论文标题
暴露暴露:一项测量和用户研究,以评估上下文移动数据隐私
Exposures Exposed: A Measurement and User Study to Assess Mobile Data Privacy in Context
论文作者
论文摘要
移动设备可以访问个人,潜在的敏感数据,并且有大量的移动应用程序和第三方库将通过网络传输此信息传输到远程服务器(包括应用程序开发人员服务器和第三方服务器)。在本文中,我们对不仅了解个人身份信息(PII)的程度,而且对其上下文(即应用程序,目标服务器,所使用的加密等)以及当今移动用户感知的风险感兴趣。为此,我们采取了两个步骤。首先,我们进行了一项测量研究:我们通过手动和自动测试收集新数据集,并从400个最受欢迎的Android应用程序中捕获16种PII类型的暴露。我们分析了这些暴露,并提供有关共享PII的移动应用程序的程度和模式的见解,后来可用于预测和预防。其次,我们对220名参与者在亚马逊机械土耳其人上进行了一项用户研究:我们总结了类别的测量研究结果,以现实的环境呈现它们,并评估用户的理解,关注和采取行动的意愿。据我们所知,我们的用户研究是第一个以这种精细的粒度和实际(不仅仅是潜在或允许)在移动设备上的隐私暴露的收集和分析用户输入的人。尽管许多用户最初并不了解其PII的全部含义,但是在通过研究中得到更好的了解后,他们对更好的隐私惯例感到欣赏和感兴趣。
Mobile devices have access to personal, potentially sensitive data, and there is a large number of mobile applications and third-party libraries that transmit this information over the network to remote servers (including app developer servers and third party servers). In this paper, we are interested in better understanding of not just the extent of personally identifiable information (PII) exposure, but also its context i.e., functionality of the app, destination server, encryption used, etc.) and the risk perceived by mobile users today. To that end we take two steps. First, we perform a measurement study: we collect a new dataset via manual and automatic testing and capture the exposure of 16 PII types from 400 most popular Android apps. We analyze these exposures and provide insights into the extent and patterns of mobile apps sharing PII, which can be later used for prediction and prevention. Second, we perform a user study with 220 participants on Amazon Mechanical Turk: we summarize the results of the measurement study in categories, present them in a realistic context, and assess users' understanding, concern, and willingness to take action. To the best of our knowledge, our user study is the first to collect and analyze user input in such fine granularity and on actual (not just potential or permitted) privacy exposures on mobile devices. Although many users did not initially understand the full implications of their PII being exposed, after being better informed through the study, they became appreciative and interested in better privacy practices.