Toward a framework for detecting privacy policy violations in android application code
Abstract
Mobile applications frequently access sensitive personal information to meet user or business requirements. Because such information is sensitive in general, regulators increasingly require mobile-app developers to publish privacy policies that describe what information is collected. Furthermore, regulators have fined companies when these policies are inconsistent with the actual data practices of mobile apps. To help mobile-app developers check their privacy policies against their apps' code for consistency, we propose a semi-automated framework that consists of a policy terminology-API method map that links policy phrases to API methods that produce sensitive information, and information flow analysis to detect misalignments. We present an implementation of our framework based on a privacy-policy-phrase ontology and a collection of mappings from API methods to policy phrases. Our empirical evaluation on 477 top Android apps discovered 341 potential privacy policy violations.
BibTeX
@inproceedings{Slavin-al:ICSE16,
author = {Rocky Slavin and
Xiaoyin Wang and
Mitra Bokaei Hosseini and
James Hester and
Ram Krishnan and
Jaspreet Bhatia and
Travis D. Breaux and
Jianwei Niu},
title = {Toward a framework for detecting privacy policy violations in android application code},
booktitle = {ICSE},
pages = {25--36},
publisher = {{ACM}},
year = {2016},
}