(Press-News.org) DURHAM, N.C. -- Flicking through a wallpaper app with backgrounds of Mickey Mouse and a tropical waterfall, Peter Gilbert gets a plain, black and white text notification on his smartphone.
A third of the way down the screen it says, "Taint: Phone Number, IMEI, ICCID (sim card identifier)." The message alerts Gilbert that the wallpaper app has sent his phone's number and other identifying information to imnet.us. Checking online, it appears the address is a website in Shenzhen, China.
The notification came from TaintDroid, a prototype extension to the Android mobile-phone platform designed to identify apps that transmit private data. The phone-based tool monitors how applications access and use privacy sensitive data, such as location, microphone, camera and phone numbers, and provides feedback within seconds of using a newly installed app.
TaintDroid recently identified that 15 of 30 randomly selected, popular, free Android Marketplace applications sent users' private information to remote advertising servers and two-thirds of the apps handled data in ambiguous ways.
Gilbert, a graduate student in computer science at Duke University, and his adviser, Landon Cox, an assistant computer science professor, helped develop TaintDroid. They collaborated with Jaeyeon Jung, Byung-Gon Chun and Anmol Sheth of Intel Labs, and William Enck and Patrick McDaniel of Penn State University.
"We found it surprising that location information was shared with ad networks without further explanation or notification," said Jung, lead co-author, along with Enck, of a new study that describes TaintDroid and the team's results.
The paper will be posted online Sept. 30 as part of the USENIX Symposium on OSDI, or Operating Systems Design and Implementation. Enck will also present the research findings Oct. 6 at the affiliated OSDI conference in Vancouver, BC.
The team found that some applications shared GPS sensor location information with advertisement servers only when displaying ads to the user. Other applications shared location even when the user was not running the application. In some cases, location information was being shared as frequently as every 30 seconds.
The results support and expand upon a controversial SMobile Systems study published in June 2010 which found that 20 percent of the then-available 48,000 third-party applications for the Android operating system provided sensitive or private information to outside sources. In the new study, the team only monitored the Android platform, but the findings suggest that investigating other operating systems is warranted.
"We don't have the data to say that a majority of third-party apps are untrustworthy. This study, however, is a proof-of-concept to show the value of enhancing smartphone platforms to include real-time monitoring tools like TaintDroid to give users an awareness of how their information is being shared," Cox said.
Currently, mobile-phone operating systems do offer users some controls to regulate whether an application can access private information. When installing an app, like the wallpaper app, for example, Android asks the user which services and data an app may access, Gilbert says.
If the user chooses not to allow this access, the application cannot be installed. But if the user does install the app, the permission checks don't always explain how these services and data will be used. This forces users to blindly trust that applications will handle private data properly once they are installed, he says.
"The permissions don't tell the user how their data will be used, and in some cases misused," Cox adds, noting that in some cases, a privacy violation can occur where services and data are used in ways that are unexpected. Mobile anti-virus packages such as software sold by SMobile Systems can alert users to the presence of previously identified malicious applications, but they do not provide real-time information about where applications send users' data.
TaintDroid uses a scientific technique called "dynamic taint analysis" to mark information of interest with an identifier called a "taint." The taint stays with the information when it is used, and the tracking system then monitors the movement of tainted information, such as the Internet destination of the user's information. It then sends the user a notification of the movement of information as soon as the app is closed.
"This automatic feedback gives users greater insight into what their mobile applications are doing and could help users decide whether they should consider uninstalling an app," Gilbert says.
The team plans to make TaintDroid publicly available to continue to improve smartphone application monitoring.
###
END
Troy, N.Y. – The purification of drug components is a large hurdle facing modern drug development. This is particularly true of drugs that utilize proteins, which are notoriously difficult to separate from other potentially deadly impurities. Scientists within the Center for Biotechnology and Interdisciplinary Studies (CBIS) at Rensselaer Polytechnic Institute are using nuclear magnetic resonance (NMR) to understand and improve an important protein purification process.
"We hope to use our insights to help those in the industry develop improved processes to provide ...
Publicly available cell-phone applications from application markets are releasing consumers' private information to online advertisers, according to a joint study by Intel Labs, Penn State, and Duke University.
