Classification and security assessment of android apps

被引:0
作者
Caushaj E. [1 ]
Sugumaran V. [1 ]
机构
[1] Department of Decision and Information Sciences, School of Business Administration, Oakland University, Rochester, 48309, MI
来源
Discover Internet of Things | 2023年 / 3卷 / 01期
关键词
Android platform; Application permission; Authorization; Human factors; Privacy; Security;
D O I
10.1007/s43926-023-00047-0
中图分类号
学科分类号
摘要
Current mobile platforms pose many privacy risks for the users. Android applications (apps) request access to device resources and data, such as storage, GPS location, camera, microphone, SMS, phone identity, and network information. Legitimate mobile apps, advertisements (ads), and malware all require access to mobile resources and data to function properly. Therefore, it is difficult for the user to make informed decisions that effectively balance their privacy and app functionality. This study analyzes the Android application permissions, ad networks and the impact on end-user’s privacy. Dangerous combinations of app permissions, and ad networks are used as features in our prediction models to understand the behavior of apps. Our models have a high classification accuracy of 95.9% considering the imbalance in real life between benign and malicious apps. Our assumption that certain app permissions can be a potential threat to the privacy of end users is confirmed to be one of the most impactful features of our prediction models. Since our study considers the impact of ad networks and malware permissions, it will help end-users make more informed decision about the app permissions they grant and understand that the app permissions open doors to more vulnerabilities, and at some point, benign apps can behave maliciously. © The Author(s) 2023.
引用
收藏
相关论文
共 58 条
[1]  
Turner A., Android Vs. Apple Market Share: Leading Mobile Operating Systems (OS).
[2]  
Turner A., How Many Smartphones are in the World?, (2023)
[3]  
International Data Corporation. Smartphone Market Share, (2023)
[4]  
Ceci L., Google Play: Number of Available Apps 2009–2023
[5]  
2023.
[6]  
The mobile malware landscape in 2022—of spyware, zero-click attacks, smishing and store security, (2022)
[7]  
Ashawa M., Morris S., Modeling correlation between android permissions based on threat and protection level using exploratory factor plane analysis, J Cybersecur Priv, 1, pp. 704-742, (2021)
[8]  
Alshehri A., Hewins A., McCulley M., Alshahrani H., Fu H., Zhu Y., Risks behind device information permissions in Android OS, Commun Netw, 9, 4, pp. 219-234, (2017)
[9]  
Cajucom E., Dacuno P., Aquino K., Aquilino B., Hilyati A., Jamaludin S., Threat Repor, (2015)
[10]  
Shrivastava G., Kumar P., Gupta D., Rodrigues J.J., Privacy issues of android application permissions: a literature review, Trans Emerg Telecommun Technol, 31, 12, (2019)