Styx: Privacy risk communication for the Android smartphone platform based on apps' data-access behavior patterns. Issue 53 (September 2015)
- Record Type:
- Journal Article
- Title:
- Styx: Privacy risk communication for the Android smartphone platform based on apps' data-access behavior patterns. Issue 53 (September 2015)
- Main Title:
- Styx: Privacy risk communication for the Android smartphone platform based on apps' data-access behavior patterns
- Authors:
- Bal, Gökhan
Rannenberg, Kai
Hong, Jason I. - Abstract:
- Abstract: Modern smartphone platforms offer a multitude of useful features to their users but at the same time they are highly privacy affecting. However, smartphone platforms are not effective in properly communicating privacy risks to their users. Furthermore, common privacy risk communication approaches in smartphone app ecosystems do not consider the actual data-access behavior of individual apps in their risk assessments. Beyond privacy risks such as the leakage of single information (first-order privacy risk), we argue that privacy risk assessments and risk communication should also consider threats to user privacy coming from user-profiling and data-mining capabilities based on the long-term data-access behavior of apps (second-order privacy risk). In this paper, we introduce Styx, a novel privacy risk communication system for Android that provides users with privacy risk information based on the second-order privacy risk perspective. We discuss results from an experimental evaluation of Styx regarding its effectiveness in risk communication and its effects on user perceptions such as privacy concerns and the trustworthiness of a smartphone. Our results suggest that privacy risk information provided by Styx improves the comprehensibility of privacy risk information and helps the users in comparing different apps regarding their privacy properties. The results further suggest that an improved privacy risk communication on smartphones can increase trust towards aAbstract: Modern smartphone platforms offer a multitude of useful features to their users but at the same time they are highly privacy affecting. However, smartphone platforms are not effective in properly communicating privacy risks to their users. Furthermore, common privacy risk communication approaches in smartphone app ecosystems do not consider the actual data-access behavior of individual apps in their risk assessments. Beyond privacy risks such as the leakage of single information (first-order privacy risk), we argue that privacy risk assessments and risk communication should also consider threats to user privacy coming from user-profiling and data-mining capabilities based on the long-term data-access behavior of apps (second-order privacy risk). In this paper, we introduce Styx, a novel privacy risk communication system for Android that provides users with privacy risk information based on the second-order privacy risk perspective. We discuss results from an experimental evaluation of Styx regarding its effectiveness in risk communication and its effects on user perceptions such as privacy concerns and the trustworthiness of a smartphone. Our results suggest that privacy risk information provided by Styx improves the comprehensibility of privacy risk information and helps the users in comparing different apps regarding their privacy properties. The results further suggest that an improved privacy risk communication on smartphones can increase trust towards a smartphone and reduce privacy concern. Highlights: We conceptualize long-term privacy risks of smartphone app usage. We design Styx, a new privacy risk communication system for Android. We experimentally evaluate the effectiveness of Styx regarding risk communication. Styx provides more comprehensible privacy-risk information. Styx improves users' risk and trust perceptions and eases the comparison of apps. … (more)
- Is Part Of:
- Computers & security. Issue 53(2015)
- Journal:
- Computers & security
- Issue:
- Issue 53(2015)
- Issue Display:
- Volume 53, Issue 53 (2015)
- Year:
- 2015
- Volume:
- 53
- Issue:
- 53
- Issue Sort Value:
- 2015-0053-0053-0000
- Page Start:
- 187
- Page End:
- 202
- Publication Date:
- 2015-09
- Subjects:
- Smartphone privacy -- Privacy risk communication -- Privacy behavior -- Human factors -- Experimental research -- Information-flow monitoring
Computer security -- Periodicals
Electronic data processing departments -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.sciencedirect.com/science/journal/01674048 ↗
http://www.elsevier.com/journals ↗ - DOI:
- 10.1016/j.cose.2015.04.004 ↗
- Languages:
- English
- ISSNs:
- 0167-4048
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - 3394.781000
British Library DSC - BLDSS-3PM
British Library HMNTS - ELD Digital store - Ingest File:
- 895.xml