kirancodes.me
To Proof Maintenance & Beyond!

Taintmini: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis

Chao Wang, Ronny Ko, Yue Zhang, Yuqing Yang, Zhiqiang Lin

Abstract

Mini-programs, which are programs running inside mobile super apps such as WeChat, often have access to privacy-sensitive information, such as location data and phone numbers, through APUs provided by the super apps. This access poses a risk of privacy sensitive data leaks, either accidentally from carelessly programmed mini-programs or intentionally from malicious ones. To address this concern, it is crucial to track the flow of sensitive data in mini-programs for either human analysis or automated tools. Although existing taint analysis techniques have been widely studied, they face unique challenges in tracking sensitive data flows in mini-programs, such as cross-language, cross-page, and cross-mini-program data flows. This paper presents a novel framework, Taintmini, which addresses these challenges by using a novel universal data flow graph approach that captures data flows within and across mini-programs. We have evaluated Taintminiwith 238,866 mini-programs and detect 27,184 that contain sensitive data flows. We have also applied Taintminito detect privacy leakage colluding mini-programs and identify 455 such programs from them that clearly violate privacy policy.

BibTeX
@inproceedings{Wang-al:ICSE23,
  author    = {Chao Wang and
               Ronny Ko and
               Yue Zhang and
               Yuqing Yang and
               Zhiqiang Lin},
  title     = {Taintmini: Detecting Flow of Sensitive Data in {Mini-Programs} with Static Taint Analysis},
  booktitle = {ICSE},
  pages     = {932--944},
  publisher = {{IEEE}},
  year      = {2023},
}

Related papers