• English
  • Deutsch
  • Log In
    Password Login
    Research Outputs
    Fundings & Projects
    Researchers
    Institutes
    Statistics
Repository logo
Fraunhofer-Gesellschaft
  1. Home
  2. Fraunhofer-Gesellschaft
  3. Konferenzschrift
  4. Sensitive and Personal Data: What Exactly Are You Talking About?
 
  • Details
  • Full
Options
July 11, 2023
Conference Paper
Title

Sensitive and Personal Data: What Exactly Are You Talking About?

Abstract
Mobile devices are pervasively used for a variety of tasks, including the processing of sensitive data in mobile apps. While in most cases access to this data is legitimate, malware often targets sensitive data and even benign apps collect more data than necessary for their task. Therefore, researchers have proposed several frameworks to detect and track the use of sensitive data in apps, so as to disclose and prevent unauthorized access and data leakage. Unfortunately, a review of the literature reveals a lack of consensus on what sensitive data is in the context of technical frameworks like Android. Authors either provide an intuitive definition or an ad-hoc definition, derive their definition from the Android permission model, or rely on previous research papers which do or do not give a definition of sensitive data. In this paper, we provide an overview of existing definitions of sensitive data in literature and legal frameworks. We further provide a sound definition of sensitive data derived from the definition of personal data of several legal frameworks. To help the scientific community further advance in this field, we publicly provide a list of sensitive sources from the Android framework, thus starting a community project leading to a complete list of sensitive API methods across different frameworks and programming languages.
Author(s)
Kober, Maria  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Samhi, Jordan
Arzt, Steven  
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
Bissyandé, Tegawendé F.
Klein, Jacques
Mainwork
IEEE/ACM 10th International Conference on Mobile Software Engineering and Systems, MOBILESoft 2023  
Conference
International Conference on Mobile Software Engineering and Systems 2023  
Open Access
DOI
10.1109/MOBILSoft59058.2023.00016
Additional full text version
Landing Page
Language
English
Fraunhofer-Institut für Sichere Informationstechnologie SIT  
  • Cookie settings
  • Imprint
  • Privacy policy
  • Api
  • Contact
© 2024