Reference : Sensitive and Personal Data: What Exactly Are You Talking About?
Scientific congresses, symposiums and conference proceedings : Paper published in a book
Engineering, computing & technology : Computer science
Security, Reliability and Trust
http://hdl.handle.net/10993/54761
Sensitive and Personal Data: What Exactly Are You Talking About?
English
Kober, Maria []
Samhi, Jordan mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX >]
Arzt, Steven []
Bissyande, Tegawendé François D Assise mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX >]
Klein, Jacques mailto [University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX >]
May-2023
10th International Conference on Mobile Software Engineering and Systems 2023
Yes
No
International
10th International Conference on Mobile Software Engineering and Systems 2023
From 15/05/2023 to 16/05/2023
Melbourne
Australia
[en] Sensitive data ; Android
[en] Mobile devices are pervasively used for a variety of tasks, including the processing of sensitive data in mobile apps.
While in most cases access to this data is legitimate, malware often targets sensitive data and even benign apps collect more data than necessary for their task.
Therefore, researchers have proposed several frameworks to detect and track the use of sensitive data in apps, so as to disclose and prevent unauthorized access and data leakage. Unfortunately, a review of the literature reveals a lack of consensus on what sensitive data is in the context of technical frameworks like Android. Authors either
provide an intuitive definition or an ad-hoc definition, derive their definition from the Android permission model, or rely on previous research papers which do or do not give a definition of sensitive data.
In this paper, we provide an overview of existing definitions of sensitive data in literature and legal frameworks.
We further provide a sound definition of sensitive data derived from the definition of personal data of several legal frameworks.
To help the scientific community further advance in this field, we publicly provide a list of sensitive sources from the Android framework, thus starting a community project leading to a complete list of sensitive API methods across different frameworks and programming languages.
Interdisciplinary Centre for Security, Reliability and Trust (SnT) > TruX - Trustworthy Software Engineering
Fonds National de la Recherche - FnR
Researchers
http://hdl.handle.net/10993/54761
FnR ; FNR14596679 > Jordan Samhi > DIANA > Dissecting Android Applications Using Static Analysis > 01/03/2020 > 31/10/2023 > 2020

File(s) associated to this reference

Fulltext file(s):

FileCommentaryVersionSizeAccess
Open access
sensitive_data.pdfAuthor preprint158.07 kBView/Open

Bookmark and Share SFX Query

All documents in ORBilu are protected by a user license.