GUILeak: Tracing Privacy Policy Claims on User Input Data for Android Applications

Xiaoyin Wang, Xue Qin, M. Hosseini, Rocky Slavin, T. Breaux, Jianwei Niu
{"title":"GUILeak: Tracing Privacy Policy Claims on User Input Data for Android Applications","authors":"Xiaoyin Wang, Xue Qin, M. Hosseini, Rocky Slavin, T. Breaux, Jianwei Niu","doi":"10.1145/3180155.3180196","DOIUrl":null,"url":null,"abstract":"The Android mobile platform supports billions of devices across more than 190 countries around the world. This popularity coupled with user data collection by Android apps has made privacy protection a well-known challenge in the Android ecosystem. In practice, app producers provide privacy policies disclosing what information is collected and processed by the app. However, it is difficult to trace such claims to the corresponding app code to verify whether the implementation is consistent with the policy. Existing approaches for privacy policy alignment focus on information directly accessed through the Android platform (e.g., location and device ID), but are unable to handle user input, a major source of private information. In this paper, we propose a novel approach that automatically detects privacy leaks of user-entered data for a given Android app and determines whether such leakage may violate the app's privacy policy claims. For evaluation, we applied our approach to 120 popular apps from three privacy-relevant app categories: finance, health, and dating. The results show that our approach was able to detect 21 strong violations and 18 weak violations from the studied apps.","PeriodicalId":6560,"journal":{"name":"2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)","volume":"63 1","pages":"37-47"},"PeriodicalIF":0.0000,"publicationDate":"2018-05-27","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"69","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2018 IEEE/ACM 40th International Conference on Software Engineering (ICSE)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1145/3180155.3180196","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 69

Abstract

The Android mobile platform supports billions of devices across more than 190 countries around the world. This popularity coupled with user data collection by Android apps has made privacy protection a well-known challenge in the Android ecosystem. In practice, app producers provide privacy policies disclosing what information is collected and processed by the app. However, it is difficult to trace such claims to the corresponding app code to verify whether the implementation is consistent with the policy. Existing approaches for privacy policy alignment focus on information directly accessed through the Android platform (e.g., location and device ID), but are unable to handle user input, a major source of private information. In this paper, we propose a novel approach that automatically detects privacy leaks of user-entered data for a given Android app and determines whether such leakage may violate the app's privacy policy claims. For evaluation, we applied our approach to 120 popular apps from three privacy-relevant app categories: finance, health, and dating. The results show that our approach was able to detect 21 strong violations and 18 weak violations from the studied apps.
追踪Android应用程序用户输入数据的隐私政策索赔
Android移动平台支持全球190多个国家的数十亿台设备。这种受欢迎程度加上Android应用收集用户数据,使得隐私保护成为Android生态系统中一个众所周知的挑战。在实践中,应用程序生产者提供了隐私政策,披露了应用程序收集和处理的信息。然而,很难将这些声明追溯到相应的应用程序代码,以验证其实现是否与政策一致。现有的隐私政策调整方法侧重于通过Android平台直接访问的信息(例如,位置和设备ID),但无法处理用户输入,这是私人信息的主要来源。在本文中,我们提出了一种新方法,可以自动检测给定Android应用程序的用户输入数据的隐私泄露,并确定这种泄漏是否可能违反应用程序的隐私政策声明。为了进行评估,我们将我们的方法应用于120个流行的应用程序,这些应用程序来自三个与隐私相关的应用程序类别:金融、健康和约会。结果表明,我们的方法能够从研究的应用程序中检测到21个强违规和18个弱违规。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 求助全文
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信