Identifying Cross-User Privacy Leakage in Mobile Mini-Apps at a Large Scale

被引:0
|
作者
Li, Shuai [1 ]
Yang, Zhemin [1 ]
Yang, Yunteng [1 ]
Liu, Dingyi [1 ]
Yang, Min [1 ,2 ,3 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
[2] Shanghai Inst Intelligent Elect & Syst, Sch Comp Sci, Shanghai 200433, Peoples R China
[3] Engn Res Ctr Cyber Secur Auditing & Monitoring, Shanghai 200433, Peoples R China
关键词
Data privacy; Privacy; Medical services; Social networking (online); Security; Message services; Threat modeling; Mobile mini-apps; cross user; privacy leakage; dynamic analysis; information loss analysis; security assessment;
D O I
10.1109/TIFS.2024.3356197
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the characteristics of free installation and rich functionalities, mobile mini-apps have become more and more popular in people's daily life. A large amount of sensitive personal data is thus involved in them and shared across users for providing various services, which raises great privacy concerns. However, few researchers have paid attention to the potential privacy risks that may exist when user data is shared across users in mobile mini-apps. In this paper, we introduce a novel privacy risk that is brought forward by cross-user personal data over-delivery (denoted as XPO) in mobile mini-apps. Such a discovered privacy risk is demonstrated to be able to cause serious leakage of diverse user data. To detect XPO risk, a dynamic and lightweight mini-app analysis framework - XPOScope is proposed. XPOScope is able to automatically identify XPO risk at a large scale. By applying it to 4,273 mini-apps hosted on three popular platforms, i.e., WeChat, Baidu and Alipay, XPOScope reported 71 vulnerable ones, with a precision of 92.21% and a recall of 80.68%. In addition to the mere exposure of diverse private user data, case studies performed show that XPO in mini-apps can further lead to impersonation attacks, the infringement of employees' privacy, economic loss and even the leakage of sensitive business secrets. The results call for the awareness and actions of mobile mini-app developers to secure cross-user personal data delivery.
引用
收藏
页码:3135 / 3147
页数:13
相关论文
共 50 条
  • [21] Tracking Location Privacy Leakage of Mobile Ad Networks at Scale
    Hu, Boyang
    Yan, Qiben
    Zheng, Yao
    IEEE INFOCOM 2018 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2018,
  • [22] Efficient Mobile Authentication Scheme Preserving User Privacy for Large-Scale Wireless Networks
    Wei, Li
    Yao, Yongtao
    Ding, Zhijun
    Pu, Qiong
    AD HOC & SENSOR WIRELESS NETWORKS, 2013, 17 (3-4) : 313 - 339
  • [23] MiniTracker: Large-Scale Sensitive Information Tracking in Mini Apps
    Li, Wei
    Yang, Borui
    Ye, Hangyu
    Xiang, Liyao
    Tao, Qingxiao
    Wang, Xinbing
    Zhou, Chenghu
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2024, 21 (04) : 2099 - 2114
  • [24] Assessing user benefits and privacy concerns in utilitarian and hedonic mobile augmented reality apps
    Qin, Hong
    David, Alsius
    Harun, Ahasan
    Al Mamun, Md Rasel
    Peak, Daniel
    Prybutok, Victor
    INDUSTRIAL MANAGEMENT & DATA SYSTEMS, 2024, 124 (01) : 442 - 482
  • [25] Mobile Augmented Reality Apps in Education: Exploring the User Experience Through Large-Scale Public Reviews
    Alfaro, Jessica Lizeth Dominguez
    Van Puyvelde, Peter
    AUGMENTED REALITY, VIRTUAL REALITY, AND COMPUTER GRAPHICS, 2021, 12980 : 428 - 450
  • [26] MobileRec: A Large-Scale Dataset for Mobile Apps Recommendation
    Maqbool, M. H.
    Farooq, Umar
    Mosharrof, Adib
    Siddique, A. B.
    Foroosh, Hassan
    PROCEEDINGS OF THE 46TH INTERNATIONAL ACM SIGIR CONFERENCE ON RESEARCH AND DEVELOPMENT IN INFORMATION RETRIEVAL, SIGIR 2023, 2023, : 3007 - 3016
  • [27] I Know Where You All Are! Exploiting Mobile Social Apps for Large-Scale Location Privacy Probing
    Zhao, Shuang
    Luo, Xiapu
    Bai, Bo
    Ma, Xiaobo
    Zou, Wei
    Qiu, Xinliang
    Au, Man Ho
    INFORMATION SECURITY AND PRIVACY, PT I, 2016, 9722 : 3 - 19
  • [28] Is It a Trap? A Large-scale Empirical Study And Comprehensive Assessment of Online Automated Privacy Policy Generators for Mobile Apps
    Pan, Shidong
    Zhang, Dawen
    Staples, Mark
    Xing, Zhenchang
    Chen, Jieshan
    Xu, Xiwei
    Thong Hoang
    PROCEEDINGS OF THE 33RD USENIX SECURITY SYMPOSIUM, SECURITY 2024, 2024, : 5681 - 5698
  • [29] Modeling Privacy Leakage Risks in Large-Scale Social Networks
    Du, Suguo
    Li, Xiaolong
    Zhong, Jinli
    Zhou, Lu
    Xue, Minhui
    Zhu, Haojin
    Sun, Limin
    IEEE ACCESS, 2018, 6 : 17653 - 17665
  • [30] A Large-Scale Empirical Study on Software Reuse in Mobile Apps
    Mojica, Israel J.
    Adams, Bram
    Nagappan, Meiyappan
    Dienst, Steffen
    Berger, Thorsten
    Hassan, Ahmed E.
    IEEE SOFTWARE, 2014, 31 (02) : 78 - 86