Researchers at the participating institutions have developed a realtime monitoring service called TaintDroid that precisely analyses how private information is obtained and released by
applications "downloaded" to consumer phones. TaintDroid is an extension to the Android mobile-phone platform that tracks the flow of sensitive data through third-party applications.
In ...
MANHATTAN, KAN. -- For two Kansas State University professors, receiving one of software engineering's most prestigious awards was more than 10 years in the making.
A seven-member research team that included K-State's John Hatcliff, professor of computer and information science, and Robby, associate professor of computing and information science, set out in 1998 to illustrate how different technologies could test for problems that arise when computer programs multitask. The team published "Bandera: Extracting Finite-State Models from Java Source code" in 2000.
The publication ...
A new approach to anchor teeth back in the jaw using stem cells has been developed and successfully tested in the laboratory for the first time by researchers at the University of Illinois at Chicago.
The new strategy represents a potential major advance in the battle against gum disease, a serious infection that eventually leads to tooth loss. About 80 percent of U.S. adults suffer from gum disease, according to the National Institute of Dental and Craniofacial Research.
Researchers in UIC's Brodie Laboratory for Craniofacial Genetics used stem cells obtained from ...
PHILADELPHIA – After experiencing a potentially traumatic event – a car accident, a physical or sexual assault, a sports injury, witnessing violence – as many as 1 in 5 children will develop Posttraumatic Stress Disorder (PTSD).
A new approach that helps improve communication between child and caregiver, such as recognizing and managing traumatic stress symptoms and teaching coping skills, was able to prevent chronic and sub-clinical PTSD in 73 percent of children. The intervention, called the Child and Family Traumatic Stress Intervention (CFTSI) also reduced PTSD symptoms ...
INDIANAPOLIS -- Researchers at the Indiana University Melvin and Bren Simon Cancer Center have published the first report using imaging to show that changes in brain tissue can occur in breast cancer patients undergoing chemotherapy.
The cognitive effects of chemotherapy, often referred to as "chemobrain," have been known for years. However, the IU research is the first to use brain imaging to study women with breast cancer before and after treatment, showing that chemotherapy can affect gray matter. The researchers reported their findings in the October 2010 edition ...
DALLAS – Sept. 29, 2010 – More people are drinking than 20 years ago, according to a UT Southwestern Medical Center analysis of national alcohol consumption patterns. Gathered from more than 85,000 respondents, the data suggests that a variety of factors, including social, economic and ethnic influences and pressures, are involved in the increase.
"The reasons for the uptick vary and may involve complex sociodemographic changes in the population, but the findings are clear: More people are consuming alcohol now than in the early 1990s," said Dr. Raul Caetano, dean of ...
The Magellanic Stream is an arc of hydrogen gas spanning more than 100 degrees of the sky as it trails behind the Milky Way's neighbor galaxies, the Large and Small Magellanic Clouds. Our home galaxy, the Milky Way, has long been thought to be the dominant gravitational force in forming the Stream by pulling gas from the Clouds. A new computer simulation by Gurtina Besla (Harvard-Smithsonian Center for Astrophysics) and her colleagues now shows, however, that the Magellanic Stream resulted from a past close encounter between these dwarf galaxies rather than effects of the ...
In recent human trials for a promising new class of drug designed to target the hepatitis C virus (HCV) without shutting down the immune system, some of the HCV strains being treated exhibited signs of drug resistance.
In response, an interdisciplinary team of Florida State University biologists, chemists and biomedical researchers devised a novel genetic screening method that can identify the drug-resistant HCV strains and the molecular-level mechanisms that make them that way –– helping drug developers to tailor specific therapies to circumvent them.
The potentially ...
ROCHESTER, Minn. -- In the largest, most modern, single-institution study of its kind, Mayo Clinic urologists mined a long-term data registry for survival rates of patients who underwent radical prostatectomy (http://www.mayoclinic.org/radical-prostatectomy/) for localized prostate cancer. The findings are being presented at the North Central Section of the American Urological Association's 84th Annual Meeting in Chicago.
A radical prostatectomy is an operation to remove the prostate gland and some of the tissue around it. In this study, Mayo Clinic researchers discovered ...