跳到主要导航 跳到搜索 跳到主要内容

Giving without Notifying: Assessing Compliance of Data Transmission in Android Apps

  • Xi'an Jiaotong University
  • Nanjing University of Posts and Telecommunications

科研成果: 书/报告/会议事项章节会议稿件同行评审

1 引用 (Scopus)

摘要

Mobile apps often access personal information to meet business needs, raising concerns about privacy breaches. Compliance detection methods are proposed to check for inconsistencies between program code and privacy policies. However, existing methods face challenges with the low efficiency of static data flow analysis tools and often neglect physical data transmission destinations.To address these issues, we propose an automated compliance detection method called GNChecker. It uses an efficient static data flow analysis technique with a segmentation strategy, significantly reducing the search scope and improving efficiency. Additionally, a fine-grained consistency detection framework is proposed by integrating static data flow and dynamic traffic flow results into a unified tuple form, i.e., (information type, transmission address). Evaluation results on 50 popular apps show that GNChecker outperforms state-of-the-art data flow analysis tools. Among 1,134 real-world apps, GNChecker identified 1,410 true non-compliant transmission behaviors in 379 apps, significantly surpassing existing compliance detection tools.

源语言英语
主期刊名Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024
出版商Association for Computing Machinery, Inc
1595-1606
页数12
ISBN(电子版)9798400712487
DOI
出版状态已出版 - 27 10月 2024
活动39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024 - Sacramento, 美国
期限: 28 10月 20241 11月 2024

出版系列

姓名Proceedings - 2024 39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024

会议

会议39th ACM/IEEE International Conference on Automated Software Engineering, ASE 2024
国家/地区美国
Sacramento
时期28/10/241/11/24

学术指纹

探究 'Giving without Notifying: Assessing Compliance of Data Transmission in Android Apps' 的科研主题。它们共同构成独一无二的指纹。

引用此