대구한의대학교 향산도서관

상세정보

부가기능

Privacy Risks of Sensitive User Data Exposure in Mobile Ecosystems

상세 프로파일

상세정보
자료유형학위논문
서명/저자사항Privacy Risks of Sensitive User Data Exposure in Mobile Ecosystems.
개인저자Andow, Benjamin Eric.
단체저자명North Carolina State University.
발행사항[S.l.]: North Carolina State University., 2019.
발행사항Ann Arbor: ProQuest Dissertations & Theses, 2019.
형태사항164 p.
기본자료 저록Dissertations Abstracts International 81-05B.
Dissertation Abstract International
ISBN9781392811092
학위논문주기Thesis (Ph.D.)--North Carolina State University, 2019.
일반주기 Source: Dissertations Abstracts International, Volume: 81-05, Section: B.
Advisor: Reaves, Bradley
이용제한사항This item must not be sold to any third party vendors.
요약Mobile applications frequently collect and share a wide-range of privacy-sensitive user data. Such data is an extremely valuable commodity for legitimate business purposes, but also for nefarious and illicit purposes. Therefore, identifying the privacy risks of exposing privacy-sensitive user data to applications has been a topic of great research interest over the past decade. However, prior works in this domain are plagued with significant limitations that result in incomplete or imprecise approximations of the privacy risks. These limitations are mainly due to an incomplete characterization of the types of data that applications request and the context-insensitivity of their privacy policy analysis techniques, or lack thereof. In this dissertation, we characterize and identify privacy risks resulting from disclosing privacy-sensitive user data to applications, addressing much of the limitations of prior works. In particular, we analyze how privacy-sensitive user data is obtained and used, how privacy disclosures are discussed, and whether all uses of such data are disclosed. First, we characterize the space of privacy-sensitive user data sources to understand what types of data applications are requesting from users. We design and implement UiRef, an analysis framework to resolve the semantics of user input requests, and apply it to study privacy risks associated with user input requests in 50,162 Android applications from Google Play. Our analysis uncovers several concerning developer practices, including insecure exposure of account passwords and privacy violations due to non-consensual disclosures of privacysensitive user input to third parties. Second, we characterize the semantics of sharing and collection statements within privacy policies to understand how privacy practices are being disclosed. We demonstrate the importance of holistic analysis of privacy policies through our identification and formalization of self-contradictory policy statements. We design and implement PolicyLint to extract sharing and collection statements from privacy policies and identify self-contradictory policy statements. We perform a large-scale study on the privacy policies for 11,430 Android applications using PolicyLint and find that around 14.2% have potentially deceptive and ambiguous privacy policies due to self-contradictory statements. Third, we combine insights gained from our prior studies to provide a formal specification for an entity-sensitive (e.g., first-party vs. third-party) and negation-sensitive (e.g., collect vs. not collect) flow-to-policy consistency model. We design and implement POLICHECK to perform a large-scale study on 13,796 Android applications and their corresponding privacy policies and find that up to 42.4% of applications either incorrectly disclose or omit disclosing their privacy-sensitive data flows. Our characterization of the problem space, formal specifications, analysis techniques, and insights drawn from our empirical studies lay the foundation for identifying privacysensitive user data, precisely and soundly reasoning over privacy policies, and evaluating flow-to-policy consistency at scale. The findings from our empirical studies highlight significant privacy risks associated with exposing privacy-sensitive user data to applications and provide concrete examples of such cases that impact tens-to-hundreds of millions of users. Our results show the poor state of privacy disclosures for Android applications, which demonstrates the need for additional oversight and auditing by application markets and regulatory agencies. Further, our findings identify several future areas of research in assessing and preventing privacy risks, such as analyzing consent, improving the usability aspects of creating privacy policies, and introducing stronger privacy protection mechanisms.
일반주제명Computer science.
언어영어
바로가기URL : 이 자료의 원문은 한국교육학술정보원에서 제공합니다.

서평(리뷰)

  • 서평(리뷰)

태그

  • 태그

나의 태그

나의 태그 (0)

모든 이용자 태그

모든 이용자 태그 (0) 태그 목록형 보기 태그 구름형 보기
 
로그인폼