142 47

Enhancing Fidelity of Description in Android Apps With Category-Based Common Permissions

Title
Enhancing Fidelity of Description in Android Apps With Category-Based Common Permissions
Author
Scott Uk-Jin Lee
Keywords
Random variables; Libraries; Semantics; Thesauri; Security; Internet; Smart phones; Android; app description; categorical common permissions; fidelity assessment; permission relation graph
Issue Date
2021-08
Publisher
Institute of Electrical and Electronics Engineers Inc.
Citation
IEEE Access, v. 9, article no. 9496656, Page. 105493.0-105505.0
Abstract
Application description analysis is applied for various purposes in software engineering domains. Besides the inherent challenges from the ambiguity of natural language, sparse permission semantics raise the difficulties of predicting functionalities and permission usages from app descriptions. More specifically, the functionalities common to the app's category are intentionally abbreviated by developers due to the limited number of characters, and the permissions are often over-claimed. These are the main reasons that cause false positives in predicting permissions from app descriptions. Such unmentioned permissions can only be detected as suspicious in previous studies where effective assistance for developers in refining app descriptions and preventing potential security risks is not provided. In this paper, we propose the FideDroid, a framework to identify category-based common permissions to offset those essential functionalities while assessing the fidelity of app descriptions. Our framework augments the labeled dataset of app descriptions to improve the prediction of permissions. FideDroid compares inferred permissions with used ones to reveal the suspicious and unnecessary permissions based on the prediction. It helps developers to refine app descriptions and maintain permission usages. In our experiments on large real-world apps, we analyzed and revealed that the category-based common permissions may cover more unmentioned functionalities without considering all possible permissions during app description analysis. In addition, we discovered three factors causing the inconsistency between descriptions and permission usages to be: 1) human interventions in writing description; 2) bad practices on permission usages; and 3) prolific developers. These findings will facilitate developers to refine app descriptions and optimize permission usages in the apps.
URI
https://www.scopus.com/record/display.uri?eid=2-s2.0-85112660532&origin=inward&txGid=f2d708a71443f6e9b3144afa8fe85e2ehttps://repository.hanyang.ac.kr/handle/20.500.11754/187949
ISSN
2169-3536
DOI
10.1109/ACCESS.2021.3100118
Appears in Collections:
ETC[S] > ETC
Files in This Item:
109309_Scott Uk-Jin Lee.pdfDownload
Export
RIS (EndNote)
XLS (Excel)
XML


qrcode

Items in DSpace are protected by copyright, with all rights reserved, unless otherwise indicated.

BROWSE