Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?

Analysis of Privacy Protections in Fitness Tracking Social Networks -or- You can run, but can you hide?
复制标题

DOI:
--
复制
发表时间:
2018
期刊:
--
影响因子:
--
通讯作者:
Wajih Ul Hassan;Saad Hussain;Adam Bates
Wajih Ul Hassan;Saad Hussain;Adam Bates
中科院分区:
其他
文献类型:
--
作者:
Wajih Ul Hassan;Saad Hussain;Adam Bates

文献摘要

相似文献

移动健身跟踪应用程序允许用户跟踪自己的锻炼情况,并通过在线社交网络与朋友分享。虽然共享个人数据是所有社交网络的固有风险,但共享由地理空间和健康数据组成的个人锻炼所带来的危险可能特别严重。虽然健身应用提供了各种各样的隐私功能,但目前还不清楚这些对策是否足以挫败一个顽固的攻击者,也不清楚这些服务的用户中有多少人处于危险之中。在这项工作中,我们对健身跟踪社交网络中的隐私行为和威胁进行了系统的分析。我们收集了一个流行健身追踪服务长达一个月的公开帖子快照(2100万个帖子,300万用户),观察到16.5%的用户使用端点隐私区(EPZs),该区域隐藏了用户指定的敏感位置(例如,家,办公室)附近的健身活动。我们继续开发一种针对epz的攻击,该攻击从公开帖子中的剩余可用信息推断用户的受保护位置,发现95.1%的中度活跃用户面临被攻击者提取其受保护位置的风险。最后,我们通过适应地理不可区分技术以及开发一种新的EPZ模糊技术来考虑最先进的隐私机制的有效性。受影响的公司已被告知发现的漏洞,并在发布时将我们提出的对策纳入其生产系统。
Mobile fitness tracking apps allow users to track their workouts and share them with friends through online social networks. Although the sharing of personal data is an inherent risk in all social networks, the dangers presented by sharing personal workouts comprised of geospatial and health data may prove especially grave. While fitness apps offer a variety of privacy features, at present it is unclear if these countermeasures are suffi-cient to thwart a determined attacker, nor is it clear how many of these services’ users are at risk. In this work, we perform a systematic analysis of privacy behaviors and threats in fitness tracking social networks. Collecting a month-long snapshot of public posts of a popular fitness tracking service (21 million posts, 3 million users), we observe that 16.5% of users make use of Endpoint Privacy Zones (EPZs), which conceal fitness activity near user-designated sensitive locations (e.g., home, office). We go on to develop an attack against EPZs that infers users’ protected locations from the remaining available information in public posts, discovering that 95.1% of moderately active users are at risk of having their protected locations extracted by an attacker. Finally, we consider the efficacy of state-of-the-art privacy mechanisms through adapting geo-indistinguishability techniques as well as developing a novel EPZ fuzzing technique. The affected companies have been notified of the discovered vulnerabilities and at the time of publication have incorporated our proposed countermeasures into their production systems.