Skip to main content
QUICK REVIEW

[论文解读] Analyzing Confidentiality and Privacy Concerns: Insights from Android Issue Logs

Sherlock A. Licorish, Stephen G. MacDonell|arXiv (Cornell University)|Feb 24, 2021
Privacy, Security, and Data Protection参考文献 24被引用 7
一句话总结

本研究通过情境分析,分析过去三个主要版本的Android问题日志中关于机密性和隐私性的关切,揭示利益相关者对这些议题的看法。研究发现,Jelly Bean版本中隐私与机密性问题最为普遍,主要集中在访问控制、凭证管理和手机锁定方面;同时识别出用户对安全功能的偏好存在显著差异,建议采用可配置的默认安全设置,以在可用性与保护性之间取得平衡。

ABSTRACT

Context: Post-release user feedback plays an integral role in improving software quality and informing new features. Given its growing importance, feedback concerning security enhancements is particularly noteworthy. In considering the rapid uptake of Android we have examined the scale and severity of Android security threats as reported by its stakeholders. Objective: We systematically mine Android issue logs to derive insights into stakeholder perceptions and experiences in relation to certain Android security issues. Method: We employed contextual analysis techniques to study issues raised regarding confidentiality and privacy in the last three major Android releases, considering covariance of stakeholder comments, and the level of consistency in user preferences and priorities. Results: Confidentiality and privacy concerns varied in severity, and were most prevalent over Jelly Bean releases. Issues raised in regard to confidentiality related mostly to access, user credentials and permission management, while privacy concerns were mainly expressed about phone locking. Community users also expressed divergent preferences for new security features, ranging from more relaxed to very strict. Conclusion: Strategies that support continuous corrective measures for both old and new Android releases would likely maintain stakeholder confidence. An approach that provides users with basic default security settings, but with the power to configure additional security features if desired, would provide the best balance for Android's wide cohort of stakeholders.

研究动机与目标

  • 通过发布后的反馈,理解利益相关者对Android中机密性与隐私问题的看法。
  • 识别在主要Android版本中安全关切的严重性与普遍性。
  • 研究用户对新安全功能的偏好与优先级,尤其关注隐私与访问控制方面。
  • 探讨用户反馈中不一致性的成因及其对Android安全设计的影响。
  • 为持续改进遗产版本与新版本Android的安全策略提供建议。

提出的方法

  • 系统性挖掘过去三个主要版本(Jelly Bean、Lollipop、Marshmallow)的Android问题日志。
  • 应用情境分析技术,解读利益相关者关于机密性与隐私的评论。
  • 对用户评论进行协方差分析,评估其在偏好与优先级上的一致性。
  • 将报告的问题分类为机密性问题(如访问、凭证、权限)与隐私问题(如手机锁定)。
  • 识别用户对安全功能的偏好差异,涵盖从宽松到严格的不同配置。
  • 将研究发现整合为设计建议,以实现平衡且可配置的安全默认设置。

实验结果

研究问题

  • RQ1在近期版本中,Android利益相关者报告的最常见机密性与隐私关切是什么?
  • RQ2用户对安全功能的偏好如何变化?其反馈中呈现出哪些模式?
  • RQ3隐私与机密性问题在Android主要版本中的严重性与普遍性分布如何?
  • RQ4利益相关者在表达安全增强优先级时,其评论的一致性如何?
  • RQ5哪些设计策略可实现默认安全与用户可配置性的平衡,以维持利益相关者信任?

主要发现

  • 机密性与隐私关切在Jelly Bean发布周期中最为普遍。
  • 机密性问题主要涉及访问控制、用户凭证与权限管理。
  • 隐私关切主要与手机锁定机制及用户数据暴露有关。
  • 用户对新安全功能的偏好存在显著差异,配置范围从非常严格到相对宽松不等。
  • 本研究识别出,为维护利益相关者信任,需在旧版与新版Android中持续实施纠正措施。
  • 推荐采用平衡策略——即提供强默认安全设置,同时允许用户自定义高级配置,以满足多样化用户需求。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。