Identifying Cross-User Privacy Leakage in Mobile Mini-Apps at a Large Scale

被引:0
|
作者
Li, Shuai [1 ]
Yang, Zhemin [1 ]
Yang, Yunteng [1 ]
Liu, Dingyi [1 ]
Yang, Min [1 ,2 ,3 ]
机构
[1] Fudan Univ, Sch Comp Sci, Shanghai 200433, Peoples R China
[2] Shanghai Inst Intelligent Elect & Syst, Sch Comp Sci, Shanghai 200433, Peoples R China
[3] Engn Res Ctr Cyber Secur Auditing & Monitoring, Shanghai 200433, Peoples R China
关键词
Data privacy; Privacy; Medical services; Social networking (online); Security; Message services; Threat modeling; Mobile mini-apps; cross user; privacy leakage; dynamic analysis; information loss analysis; security assessment;
D O I
10.1109/TIFS.2024.3356197
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the characteristics of free installation and rich functionalities, mobile mini-apps have become more and more popular in people's daily life. A large amount of sensitive personal data is thus involved in them and shared across users for providing various services, which raises great privacy concerns. However, few researchers have paid attention to the potential privacy risks that may exist when user data is shared across users in mobile mini-apps. In this paper, we introduce a novel privacy risk that is brought forward by cross-user personal data over-delivery (denoted as XPO) in mobile mini-apps. Such a discovered privacy risk is demonstrated to be able to cause serious leakage of diverse user data. To detect XPO risk, a dynamic and lightweight mini-app analysis framework - XPOScope is proposed. XPOScope is able to automatically identify XPO risk at a large scale. By applying it to 4,273 mini-apps hosted on three popular platforms, i.e., WeChat, Baidu and Alipay, XPOScope reported 71 vulnerable ones, with a precision of 92.21% and a recall of 80.68%. In addition to the mere exposure of diverse private user data, case studies performed show that XPO in mini-apps can further lead to impersonation attacks, the infringement of employees' privacy, economic loss and even the leakage of sensitive business secrets. The results call for the awareness and actions of mobile mini-app developers to secure cross-user personal data delivery.
引用
收藏
页码:3135 / 3147
页数:13
相关论文
共 50 条
  • [31] A Large-Scale Empirical Study of Internet Users' Privacy Leakage in China
    Zhang, Yuanming
    Zhang, Shuo
    Zhang, Yuchao
    Tao, Jing
    Wang, Pinghui
    IEEE 17TH INT CONF ON DEPENDABLE, AUTONOM AND SECURE COMP / IEEE 17TH INT CONF ON PERVAS INTELLIGENCE AND COMP / IEEE 5TH INT CONF ON CLOUD AND BIG DATA COMP / IEEE 4TH CYBER SCIENCE AND TECHNOLOGY CONGRESS (DASC/PICOM/CBDCOM/CYBERSCITECH), 2019, : 406 - 411
  • [32] Factors Related to User Ratings and User Downloads of Mobile Apps for Maternal and Infant Health: Cross-Sectional Study
    Biviji, Rizwana
    Vest, Joshua R.
    Dixon, Brian E.
    Cullen, Theresa
    Harle, Christopher A.
    JMIR MHEALTH AND UHEALTH, 2020, 8 (01):
  • [33] Security and privacy in a middleware for large scale mobile and pervasive augmented reality
    Ferreira, Pedro
    Orvalho, Joao
    Boavida, Fernando
    SOFTCOM 2007: 15TH INTERNATIONAL CONFERENCE ON SOFTWARE, TELECOMMUNICATIONS AND COMPUTER NETWORKS, 2007, : 365 - 369
  • [34] Field experience with obfuscating million-user iOS apps in large enterprise mobile development
    Wang, Pei
    Wu, Dinghao
    Chen, Zhaofeng
    Wei, Tao
    SOFTWARE-PRACTICE & EXPERIENCE, 2019, 49 (02): : 252 - 273
  • [35] Assessing the Quality of Mobile Apps Used by Occupational Therapists: Evaluation Using the User Version of the Mobile Application Rating Scale
    LeBeau, Kelsea
    Huey, Lauren G.
    Hart, Mark
    JMIR MHEALTH AND UHEALTH, 2019, 7 (05):
  • [36] Privacy Analysis of User Association Logs in a Large-scale Wireless LAN
    Tan, Keren
    Yan, Guanhua
    Yeo, Jihwang
    Kotz, David
    2011 PROCEEDINGS IEEE INFOCOM, 2011, : 31 - 35
  • [37] Identifying Privacy Leakage from User-Generated Content in An Online Health Community - A deep learning approach
    Zhu, Yushan
    Tong, Xing
    Wang, Xi
    2019 IEEE INTERNATIONAL CONFERENCE ON HEALTHCARE INFORMATICS (ICHI), 2019, : 407 - 408
  • [38] LinkFlow: Efficient Large-Scale Inter-app Privacy Leakage Detection
    He, Yi
    Li, Qi
    Sun, Kun
    SECURITY AND PRIVACY IN COMMUNICATION NETWORKS, SECURECOMM 2017, 2018, 238 : 291 - 311
  • [39] Testing of Mobile Applications in the Wild: A Large-Scale Empirical Study on Android Apps
    Pecorelli, Fabiano
    Catolino, Gemma
    Ferrucci, Filomena
    De Lucia, Andrea
    Palomba, Fabio
    2020 IEEE/ACM 28TH INTERNATIONAL CONFERENCE ON PROGRAM COMPREHENSION, ICPC, 2020, : 296 - 307
  • [40] UNITI Mobile-EMI-Apps for a Large-Scale European Study on Tinnitus
    Vogel, Carsten
    Schobel, Johannes
    Schlee, Winfried
    Engelke, Milena
    Pryss, Rudiger
    2021 43RD ANNUAL INTERNATIONAL CONFERENCE OF THE IEEE ENGINEERING IN MEDICINE & BIOLOGY SOCIETY (EMBC), 2021, : 2358 - 2362