Published June 8, 2019 | Version v1
Conference paper Open

A Multilateral Privacy Impact Analysis Method for Android Apps

  • 1. Goethe University Frankfurt
  • 2. Karlstad University

Description

Smartphone apps have the power to monitor most of people’s private lives. Apps can permeate private spaces, access and map social relationships, monitor whereabouts and chart people’s activities in digital and/or real world. We are therefore interested in how much information a particular app can and intends to retrieve in a smartphone. Privacy-friendliness of smartphone apps is typically measured based on single-source analyses, which in turn, does not provide a comprehensive measurement regarding the actual privacy risks of apps. This paper presents a multi-source method for privacy analysis and data extraction transparency of Android apps. We describe how we generate several data sets derived from privacy policies, app manifestos, user reviews and actual app profiling at run time. To evaluate our method, we present results from a case study carried out on ten popular fitness and exercise apps. Our results revealed interesting differences concerning the potential privacy impact of apps, with some of the apps in the test set violating critical privacy principles. The result of the case study shows large differences that can help make relevant app choices.

Files

Hatamian-apf2019.pdf

Files (946.5 kB)

Name Size Download all
md5:c823fd25b6dd3c99cb4a673e01825097
946.5 kB Preview Download

Additional details

Funding

Privacy.Us – Privacy and Usability 675730
European Commission