IDPFilter: Mitigating interdependent privacy issues in third-party apps

被引:0
|
作者
Liu, Shuaishuai [1 ]
Biczok, Gergely [1 ,2 ,3 ]
机构
[1] Budapest Univ Technol & Econ, Dept Networked Syst & Serv, CrySyS Lab, Budapest, Hungary
[2] HUN REN BME Informat Syst Res Grp, Bugapest, Hungary
[3] Univ Michigan, Dept EECS, Ann Arbor, MI USA
关键词
Interdependent privacy; Third-party apps; Permissions; Information filtering; Application programming interface;
D O I
10.1016/j.cose.2025.104321
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Third-party applications have become an essential part of today's online ecosystem, enhancing the functionality of popular platforms. However, the intensive data exchange underlying their proliferation has raised concerns about interdependent privacy (IDP). This paper investigates the IDP issues of third-party apps that were previously not studied comprehensively. Specifically, first, we analyze the permission structure of multiple app platforms, identifying permissions that have the potential to cause interdependent privacy issues by enabling a user to share someone else's personal data with an app. Second, we collect datasets and characterize the extent to which existing apps request these permissions, revealing the relationship between characteristics such as the respective app platform, the app's type, and the number of interdependent privacy-related permissions it requests. Third, we analyze why IDP is neglected by both data protection regulations and app platforms and then devise the principles that should be followed when designing a mitigation solution. Finally, based on these principles and satisfying clearly defined objectives, we propose IDPFilter, a platform-agnostic API that enables application providers to minimize collateral information collection by filtering out data collected from their users, but implicating others as data subjects. We implement a proof-of-concept prototype, IDPTextFilter, that implements the filtering logic on textual data, and provide its initial performance evaluation concerning privacy, accuracy, and efficiency.
引用
收藏
页数:17
相关论文
共 50 条
  • [1] Interdependent Privacy Issues Are Pervasive Among Third-Party Applications
    Liu, Shuaishuai
    Herendi, Barbara
    Biczok, Gergely
    DATA PRIVACY MANAGEMENT, CRYPTOCURRENCIES AND BLOCKCHAIN TECHNOLOGY, ESORICS 2021, 2022, 13140 : 70 - 86
  • [2] Understanding and Mitigating Privacy Leaks from Third-Party Smart Speaker Apps
    Alrumayh, Abrar S.
    Lehman, Sarah M.
    Tan, Chiu C.
    2021 IEEE CONFERENCE ON COMMUNICATIONS AND NETWORK SECURITY (CNS), 2021, : 263 - 271
  • [3] Third-Party Apps on Facebook: Privacy and the Illusion of Control
    Wang, Na
    Xu, Heng
    Grossklags, Jens
    PROCEEDINGS OF THE 5TH ACM SYMPOSIUM ON COMPUTER HUMAN INTERACTION FOR MANAGEMENT OF INFORMATION TECHNOLOGY (CHIMIT 2011), 2011,
  • [4] Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps
    Zhao, Kaifa
    Zhan, Xian
    Yu, Le
    Zhou, Shiyao
    Zhou, Hao
    Luo, Xiapu
    Wang, Haoyu
    Liu, Yepang
    2023 IEEE/ACM 45TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING, ICSE, 2023, : 1583 - 1595
  • [5] Demystifying Privacy Policy of Third-Party Libraries in Mobile Apps
    Zhao, Kaifa
    Zhan, Xian
    Yu, Le
    Zhou, Shiyao
    Zhou, Hao
    Luo, Xiapu
    Wang, Haoyu
    Liu, Yepang
    Proceedings - International Conference on Software Engineering, 2023, : 1583 - 1595
  • [6] LibKit: Detecting Third-Party Libraries in iOS Apps
    Dominguez-Alvarez, Daniel
    de la Cruz, Alejandro
    Gorla, Alessandra
    Caballero, Juan
    PROCEEDINGS OF THE 31ST ACM JOINT MEETING EUROPEAN SOFTWARE ENGINEERING CONFERENCE AND SYMPOSIUM ON THE FOUNDATIONS OF SOFTWARE ENGINEERING, ESEC/FSE 2023, 2023, : 1407 - 1418
  • [7] A First Look at Android Apps' Third-Party Resources Loading
    Qayyum, Hina
    Salman, Muhammad
    Sentana, I. Wayan Budi
    Duc Linh Giang Nguyen
    Ikram, Muhammad
    Tyson, Gareth
    Kaafar, Mohamed Ali
    NETWORK AND SYSTEM SECURITY, NSS 2022, 2022, 13787 : 193 - 213
  • [8] Do Developers Update Third-Party Libraries in Mobile Apps?
    Salza, Pasquale
    Palomba, Fabio
    Di Nucci, Dario
    D'Uva, Cosmo
    De Lucia, Andrea
    Ferrucci, Filomena
    2018 IEEE/ACM 26TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION (ICPC 2018), 2018, : 255 - 265
  • [9] Brahmastra: Driving Apps to Test the Security of Third-Party Components
    Bhoraskar, Ravi
    Han, Seungyeop
    Jeon, Jinseong
    Azim, Tanzirul
    Chen, Shuo
    Jung, Jaeyeon
    Nath, Suman
    Wang, Rui
    Wetherall, David
    PROCEEDINGS OF THE 23RD USENIX SECURITY SYMPOSIUM, 2014, : 1021 - 1036
  • [10] Splitting Third-Party Libraries' Privileges from Android Apps
    Zhan, Jiawei
    Zhou, Quan
    Gu, Xiaozhuo
    Wang, Yuewu
    Niu, Yingjiao
    INFORMATION SECURITY AND PRIVACY, ACISP 2017, PT II, 2017, 10343 : 80 - 94