Identifying organizations receiving personal data in Android Apps

04/19/2022
by   David Rodriguez, et al.
0

Many studies have demonstrated that mobile applications are common means to collect massive amounts of personal data. This goes unnoticed by most users, who are also unaware that many different organizations are receiving this data, even from multiple apps in parallel. This paper assesses different techniques to identify the organizations that are receiving personal data flows in the Android ecosystem, namely the WHOIS service, SSL certificates inspection, and privacy policy textual analysis. Based on our findings, we propose a fully automated method that combines the most successful techniques, achieving a 94.73 demonstrate our method by evaluating 1,000 Android apps and exposing the corporations that collect the users' personal data.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
07/08/2020

Security Apps under the Looking Glass: An Empirical Analysis of Android Security Apps

Third-party security apps are an integral part of the Android app ecosys...
research
12/23/2021

Statistical Feature-based Personal Information Detection in Mobile Network Traffic

With the popularity of smartphones, mobile applications (apps) have pene...
research
10/10/2022

Systematic Evaluation and User Study of Privacy of Default Apps in Apple's Mobile Ecosystem

Users need to configure default apps when they first start using their d...
research
05/11/2023

PriGen: Towards Automated Translation of Android Applications' Code to Privacy Captions

Mobile applications are required to give privacy notices to the users wh...
research
06/19/2020

A First Look at Android Applications in Google Play related to Covid-19

Due to the convenience of access-on-demand to information and business s...
research
02/25/2021

Understanding Worldwide Private Information Collection on Android

Mobile phones enable the collection of a wealth of private information, ...
research
06/26/2021

How Private is Android's Private DNS Setting? Identifying Apps by Encrypted DNS Traffic

DNS over TLS (DoT) and DNS over HTTPS (DoH) promise to improve privacy a...

Please sign up or login with your details

Forgot password? Click here to reset