We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: On the (Un)Reliability of Privacy Policies in Android Apps

Abstract: Access to privacy-sensitive information on Android is a growing concern in the mobile community. Albeit Google Play recently introduced some privacy guidelines, it is still an open problem to soundly verify whether apps actually comply with such rules. To this aim, in this paper, we discuss a novel methodology based on a fruitful combination of static analysis, dynamic analysis, and machine learning techniques, which allows assessing such compliance. More in detail, our methodology checks whether each app i) contains a privacy policy that complies with the Google Play privacy guidelines, and ii) accesses privacy-sensitive information only upon the acceptance of the policy by the user. Furthermore, the methodology also allows checking the compliance of third-party libraries embedded in the apps w.r.t. the same privacy guidelines. We implemented our methodology in a tool, 3PDroid, and we carried out an assessment on a set of recent and most-downloaded Android apps in the Google Play Store. Experimental results suggest that more than 95% of apps access user's privacy-sensitive information, but just a negligible subset of them (around 1%) fully complies with the Google Play privacy guidelines.
Subjects: Cryptography and Security (cs.CR)
Journal reference: Proc.of the IEEE International Joint Conference on Neural Networks (IJCNN 2020)
DOI: 10.1109/IJCNN48605.2020.9206660
Cite as: arXiv:2004.08559 [cs.CR]
  (or arXiv:2004.08559v1 [cs.CR] for this version)

Submission history

From: Alessio Merlo Dr. [view email]
[v1] Sat, 18 Apr 2020 08:43:49 GMT (7281kb,D)

Link back to: arXiv, form interface, contact.