USENIX Security2019Top-tier venue
Understanding iOS-based Crowdturfing Through Hidden UI Analysis
Yeonjoon Lee, Xueqiang Wang, Kwangwuk Lee, Xiaojing Liao, XiaoFeng Wang, Tongxin Li, Xianghang Mi
Abstract
A new type of malicious crowdsourcing (a.k.a., crowdturfing) clients, mobile apps with hidden crowdturfing user interface (UI), is increasingly being utilized by miscreants to coordinate crowdturfing workers and publish mobile-based crowdturfing tasks (e.g., app ranking manipulation) even on the strictly controlled Apple App Store. These apps hide their crowdturfing content behind innocent-looking UIs to bypass app vetting and infiltrate the app store. To the best of our knowledge, little has been done so far to understand this new abusive service, in terms of its scope, impact and techniques, not to mention any effort to identify such stealthy crowdturfing apps on a large scale, particularly on the Apple platform. In this paper, we report the first measurement study on iOS apps with hidden crowdturfing UIs. Our findings bring to light the mobile-based crowdturfing ecosystem (e.g., app promotion for worker recruitment, campaign identification) and the underground developer's tricks (e.g., scheme, logic bomb) for evading app vetting.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 554617be-2df0-4aec-a1c9-2d352f89c4a4Cited by top-tier papers10
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee et al.USENIX Security 2024 · 29 citations
- Analyzing Ground-Truth Data of Mobile Gambling ScamsGeng Hong, Zhemin Yang, Sen Yang, Xiaojing Liao et al.S&P 2022 · 29 citations
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson et al.CCS 2022 · 11 citations
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie et al.USENIX Security 2024 · 6 citations
- CydiOS: A Model-Based Testing Framework for iOS AppsShuohan Wu, Jianfeng Li, Hao Zhou, Yongsheng Fang et al.ISSTA 2023 · 4 citations
Builds on2
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang et al.S&P 2016 · 111 citations
- Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConfXiaolong Bai, Luyi Xing, Nan Zhang, XiaoFeng Wang et al.S&P 2016 · 33 citations
Related papers
- The Art and Craft of Fraudulent App Promotion in Google PlayMizanur Rahman, Nestor Hernandez, Ruben Recabarren, Syed Ishtiaque Ahmed et al.CCS 2019 · 28 citations
- Mobilizing Crowdwork: A Systematic Assessment of the Mobile Usability of HITsSenjuti Dutta, Rhema Linder, Doug Lowe, Richard Rosenbalm et al.CHI 2022 · 4 citations
- A Longitudinal Study of Removed Apps in iOS App StoreFuqi Lin, Haoyu Wang, Liu Wang, Xuanzhe LiuWWW 2021 · 20 citations
- Improving Data Quality via Pre-Task Participant Screening in Crowdsourced GUI ExperimentsTakaya Miyama, Satoshi Nakamura, Shota YamanakaCHI 2026 · 2 citations
- A Tale of Two Communities: Privacy of Third Party App Users in Crowdsourcing - The Case of Receipt TranscriptionWeiping Pei, Yanina Likhtenshteyn, Chuan YueCSCW 2023 · 1 citation
