Saved in:
Bibliographic Details
Main Authors: Rodriguez, David, Del Alamo, Jose M., Cozar, Miguel, Garcia, Boni
Format: Preprint
Published: 2022
Subjects:
Online Access:https://arxiv.org/abs/2204.09495
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866908720439492608
author Rodriguez, David
Del Alamo, Jose M.
Cozar, Miguel
Garcia, Boni
author_facet Rodriguez, David
Del Alamo, Jose M.
Cozar, Miguel
Garcia, Boni
contents Many studies have exposed the massive collection of personal data in the digital ecosystem through, for instance, websites, mobile apps, or smart devices. This fact goes unnoticed by most users, who are also unaware that the collectors are sharing their personal data with many different organizations around the globe. This paper assesses techniques available in the state of the art to identify the organizations receiving this personal data. Based on our findings, we propose ROI (Receiver Organization Identifier), a fully automated method that combines different techniques to achieve a 95.71% precision score in identifying an organization receiving personal data. We demonstrate our method in the wild by evaluating 10,000 Android apps and exposing the organizations that receive users' personal data.
format Preprint
id arxiv_https___arxiv_org_abs_2204_09495
institution arXiv
publishDate 2022
record_format arxiv
spellingShingle ROI: A method for identifying organizations receiving personal data
Rodriguez, David
Del Alamo, Jose M.
Cozar, Miguel
Garcia, Boni
Cryptography and Security
Machine Learning
I.7.0; D.4.6
Many studies have exposed the massive collection of personal data in the digital ecosystem through, for instance, websites, mobile apps, or smart devices. This fact goes unnoticed by most users, who are also unaware that the collectors are sharing their personal data with many different organizations around the globe. This paper assesses techniques available in the state of the art to identify the organizations receiving this personal data. Based on our findings, we propose ROI (Receiver Organization Identifier), a fully automated method that combines different techniques to achieve a 95.71% precision score in identifying an organization receiving personal data. We demonstrate our method in the wild by evaluating 10,000 Android apps and exposing the organizations that receive users' personal data.
title ROI: A method for identifying organizations receiving personal data
topic Cryptography and Security
Machine Learning
I.7.0; D.4.6
url https://arxiv.org/abs/2204.09495