USENIX Security2021Top-tier venue
Scalable Detection of Promotional Website Defacements in Black Hat SEO Campaigns
Ronghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang, Jiawei He, Siming Pang, Wing Cheong Lau
Abstract
Miscreants from online underground economies regularly exploit website vulnerabilities and inject fraudulent content into victim web pages to promote illicit goods and services. Scalable detection of such promotional website defacements remains an open problem despite their prevalence in Black Hat Search Engine Optimization (SEO) campaigns. Adversaries often manage to inject content in a stealthy manner by obfuscating the description of illicit products and/or the presence of defacements to make them undetectable. In this paper, we design and implement DMOS -a Defacement Monitoring System which protects websites from promotional defacements at scale. Our design is based on two key observations: Firstly, for effective advertising, the obfuscated jargons of illicit goods or services need to be easily understood by their target customers (e.g., sharing similar shape or pronunciation). Secondly, to promote the underground business, the defacements are crafted to boost search engine ranking of the defaced web pages while trying to stay stealthy from the maintainers and legitimate users of the compromised websites. Leveraging these insights, we first follow the human convention and design a jargon normalization algorithm to map obfuscated jargons to their original forms. We then develop a tag embedding mechanism, which enables DMOS to focus more on those not-so-visually-obvious, yet site-ranking influential HTML tags (e.g., title, meta). Consequently, DMOS can reliably detect illicit content hidden in compromised web pages. In particular, we have deployed DMOS as a cloudbased monitoring service for a five-month trial run. It has analyzed more than 38 million web pages across 7000+ commercial Chinese websites and found defacements in 11% of these websites. It achieves a recall over 99% with a precision about 89%. While the original design of DMOS focuses on the detection of Chinese promotional defacements, we have extended the system and demonstrated its applicability for English website defacement detection via proof-of-concept experiments.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers2
- SoK: State of the Krawlers - Evaluating the Effectiveness of Crawling Algorithms for Web Security MeasurementsAleksei Stafeev, Giancarlo PellegrinoUSENIX Security 2024 · 12 citations
- Exposing the Hidden Layer: Software Repositories in the Service of Seo ManipulationMengying Wu, Geng Hong, Wuyuao Mai, Xinyi Wu et al.ICSE 2025 · 1 citation
Builds on7
- ALBERT: A Lite BERT for Self-supervised Learning of Language RepresentationsZhenzhong Lan, Mingda Chen, Sebastian Goodman, Kevin Gimpel et al.ICLR 2020 · 7,418 citations
- Reading Thieves' Cant: Automatically Identifying and Understanding Dark Jargons from Cybercrime MarketplacesKan Yuan, Haoran Lu, Xiaojing Liao, XiaoFeng WangUSENIX Security 2018 · 56 citations
- Stealthy Porn: Understanding Real-World Adversarial Images for Illicit Online PromotionKan Yuan, Di Tang, Xiaojing Liao, XiaoFeng Wang et al.S&P 2019 · 49 citations
- How to Learn Klingon without a Dictionary: Detection and Measurement of Black Keywords Used by the Underground EconomyHao Yang, Xiulin Ma, Kun Du, Zhou Li et al.S&P 2017 · 48 citations
- Seeking Nonsense, Looking for Trouble: Efficient Promotional-Infection Detection through Semantic Inconsistency SearchXiaojing Liao, Kan Yuan, XiaoFeng Wang, Zhongyu Pei et al.S&P 2016 · 41 citations
Related papers
- The Chameleon on the Web: an Empirical Study of the Insidious Proactive Web DefacementsRui ZhaoWWW 2023 · 4 citations
- Breaking Free from Ivory Tower: Evaluating and Enhancing Real-world Chinese Underground Adversarial Jargon DetectionZhifan Jiang, Mingxuan Liu, Yue Qin, Baojun LiuS&P 2026 · 2 citations
- MAWSEO: Adversarial Wiki Search Poisoning for Illicit Online PromotionZilong Lin, Zhengyi Li, Xiaojing Liao, XiaoFeng Wang et al.S&P 2024 · 16 citations
- NOKEScam: Understanding and Rectifying Non-Sense Keywords Spear Scam in Search EnginesMingxuan Liu, Yunyi Zhang, Lijie Wu, Baojun Liu et al.USENIX Security 2025
- Shielding QR Codes: Unveiling the Real-World Illicit Promotion Behind Adversarial QR CodesLijie Wu, Xiaoping Zhang, Mingxuan Liu, Yue Qin et al.USENIX Security 2026
