{"title":"Android permission system and user privacy — A review of concept and approaches","authors":"A. Khatoon, P. Corcoran","doi":"10.1109/ICCE-Berlin.2017.8210616","DOIUrl":null,"url":null,"abstract":"Use of smartphones in our everyday life has become widely popular. A large proportion of smartphones use Android OS, which supports third party software development, so there is increasing number of developers developing applications for the android platform. But this means there are significant privacy risks associated with the use of android based smartphone applications. In this paper the process through which different apps gain access to sensitive device permissions when installed on an android devices is studied. More specifically we emphasize the difficulty for the user to understand how different device permissions can affect its privacy. The context and use-case for each permission affects its impact and when multiple permissions are granted determining the potential impact on the privacy of users becomes a much more complex problem. In this work we quantify the potential impact of the most important individual permissions and take some first steps towards an evaluation of privacy impact of multiple device permissions. It is also noted that many ‘free’ apps tend to request unnecessary or redundant permissions, often with the aim to gather valuable user data. This is discussed and some strategies to discourage such permission requesting are outlined. Some ideas for further development of this research are provided in the concluding discussion.","PeriodicalId":355536,"journal":{"name":"2017 IEEE 7th International Conference on Consumer Electronics - Berlin (ICCE-Berlin)","volume":"153 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2017-09-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"9","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2017 IEEE 7th International Conference on Consumer Electronics - Berlin (ICCE-Berlin)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/ICCE-Berlin.2017.8210616","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 9
Abstract
Use of smartphones in our everyday life has become widely popular. A large proportion of smartphones use Android OS, which supports third party software development, so there is increasing number of developers developing applications for the android platform. But this means there are significant privacy risks associated with the use of android based smartphone applications. In this paper the process through which different apps gain access to sensitive device permissions when installed on an android devices is studied. More specifically we emphasize the difficulty for the user to understand how different device permissions can affect its privacy. The context and use-case for each permission affects its impact and when multiple permissions are granted determining the potential impact on the privacy of users becomes a much more complex problem. In this work we quantify the potential impact of the most important individual permissions and take some first steps towards an evaluation of privacy impact of multiple device permissions. It is also noted that many ‘free’ apps tend to request unnecessary or redundant permissions, often with the aim to gather valuable user data. This is discussed and some strategies to discourage such permission requesting are outlined. Some ideas for further development of this research are provided in the concluding discussion.