Tickets or Privacy? Understand the Ecosystem of Chinese Ticket Grabbing Apps
Yijing Liu, Yiming Zhang, Baojun Liu, Haixin Duan, Qiang Li, Mingxuan Liu, Ruixuan Li, Jia Yao
摘要
Due to the prevalence of scalping and the promotion of realname ticketing systems, user-oriented mobile ticket grabbing apps have become a popular pattern for scalpers. Compared with traditional scalper-oriented scalping, ticket grabbing apps pose security and privacy risks to users directly. In our study, we take the first step towards revealing the ticket grabbing app ecosystem from the perspectives of app developers, app users, and target platforms synthetically. We built a large-scale dataset of ticket grabbing apps in the wild within China, containing 758 Chinese ticket grabbing apps with 3,121 versions. Based on the detailed analysis of these apps, we found that ticket grabbing has formed a mature industrial chain, with various specialized technical characteristics to enhance the success rate, such as the abuse of Android accessibility services. We also revealed the profit model of ticket grabbing apps, and disclosed severe security and privacy hazards they pose to end users, including the collection of sensitive information and continuous screenshots. We further conducted an online survey involving 184 participants to get users' usage and privacy concerns on ticket grabbing apps, and regrettably found that users prioritize "tickets" over "privacy". Finally, we proposed an "Indirect Combat" approach to assist in the defense mechanisms. In summary, our findings provide target platforms and users with a better understanding of the ticket grabbing app ecosystem in China, enabling them to better detect and combat these apps.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper3
- CtPhishCapture: Uncovering Credential-Theft-Based Phishing Scams Targeting Cryptocurrency WalletsHui Jiang, Zhenrui Zhang, Xiang Li, Yan Li 等NDSS 2026 · 被引用 1 次
- CHAMELEOSCAN: Demystifying and Detecting iOS Chameleon Apps via LLM-Powered UI ExplorationHongyu Lin, Yicheng Hu, Haitao Xu, Yanchen Lu 等NDSS 2026 · 被引用 1 次
- Cracks in the Walled Garden: Dissecting the Gray-Market of Unauthorized iOS App Distribution via Ad Hoc SideloadingYijing Liu, Yiming Zhang, Baojun Liu, Haixin DuanUSENIX Security 2026
它引用的顶会 Paper9
- The Spyware Used in Intimate Partner ViolenceRahul Chatterjee, Periwinkle Doerfler, Hadas Orgad, Sam Havron 等S&P 2018 · 被引用 167 次
- "Now I'm a bit angry: " Individuals' Awareness, Perception, and Responses to Data Breaches that Affected ThemPeter Mayer, Yixin Zou, Florian Schaub, Adam J. AvivUSENIX Security 2021 · 被引用 65 次
- Exploring the Needs of Users for Supporting Privacy-Protective Behaviors in Smart HomesHaojian Jin, Boyuan Guo, Rituparna Roychoudhury, Yaxing Yao 等CHI 2022 · 被引用 48 次
- Are Privacy Dashboards Good for End Users? Evaluating User Perceptions and Reactions to Google's My ActivityFlorian M. Farke, David G. Balash, Maximilian Golla, Markus Dürmuth 等USENIX Security 2021 · 被引用 48 次
- Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof HostingArman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Hernandez Gañán 等USENIX Security 2019 · 被引用 40 次
相关 Paper
- Understanding Worldwide Private Information Collection on AndroidYun Shen, Pierre-Antoine Vervier, Gianluca StringhiniNDSS 2021
- Doxing-as-a-Service: Demystifying the Chinese Online Doxing EcosystemYiran Gao, Pengcheng Xia, Liu Wang, Tianming Liu 等WWW 2026
- Maginot Line: Assessing a New Cross-app Threat to PII-as-Factor Authentication in Chinese Mobile AppsFannv He, Yan Jia, Jiayu Zhao, Yue Fang 等NDSS 2024
- Demystifying Resource Management Risks in Emerging Mobile App-in-App EcosystemsHaoran Lu, Luyi Xing, Yue Xiao, Yifan Zhang 等CCS 2020 · 被引用 48 次
- Demystifying Illegal Mobile Gambling AppsYuhao Gao, Haoyu Wang, Li Li, Xiapu Luo 等WWW 2021 · 被引用 30 次
