For an Android-powered device, its security is established such that an application, when it is installed, declares the functions and other information that it will use, and user approves or rejects the declaration according to reviewing results. The problem is that, however, it is difficult for users to completely understand the details of a declaration, and careless users may neglect the approval process. In particular, in the case that a combination of multiple functions is involved, it would be impossible for users who are unfamiliar with technical details to evaluate its risk. In this paper, we propose a system model for supporting users' approval decision when an application is installed. Our system introduces reputation based security evaluation and also employs original analyses of combinations of permissions for malicious applications. We describe an implementation of the proposed system. Our interface design introduces user centered design that is especially suitable for users who are unfamiliar with technical details. We evaluate our system by employing subjects to measure the time and precision to distinguish malwares from innocent applications. As a result, we confirmed that our proposed system is considerably effective to distinguish malwares when an applications is installed.
[1]
Jeffrey M. Voas,et al.
Building Security into Off-the-Shelf Smartphones
,
2012,
Computer.
[2]
Donald A. Norman,et al.
User Centered System Design
,
1986
.
[3]
Jan Gulliksen,et al.
User-centered System Design
,
2011
.
[4]
Toshiaki Tanaka,et al.
A Small But Non-negligible Flaw in the Android Permission Scheme
,
2010,
2010 IEEE International Symposium on Policies for Distributed Systems and Networks.
[5]
Wagner A. Kamakura,et al.
Reviewing the reviewers: The impact of individual film critics on box office performance
,
2007
.
[6]
Patrick D. McDaniel,et al.
On lightweight mobile phone application certification
,
2009,
CCS.
[7]
Bin Gu,et al.
Do online reviews matter? - An empirical investigation of panel data
,
2008,
Decis. Support Syst..