论文标题
移动心理健康应用:替代干预还是入侵?
Mobile Mental Health Apps: Alternative Intervention or Intrusion?
论文作者
论文摘要
心理健康是一个极为重要的主题,尤其是在Covid-19-19大流行的这些史无前例的时期。无处不在的手机可以使用户能够补充精神病治疗并管理其心理健康。移动心理健康(MMH)应用程序是一种有效的替代方法,可帮助患有越来越多的心理疾病,填补了急需的患者提供者的可及性差距。但是,这也引起了敏感信息泄漏的重大关注。缺乏透明的隐私政策和缺乏用户意识可能会对破坏这种工具的适用性构成重大威胁。我们进行了一项多胎研究-1)隐私政策(手动和使用Polisis,一个自动化的框架来评估隐私政策); 2)应用权限; 3)固有安全问题的静态分析; 4)威胁表面和漏洞检测的动态分析,以及5)流量分析。 我们的结果表明,应用程序的可剥削缺陷,危险的许可和不安全的数据处理对用户的隐私和安全构成了潜在的威胁。动态分析确定了20个顶级MMH应用程序中的145个漏洞,攻击者和恶意应用程序可以访问敏感信息。 45%的MMH应用程序使用唯一的标识符,硬件ID,可以将唯一ID链接到特定用户并探测用户的心理健康。交通分析表明,敏感的心理健康数据可以通过不安全的数据传输泄漏。 MMH应用程序需要更好地审查和法规,以进行更广泛的用法,以满足日益增长的心理保健需求,而不会受到已经脆弱的人群的影响。
Mental health is an extremely important subject, especially in these unprecedented times of the COVID-19 pandemic. Ubiquitous mobile phones can equip users to supplement psychiatric treatment and manage their mental health. Mobile Mental Health (MMH) apps emerge as an effective alternative to assist with a broad range of psychological disorders filling the much-needed patient-provider accessibility gap. However, it also raises significant concerns with sensitive information leakage.The absence of a transparent privacy policy and lack of user awareness may pose a significant threat to undermining the applicability of such tools. We conducted a multifold study of - 1) Privacy Policies (Manually and with Polisis, an automated framework to evaluate privacy policies); 2) App permissions; 3) Static Analysis for inherent security issues; 4) Dynamic Analysis for threat surface and vulnerabilities detection, and 5) Traffic Analysis. Our results indicate that apps' exploitable flaws, dangerous permissions, and insecure data handling pose a potential threat to the users' privacy and security. The Dynamic analysis identified 145 vulnerabilities in 20 top-rated MMH apps where attackers and malicious apps can access sensitive information. 45% of MMH apps use a unique identifier, Hardware Id, which can link a unique id to a particular user and probe users' mental health. Traffic analysis shows that sensitive mental health data can be leaked through insecure data transmission. MMH apps need better scrutiny and regulation for more widespread usage to meet the increasing need for mental health care without being intrusive to the already vulnerable population.