Many studies have demonstrated that mobile applications are common means to collect massive amounts of personal data. This goes unnoticed by most users, who are also unaware that many different organizations are receiving this data, even from multiple apps in parallel. This paper assesses different techniques to identify the organizations that are receiving personal data flows in the Android ecosystem, namely the WHOIS service, SSL certificates inspection, and privacy policy textual analysis. Based on our findings, we propose a fully automated method that combines the most successful techniques, achieving a 94.73% precision score in identifying the recipient organization. We further demonstrate our method by evaluating 1,000 Android apps and exposing the corporations that collect the users' personal data.
翻译:许多研究显示,移动应用程序是收集大量个人数据的共同手段,大多数用户对此视而不见,他们不知道许多不同组织正在接收这些数据,甚至从多个平行应用程序接收这些数据。本文评估了用于确定在Android生态系统中接收个人数据流动的组织的不同技术,即WHOIS服务、SSL证书检查和隐私政策文字分析。根据我们的调查结果,我们建议一种完全自动化的方法,结合最成功的技术,在确定接受组织方面达到94.73%的精确分数。我们进一步展示了我们的方法,对1,000个Android应用程序进行评估,并揭露收集用户个人数据的公司。