论文标题
ROI:一种识别接收个人数据的组织的方法
ROI: A method for identifying organizations receiving personal data
论文作者
论文摘要
许多研究通过例如网站,移动应用程序或智能设备来揭示数字生态系统中大量个人数据的收集。大多数用户都没有注意到这一事实,他们也没有意识到收藏家正在与全球许多不同组织共享其个人数据。本文评估了最新技术可用的技术,以确定接收此个人数据的组织。根据我们的发现,我们提出了ROI(接收器组织标识符),这是一种完全自动化的方法,它结合了不同的技术,以在确定接收个人数据的组织时获得95.71%的精度得分。我们通过评估10,000个Android应用程序并揭露接收用户个人数据的组织来证明我们的方法。
Many studies have exposed the massive collection of personal data in the digital ecosystem through, for instance, websites, mobile apps, or smart devices. This fact goes unnoticed by most users, who are also unaware that the collectors are sharing their personal data with many different organizations around the globe. This paper assesses techniques available in the state of the art to identify the organizations receiving this personal data. Based on our findings, we propose ROI (Receiver Organization Identifier), a fully automated method that combines different techniques to achieve a 95.71% precision score in identifying an organization receiving personal data. We demonstrate our method in the wild by evaluating 10,000 Android apps and exposing the organizations that receive users' personal data.