Inspection method of data minimization compliance for cross-user privacy sharing behavior in mobile social applications
Online published: 2024-11-16
Copyright
The social interaction functions provided by mobile social applications (apps) allow users to easily obtain the personal information of other users, thereby promoting cross-user privacy sharing. According to the data minimization principle stipulated in relevant laws and regulations, the personal information shared by the application should be limited to the minimum scope necessary to the display function. Therefore, personal information not stated in the privacy policy and not displayed on the user interface shall not be shared. However, security communities barely pay attention to the compliance of cross-user privacy sharing. Therefore, an automated compliance detection system was designed to use privacy policies and user interfaces as the basis for determining whether the data minimization principle is met in cross-user privacy sharing behaviors. According to the compliance inspection results of 509 mobile social apps, which each app is dynamically tested for 20 minutes, a total of 101 unique violations of privacy sharing behaviors was found in 47 mobile apps, involving 18 types of user privacy data. Through manual verification, it was confirmed that 91.09% violations of privacy sharing behaviors actually exist. Experimental results show that the system performs well in both precision and recall compared to previous work.
ZHU Qirui , CHEN Ronghua , YANG Zhemin , LI Shuai , ZHANG Yuan , YANG Min . Inspection method of data minimization compliance for cross-user privacy sharing behavior in mobile social applications[J]. Journal of Cybersecurity, 2024 , 2(3) : 3 -12 . DOI: 10.20172/j.issn.2097-3136.240301
表 1 系统性能评估Table 1 Performance of system |
| TP | FP | TN | FN | precision | recall | |
| 违规应用 | 40 | 7 | — | — | 85.11% | 90.91% |
| 合规应用 | — | — | 43 | 4 |
| 1 |
ANDOW B,MAHMUD S Y,WANG W,et al. Policylint:investigating internal privacy policy contradictions on Google play[C]// 28th USENIX Conference on Security Symposium. USA:USENIX Association,2019:585-602.
|
| 2 |
YU L, LUO X, CHEN J, et al. PPChecker: Towards accessing the trustworthiness of android Apps' privacy policies[J]. IEEE Transactions on Software Engineering, 2018, 47 (2): 1- 1.
|
| 3 |
ANDOW B,MAHMUD S Y,WHITAKER J,et al. Actions speak louder than words:Entity-sensitive privacy policy and data flow analysis with POLICHECK[C]// 29th USENIX Conference on Security Symposium. USA:USENIX Association,2020:985-1002.
|
| 4 |
程啸. 隐私政策的性质与法律规制[J/OL]. (2022-07-05)[2024-01-22]. http://www.legaldaily.com.cn/IT/content/2022-07/05/content_8743317.html.
CHENG X. The nature and legal regulation of the privacy policy[J/OL]. (2022-07-05)[2024-01-22]. http://www.legaldaily.com.cn/IT/content/2022-07/05/content_8743317.html.
|
| 5 |
MU Z,YUE D,QIAN F,et al. Towards automatic generation of security-centric descriptions for android apps[C]// ACM Sigsac Conference on Computer & Communications Security. New York:ACM,2015:518-529.
|
| 6 |
LE Y, TAO Z, LUO X, et al. Toward automatically generating privacy policy for android apps[J]. IEEE Transactions on Information Forensics & Security, 2017, 12 (4): 865- 880.
|
| 7 |
PANDITA R,XIAO X,WEI Y,et al. WHYPER:Towards automating risk assessment of mobile applications[C]// 22nd USENIX conference on Security. USA:USENIX Association,2013:527-542.
|
| 8 |
QU Z,RASTOGI V,ZHANG X,et al. Autocog:Measuring the description-to-permission fidelity in android applications[C]// 2014 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2014:1354-1365.
|
| 9 |
SLAVIN R,WANG X,HOSSEINI M B,et al. Toward a framework for detecting privacy policy violations in android application code[C]// 38th International Conference on Software Engineering. New York:ACM,2016:25-36.
|
| 10 |
WANG X,QIN X,HOSSEINI M B,et al. GUILeak:Tracing privacy policy claims on user input data for Android applications[C]//International Conference on Software Engineering. New York:ACM,2018:37-47.
|
| 11 |
ZIMMECK S,WANG Z,ZOU L,et al. Automated analysis of privacy requirements for mobile apps[C]// Network and Distributed System Security Symposium,2017.
