  • 来源
    《ACM Transactions on Information Systems》 |2017年第4期|43.1-43.40|共40页
  • 作者单位

    Beijing Univ Posts & Telecommun, Sch Comp Sci, Beijing Key Lab Intelligent Telecommun Software &, Beijing, Peoples R China;

    Peking Univ, Sch Elect Engn & Comp Sci, Key Lab High Confidence Software Technol MOE, Beijing, Peoples R China;

    Peking Univ, Sch Elect Engn & Comp Sci, Key Lab High Confidence Software Technol MOE, Beijing, Peoples R China;

    Carnegie Mellon Univ, Human Comp Interact Inst, Sch Comp Sci, Pittsburgh, PA 15213 USA;

    Carnegie Mellon Univ, Human Comp Interact Inst, Sch Comp Sci, Pittsburgh, PA 15213 USA;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    Permission; purpose; mobile applications; Android; privacy; access control;

    机译:权限;目的;移动应用程序;Android;隐私;访问控制;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号