Haven't we met before? Detecting Device Fingerprinting Activity on Android Apps

被引:0
作者
Heid, Kris [1 ]
Heider, Jens [1 ]
机构
[1] Natl Res Ctr Appl Cybersecur, Fraunhofer SIT, ATHENE, Darmstadt, Germany
来源
PROCEEDINGS OF THE 2024 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2024 | 2024年
关键词
Android; Device Fingerprinting; Privacy; static analysis; dynamic analysis;
D O I
10.1145/3655693.3655695
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
This paper examines the prevalence of device fingerprinting in Android apps, a technique for apps to uniquely identify the device an app is executed on. Methods are investigated and refined to detect device fingerprinting on mobile devices. While device fingerprinting has been extensively studied for web browsers, there is limited research on its use in mobile apps and its privacy implications. The paper presents an analysis of current device fingerprinting techniques in Android apps and explores static and dynamic app analysis techniques to detect fingerprinting. Additionally, a heuristic approach is introduced and tested on the top 1000 Android apps for automatically detecting behaviour-based fingerprinting on Android devices using the spatial and temporal context of relevant API calls.
引用
收藏
页码:11 / 18
页数:8
相关论文
共 19 条
[1]  
Agarwal Yuvraj, 2013, MobiSys '13
[2]  
Chitkara Saksham, 2017, ACM Interact. Mob. Wearable Ubiquitous Technol
[3]  
Claesson Andreas, 2020, Technical Report
[4]   The Web's Sixth Sense: A Study of Scripts Accessing Smartphone Sensors [J].
Das, Anupam ;
Acar, Gunes ;
Borisov, Nikita ;
Pradeep, Amogh .
PROCEEDINGS OF THE 2018 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY (CCS'18), 2018, :1515-1532
[5]  
Egele M., 2011, NDSS, P177
[6]   TaintDroid: An Information-Flow Tracking System for Realtime Privacy Monitoring on Smartphones [J].
Enck, William ;
Gilbert, Peter ;
Han, Seungyeop ;
Tendulkar, Vasant ;
Chun, Byung-Gon ;
Cox, Landon P. ;
Jung, Jaeyeon ;
McDaniel, Patrick ;
Sheth, Anmol N. .
ACM TRANSACTIONS ON COMPUTER SYSTEMS, 2014, 32 (02)
[7]   Towards detecting device fingerprinting on iOS with API function hooking [J].
Heid, Kris ;
Andrae, Vincent ;
Heider, Jens .
PROCEEDINGS OF THE 2023 EUROPEAN INTERDISCIPLINARY CYBERSECURITY CONFERENCE, EICC 2023, 2023, :78-84
[8]  
Hils Maximilian, 2010, mitmproxy: A free and open source interactive HTTPS proxy
[9]  
Iqbal U, 2021, P IEEE S SECUR PRIV, P1143, DOI 10.1109/SP40001.2021.00017
[10]  
Kollnig K., 2022, Working Paper