{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,13]],"date-time":"2026-04-13T17:11:33Z","timestamp":1776100293897,"version":"3.50.1"},"publisher-location":"Singapore","reference-count":37,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819635306","type":"print"},{"value":"9789819635313","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-981-96-3531-3_3","type":"book-chapter","created":{"date-parts":[[2025,3,13]],"date-time":"2025-03-13T12:11:48Z","timestamp":1741867908000},"page":"39-59","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["AndroPROTECT: Hardening the\u00a0Android API Against Fingerprinting"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-6633-858X","authenticated-orcid":false,"given":"Gerald","family":"Palfinger","sequence":"first","affiliation":[]}],"member":"297","published-online":{"date-parts":[[2025,3,14]]},"reference":[{"key":"3_CR1","unstructured":"Proceedings of the 20th International Conference on Security and Cryptography, SECRYPT 2023, Rome, Italy, 10\u201312 July 2023 (2023)"},{"key":"3_CR2","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"161","DOI":"10.1007\/978-3-030-91356-4_9","volume-title":"Information Security","author":"SA Akhavani","year":"2021","unstructured":"Akhavani, S.A., Jueckstock, J., Su, J., Kapravelos, A., Kirda, E., Lu, L.: Browserprint: an\u00a0analysis of\u00a0the\u00a0impact of\u00a0browser features on\u00a0fingerprintability and\u00a0web privacy. In: Liu, J.K., Katsikas, S., Meng, W., Susilo, W., Intan, R. (eds.) ISC 2021. LNCS, vol. 13118, pp. 161\u2013176. Springer, Cham (2021). https:\/\/doi.org\/10.1007\/978-3-030-91356-4_9"},{"key":"3_CR3","unstructured":"Android-Developers: Privacy changes in android 10 - restriction on non-resettable device identifiers (2019). https:\/\/developer.android.com\/about\/versions\/10\/privacy\/changes#non-resettable-device-ids\/"},{"key":"3_CR4","unstructured":"Android-Developers: <provider> - android:initorder (2023). https:\/\/developer.android.com\/guide\/topics\/manifest\/provider-element.html\/#init"},{"key":"3_CR5","unstructured":"Android-Developers: Ui\/application exerciser monkey (2023). https:\/\/developer.android.com\/studio\/test\/other-testing-tools\/monkey"},{"key":"3_CR6","unstructured":"Android-Developers: Restrictions on non-SDK interfaces - android developers (2024). https:\/\/developer.android.com\/guide\/app-compatibility\/restrictions-non-sdk-interfaces\/"},{"key":"3_CR7","doi-asserted-by":"crossref","unstructured":"Draschbacher, F.: A2P2 - an android application patching pipeline based on generic changesets. In: Availability, Reliability and Security \u2013 ARES, pp. 1:1\u20131:11 (2023)","DOI":"10.1145\/3600160.3600172"},{"key":"3_CR8","doi-asserted-by":"crossref","unstructured":"Duan, R., et al.: Automating patching of vulnerable open-source software versions in application binaries. In: Network and Distributed System Security Symposium \u2013 NDSS (2019)","DOI":"10.14722\/ndss.2019.23126"},{"key":"3_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2022.102452","volume":"125","author":"F Faghihi","year":"2022","unstructured":"Faghihi, F., Zulkernine, M., Ding, S.H.H.: CamoDroid: an Android application analysis environment resilient against sandbox evasion. J. Syst. Archit. 125, 102452 (2022)","journal-title":"J. Syst. Archit."},{"key":"3_CR10","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"293","DOI":"10.1007\/978-3-319-20810-7_21","volume-title":"Data and Applications Security and Privacy XXIX","author":"A FaizKhademi","year":"2015","unstructured":"FaizKhademi, A., Zulkernine, M., Weldemariam, K.: FPGuard: detection and prevention of browser fingerprinting. In: Samarati, P. (ed.) DBSec 2015. LNCS, vol. 9149, pp. 293\u2013308. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-20810-7_21"},{"key":"3_CR11","doi-asserted-by":"crossref","unstructured":"Haryono, S.A., et al.: Automatic android deprecated-API usage update by learning from single updated example. In: ICPC 2020: 28th International Conference on Program Comprehension, Seoul, Republic of Korea, 13\u201315 July 2020, pp. 401\u2013405 (2020)","DOI":"10.1145\/3387904.3389285"},{"issue":"3","key":"3_CR12","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10664-021-10096-0","volume":"27","author":"SA Haryono","year":"2022","unstructured":"Haryono, S.A., et al.: AndroEvolve: automated Android API update with data flow analysis and variable denormalization. Empir. Softw. Eng. 27(3), 1\u201331 (2022). https:\/\/doi.org\/10.1007\/s10664-021-10096-0","journal-title":"Empir. Softw. Eng."