小程序生态下一种新型隐私泄露问题研究

A NEW TYPE OF PRIVACY LEAKAGE IN MINI PROGRAM ECOSYSTEM

  • 摘要: 小程序作为当下火热的新型应用形态,汇集了大量的隐私数据。然而,现有的研究对小程序复杂的多方参与的隐私生态却之甚少,缺乏对其生态下独有的隐私泄露渠道的思考。针对此研究现状,对小程序隐私生态做出分析研究,厘清其技术特点,提出一种小程序生态下独有的新型隐私泄露问题,并开发相关检测工具。最终在10个热门小程序平台中检测出8个漏洞平台,在1030个小程序中,检测出131个直接泄露隐私数据的高危小程序。

     

    Abstract: Mini programs, as a popular new form of application at present, gather a large amount of privacy data. The existing research on the privacy security of mini program has not gone deep into the privacy ecosystem, and lacks thinking about the unique privacy leakage channels. In response to this research situation, an analysis and research on the privacy ecosystem of mini programs is conducted, clarifying its technical characteristics. A new type of unique privacy leakage problem in the mini program ecosystem was proposed, and relevant detection tools were developed. 8 vulnerable platforms were detected out of 10 popular mini program platforms, and among 1030 mini programs, 131 high-risk mini programs that directly leaked private data were detected.

     

/

返回文章
返回