Identifying Cross-User Privacy Leakage in Mobile Mini-Apps at a Large Scale

被引:0
|
作者
Li, Shuai [1 ]
Yang, Zhemin [1 ]
Yang, Yunteng [1 ]
Liu, Dingyi [1 ]
Yang, Min [1 ,2 ,3 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
[2] Shanghai Inst Intelligent Elect & Syst, Sch Comp Sci, Shanghai 200433, Peoples R China
[3] Engn Res Ctr Cyber Secur Auditing & Monitoring, Shanghai 200433, Peoples R China
关键词
Data privacy; Privacy; Medical services; Social networking (online); Security; Message services; Threat modeling; Mobile mini-apps; cross user; privacy leakage; dynamic analysis; information loss analysis; security assessment;
D O I
10.1109/TIFS.2024.3356197
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the characteristics of free installation and rich functionalities, mobile mini-apps have become more and more popular in people's daily life. A large amount of sensitive personal data is thus involved in them and shared across users for providing various services, which raises great privacy concerns. However, few researchers have paid attention to the potential privacy risks that may exist when user data is shared across users in mobile mini-apps. In this paper, we introduce a novel privacy risk that is brought forward by cross-user personal data over-delivery (denoted as XPO) in mobile mini-apps. Such a discovered privacy risk is demonstrated to be able to cause serious leakage of diverse user data. To detect XPO risk, a dynamic and lightweight mini-app analysis framework - XPOScope is proposed. XPOScope is able to automatically identify XPO risk at a large scale. By applying it to 4,273 mini-apps hosted on three popular platforms, i.e., WeChat, Baidu and Alipay, XPOScope reported 71 vulnerable ones, with a precision of 92.21% and a recall of 80.68%. In addition to the mere exposure of diverse private user data, case studies performed show that XPO in mini-apps can further lead to impersonation attacks, the infringement of employees' privacy, economic loss and even the leakage of sensitive business secrets. The results call for the awareness and actions of mobile mini-app developers to secure cross-user personal data delivery.
引用
收藏
页码:3135 / 3147
页数:13
相关论文
共 50 条
  • [1] Identifying User-Input Privacy in Mobile Applications at a Large Scale
    Nan, Yuhong
    Yang, Zhemin
    Yang, Min
    Zhou, Shunfan
    Zhang, Yuan
    Gu, Guofei
    Wang, Xiaofeng
    Sun, Limin
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2017, 12 (03) : 647 - 661
  • [2] Privacy in Cross-User Data Deduplication
    Jannati, Hoda
    Ardeshir-Larijani, Ebrahim
    Bahrak, Behnam
    MOBILE NETWORKS & APPLICATIONS, 2021, 26 (06): : 2567 - 2579
  • [3] Privacy in Cross-User Data Deduplication
    Hoda Jannati
    Ebrahim Ardeshir-Larijani
    Behnam Bahrak
    Mobile Networks and Applications, 2021, 26 : 2567 - 2579
  • [4] The Privacy Calculus: Mobile Apps and User Perceptions of Privacy and Security
    Fife, Elizabeth
    Orjuela, Juan
    INTERNATIONAL JOURNAL OF ENGINEERING BUSINESS MANAGEMENT, 2012, 4
  • [5] Cross-User Leakage Mitigation for Authorized Multi-User Encrypted Data Sharing
    Wang, Mingyue
    Chen, Zizhuo
    Miao, Yinbin
    Huang, Hejiao
    Wang, Cong
    Jia, Xiaohua
    IEEE TRANSACTIONS ON INFORMATION FORENSICS AND SECURITY, 2024, 19 : 1213 - 1226
  • [6] Empowering mobile crowdsourcing apps with user privacy control
    Meftah, Lakhdar
    Rouvoy, Romain
    Chrisment, Isabelle
    JOURNAL OF PARALLEL AND DISTRIBUTED COMPUTING, 2021, 147 : 1 - 15
  • [7] A Study of User Privacy in Android Mobile AR Apps
    Yang, Xiaoyi
    Zhang, Xueling
    PROCEEDINGS OF THE 37TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE 2022, 2022,
  • [8] MOBILE APPS - USER AWARENESS ON PERMISSIONS, INFORMATION PRIVACY AND SECURITY
    Tutunea, Mihaela Filofteia
    PROCEEDINGS OF THE 16TH INTERNATIONAL CONFERENCE ON INFORMATICS IN ECONOMY (IE 2017): EDUCATION, RESEARCH & BUSINESS TECHNOLOGIES, 2017, : 70 - 77
  • [9] Data Sharing in Mobile Apps - User Privacy Expectations in Europe
    Quermann, Nils
    Degeling, Martin
    2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 107 - 119
  • [10] Exploiting Proximity-Based Mobile Apps for Large-Scale Location Privacy Probing
    Zhao, Shuang
    Luo, Xiapu
    Ma, Xiaobo
    Bai, Bo
    Zhao, Yankang
    Zou, Wei
    Yang, Zeming
    Au, Man Ho
    Qiu, Xinliang
    SECURITY AND COMMUNICATION NETWORKS, 2018,