},{"key":"3_CR13","doi-asserted-by":"crossref","unstructured":"Heid, K., Andrae, V., Heider, J.: Towards detecting device fingerprinting on iOS with API function hooking. In: European Interdisciplinary Cybersecurity Conference \u2013 EICC, pp. 78\u201384 (2023)","DOI":"10.1145\/3590777.3590790"},{"key":"3_CR14","doi-asserted-by":"crossref","unstructured":"Ibrahim, M., Imran, A., Bianchi, A.: SafetyNOT: on the usage of the SafetyNet attestation API in Android. In: Mobile Systems \u2013 MobiSys, pp. 150\u2013162 (2021)","DOI":"10.1145\/3458864.3466627"},{"key":"3_CR15","doi-asserted-by":"crossref","unstructured":"Jing, Y., Zhao, Z., Ahn, G., Hu, H.: Morpheus: automatically generating heuristics to detect Android emulators. In: Annual Computer Security Applications Conference \u2013 ACSAC, pp. 216\u2013225 (2014)","DOI":"10.1145\/2664243.2664250"},{"key":"3_CR16","doi-asserted-by":"publisher","first-page":"6","DOI":"10.2478\/popets-2022-0033","volume":"2022","author":"K Kollnig","year":"2022","unstructured":"Kollnig, K., Shuba, A., Binns, R., Kleek, M.V., Shadbolt, N.: Are iPhones really better for privacy? A comparative study of iOS and android apps. Proc. Priv. Enhancing Technol. 2022, 6\u201324 (2022)","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"3_CR17","doi-asserted-by":"crossref","unstructured":"Kollnig, K., Shuba, A., Kleek, M.V., Binns, R., Shadbolt, N.: Goodbye tracking? Impact of iOS app tracking transparency and privacy labels. In: Conference on Fairness, Accountability, and Transparency \u2013 FAccT, pp. 508\u2013520 (2022)","DOI":"10.1145\/3531146.3533116"},{"key":"3_CR18","doi-asserted-by":"crossref","unstructured":"Kondracki, B., Azad, B.A., Miramirkhani, N., Nikiforakis, N.: The droid is in the details: environment-aware evasion of android sandboxes. In: Network and Distributed System Security Symposium \u2013 NDSS (2022)","DOI":"10.14722\/ndss.2022.23056"},{"key":"3_CR19","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1515\/popets-2015-0027","volume":"2016","author":"A Kurtz","year":"2016","unstructured":"Kurtz, A., Gascon, H., Becker, T., Rieck, K., Freiling, F.C.: Fingerprinting mobile devices using personalized configurations. Proc. Priv. Enhancing Technol. 2016, 4\u201319 (2016)","journal-title":"Proc. Priv. Enhancing Technol."},{"key":"3_CR20","doi-asserted-by":"crossref","unstructured":"Laperdrix, P., Bielova, N., Baudry, B., Avoine, G.: Browser Fingerprinting: a Survey. ACM Trans. Web 14, 8:1\u20138:33 (2020)","DOI":"10.1145\/3386040"},{"key":"3_CR21","doi-asserted-by":"crossref","unstructured":"Meng, M.H., et al.: Post-GDPR threat hunting on android phones: dissecting OS-level safeguards of user-unresettable identifiers. In: Network and Distributed System Security Symposium \u2013 NDSS (2023)","DOI":"10.14722\/ndss.2023.23176"},{"key":"3_CR22","unstructured":"Mozilla-Corporation: Enhanced tracking protection in firefox for desktop (2023). https:\/\/support.mozilla.org\/en-US\/kb\/enhanced-tracking-protection-firefox-desktop\/"},{"key":"3_CR23","doi-asserted-by":"crossref","unstructured":"Nikiforakis, N., Joosen, W., Livshits, B.: PriVaricator: deceiving fingerprinters with little white lies. In: International Conference on World Wide Web \u2013 WWW, pp. 820\u2013830 (2015)","DOI":"10.1145\/2736277.2741090"},{"key":"3_CR24","doi-asserted-by":"crossref","unstructured":"Palfinger, G.: OCScraper: automated analysis of the fingerprintability of the iOS API. In: International Conference on Security and Cryptography \u2013 SECRYPT [1], pp. 433\u2013441","DOI":"10.5220\/0012089600003555"},{"key":"3_CR25","doi-asserted-by":"crossref","unstructured":"Palfinger, G., Pr\u00fcnster, B.: AndroPRINT: analysing the fingerprintability of the Android API. In: Availability, Reliability and Security \u2013 ARES, pp. 94:1\u201394:10 (2020)","DOI":"10.1145\/3407023.3407055"},{"key":"3_CR26","unstructured":"Perry, M., Clark, E., Murdoch, S., Koppen, G.: The design and implementation of the tor browser - cross-origin fingerprinting unlinkability (2019). https:\/\/www.torproject.org\/projects\/torbrowser\/design\/#fingerprinting-linkability"},{"key":"3_CR27","doi-asserted-by":"crossref","unstructured":"Polc\u00e1k, L., Salon, M., Maone, G., Hranick\u00fd, R., McMahon, M.: JShelter: give me my browser back. In: International Conference on Security and Cryptography \u2013 SECRYPT [1], pp. 287\u2013294","DOI":"10.5220\/0011965600003555"},{"key":"3_CR28","doi-asserted-by":"crossref","unstructured":"Pr\u00fcnster, B., Palfinger, G., Kollmann, C.: Fides: unleashing the full potential of remote attestation. In: