Static Analysis for Android GDPR Compliance Assurance

被引:0
|
作者
Khedkar, Mugdha [1 ]
机构
[1] Paderborn Univ, Heinz Nixdorf Inst, Paderborn, Germany
关键词
static analysis; data protection and privacy; GDPR compliance;
D O I
10.1109/ICSE-COMPANION58688.2023.00054
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Many Android applications collect data from users. When they do, they must protect this collected data according to the current legal frameworks. Such data protection has become even more important since the European Union rolled out the General Data Protection Regulation (GDPR). App developers have limited tool support to reason about data protection throughout their app development process. Although many Android applications state a privacy policy, privacy policy compliance checks are currently manual, expensive, and prone to error. One of the major challenges in privacy audits is the significant gap between legal privacy statements (in English text) and technical measures that Android apps use to protect their user's privacy. In this thesis, we will explore to what extent we can use static analysis to answer important questions regarding data protection. Our main goal is to design a tool based approach that aids app developers and auditors in ensuring data protection in Android applications, based on automated static program analysis.
引用
收藏
页码:197 / 199
页数:3
相关论文
共 50 条
  • [1] An Empirical Evaluation of GDPR Compliance Violations in Android mHealth Apps
    Fan, Ming
    Yu, Le
    Chen, Sen
    Zhou, Hao
    Luo, Xiapu
    Li, Shuyue
    Liu, Yang
    Liu, Jun
    Liu, Ting
    [J]. 2020 IEEE 31ST INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE 2020), 2020, : 253 - 264
  • [2] Analysis of solutions for a blockchain compliance with GDPR
    Godyn, Mateusz
    Kedziora, Michal
    Ren, Yingying
    Liu, Yongxin
    Song, Houbing Herbert
    [J]. SCIENTIFIC REPORTS, 2022, 12 (01)
  • [3] Analysis of solutions for a blockchain compliance with GDPR
    Mateusz Godyn
    Michal Kedziora
    Yingying Ren
    Yongxin Liu
    Houbing Herbert Song
    [J]. Scientific Reports, 12
  • [4] GDPR Compliance Assessment for Cross-Border Personal Data Transfers in Android Apps
    Guaman, Danny S.
    Del Alamo, Jose M.
    Caiza, Julio C.
    [J]. IEEE ACCESS, 2021, 9 : 15961 - 15982
  • [5] The road to gdpr compliance
    Barclay, Corlane
    [J]. ISACA Journal, 2019, 1 : 24 - 29
  • [6] GDPR Compliance: The IT Role
    Vedula, Murty
    [J]. ITNOW, 2019, 61 (01) : 44 - 45
  • [7] Automated GDPR compliance assessment for cross-border personal data transfers in android applications
    Guaman, Danny S.
    Rodriguez, David
    del Alamo, Jose M.
    Such, Jose
    [J]. COMPUTERS & SECURITY, 2023, 130
  • [8] Static analysis of Android programs
    Payet, Etienne
    Spoto, Fausto
    [J]. INFORMATION AND SOFTWARE TECHNOLOGY, 2012, 54 (11) : 1192 - 1201
  • [9] Static Analysis of Android Programs
    Payet, Etienne
    Spoto, Fausto
    [J]. AUTOMATED DEDUCTION - CADA-23, 2011, 6803 : 439 - 445
  • [10] Static analysis and software assurance
    Wagner, D
    [J]. STATIC ANALYSIS, PROCEEDINGS, 2001, 2126 : 431 - 431