Affiliation:
1. Ohio State University, Columbus, OH, USA
Abstract
A new mobile computing paradigm, dubbed mini-app, has been growing rapidly over the past few years since being introduced by WeChat in 2017. In this paradigm, a host app allows its end-users to install and run mini-apps inside itself, enabling the host app to build an ecosystem around (much like Google Play and Apple AppStore), enrich the host's functionalities, and offer mobile users elevated convenience without leaving the host app. It has been reported that there are over millions of mini-apps in WeChat. However, little information is known about these mini-apps at an aggregated level. In this paper, we present MiniCrawler, the first scalable and open source WeChat mini-app crawler that has indexed over 1,333,308 mini-apps. It leverages a number of reverse engineering techniques to uncover the interfaces and APIs in WeChat for crawling the mini-apps. With the crawled mini-apps, we then measure their resource consumption, API usage, library usage, obfuscation rate, app categorization, and app ratings at an aggregated level. The details of how we develop MiniCrawler and our measurement results are reported in this paper.
Funder
National Science Foundation
Publisher
Association for Computing Machinery (ACM)
Subject
Computer Networks and Communications,Hardware and Architecture,Safety, Risk, Reliability and Quality,Computer Science (miscellaneous)
Reference46 articles.
1. C. Lee "WeChat launches mini-app feature " https://www.zdnet.com/article/wechat-launches-mini-app-feature/ 01 2017 (Accessed on 04/21/2021). C. Lee "WeChat launches mini-app feature " https://www.zdnet.com/article/wechat-launches-mini-app-feature/ 01 2017 (Accessed on 04/21/2021).
2. K. Leswing "Three ways to get iPhone software without using Apple's App Store " https://www.cnbc.com/2020/09/01/how-to-get-iphone-software-without-using-apples-app-store.html 9 2020 (Accessed on 04/21/2021). K. Leswing "Three ways to get iPhone software without using Apple's App Store " https://www.cnbc.com/2020/09/01/how-to-get-iphone-software-without-using-apples-app-store.html 9 2020 (Accessed on 04/21/2021).
3. "How brands are using WeChat mini programs " https://mavsocial.com/wechat-mini-programs-for-brands/ 2018. "How brands are using WeChat mini programs " https://mavsocial.com/wechat-mini-programs-for-brands/ 2018.
Cited by
12 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献
1. Identifying Cross-User Privacy Leakage in Mobile Mini-Apps at a Large Scale;IEEE Transactions on Information Forensics and Security;2024
2. Potential Risks Arising from the Absence of Signature Verification in Miniapp Plugins;Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps;2023-11-26
3. TrustedDomain Compromise Attack in App-in-app Ecosystems;Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps;2023-11-26
4. MUID: Detecting Sensitive User Inputs in Miniapp Ecosystems;Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps;2023-11-26
5. Towards a Better Super-App Architecture from a Browser Security Perspective;Proceedings of the 2023 ACM Workshop on Secure and Trustworthy Superapps;2023-11-26