We gratefully acknowledge support from
the Simons Foundation and member institutions.
Full-text links:

Download:

Current browse context:

cs.CR

Change to browse by:

cs

References & Citations

DBLP - CS Bibliography

Bookmark

(what is this?)
CiteULike logo BibSonomy logo Mendeley logo del.icio.us logo Digg logo Reddit logo

Computer Science > Cryptography and Security

Title: Dissecting contact tracing apps in the Android platform

Abstract: Contact tracing has historically been used to retard the spread of infectious diseases, but if it is exercised by hand in large-scale, it is known to be a resource-intensive and quite deficient process. Nowadays, digital contact tracing has promptly emerged as an indispensable asset in the global fight against the coronavirus pandemic. The work at hand offers a meticulous study of all the official Android contact tracing apps deployed hitherto by European countries. Each app is closely scrutinized both statically and dynamically by means of dynamic instrumentation. Depending on the level of examination, static analysis results are grouped in two axes. The first encompasses permissions, API calls, and possible connections to external URLs, while the second concentrates on potential security weaknesses and vulnerabilities, including the use of trackers, in-depth manifest analysis, shared software analysis, and taint analysis. Dynamic analysis on the other hand collects data pertaining to Java classes and network traffic. The results demonstrate that while overall these apps are well-engineered, they are not free of weaknesses, vulnerabilities, and misconfigurations that may ultimately put the user security and privacy at risk.
Comments: Fixed issues with Figures
Subjects: Cryptography and Security (cs.CR)
Journal reference: PLOS ONE 16(5), 2021
DOI: 10.1371/journal.pone.0251867
Cite as: arXiv:2008.00214 [cs.CR]
  (or arXiv:2008.00214v5 [cs.CR] for this version)

Submission history

From: Vasileios Kouliaridis [view email]
[v1] Sat, 1 Aug 2020 08:39:53 GMT (303kb,D)
[v2] Thu, 27 Aug 2020 17:50:31 GMT (85kb,D)
[v3] Mon, 21 Sep 2020 13:45:10 GMT (88kb,D)
[v4] Mon, 17 May 2021 13:46:41 GMT (106kb,D)
[v5] Fri, 21 May 2021 07:30:58 GMT (536kb,D)

Link back to: arXiv, form interface, contact.