Unveiling Collusion-Based Ad Attribution Laundering Fraud: Detection, Analysis, and Security Implications
Tong Zhu, Chaofan Shou, Zhen Huang, Guoxing Chen, Xiaokuan Zhang, Yan Meng, Shuang Hao, Haojin Zhu
摘要
In recent years, the growth of mobile advertising has been driven by in-app programmatic advertising and technologies like Real-Time Bidding (RTB). However, this growth has also led to an increase in ad fraud, such as click injection, background ad activity, etc. While existing studies have primarily concentrated on ad fraud within individual apps or devices, this paper introduces a new form of collusion-based ad fraud, named ad attribution laundering fraud (ALF). ALF involves multiple apps collaborating to deceive advertisers by misrepresenting the app where ads are displayed. The collusion-based approach allows lower-quality apps to exploit the reputable identities of seemingly legitimate apps. This deceives advertisers or ad networks into believing that the advertisements they place are reaching potentially valid end-users on the legitimate app. The seemingly legitimate ad events and ad attribution procedures employed by individual apps in such attacks can evade detection by existing tools.
To detect ALF, we design and implement the first detection framework, AlfScan. It overcomes two challenges to extract apps' identities from diverse and obfuscated apps using both static and dynamic analysis techniques, then cross-check the identities to identify ALF. We evaluate AlfScan on a 200-app ground truth dataset, and it achieves 92% precision and 92% recall. We use AlfScan to conduct a large-scale analysis on 91, 006 apps and identify 4, 515 unique fraudulent apps and 1, 483 fraudulent clusters, exposing patterns among fraudulent developers and revealing reliability * Guoxing Chen and Haojin Zhu are the corresponding authors.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
它引用的顶会 Paper14
- Intriguing Properties of Adversarial ML Attacks in the Problem SpaceFabio Pierazzi, Feargus Pendlebury, Jacopo Cortellazzi, Lorenzo CavallaroS&P 2020 · 被引用 334 次
- IntelliDroid: A Targeted Input Generator for the Dynamic Analysis of Android MalwareMichelle Y. Wong, David LieNDSS 2016 · 被引用 253 次
- Time-travel testing of Android appsZhen Dong, Marcel Böhme, Lucia Cojocaru, Abhik RoychoudhuryICSE 2020 · 被引用 104 次
- What Makes a "Bad" Ad? User Perceptions of Problematic Online AdvertisingEric Zeng, Tadayoshi Kohno, Franziska RoesnerCHI 2021 · 被引用 55 次
- Unleashing the Walking Dead: Understanding Cross-App Remote Infections on Mobile WebViewsTongxin Li, Xueqiang Wang, Mingming Zha, Kai Chen 等CCS 2017 · 被引用 47 次
相关 Paper
- The Abuser Inside Apps: Finding the Culprit Committing Mobile Ad FraudJoongyum Kim, Junghwan Park, Sooel SonNDSS 2021
- Understanding and Detecting Mobile Ad Fraud Through the Lens of Invalid TrafficSuibin Sun, Le Yu, Xiaokuan Zhang, Minhui Xue 等CCS 2021 · 被引用 22 次
- Dissecting Click Fraud Autonomy in the WildTong Zhu, Yan Meng, Haotian Hu, Xiaokuan Zhang 等CCS 2021 · 被引用 14 次
- AdLens: Efficient Detection of Deceptive Software AdsRitik Roongta, Marwan Adnan Darwish, Masoud Poorghaffar Aghdam, Rachel Greenstadt 等CCS 2026
- MadDroid: Characterizing and Detecting Devious Ad Contents for Android AppsTianming Liu, Haoyu Wang, Li Li, Xiapu Luo 等WWW 2020 · 被引用 44 次
