{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,28]],"date-time":"2025-03-28T01:55:29Z","timestamp":1743126929067,"version":"3.40.3"},"publisher-location":"Cham","reference-count":34,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783031255373"},{"type":"electronic","value":"9783031255380"}],"license":[{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,1]],"date-time":"2023-01-01T00:00:00Z","timestamp":1672531200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2023]]},"DOI":"10.1007\/978-3-031-25538-0_30","type":"book-chapter","created":{"date-parts":[[2023,2,3]],"date-time":"2023-02-03T13:03:34Z","timestamp":1675429414000},"page":"569-587","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["Detection and\u00a0Privacy Leakage Analysis of\u00a0Third-Party Libraries in\u00a0Android Apps"],"prefix":"10.1007","author":[{"given":"Xiantong","family":"Hao","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dandan","family":"Ma","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hongliang","family":"Liang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2023,2,4]]},"reference":[{"key":"30_CR1","unstructured":"IDC. Smartphone Market Share. https:\/\/www.idc.com\/promo\/smartphone-market-share\/os"},{"key":"30_CR2","unstructured":"Lin, J., Liu, B., Sadeh, N., et al.: Modeling users mobile app privacy preferences: restoring usability in a sea of permission settings. In: Proceeding SOUPS 2014 Proceedings of the Tenth USENIX Conference on Usable Privacy and Security, vol. 199 (2014)"},{"key":"30_CR3","doi-asserted-by":"crossref","unstructured":"Wang, H., Guo, Y., Ma, Z., Chen, X.: WuKong: a scalable and accurate two-phase approach to Android app clone detection. In: Proceedings of the 2015 International Symposium on Software Testing and Analysis, pp. 71\u201382. ACM, Baltimore (2015).https:\/\/doi.org\/10.1145\/2771783.2771795","DOI":"10.1145\/2771783.2771795"},{"key":"30_CR4","unstructured":"Slowmist Knowledge-Base. https:\/\/github.com\/slowmist\/Knowledge-Base\/blob\/master\/tradingview-xss-vul.md"},{"key":"30_CR5","doi-asserted-by":"crossref","unstructured":"Wu, D., Gao, D., Chang, R.K.C., He, E., Cheng, E.K.T., Deng, R.H.: Understanding open ports in android applications: discovery, diagnosis, and security assessment. In: Proceedings 2019 Network and Distributed System Security Symposium. Internet Society, San Diego (2019). https:\/\/doi.org\/10.14722\/ndss.2019.23171","DOI":"10.14722\/ndss.2019.23171"},{"key":"30_CR6","doi-asserted-by":"publisher","unstructured":"Almanee, S., Unal, A., Payer, M., Garcia, J.: Too quiet in the library: an empirical study of security updates in android apps\u2019 native code. In: 2021 IEEE\/ACM 43rd International Conference on Software Engineering (ICSE), pp. 1347\u20131359. IEEE, Madrid (2021). https:\/\/doi.org\/10.1109\/ICSE43902.2021.00122","DOI":"10.1109\/ICSE43902.2021.00122"},{"key":"30_CR7","unstructured":"Reardon, J., Feal, \u00c1., Wijesekera, P.: 50 ways to leak your data: an exploration of apps\u2019 circumvention of the android permissions system, vol. 19 (2019)"},{"key":"30_CR8","unstructured":"Mobile application (App) data security and personal information protection white paper. http:\/\/www.caict.ac.cn\/kxyj\/qwfb\/bps\/201912\/P020191230332039577332.pdf"},{"key":"30_CR9","unstructured":"Maven Repository. https:\/\/mvnrepository.com\/"},{"key":"30_CR10","unstructured":"GitHub: Where the world builds software. https:\/\/github.com\/"},{"key":"30_CR11","doi-asserted-by":"publisher","unstructured":"Lin, J., Sadeh, N., Amini, S., Lindqvist, J., Hong, J.I., Zhang, J.: Expectation and purpose: understanding users\u2019 mental models of mobile app privacy through crowdsourcing. In: Proceedings of the 2012 ACM Conference on Ubiquitous Computing - UbiComp 2012, p. 501. ACM Press, Pittsburgh (2012). https:\/\/doi.org\/10.1145\/2370216.2370290","DOI":"10.1145\/2370216.2370290"},{"key":"30_CR12","doi-asserted-by":"publisher","unstructured":"Liu, B., Liu, B., Jin, H., Govindan, R.: Efficient privilege de-escalation for ad libraries in mobile apps. In: Proceedings of the 13th Annual International Conference on Mobile Systems, Applications, and Services, pp. 89\u2013103. ACM, Florence (2015). https:\/\/doi.org\/10.1145\/2742647.2742668","DOI":"10.1145\/2742647.2742668"},{"key":"30_CR13","doi-asserted-by":"publisher","unstructured":"Zhang, J., Beresford, A.R., Kollmann, S.A.: LibID: reliable identification of obfuscated third-party Android libraries. In: