跳到主要导航 跳到搜索 跳到主要内容

基于隐蔽通信的小程序隐私泄露风险分析

  • Beihang University
  • Tianmushan Laboratory

科研成果: 期刊稿件文章同行评审

摘要

Mini programs, exemplifying the "app-in-app" paradigm, have become deeply integrated into people's work and daily lives, accessing substantial amounts of user privacy data. To prevent privacy leaks, mini program platforms monitor and regulate regular communication methods. However, mini programs can use covert communication to evade detection. Aiming at the security threat of covert communication to user privacy leakage, this paper analyzes the risk of privacy leakage of mini programs covert communication. On the basis of summarizing the covert communication model and communication conditions of mini programs, we design covert communication methods for both mini-program-to-mini-program and mini-program-to-server communications based on the mini program APIs and components. Invisible character-based source coding and forged pages are adopted to improve the covertness respectively. Experiments verify that the above covert communication methods can realize secret information transmission, and that two attack scenarios are designed to analyze the privacy leakage risk brought by the covert communication methods. Finally, corresponding mitigation measures are discussed.

投稿的翻译标题Analysis of privacy leakage of the mini program based on covert communication
源语言繁体中文
页(从-至)173-182
页数10
期刊Xi'an Dianzi Keji Daxue Xuebao/Journal of Xidian University
52
5
DOI
出版状态已出版 - 10月 2025

关键词

  • covert communication
  • mini program
  • mobile security
  • privacy leakage
  • security of data

指纹

探究 '基于隐蔽通信的小程序隐私泄露风险分析' 的科研主题。它们共同构成独一无二的指纹。

引用此