题名 | Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps |
作者 | |
通讯作者 | Yu, Le |
DOI | |
发表日期 | 2023
|
会议名称 | 45th IEEE/ACM International Conference on Software Engineering (ICSE)
|
ISSN | 0270-5257
|
ISBN | 978-1-6654-5702-6
|
会议录名称 | |
页码 | 1583-1595
|
会议日期 | MAY 14-20, 2023
|
会议地点 | null,Melbourne,AUSTRALIA
|
出版地 | 10662 LOS VAQUEROS CIRCLE, PO BOX 3014, LOS ALAMITOS, CA 90720-1264 USA
|
出版者 | |
摘要 | The privacy of personal information has received significant attention in mobile software. Although researchers have designed methods to identify the conflict between app behavior and privacy policies, little is known about the privacy compliance issues relevant to third-party libraries (TPLs). The regulators enacted articles to regulate the usage of personal information for TPLs (e.g., the CCPA requires businesses clearly notify consumers if they share consumers' data with third parties or not). However, it remains challenging to investigate the privacy compliance issues of TPLs due to three reasons: 1) Difficulties in collecting TPLs' privacy policies. In contrast to Android apps, which are distributed through markets like Google Play and must provide privacy policies, there is no unique platform for collecting privacy policies of TPLs. 2) Difficulties in analyzing TPL's user privacy access behaviors. TPLs are mainly provided in binary files, such as jar or aar, and their whole functionalities usually cannot be executed independently without host apps. 3) Difficulties in identifying consistency between TPL's functionalities and privacy policies, and host app's privacy policy and data sharing with TPLs. This requires analyzing not only the privacy policies of TPLs and host apps but also their functionalities. In this paper, we propose an automated system named ATPChecker to analyze whether Android TPLs comply with the privacy-related regulations. We construct a data set that contains a list of 458 TPLs, 247 TPL's privacy policies, 187 TPL's binary files and 641 host apps and their privacy policies. Then, we analyze the bytecode of TPLs and host apps, design natural language processing systems to analyze privacy policies, and implement an expert system to identify TPL usage-related regulation compliance. The experimental results show that 23% TPLs violate regulation requirements for providing privacy policies. Over 47% TPLs miss disclosing data usage in their privacy policies. Over 65% host apps share user data with TPLs while 65% of them miss disclosing interactions with TPLs. Our findings remind developers to be mindful of TPL usage when developing apps or writing privacy policies to avoid violating regulations. |
关键词 | |
学校署名 | 其他
|
语种 | 英语
|
相关链接 | [来源记录] |
收录类别 | |
资助项目 | Hong Kong RGC Projects[
|
WOS研究方向 | Computer Science
|
WOS类目 | Computer Science, Software Engineering
; Computer Science, Theory & Methods
|
WOS记录号 | WOS:001032629800128
|
EI入藏号 | 20233914775291
|
EI主题词 | Android (operating system)
; Automation
; Behavioral research
; Data privacy
; Expert systems
; Natural language processing systems
|
EI分类号 | Ergonomics and Human Factors Engineering:461.4
; Computer Software, Data Handling and Applications:723
; Data Processing and Image Processing:723.2
; Expert Systems:723.4.1
; Automatic Control Principles and Applications:731
; Libraries:903.4.1
; Social Sciences:971
|
来源库 | Web of Science
|
全文链接 | https://ieeexplore.ieee.org/stamp/stamp.jsp?tp=&arnumber=10172865 |
引用统计 |
被引频次[WOS]:2
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/553208 |
专题 | 南方科技大学 |
作者单位 | 1.Hong Kong Polytechn Univ, Hong Kong, Peoples R China 2.Southern Univ Sci & Technol, Shenzhen, Peoples R China 3.Huazhong Univ Sci & Technol, Wuhan, Hubei, Peoples R China |
推荐引用方式 GB/T 7714 |
Zhao, Kaifa,Zhan, Xian,Yu, Le,et al. Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps[C]. 10662 LOS VAQUEROS CIRCLE, PO BOX 3014, LOS ALAMITOS, CA 90720-1264 USA:IEEE COMPUTER SOC,2023:1583-1595.
|
条目包含的文件 | 条目无相关文件。 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论