Proceedings of the 28th ACM SIGSOFT International Symposium on Software Testing and Analysis, pp. 55\u201365. ACM, Beijing (2019). https:\/\/doi.org\/10.1145\/3293882.3330563","DOI":"10.1145\/3293882.3330563"},{"key":"30_CR14","doi-asserted-by":"publisher","unstructured":"Wang, Y., Wu, H., Zhang, H., Rountev, A.: ORLIS: obfuscation-resilient library detection for Android. In: Proceedings of the 5th International Conference on Mobile Software Engineering and Systems - MOBILESoft 2018, pp. 13\u201323. ACM Press, Gothenburg (2018). https:\/\/doi.org\/10.1145\/3197231.3197248","DOI":"10.1145\/3197231.3197248"},{"key":"30_CR15","doi-asserted-by":"publisher","unstructured":"Ma, Z., Wang, H., Guo, Y., Chen, X.: LibRadar: of third-party libraries in Android apps. In: Proceedings of the 38th International Conference on Software Engineering Companion - ICSE 2016, pp. 653\u2013656. ACM Press, Austin (2016). https:\/\/doi.org\/10.1145\/2889160.2889178","DOI":"10.1145\/2889160.2889178"},{"key":"30_CR16","doi-asserted-by":"publisher","unstructured":"Backes, M., Bugiel, S., Derr, E.: Reliable third-party library detection in android and its security applications. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security - CCS 2016, pp. 356\u2013367. ACM Press, Vienna (2016). https:\/\/doi.org\/10.1145\/2976749.2978333","DOI":"10.1145\/2976749.2978333"},{"key":"30_CR17","doi-asserted-by":"publisher","unstructured":"Li, M., et al.: LibD: scalable and precise third-party library detection in android markets. In: 2017 IEEE\/ACM 39th International Conference on Software Engineering (ICSE), pp. 335\u2013346 (2017). https:\/\/doi.org\/10.1109\/ICSE.2017.38","DOI":"10.1109\/ICSE.2017.38"},{"key":"30_CR18","doi-asserted-by":"publisher","unstructured":"Enck, W., et al.: TaintDroid: an information flow tracking system for real-time privacy monitoring on smartphones. Commun. ACM. 57, 99\u2013106 . https:\/\/doi.org\/10.1145\/2494522","DOI":"10.1145\/2494522"},{"key":"30_CR19","doi-asserted-by":"publisher","first-page":"209","DOI":"10.1109\/TDSC.2017.2740169","volume":"17","author":"W You","year":"2020","unstructured":"You, W., Liang, B., Shi, W., Wang, P., Zhang, X.: TaintMan: an ART-compatible dynamic taint analysis framework on unmodified and non-rooted android devices. IEEE Trans. Depend. Secure Comput. 17, 209\u2013222 (2020). https:\/\/doi.org\/10.1109\/TDSC.2017.2740169","journal-title":"IEEE Trans. Depend. Secure Comput."},{"key":"30_CR20","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1016\/j.jisa.2019.03.014","volume":"46","author":"Y He","year":"2019","unstructured":"He, Y., Yang, X., Hu, B., Wang, W.: Dynamic privacy leakage analysis of Android third-party libraries. J. Inf. Secur. Appl. 46, 259\u2013270 (2019). https:\/\/doi.org\/10.1016\/j.jisa.2019.03.014","journal-title":"J. Inf. Secur. Appl."},{"key":"30_CR21","doi-asserted-by":"publisher","unstructured":"Wongwiwatchai, N., Pongkham, P., Sripanidkulchai, K.: Comprehensive detection of vulnerable personal information leaks in android applications. In: IEEE INFOCOM 2020 - IEEE Conference on Computer Communications Workshops (INFOCOM WKSHPS), pp. 121\u2013126. IEEE, Toronto (2020). https:\/\/doi.org\/10.1109\/INFOCOMWKSHPS50562.2020.9163043","DOI":"10.1109\/INFOCOMWKSHPS50562.2020.9163043"},{"key":"30_CR22","series-title":"Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1007\/978-3-030-01701-9_10","volume-title":"Security and Privacy in Communication Networks","author":"S Dong","year":"2018","unstructured":"Dong, S., et al.: Understanding android obfuscation techniques: a large-scale investigation in the wild. In: Beyah, R., Chang, B., Li, Y., Zhu, S. (eds.) SecureComm 2018. LNICST, vol. 254, pp. 172\u2013192. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-030-01701-9_10"},{"key":"30_CR23","doi-asserted-by":"publisher","unstructured":"Allix, K., Bissyand\u00e9, T.F., Klein, J., Le Traon, Y.: AndroZoo: collecting millions of Android apps for the research community. In: Proceedings of the 13th International Conference on Mining Software Repositories, pp. 468\u2013471. ACM, Austin (2016). https:\/\/doi.org\/10.1145\/2901739.2903508","DOI":"10.1145\/2901739.2903508"},{"key":"30_CR24","unstructured":"A tool for reverse engineering Android apk files. https:\/\/ibotpeaches.github.io\/Apktool\/"},{"key":"30_CR25","unstructured":"Android Developer. https:\/\/developer.android.com\/reference\/packages"},{"key":"30_CR26","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1145\/235968.233324","volume":"25","author":"T Zhang","year":"1996","unstructured":"Zhang, T., Ramakrishnan, R., Livny, M.: BIRCH: an efficient data clustering method for very large databases. SIGMOD Rec. 25, 103\u2013114 (1996). https:\/\/doi.org\/10.1145\/235968.233324","journal-title":"SIGMOD Rec."