|
| 12 |
REN J,RAO A,LINDORFER M,et al. ReCon:Revealing and controlling PII leaks in mobile network traffic[C]// 14th Annual International Conference on Mobile Systems,Applications,and Services. New York:ACM,2015:361-374.
|
| 13 |
CONTINELLA A,FRATANTONIO Y,LINDORFER M,et al. Obfuscation-resilient privacy leak detection for mobile apps through differential analysis[C]// Network and Distributed System Security Symposium,2017.
|
| 14 |
LI S,YANG Z,HUA N,et al. Collect responsibly but deliver arbitrarily? A study on cross-user privacy leakage in mobile apps[C]// 2022 ACM SIGSAC Conference on Computer and Communications Security. New York:ACM,2022:1887-1900.
|
| 15 |
KOCH W,CHAABANE A,EGELE M,et al. Semi-automated discovery of server-based information oversharing vulnerabi-lities in Android applications[C]// 26th ACM SIGSOFT International Symposium on Software Testing and Analysis. New York:ACM,2017:147-157.
|
| 16 |
LI Y,YANG Z,YAO G,et al. DroidBot:A lightweight UI-guided test input generator for android[C]// 2017 IEEE/ACM 39th International Conference on Software Engineering Companion (ICSE-C). New York:ACM,2017:23-26.
|
| 17 |
ALDO C,MAXIMILIAN H,THOMAS K. Mitmproxy - an interactive HTTPS proxy[DB/OL]. (2024-01-04)[2024-01-22]. https://mitmproxy.org/.
|
| 18 |
HUANG J ,LI Z ,XIAO X ,et al. Supor:precise and scalable sensitive user input detection for android apps[C]// Usenix Conference on Security Symposium. USA:USENIX Association,2015:977-992.
|
| 19 |
HUANG J,ZHANG X,TAN L. Detecting sensitive data disclosure via bi-directional text correlation analysis[C]// 24th ACM SIGSOFT International Symposium on Foundations of Software Engineering. New York:ACM,2016:169-180.
|
| 20 |
NAN Y,YANG M,YANG Z,et al. UIPi-cker:User-input privacy identification in mobile applications[C]// Usenix Co-nference on Security Symposium. USA:USENIX Association,2015:993-1008.
|
| 21 |
NAN Y,YANG Z,WANG X,et al. Finding clues for your secrets:semantics-driven,learning-based privacy discovery in mobile Apps[C]// Network and Distributed System Security Symposium,2018.
|
| 22 |
MILLER G A. WordNet: A lexical database for English[J]. Communications of the ACM 38, 1995, 38 (11): 39- 41.
|
| 23 |
SPEER R,CHIN J,HAVASI C. ConceptNet 5.5:An open multilingual graph of general knowledge[C]// National Conference on Artificial Intelligence. AAAI Press,2017:4444-4451.
|
| 24 |
DEVLIN J,CHANG M W,LEE K,et al. BERT:Pretraining of deep bidirectional transformers for language understa-nding[C]// North American Chapter of the Association for Computational Linguistics,2018:4171-4186.
|
| 25 |
ZHANG T,WU F,KATIYAR A,et al. Revisiting few-sample BERT fine-tuning[C]// 9th International Conference on Learning Representations,2021.
|
| 26 |
DODGE J,ILHARCO G,SCHWARTZ R,et al. Fine-tuning pretrained language models:weight initializations,data orders,and early stopping[J]. ArXiv Preprint ArXiv,2020:2002.06305.
|
| 27 |
YOSINSKI J,CLUNE J,BENGIO Y,et al. How transferable are features in deep neural networks?[C]// 27th International Conference on Neural Information Processing Systems. USA:MIT Press,2014:3320-3328.
|
| 28 |
JIAO X,YIN Y,SHANG L,et al. TinyB-ERT:Distilling BERT for natural language understanding[C]// Findings of the Association for Computational Linguistic. Association for Computational Linguistics,2020:4163-4174.
|
| 29 |
REGINA M,MEYER M,GOUTAL S. Text data augmentation:Towards better detection of spear-phishing emails[J]. ArXiv Preprint ArXiv,2020:2007.02033.
|
| 30 |
XIE Q,DAI Z,HOVY E,et al. Unsupervised data augmentation for consistency training[C]// Neural Information Processing Systems. New York:Curran Associates Inc,2020:6256-6268.
|
| 31 |
OpenAI. Introducing ChatGPT[EB/OL]. (2022-11-30)[2024-01-22]. https://openai.com/index/chatgpt/.
|
/
| 〈 |
|
〉 |