Short Text, Large Effect: Measuring the Impact of User Reviews on Android App Security & Privacy

被引:27
作者
Duc Cuong Nguyen [1 ]
Derr, Erik [1 ]
Backes, Michael [2 ]
Bugiel, Sven [2 ]
机构
[1] Saarland Univ, CISPA, Saarbrucken, Germany
[2] CISPA Helmholtz Ctr iG, Saarbrucken, Germany
来源
2019 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2019) | 2019年
关键词
D O I
10.1109/SP.2019.00012
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Application markets streamline the end-users' task of finding and installing applications. They also form an immediate communication channel between app developers and their end-users in form of app reviews, which allow users to provide developers feedback on their apps. However, it is unclear to which extent users employ this channel to point out their security and privacy concerns about apps, about which aspects of apps users express concerns, and how developers react to such security- and privacy-related reviews. In this paper, we present the first study of the relationship between end-user reviews and security- & privacy-related changes in apps. Using natural language processing on 4.5M user reviews for the top 2,583 apps in Google Play, we identified 5,527 security and privacy relevant reviews (SPR). For each app version mentioned in the SPR, we use static code analysis to extract permission-protected features mentioned in the reviews. We successfully mapped SPRs to privacy-related changes in app updates in 60.77% of all cases. Using exploratory data analysis and regression analysis we are able to show that preceding SPR are a significant factor for predicting privacy-related app updates, indicating that user reviews in fact lead to privacy improvements of apps. Our results further show that apps that adopt runtime permissions receive a significantly higher number of SPR, showing that runtime permissions put privacy-jeopardizing actions better into users' minds. Further, we can attribute about half of all privacy-relevant app changes exclusively to third-party library code. This hints at larger problems for app developers to adhere to users' privacy expectations and markets' privacy regulations. Our results make a call for action to make app behavior more transparent to users in order to leverage their reviews in creating incentives for developers to adhere to security and privacy best practices, while our results call at the same time for better tools to support app developers in this endeavor.
引用
收藏
页码:555 / 569
页数:15
相关论文
共 59 条
  • [1] SoK: Lessons Learned From Android Security Research For Appified Software Platforms
    Acar, Yasemin
    Backes, Michael
    Bugiel, Sven
    Fahl, Sascha
    McDaniel, Patrick
    Smith, Matthew
    [J]. 2016 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP), 2016, : 433 - 451
  • [2] [Anonymous], P 38 IEEE S SEC PRIV
  • [3] [Anonymous], 2012, P 7 USENIX C HOT TOP
  • [4] [Anonymous], 2012, UNSAFE EXPOSURE ANAL
  • [5] [Anonymous], 2018, ANDROID USERS AVOID
  • [6] [Anonymous], 2012, WORKSH MOB SEC TECHN
  • [7] [Anonymous], 2015, GOOGLES UNWANTED SOF
  • [8] [Anonymous], 2017, ADDITIONAL PROTECTIO
  • [9] [Anonymous], 2017, IMPROVING APP SECURI
  • [10] [Anonymous], 2010, Multilevel methods: Techniques and analysis