loading
Papers Papers/2022 Papers Papers/2022

Research.Publish.Connect.

Paper

Paper Unlock

Authors: I. Wayan Budi Sentana 1 ; Muhammad Ikram 1 ; Mohamed Ali Kaafar 1 and Shlomo Berkovsky 2

Affiliations: 1 Department of Computing, Macquarie University, 4 Research Park Drive, Macquarie Park, NSW, Australia ; 2 Centre for Health Informatics, Australian Institute of Health Innovation, Macquarie University, 75 Talavera Rd, North Ryde, NSW, Australia

Keyword(s): Android Apps, Privacy, Security, Static Analysis, Dynamic Fingerprinting.

Abstract: Smartphone technology has drastically improved over the past decade. These improvements have seen the creation of specialized health applications, which offer consumers a range of health-related activities such as tracking and checking symptoms of health conditions or diseases through their smartphones. We term these applications as Symptom Checking apps or simply SymptomCheckers. Due to the sensitive nature of the private data they collect, store and manage, leakage of user information could result in significant consequences. In this paper, we use a combination of techniques from both static and dynamic analysis to detect, trace and categorize security and privacy issues in 36 popular SymptomCheckers on Google Play. Our analyses reveal that SymptomCheckers request a significantly higher number of sensitive permissions and embed a higher number of third-party tracking libraries for targeted advertisements and analytics exploiting the privileged access of the SymptomCheckers in whic h they exist, as a mean of collecting and sharing critically sensitive data about the user and their device. We find that these are sharing the data that they collect through unencrypted plain text to the third-party advertisers and, in some cases, to malicious domains. The results reveal that the exploitation of SymptomCheckers is present in popular apps, still readily available on Google Play. (More)

CC BY-NC-ND 4.0

Sign In Guest: Register as new SciTePress user now for free.

Sign In SciTePress user: please login.

PDF ImageMy Papers

You are not signed in, therefore limits apply to your IP address 3.145.50.206

In the current month:
Recent papers: 100 available of 100 total
2+ years older papers: 200 available of 200 total

Paper citation in several formats:
Sentana, I.; Ikram, M.; Kaafar, M. and Berkovsky, S. (2021). Empirical Security and Privacy Analysis of Mobile Symptom Checking Apps on Google Play. In Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT; ISBN 978-989-758-524-1; ISSN 2184-7711, SciTePress, pages 665-673. DOI: 10.5220/0010520106650673

@conference{secrypt21,
author={I. Wayan Budi Sentana. and Muhammad Ikram. and Mohamed Ali Kaafar. and Shlomo Berkovsky.},
title={Empirical Security and Privacy Analysis of Mobile Symptom Checking Apps on Google Play},
booktitle={Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT},
year={2021},
pages={665-673},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010520106650673},
isbn={978-989-758-524-1},
issn={2184-7711},
}

TY - CONF

JO - Proceedings of the 18th International Conference on Security and Cryptography - SECRYPT
TI - Empirical Security and Privacy Analysis of Mobile Symptom Checking Apps on Google Play
SN - 978-989-758-524-1
IS - 2184-7711
AU - Sentana, I.
AU - Ikram, M.
AU - Kaafar, M.
AU - Berkovsky, S.
PY - 2021
SP - 665
EP - 673
DO - 10.5220/0010520106650673
PB - SciTePress