LeakDoctor: Toward Automatically Diagnosing Privacy Leaks in Mobile Applications

Xiaolei Wang, Andrea Continella, Yuexiang Yang, Yongzhong He, Sencun Zhu

Research output: Contribution to journalArticleAcademicpeer-review

275 Downloads (Pure)

Abstract

With the enormous popularity of smartphones, millions of mobile apps are developed to provide rich functionalities for users by accessing certain personal data, leading to great privacy concerns. To address this problem, many approaches have been proposed to detect privacy disclosures in mobile apps, but they largely fail to automatically determine whether the privacy disclosures are necessary for the functionality of apps. As a result, security analysts may easily face with a large number of false positives when directly adopting such approaches for app analysis. In this paper, we propose LeakDoctor, an analysis system seeking to automatically diagnose privacy leaks by judging if a privacy disclosure from an app is necessary for some functionality of the app. Functionality-irrelevant privacy disclosures are not justifiable, so considered as potential privacy leak cases. To achieve this goal, LeakDoctor integrates dynamic response differential analysis with static response taint analysis. In addition, it employs a novel technique to locate the program statements of each privacy disclosure. We implement a prototype of LeakDoctor and evaluate it against 1060 apps, which contain 2,095 known disclosure cases. Our experimental results show that LeakDoctor can automatically determine that 71.9% of the privacy disclosure cases indeed serve apps' functionalities and are justifiable. Hence, with the diagnosis results of LeakDoctor, analysts may avoid analyzing many justifiable privacy disclosures and only focus on the those unjustifiable cases.
Original languageEnglish
Article number28
Number of pages1
JournalProceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies
Volume3
Issue number1
DOIs
Publication statusPublished - 2019
Externally publishedYes

Fingerprint

Dive into the research topics of 'LeakDoctor: Toward Automatically Diagnosing Privacy Leaks in Mobile Applications'. Together they form a unique fingerprint.

Cite this