Identifying Organizations Receiving Personal Data in Android Apps

被引:0
作者
Rodriguez, David [1 ]
Cozar, Miguel [1 ]
Alamo, Jose [1 ]
机构
[1] Univ Politecn Madrid, ETSI Telecomunicac, Madrid, Spain
来源
SECRYPT : PROCEEDINGS OF THE 19TH INTERNATIONAL CONFERENCE ON SECURITY AND CRYPTOGRAPHY | 2022年
关键词
Privacy; Data Protection; Personal Data; Data Controller; First-Party; Corporation; Android; Apps;
D O I
10.5220/0011290100003283
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many studies have demonstrated that mobile applications are common means to collect massive amounts of personal data. This goes unnoticed by most users, who are also unaware that many different organizations are receiving this data, even from multiple apps in parallel. This paper assesses different techniques to identify the organizations that are receiving personal data flows in the Android ecosystem, namely the WHOIS service, SSL certificates inspection, and privacy policy textual analysis. Based on our findings, we propose a fully automated method that combines the most successful techniques, achieving a 94.73% precision score in identifying the recipient organization. We further demonstrate our method by evaluating 1,000 Android apps and exposing the corporations that collect the users' personal data.
引用
收藏
页码:592 / 596
页数:5
相关论文
共 18 条
[1]  
[Anonymous], UI APPL EX MONK
[2]  
[Anonymous], TECHN OV ICANN WHOIS
[3]  
[Anonymous], SSL SURV
[4]  
[Anonymous], 2016, REG EU 2016 679 EUR
[5]  
[Anonymous], 2013, P 9 S USABLE PRIVACY, DOI DOI 10.1145/2501604.2501616
[6]  
[Anonymous], CURR ISS ICANN WHOIS
[7]  
Balebako R, 2014, The privacy and security behaviors of smartphone app developers, DOI [DOI 10.14722/USEC.2014.23006, 10.14722/usec.2014.23006]
[8]  
Cozar M., 2022, 2022 IEEE EUROPEAN S
[9]   An Analysis of Pre-installed Android Software [J].
Gamba, Julien ;
Rashed, Mohammed ;
Razaghpanah, Abbas ;
Tapiador, Juan ;
Vallina-Rodriguez, Narseo .
2020 IEEE SYMPOSIUM ON SECURITY AND PRIVACY (SP 2020), 2020, :1039-1055
[10]   GDPR Compliance Assessment for Cross-Border Personal Data Transfers in Android Apps [J].
Guaman, Danny S. ;
Del Alamo, Jose M. ;
Caiza, Julio C. .
IEEE ACCESS, 2021, 9 :15961-15982