Automated Analysis of Privacy Requirements for Mobile Apps
Sebastian Zimmeck, Ziqi Wang, Lieyong Zou, Roger Iyengar, Bin Liu, Florian Schaub, Shomir Wilson, Norman M. Sadeh, Steven M. Bellovin, Joel R. Reidenberg
摘要
Mobile apps have to satisfy various privacy requirements. Notably, app publishers are often obligated to provide a privacy policy and notify users of their apps' privacy practices. But how can a user tell whether an app behaves as its policy promises? In this study we introduce a scalable system to help analyze and predict Android apps' compliance with privacy requirements. We discuss how we customized our system in a collaboration with the California Office of the Attorney General. Beyond its use by regulators and activists our system is also meant to assist app publishers and app store owners in their internal assessments of privacy requirement compliance. Our analysis of 17,991 free Android apps shows the viability of combining machine learning-based privacy policy analysis with static code analysis of apps. Results suggest that 71% of apps that lack a privacy policy should have one. Also, for 9,050 apps that have a policy, we find many instances of potential inconsistencies between what the app policy seems to state and what the code of the app appears to do. In particular, as many as 41% of these apps could be collecting location information and 17% could be sharing such with third parties without disclosing so in their policies. Overall, each app exhibits a mean of 1.83 potential privacy requirement inconsistencies. I. INTRODUCTION "We do not ask for, track, or access any location-specific information [...]." This is what Snapchat's privacy policy stated. 1 However, its Android app transmitted Wi-Fi-and cell-based location data from users' devices to analytics service providers. These discrepancies remained undetected before they eventually surfaced when a researcher examined • Part of this work was conducted while Sebastian Zimmeck was a PhD student at
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper47
- Polisis: Automated Analysis and Presentation of Privacy Policies Using Deep LearningHamza Harkous, Kassem Fawaz, Rémi Lebret, Florian Schaub 等USENIX Security 2018 · 被引用 400 次
- SmartAuth: User-Centered Authorization for the Internet of ThingsYuan Tian, Nan Zhang, Yue-Hsun Lin, XiaoFeng Wang 等USENIX Security 2017 · 被引用 231 次
- 50 Ways to Leak Your Data: An Exploration of Apps' Circumvention of the Android Permissions SystemJoel Reardon, Álvaro Feal, Primal Wijesekera, Amit Elazari Bar On 等USENIX Security 2019 · 被引用 196 次
- PolicyLint: Investigating Internal Privacy Policy Contradictions on Google PlayBenjamin Andow, Samin Yaseer Mahmud, Wenyu Wang, Justin Whitaker 等USENIX Security 2019 · 被引用 185 次
- Finding a Choice in a Haystack: Automatic Extraction of Opt-Out Statements from Privacy Policy TextVinayshekhar Bannihatti Kumar, Roger Iyengar, Namita Nisal, Yuanyuan Feng 等WWW 2020 · 被引用 93 次
它引用的顶会 Paper2
- Going Native: Using a Large-Scale Analysis of Android Apps to Create a Practical Native-Code Sandboxing PolicyVitor Monte Afonso, Paulo L. de Geus, Antonio Bianchi, Yanick Fratantonio 等NDSS 2016 · 被引用 119 次
- Free for All! Assessing User Data Exposure to Advertising Libraries on AndroidSoteris Demetriou, Whitney Merrill, Wei Yang, Aston Zhang 等NDSS 2016 · 被引用 95 次
相关 Paper
- Consistency Analysis of Data-Usage Purposes in Mobile AppsDuc Bui, Yuan Yao, Kang G. Shin, Jong-Min Choi 等CCS 2021 · 被引用 41 次
- Navigating the Privacy Compliance Maze: Understanding Risks with Privacy-Configurable Mobile SDKsYifan Zhang, Zhaojie Hu, Xueqiang Wang, Yuhui Hong 等USENIX Security 2024 · 被引用 3 次
- Navigating Developers' Quagmire: LLM-Enabled Privacy Compliance Analysis for SDK IntegrationsZhaojie Hu, Xueqiang WangS&P 2026
- PrivacyFlash Pro: Automating Privacy Policy Generation for Mobile AppsSebastian Zimmeck, Rafael Goldstein, David BarakaNDSS 2021
- PTPDroid: Detecting Violated User Privacy Disclosures to Third-Parties of Android AppsZeya Tan, Wei SongICSE 2023 · 被引用 20 次
