• DocumentCode
    3406391
  • Title

    Asking for (and about) permissions used by Android apps

  • Author

    Stevens, R. ; Ganz, Jonathan ; Filkov, Vladimir ; Devanbu, Premkumar ; Hao Chen

  • Author_Institution
    Univ. of California, Davis, Davis, CA, USA
  • fYear
    2013
  • fDate
    18-19 May 2013
  • Firstpage
    31
  • Lastpage
    40
  • Abstract
    Security policies, which specify what applications are allowed to do, are notoriously difficult to specify correctly. Many applications were found to request over-liberal permissions. On mobile platforms, this might prevent a cautious user from installing an otherwise harmless application or, even worse, increase the attack surface in vulnerable applications. As a result of such difficulties, programmers frequently ask about them in on-line fora. Our goal is to gain some insight into both the misuse of permissions and the discussions of permissions in on-line fora. We analyze about 10,000 free apps from popular Android markets and found a significant sub-linear relationship between the popularity of a permission and the number of times when it is misused. We also study the relationship of permission use and the number of questions about the permission on StackOverflow. Finally, we study the effect of the influence of a permission (the functionality that it controls) and the interference of a permission (the number of other permissions that influence the same classes) on the occurrence of both permission misuse and permission discussions in StackOverflow.
  • Keywords
    Linux; Web sites; authorisation; mobile computing; Android markets; StackOverflow; free-Android applications; mobile platforms; online fora; over-liberal permission request; permission discussions; permission interference; permission misuse; permission popularity; security policies; sublinear relationship; Androids; Documentation; Humanoid robots; Interference; Java; Security; Software;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Mining Software Repositories (MSR), 2013 10th IEEE Working Conference on
  • Conference_Location
    San Francisco, CA
  • ISSN
    2160-1852
  • Print_ISBN
    978-1-4799-0345-0
  • Type

    conf

  • DOI
    10.1109/MSR.2013.6624000
  • Filename
    6624000