Free for All! Assessing User Data Exposure to Advertising Libraries on Android

被引:19
|
作者
Demetriou, Soteris [1 ]
Merrill, Whitney [1 ]
Yang, Wei [1 ]
Zhang, Aston [1 ]
Gunter, Carl A. [1 ]
机构
[1] Univ Illinois, Champaign, IL 61820 USA
基金
美国国家科学基金会;
关键词
D O I
10.14722/ndss.2016.23082
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Many studies focused on detecting and measuring the security and privacy risks associated with the integration of advertising libraries in mobile apps. These studies consistently demonstrate the abuses of existing ad libraries. However, to fully assess the risks of an app that uses an advertising library, we need to take into account not only the current behaviors but all of the allowed behaviors that could result in the compromise of user data confidentiality. Ad libraries on Android have potential for greater data collection through at least four major channels: using unprotected APIs to learn other apps' information on the phone (e.g., app names); using protected APIs via permissions inherited from the host app to access sensitive information (e.g. Google and Facebook account information, geo locations); gaining access to files which the host app stores in its own protection domain; and observing user inputs into the host app. In this work, we systematically explore the potential reach of advertising libraries through these channels. We design a framework called Pluto that can be leveraged to analyze an app and discover whether it exposes targeted user data-such as contact information, interests, demographics, medical conditions and so on-to an opportunistic ad library. We present a prototype implementation of Pluto, that embodies novel strategies for using natural language processing to illustrate what targeted data can potentially be learned from an ad network using files and user inputs. Pluto also leverages machine learning and data mining models to reveal what advertising networks can learn from the list of installed apps. We validate Pluto with a collection of apps for which we have determined ground truth about targeted data they may reveal, together with a data set derived from a survey we conducted that gives ground truth for targeted data and corresponding lists of installed apps for about 300 users. We use these to show that Pluto, and hence also opportunistic ad networks, can achieve 75% recall and 80% precision for selected targeted data coming from app files and inputs, and even better results for certain targeted data based on the list of installed apps. Pluto is the first tool that estimates the risk associated with integrating advertising in apps based on the four available channels and arbitrary sets of targeted data.
引用
收藏
页数:15
相关论文
共 50 条
  • [1] Android Applications: Data Leaks via Advertising Libraries
    Moonsamy, Veelasha
    Batten, Lynn
    2014 INTERNATIONAL SYMPOSIUM ON INFORMATION THEORY AND ITS APPLICATIONS (ISITA), 2014, : 314 - 317
  • [2] Free and for all? A comparative study of programs with user fees in North American and Danish public libraries
    Lenstra, Noah
    Mathiasson, Mia Hoj
    LIBRARY MANAGEMENT, 2020, 41 (2/3) : 103 - 115
  • [3] An Efficient Approach to Securing User Data in Android
    Jayan, Suranya
    Sun, Jiangfeng
    Shin, Dongwan
    2017 INTERNATIONAL CONFERENCE ON INFORMATION AND COMMUNICATION TECHNOLOGY CONVERGENCE (ICTC), 2017, : 400 - 405
  • [4] User Data on Android Smartphone Must be Protected
    Andriatsimandefitra, Radoniaina
    Tong, Valerie Viet Triem
    Me, Ludovic
    ERCIM NEWS, 2012, (90): : 18 - 18
  • [5] Assessing Privacy Risks in Android: A User-Centric Approach
    Mylonas, Alexios
    Theoharidou, Marianthi
    Gritzalis, Dimitris
    RISK ASSESSMENT AND RISK-DRIVEN TESTING, RISK 2013, 2014, 8418 : 21 - 37
  • [6] User-Side Updating of Third-Party Libraries for Android Applications
    Ogawa, Hiroki
    Takimoto, Eiji
    Mouri, Koichi
    Saito, Shoichi
    2018 SIXTH INTERNATIONAL SYMPOSIUM ON COMPUTING AND NETWORKING WORKSHOPS (CANDARW 2018), 2018, : 452 - 458
  • [7] The online advertising free-riding free-for-all
    Meale, Darren
    JOURNAL OF INTELLECTUAL PROPERTY LAW & PRACTICE, 2008, 3 (12) : 779 - 787
  • [8] THE ADVERTISING EXPOSURE EFFECT OF FREE STANDING INSERTS
    SRINIVASAN, SS
    LEONE, RP
    MULHERN, FJ
    JOURNAL OF ADVERTISING, 1995, 24 (01) : 29 - 40
  • [9] Assessing the User Experience of E-Books in Academic Libraries
    Zhang, Tao
    Niu, Xi
    Promann, Marlen
    COLLEGE & RESEARCH LIBRARIES, 2017, 78 (05): : 578 - 601
  • [10] Android Smartphone Third Party Advertising Library Data Leak Analysis
    Short, Anthony
    Li, Feng
    2014 IEEE 11TH INTERNATIONAL CONFERENCE ON MOBILE AD HOC AND SENSOR SYSTEMS (MASS), 2014, : 749 - 754