Understanding iOS-based Crowdturfing Through Hidden UI Analysis
Yeonjoon Lee, Xueqiang Wang, Kwangwuk Lee, Xiaojing Liao, XiaoFeng Wang, Tongxin Li, Xianghang Mi
摘要
A new type of malicious crowdsourcing (a.k.a., crowdturfing) clients, mobile apps with hidden crowdturfing user interface (UI), is increasingly being utilized by miscreants to coordinate crowdturfing workers and publish mobile-based crowdturfing tasks (e.g., app ranking manipulation) even on the strictly controlled Apple App Store. These apps hide their crowdturfing content behind innocent-looking UIs to bypass app vetting and infiltrate the app store. To the best of our knowledge, little has been done so far to understand this new abusive service, in terms of its scope, impact and techniques, not to mention any effort to identify such stealthy crowdturfing apps on a large scale, particularly on the Apple platform. In this paper, we report the first measurement study on iOS apps with hidden crowdturfing UIs. Our findings bring to light the mobile-based crowdturfing ecosystem (e.g., app promotion for worker recruitment, campaign identification) and the underground developer's tricks (e.g., scheme, logic bomb) for evading app vetting.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper10
- When the User Is Inside the User Interface: An Empirical Study of UI Security Properties in Augmented RealityKaiming Cheng, Arkaprabha Bhattacharya, Michelle Lin, Jaewook Lee 等USENIX Security 2024 · 被引用 29 次
- Analyzing Ground-Truth Data of Mobile Gambling ScamsGeng Hong, Zhemin Yang, Sen Yang, Xiaojing Liao 等S&P 2022 · 被引用 29 次
- Detecting and Measuring Misconfigured Manifests in Android AppsYuqing Yang, Mohamed Elsabagh, Chaoshun Zuo, Ryan Johnson 等CCS 2022 · 被引用 11 次
- iHunter: Hunting Privacy Violations at Scale in the Software Supply Chain on iOSDexin Liu, Yue Xiao, Chaoqi Zhang, Kaitao Xie 等USENIX Security 2024 · 被引用 6 次
- CydiOS: A Model-Based Testing Framework for iOS AppsShuohan Wu, Jianfeng Li, Hao Zhou, Yongsheng Fang 等ISSTA 2023 · 被引用 4 次
它引用的顶会 Paper2
- Following Devil's Footprints: Cross-Platform Analysis of Potentially Harmful Libraries on Android and iOSKai Chen, Xueqiang Wang, Yi Chen, Peng Wang 等S&P 2016 · 被引用 111 次
- Staying Secure and Unprepared: Understanding and Mitigating the Security Risks of Apple ZeroConfXiaolong Bai, Luyi Xing, Nan Zhang, XiaoFeng Wang 等S&P 2016 · 被引用 33 次
相关 Paper
- The Art and Craft of Fraudulent App Promotion in Google PlayMizanur Rahman, Nestor Hernandez, Ruben Recabarren, Syed Ishtiaque Ahmed 等CCS 2019 · 被引用 28 次
- Mobilizing Crowdwork: A Systematic Assessment of the Mobile Usability of HITsSenjuti Dutta, Rhema Linder, Doug Lowe, Richard Rosenbalm 等CHI 2022 · 被引用 4 次
- A Longitudinal Study of Removed Apps in iOS App StoreFuqi Lin, Haoyu Wang, Liu Wang, Xuanzhe LiuWWW 2021 · 被引用 20 次
- Improving Data Quality via Pre-Task Participant Screening in Crowdsourced GUI ExperimentsTakaya Miyama, Satoshi Nakamura, Shota YamanakaCHI 2026 · 被引用 2 次
- A Tale of Two Communities: Privacy of Third Party App Users in Crowdsourcing - The Case of Receipt TranscriptionWeiping Pei, Yanina Likhtenshteyn, Chuan YueCSCW 2023 · 被引用 1 次
