USENIX Security2020Top-tier venue
Actions Speak Louder than Words: Entity-Sensitive Privacy Policy and Data Flow Analysis with PoliCheck
Benjamin Andow, Samin Yaseer Mahmud, Justin Whitaker, William Enck, Bradley Reaves, Kapil Singh, Serge Egelman
Abstract
Identifying privacy-sensitive data leaks by mobile applications has been a topic of great research interest for the past decade. Technically, such data flows are not "leaks" if they are disclosed in a privacy policy. To address this limitation in automated analysis, recent work has combined program analysis of applications with analysis of privacy policies to determine the flow-to-policy consistency, and hence violations thereof. However, this prior work has a fundamental weakness: it does not differentiate the entity (e.g., first-party vs. third-party) receiving the privacy-sensitive data. In this paper, we propose POLICHECK, which formalizes and implements an entity-sensitive flow-to-policy consistency model. We use POLICHECK to study 13,796 applications and their privacy policies and find that up to 42.4% of applications either incorrectly disclose or omit disclosing their privacy-sensitive data flows. Our results also demonstrate the significance of considering entities: without considering entity, prior approaches would falsely classify up to 38.4% of applications as having privacy-sensitive data flows consistent with their privacy policies. These false classifications include data flows to thirdparties that are omitted (e.g., the policy states only the firstparty collects the data type), incorrect (e.g., the policy states the third-party does not collect the data type), and ambiguous (e.g., the policy has conflicting statements about the data type collection). By defining a novel automated, entity-sensitive flow-to-policy consistency analysis, POLICHECK provides the highest-precision method to date to determine if applications properly disclose their privacy-sensitive behaviors.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 5465101d-f855-46ea-8477-c661cf18d68fCited by top-tier papers58
- Share First, Ask Later (or Never?) Studying Violations of GDPR's Explicit Consent in Android AppsTrung Tin Nguyen, Michael Backes, Ninja Marnau, Ben StockUSENIX Security 2021 · 70 citations
- Understanding Malicious Cross-library Data Harvesting on AndroidJice Wang, Yue Xiao, Xueqiang Wang, Yuhong Nan et al.USENIX Security 2021 · 41 citations
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi et al.CCS 2021 · 41 citations
- Privacy Perceptions of Custom GPTs by Users and CreatorsRongjun Ma, Caterina Maidhof, Juan Carlos Carrillo, Janne Lindqvist et al.CHI 2025 · 35 citations
- Freely Given Consent?: Studying Consent Notice of Third-Party Tracking and Its Violations of GDPR in Android AppsTrung Tin Nguyen, Michael Backes, Ben StockCCS 2022 · 32 citations
Builds on4
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub et al.USENIX Security 2018 · 400 citations
- Apps, Trackers, Privacy, and Regulators: A Global Study of the Mobile Tracking EcosystemAbbas Razaghpanah, Rishab Nithyanand, Narseo Vallina-Rodriguez, Srikanth Sundaresan et al.NDSS 2018 · 271 citations
- Automated Analysis of Privacy Requirements for Mobile AppsSebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar et al.NDSS 2017 · 255 citations
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker et al.USENIX Security 2019 · 185 citations
Related papers
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 20 citations
- Investigating Documented Privacy Changes in Android OSChuan Yan, Mark Huasong Meng, Fuman Xie, Guangdong BaiFSE 2024 · 6 citations
- Giving without Notifying: Assessing Compliance of Data Transmission in Android AppsMing Fan, Jifei Shi, Yin Wang, Le Yu et al.ASE 2024 · 4 citations
- PolicyChecker: Analyzing the GDPR Completeness of Mobile Apps' Privacy PoliciesAnhao Xiang, Weiping Pei, Chuan YueCCS 2023 · 24 citations
- Withdrawing is believing? Detecting Inconsistencies between Withdrawal Choices and Third-party Data Collections in Mobile AppsXiaolin Du, Zhemin Yang, Jiapeng Lin, Yinzhi Cao et al.S&P 2024 · 8 citations
