Communication publiée dans un ouvrage (Colloques, congrès, conférences scientifiques et actes)
Sensitive and Personal Data: What Exactly Are You Talking About?
Kober, Maria; SAMHI, Jordan; Arzt, Steven et al.
2023In 10th International Conference on Mobile Software Engineering and Systems 2023
Peer reviewed
 

Documents


Texte intégral
sensitive_data.pdf
Preprint Auteur (161.87 kB)
Télécharger

Tous les documents dans ORBilu sont protégés par une licence d'utilisation.

Envoyer vers



Détails



Mots-clés :
Sensitive data; Android
Résumé :
[en] Mobile devices are pervasively used for a variety of tasks, including the processing of sensitive data in mobile apps. While in most cases access to this data is legitimate, malware often targets sensitive data and even benign apps collect more data than necessary for their task. Therefore, researchers have proposed several frameworks to detect and track the use of sensitive data in apps, so as to disclose and prevent unauthorized access and data leakage. Unfortunately, a review of the literature reveals a lack of consensus on what sensitive data is in the context of technical frameworks like Android. Authors either provide an intuitive definition or an ad-hoc definition, derive their definition from the Android permission model, or rely on previous research papers which do or do not give a definition of sensitive data. In this paper, we provide an overview of existing definitions of sensitive data in literature and legal frameworks. We further provide a sound definition of sensitive data derived from the definition of personal data of several legal frameworks. To help the scientific community further advance in this field, we publicly provide a list of sensitive sources from the Android framework, thus starting a community project leading to a complete list of sensitive API methods across different frameworks and programming languages.
Centre de recherche :
- Interdisciplinary Centre for Security, Reliability and Trust (SnT) > TruX - Trustworthy Software Engineering
NCER-FT - FinTech National Centre of Excellence in Research
Disciplines :
Sciences informatiques
Auteur, co-auteur :
Kober, Maria
SAMHI, Jordan  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
Arzt, Steven
BISSYANDE, Tegawendé François D Assise  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
KLEIN, Jacques  ;  University of Luxembourg > Interdisciplinary Centre for Security, Reliability and Trust (SNT) > TruX
Co-auteurs externes :
yes
Langue du document :
Anglais
Titre :
Sensitive and Personal Data: What Exactly Are You Talking About?
Date de publication/diffusion :
mai 2023
Nom de la manifestation :
10th International Conference on Mobile Software Engineering and Systems 2023
Lieu de la manifestation :
Melbourne, Australie
Date de la manifestation :
From 15/05/2023 to 16/05/2023
Manifestation à portée :
International
Titre de l'ouvrage principal :
10th International Conference on Mobile Software Engineering and Systems 2023
Maison d'édition :
IEEE
Pagination :
70-74
Peer reviewed :
Peer reviewed
Focus Area :
Security, Reliability and Trust
Projet FnR :
FNR14596679 - Dissecting Android Applications Using Static Analysis, 2020 (01/03/2020-31/10/2023) - Jordan Samhi
Organisme subsidiant :
FNR - Fonds National de la Recherche
Disponible sur ORBilu :
depuis le 04 avril 2023

Statistiques


Nombre de vues
177 (dont 6 Unilu)
Nombre de téléchargements
461 (dont 8 Unilu)

citations Scopus®
 
4
citations Scopus®
sans auto-citations
4
OpenCitations
 
1
citations OpenAlex
 
4

Bibliographie


Publications similaires



Contacter ORBilu