Towards automated privacy compliance checking of applications in Cloud and Fog environments

Mozhdeh Farhadi, Guillaume Pierre, Daniele Miorandi
2021 2021 8th International Conference on Future Internet of Things and Cloud (FiCloud)  
Internet application users are increasingly concerned about the way applications handle their personal data. However, manually checking whether applications actually respect the claims made in their privacy policy is both error-prone and time-consuming. This paper claims that the privacy compliance of applications hosted in cloud or fog computing platforms can and should be automatically carried by the platform itself. We discuss the feasibility of unintrusive and application-agnostic
more » ... in the platform layer to check the privacy compliance of applications. First, the platform may monitor an application's privacy-oriented behavior through signals such as its network traffic characteristics. Second, these signals can be analyzed and compared with the principles found in the application's privacy policy. We present a procedure based on machinelearning techniques to identify the type of data being shared by applications with external third-parties even if the application uses encrypted communications. Our classifiers identify traffic samples of applications with 86% accuracy.
doi:10.1109/ficloud49777.2021.00010 fatcat:3z3pxpgrpzhxjbi6x5qqupxslm