Reliability Analysis of Privacy Policies Using Android Static Analysis


KIPS Transactions on Computer and Communication Systems, Vol. 12, No. 1, pp. 17-24, Jan. 2023
https://doi.org/10.3745/KTCCS.2023.12.1.17,   PDF Download:
Keywords: Privacy Policy, Static Analysis, data privacy, Android Application
Abstract

Mobile apps frequently request permission to access sensitive data for user convenience. However, while using mobile applications, sensitive and personal data has been leaked even if users do not allow it. To deal with this problem, Google App Store has required developers to disclose how the mobile app handles user data in a privacy policy. However, users are not certain that the privacy policy describes all the app’s behavior. They have no choice but to rely on the privacy policy to confirm how the app uses data. This study designed a system that checks the reliability of privacy policies by analyzing the privacy policy texts and mobile apps. First, the system extracts and analyzes the privacy policy texts to check which personal data the privacy policy discloses that the mobile apps can collect. After analyzing which data apps can access using android static analysis, we compare both results to analyze the reliability of privacy policies. For the experiment, we collected the APK files and metadata of about 13K android apps registered in the Google Play Store and preprocessed the apps by four conditions. According to the comparison between privacy policies and mobile app behavior, many apps can access more personal data than disclosed in the privacy policy.


Statistics
Show / Hide Statistics

Statistics (Cumulative Counts from September 1st, 2017)
Multiple requests among the same browser session are counted as one view.
If you mouse over a chart, the values of data points will be shown.


Cite this article
[IEEE Style]
Y. Jung, "Reliability Analysis of Privacy Policies Using Android Static Analysis," KIPS Transactions on Computer and Communication Systems, vol. 12, no. 1, pp. 17-24, 2023. DOI: https://doi.org/10.3745/KTCCS.2023.12.1.17.

[ACM Style]
Yoonkyo Jung. 2023. Reliability Analysis of Privacy Policies Using Android Static Analysis. KIPS Transactions on Computer and Communication Systems, 12, 1, (2023), 17-24. DOI: https://doi.org/10.3745/KTCCS.2023.12.1.17.