How Does Misconfiguration of Analytic Services Compromise Mobile Privacy?

被引:14
|
作者
Zhang, Xueling [1 ]
Wang, Xiaoyin [1 ]
Slavin, Rocky [1 ]
Breaux, Travis [2 ]
Niu, Jianwei [1 ]
机构
[1] Univ Texas San Antonio, San Antonio, TX 78249 USA
[2] Carnegie Mellon Univ, Pittsburgh, PA 15213 USA
基金
美国国家科学基金会;
关键词
Privacy; Mobile Application; Program Analysis; Analytic Services; Configuration;
D O I
10.1145/3377811.3380401
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Mobile application (app) developers commonly utilize analytic services to analyze their app users' behavior to support debugging, improve service quality, and facilitate advertising. Anonymization and aggregation can reduce the sensitivity of such behavioral data, therefore analytic services often encourage the use of such protections. However, these protections are not directly enforced so it is possible for developers to misconfigure the analytic services and expose personal information, which may cause greater privacy risks. Since people use apps in many aspects of their daily lives, such misconfigurations may lead to the leaking of sensitive personal information such as a users' real-time location, health data, or dating preferences. To study this issue and identify potential privacy risks due to such misconfigurations, we developed a semi-automated approach, Privacy-Aware Analytics Misconfiguration Detector (PAMDroid), which enables our empirical study on misconfigurations of analytic services. This paper describes a study of 1,000 popular apps using top analytic services in which we found misconfigurations in 120 apps. In 52 of the 120 apps, misconfigurations lead to a violation of either the analytic service providers' terms of service or the app's own privacy policy.
引用
收藏
页码:1572 / 1583
页数:12
相关论文
共 50 条
  • [1] Privacy in (mobile) telecommunications services
    Penders J.
    [J]. Ethics and Information Technology, 2004, 6 (4) : 247 - 260
  • [2] Privacy Preserving Profiling for Mobile Services
    Biswas, Debmalya
    Vidyasankar, Krishnamurthy
    [J]. ANT 2012 AND MOBIWIS 2012, 2012, 10 : 569 - 576
  • [3] Privacy preserving and transactional advertising for mobile services
    Biswas, Debmalya
    Vidyasankar, Krishnamurthy
    [J]. COMPUTING, 2014, 96 (07) : 613 - 630
  • [4] Privacy preserving and transactional advertising for mobile services
    Debmalya Biswas
    Krishnamurthy Vidyasankar
    [J]. Computing, 2014, 96 : 613 - 630
  • [5] Privacy for Free: How does Dataset Condensation Help Privacy?
    Dong, Tian
    Zhao, Bo
    Lyu, Lingjuan
    [J]. INTERNATIONAL CONFERENCE ON MACHINE LEARNING, VOL 162, 2022,
  • [6] Preserving Privacy in Personalized Models for Distributed Mobile Services
    Atrey, Akanksha
    Shenoy, Prashant
    Jensen, David
    [J]. 2021 IEEE 41ST INTERNATIONAL CONFERENCE ON DISTRIBUTED COMPUTING SYSTEMS (ICDCS 2021), 2021, : 875 - 886
  • [7] Privacy Preserving Framework to Support Mobile Government Services
    Almiani, Muder
    Razaque, Abdul
    Al Dmour, Ayman
    [J]. INTERNATIONAL JOURNAL OF INFORMATION TECHNOLOGY AND WEB ENGINEERING, 2016, 11 (03) : 65 - 78
  • [8] User privacy and modern mobile services: are they on the same path?
    D. Damopoulos
    G. Kambourakis
    M. Anagnostopoulos
    S. Gritzalis
    J. H. Park
    [J]. Personal and Ubiquitous Computing, 2013, 17 : 1437 - 1448
  • [9] User privacy and modern mobile services: are they on the same path?
    Damopoulos, D.
    Kambourakis, G.
    Anagnostopoulos, M.
    Gritzalis, S.
    Park, J. H.
    [J]. PERSONAL AND UBIQUITOUS COMPUTING, 2013, 17 (07) : 1437 - 1448
  • [10] How to demonstrate that eSET does not compromise the likelihood of having a baby?
    Bechoua, S.
    Astruc, K.
    Thouvenot, S.
    Girod, S.
    Chiron, A.
    Jimenez, C.
    Sagot, P.
    [J]. HUMAN REPRODUCTION, 2009, 24 (12) : 3073 - 3081