Analyzing privacy policies through syntax-driven semantic analysis of information types

Analyzing privacy policies through syntax-driven semantic analysis of information types
复制标题

DOI:
10.1016/j.infsof.2021.106608
复制
发表时间:
2021-05-12
影响因子:
3.9
通讯作者:
Wang, Xiaoyin
Wang, Xiaoyin
中科院分区:
计算机科学2区
文献类型:
--
作者:
Hosseini, Mitra Bokaei;Breaux, Travis D.;Wang, Xiaoyin

文献摘要

被引文献

相似文献

背景:几项政府法律和应用程序市场,如Google Play,要求向用户披露应用程序数据做法。这些数据实践构成了关键的隐私要求声明,因为它们支撑了应用程序的功能,同时描述了如何收集、使用各种个人信息类型以及与谁共享这些信息类型。目标:在涉及信息类型的需求声明中抽象和含糊的术语(例如,“我们收集您的设备信息”)可能会减少应用程序开发人员、策略作者和用户之间的共同理解。方法:为了解决这一挑战,我们提出了一种语法驱动的方法,首先使用上下文无关语法将给定的信息类型短语(例如移动设备标识符)解析为其组成部分,然后使用语义规则推断组成部分之间的语义关系。给定短语及其成分之间的推断语义关系生成了对短语的概括性和多义性进行建模的层次结构。通过这种方法,我们从由一组信息类型短语组成的词典中推断关系,以填充部分本体。得到的本体是一个知识图谱,可以用来指导需求作者选择最合适的信息类型术语。结果:我们使用两个标准来评估方法的性能:(1)专家对信息类型之间关系的评估;(2)非专家对信息类型之间关系的偏好。结果表明,与先前提出的方法相比,性能有所提高。考虑到从不同的数据实践中提取的信息类型(例如,收集、使用、共享等),我们还评估了该方法的可靠性。在不同应用领域的移动或基于网络的应用程序的隐私策略中。贡献:考虑到来自不同应用领域和数据实践的信息类型,该方法的平均准确率为%,召回率为87%。根据这些结果,我们得出结论,该方法可以可靠地推广到推理关系和减少隐私策略中的模糊性和抽象性。
Context: Several government laws and app markets, such as Google Play, require the disclosure of app data practices to users. These data practices constitute critical privacy requirements statements, since they underpin the app's functionality while describing how various personal information types are collected, used, and with whom they are shared.Objective: Abstract and ambiguous terminology in requirements statements concerning information types (e.g., "we collect your device information"), can reduce shared understanding among app developers, policy writers, and users.Method: To address this challenge, we propose a syntax-driven method that first parses a given information type phrase (e.g. mobile device identifier) into its constituents using a context-free grammar and second infers semantic relationships between constituents using semantic rules. The inferred semantic relationships between a given phrase and its constituents generate a hierarchy that models the generality and ambiguity of phrases. Through this method, we infer relations from a lexicon consisting of a set of information type phrases to populate a partial ontology. The resulting ontology is a knowledge graph that can be used to guide requirements authors in the selection of the most appropriate information type terms.Results: We evaluate the method's performance using two criteria: (1) expert assessment of relations between information types; and (2) non-expert preferences for relations between information types. The results suggest performance improvement when compared to a previously proposed method. We also evaluate the reliability of the method considering the information types extracted from different data practices (e.g., collection, usage, sharing, etc.) in privacy policies for mobile or web-based apps in various app domains.Contributions: The method achieves average of 89% precision and 87% recall considering information types from various app domains and data practices. Due to these results, we conclude that the method can be generalized reliably in inferring relations and reducing the ambiguity and abstraction in privacy policies.