论文标题
宠物(隐私增强技术)是否可以保护智能手机? - 案例研究
Are PETs (Privacy Enhancing Technologies) Giving Protection for Smartphones? -- A Case Study
论文作者
论文摘要
借助智能手机技术增强了与我们周围世界互动的方式,它也为更容易访问我们的私人和个人信息铺平了道路。由于数百万个应用程序对用户使用的众多嵌入式传感器的存在,这已经放大了这一点。尽管移动应用程序通过新功能积极地改变了我们生活的许多方面,但其中许多应用程序都利用了大量数据,隐私应用程序,而隐私技术的一种形式可以是智能手机的有效隐私管理工具。为了防止与敏感数据的收集,存储和共享有关的漏洞,开发人员正在构建许多隐私应用程序。但是,在这个特定领域缺乏酌处权,要求进行适当的评估,以了解这些应用程序在用户中对这些应用程序的深远利用。在此过程中,我们从我们的五百二十二章中收集了最受欢迎的隐私应用程序进行了评估,以证明他们声称在技术和传统上提供的特定数据保护措施,以衡量标准。我们将其提供的安全功能作为规模,我们进行了法医实验,以指示他们在维持保护方面未能保持一致的位置。为了合理地验证评估的隐私应用程序中的安全差距,我们还使用了NIST和OWASP指南。我们认为,这项研究将有效地进行持续改进,可以被视为建立应用程序开发阶段隐私和安全措施的共同标准的基础。
With smartphone technologies enhanced way of interacting with the world around us, it has also been paving the way for easier access to our private and personal information. This has been amplified by the existence of numerous embedded sensors utilized by millions of apps to users. While mobile apps have positively transformed many aspects of our lives with new functionalities, many of these applications are taking advantage of vast amounts of data, privacy apps, a form of Privacy Enhancing Technology can be an effective privacy management tool for smartphones. To protect against vulnerabilities related to the collection, storage, and sharing of sensitive data, developers are building numerous privacy apps. However, there has been a lack of discretion in this particular area which calls for a proper assessment to understand the far-reaching utilization of these apps among users. During this process we have conducted an evaluation of the most popular privacy apps from our total collection of five hundred and twelve to demonstrate their functionality specific data protections they are claiming to offer, both technologically and conventionally, measuring up to standards. Taking their offered security functionalities as a scale, we conducted forensic experiments to indicate where they are failing to be consistent in maintaining protection. For legitimate validation of security gaps in assessed privacy apps, we have also utilized NIST and OWASP guidelines. We believe this study will be efficacious for continuous improvement and can be considered as a foundation towards a common standard for privacy and security measures for an app's development stage.