With the rapid growth of mobile apps, users' concerns about their privacy have become increasingly prominent. Android app logs serve as crucial computer resources, aiding developers in debugging and monitoring the status of Android apps, while also containing a wealth of software system information. Previous studies have acknowledged privacy leaks in software logs and Android apps as significant issues without providing a comprehensive view of the privacy leaks in Android app logs. In this study, we build a comprehensive dataset of Android app logs and conduct an empirical study to analyze the status and severity of privacy leaks in Android app logs. Our study comprises three aspects: (1) Understanding real-world developers' concerns regarding privacy issues related to software logs; (2) Studying privacy leaks in the Android app logs; (3) Investigating the characteristics of privacy-leaking Android app logs and analyzing the reasons behind them. Our study reveals five different categories of concerns from real-world developers regarding privacy issues related to software logs and the prevalence of privacy leaks in Android app logs, with the majority stemming from developers' unawareness of such leaks. Additionally, our study provides developers with suggestions to safeguard their privacy from being logged.
翻译:随着移动应用的快速增长,用户对其隐私的担忧日益突出。Android应用日志作为重要的计算机资源,既帮助开发者调试和监控Android应用状态,也包含丰富的软件系统信息。先前研究已承认软件日志和Android应用中的隐私泄露是重要问题,但未能全面揭示Android应用日志中的隐私泄露情况。本研究构建了一个全面的Android应用日志数据集,并通过实证研究分析了Android应用日志中隐私泄露的现状与严重程度。我们的研究涵盖三个方面:(1)了解实际开发人员对软件日志相关隐私问题的关注点;(2)研究Android应用日志中的隐私泄露现象;(3)探究存在隐私泄露的Android应用日志特征并分析其成因。研究发现,实际开发人员对软件日志相关隐私问题存在五类不同的关注点,且Android应用日志中隐私泄露现象普遍存在,其主要原因在于开发者对此类泄露缺乏认知。此外,本研究为开发者提供了防止隐私信息被记录的建议。