},{"key":"30_CR27","unstructured":"Monkey. https:\/\/developer.android.com\/studio\/test\/monkey"},{"key":"30_CR28","doi-asserted-by":"publisher","unstructured":"Zhan, X., et al.: Automated third-party library detection for Android applications: are we there yet? In: Proceedings of the 35th IEEE\/ACM International Conference on Automated Software Engineering, pp. 919\u2013930. ACM, Virtual Event Australia (2020). https:\/\/doi.org\/10.1145\/3324884.3416582","DOI":"10.1145\/3324884.3416582"},{"key":"30_CR29","doi-asserted-by":"publisher","unstructured":"Duan, R., Bijlani, A., Xu, M., Kim, T., Lee, W.: Identifying open-source license violation and 1-day security risk at large scale. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 2169\u20132185. ACM, Dallas (2017). https:\/\/doi.org\/10.1145\/3133956.3134048","DOI":"10.1145\/3133956.3134048"},{"key":"30_CR30","doi-asserted-by":"publisher","unstructured":"Chen, K., Liu, P., Zhang, Y.: Achieving accuracy and scalability simultaneously in detecting application clones on Android markets. In: Proceedings of the 36th International Conference on Software Engineering - ICSE 2014, pp. 175\u2013186. ACM Press, Hyderabad (2014). https:\/\/doi.org\/10.1145\/2568225.2568286","DOI":"10.1145\/2568225.2568286"},{"key":"30_CR31","doi-asserted-by":"publisher","unstructured":"The protection of computer software - Its technology and applications: edited by Derrick Grover, 2nd Edition, 1992 (British Computer Society Monographs in Informatics - Cambridge University Press, Softcover), 307pp, \u00a317.95 (US \\$32.95), ISBN 0-521-42462-3. Computer Law & Security Review. 8, 204 (1992). https:\/\/doi.org\/10.1016\/0267-3649(92)90069-L","DOI":"10.1016\/0267-3649(92)90069-L"},{"key":"30_CR32","doi-asserted-by":"publisher","unstructured":"Zhang, Y., et al.: Detecting third-party libraries in Android applications with high precision and recall. In: 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 141\u2013152. IEEE, Campobasso (2018). https:\/\/doi.org\/10.1109\/SANER.2018.8330204","DOI":"10.1109\/SANER.2018.8330204"},{"key":"30_CR33","doi-asserted-by":"crossref","unstructured":"Zhan, X., et al.: ATVHunter: reliable version detection of third-party libraries for vulnerability identification in android applications. In: ICSE (2021)","DOI":"10.1109\/ICSE43902.2021.00150"},{"key":"30_CR34","doi-asserted-by":"publisher","unstructured":"Arzt, S., et al.: FlowDroid: precise context, flow, field, object-sensitive and lifecycle-aware taint analysis for Android apps. In: Proceedings of the 35th ACM SIGPLAN Conference on Programming Language Design and Implementation - PLDI 2014, pp. 259\u2013269. ACM Press, Edinburgh (2013). https:\/\/doi.org\/10.1145\/2594291.2594299","DOI":"10.1145\/2594291.2594299"}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Security and Privacy in Communication Networks"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-25538-0_30","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,2,3]],"date-time":"2023-02-03T13:14:58Z","timestamp":1675430098000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-25538-0_30"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023]]},"ISBN":["9783031255373","9783031255380"],"references-count":34,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-25538-0_30","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"type":"print","value":"1867-8211"},{"type":"electronic","value":"1867-822X"}],"subject":[],"published":{"date-parts":[[2023]]},"assertion":[{"value":"4 February 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"SecureComm","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Security and Privacy in Communication Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 October 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"securecomm2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/securecomm.eai-conferences.org\/2022\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Confy+","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"130","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"43","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"33% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}