Proceedings of the 16th International Joint Conference on e-Business and Telecommunications, ICETE 2019 - Volume 2: SECRYPT, Prague, Czech Republic, 26\u201328 July 2019, pp. 314\u2013321 (2019)","DOI":"10.5220\/0008121003140321"},{"key":"3_CR29","doi-asserted-by":"crossref","unstructured":"Razaghpanah, A., et al.: Apps, trackers, privacy, and regulators: a global study of the mobile tracking ecosystem. In: Network and Distributed System Security Symposium \u2013 NDSS (2018)","DOI":"10.14722\/ndss.2018.23353"},{"key":"3_CR30","doi-asserted-by":"crossref","unstructured":"Shklovski, I., Mainwaring, S.D., Sk\u00falad\u00f3ttir, H.H., Borgthorsson, H.: Leakiness and creepiness in app space: perceptions of privacy and mobile app use. In: Conference on Human Factors in Computing Systems \u2013 CHI, pp. 2347\u20132356 (2014)","DOI":"10.1145\/2556288.2557421"},{"key":"3_CR31","doi-asserted-by":"crossref","unstructured":"Spreitzer, R., Kirchengast, F., Gruss, D., Mangard, S.: ProcHarvester: fully automated analysis of procfs side-channel leaks on android. In: Asia Conference on Computer and Communications Security \u2013 AsiaCCS, pp. 749\u2013763 (2018)","DOI":"10.1145\/3196494.3196510"},{"key":"3_CR32","unstructured":"Statista: Most popular app monetization methods by publishers from the united states as of december 2023, September 2023. https:\/\/www.statista.com\/statistics\/1119916\/app-monetization-methods-united-states-app-publishers\/"},{"key":"3_CR33","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1007\/978-3-319-98989-1_4","volume-title":"Computer Security","author":"C Ferreira Torres","year":"2018","unstructured":"Ferreira Torres, C., Jonker, H.: Investigating fingerprinters and fingerprinting-alike behaviour of android applications. In: Lopez, J., Zhou, J., Soriano, M. (eds.) ESORICS 2018. LNCS, vol. 11099, pp. 60\u201380. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-98989-1_4"},{"key":"3_CR34","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1007\/978-3-319-24177-7_1","volume-title":"Computer Security \u2013 ESORICS 2015","author":"CF Torres","year":"2015","unstructured":"Torres, C.F., Jonker, H., Mauw, S.: FP-Block: usable web privacy by controlling browser fingerprinting. In: Pernul, G., Ryan, P.Y.A., Weippl, E. (eds.) ESORICS 2015. LNCS, vol. 9327, pp. 3\u201319. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-24177-7_1"},{"key":"3_CR35","doi-asserted-by":"publisher","first-page":"8073","DOI":"10.1109\/ACCESS.2016.2626395","volume":"4","author":"W Wu","year":"2016","unstructured":"Wu, W., Wu, J., Wang, Y., Ling, Z., Yang, M.: Efficient fingerprinting-based android device identification with zero-permission identifiers. IEEE Access 4, 8073\u20138083 (2016)","journal-title":"IEEE Access"},{"key":"3_CR36","unstructured":"Xu, Z., et al.: Automatic hot patch generation for android kernels. In: USENIX Security Symposium, pp. 2397\u20132414 (2020)"},{"key":"3_CR37","doi-asserted-by":"crossref","unstructured":"Zhang, M., Yin, H.: AppSealer: automatic generation of vulnerability-specific patches for preventing component hijacking attacks in android applications. In: Network and Distributed System Security Symposium \u2013 NDSS (2014)","DOI":"10.14722\/ndss.2014.23255"}],"container-title":["Lecture Notes in Computer Science","Network and System Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-96-3531-3_3","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,13]],"date-time":"2025-03-13T12:12:04Z","timestamp":1741867924000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-96-3531-3_3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9789819635306","9789819635313"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-981-96-3531-3_3","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"14 March 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The authors have no competing interests to declare that are relevant to the content of this article.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclosure of Interests"}},{"value":"NSS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Network and System Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Abu Dhabi","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"United Arab Emirates","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21 November 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 November 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nss2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/nsclab.org\/nss-socialsec2024\/index.html","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}