User Tools

Site Tools


literature:bibliography

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revisionPrevious revision
Next revision
Previous revision
literature:bibliography [2026/09/24 21:44] – Append 19 entries for security:online_scams (online scams: fake shops, support scams, crypto scams). Authored by Claude karel.kubicek.claudeliterature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude
Line 10281: Line 10281:
   series        = {USENIX Security 2011},   series        = {USENIX Security 2011},
   url           = {https://www.usenix.org/legacy/event/sec11/tech/},   url           = {https://www.usenix.org/legacy/event/sec11/tech/},
 +}
 +@inproceedings{adjibi2025_guardians,
 +  author        = {Adjibi, Boladji Vinny and Avgetidis, Athanasios and Antonakakis, Manos and Bailey, Michael and Monrose, Fabian},
 +  title         = {The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-guardians-of-name-street-studying-the-defensive-registration-practices-of-the-fortune-500/},
 +}
 +@inproceedings{adjibi2026_udrp,
 +  author        = {Adjibi, Vinny and Avgetidis, Athanasios and Antonakakis, Manos and Dainotti, Alberto and Bailey, Michael and Monrose, Fabian},
 +  title         = {Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/repairing-trust-in-domain-name-disputes-practices-insights-from-a-quarter-centurys-worth-of-squabbles/},
 +}
 +@inproceedings{akiwate2020_lame,
 +  author        = {Akiwate, Gautam and Jonker, Mattijs and Sommese, Raffaele and Foster, Ian D. and Voelker, Geoffrey M. and Savage, Stefan and Claffy, K. C.},
 +  title         = {Unresolved Issues: Prevalence, Persistence, and Perils of Lame Delegations},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423623},
 +}
 +@inproceedings{akiwate2021_risky,
 +  author        = {Akiwate, Gautam and Savage, Stefan and Voelker, Geoffrey M. and Claffy, Kimberly C.},
 +  title         = {Risky BIZness: risks derived from registrar name management},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487816},
 +}
 +@inproceedings{alhamdan2025_deno,
 +  author        = {AlHamdan, Abdullah and Staicu, Cristian-Alexandru},
 +  title         = {Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/welcome-to-jurassic-park-a-comprehensive-study-of-security-risks-in-deno-and-its-ecosystem/},
 +}
 +@inproceedings{alowaisheq2019_cracking,
 +  author        = {Alowaisheq, Eihal and Wang, Peng and Alrwais, Sumayah and Liao, Xiaojing and Wang, XiaoFeng and Alowaisheq, Tasneem and Mi, Xianghang and Tang, Siyuan and Liu, Baojun},
 +  title         = {Cracking the Wall of Confinement: Understanding and Analyzing Malicious Domain Take-downs},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2019},
 +  series        = {NDSS 2019},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/cracking-the-wall-of-confinement-understanding-and-analyzing-malicious-domain-take-downs/},
 +}
 +@inproceedings{alowaisheq2020_zombie,
 +  author        = {Alowaisheq, Eihal and Tang, Siyuan and Wang, Zhihao and Alharbi, Fatemah and Liao, Xiaojing and Wang, XiaoFeng},
 +  title         = {Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417864},
 +}
 +@inproceedings{alrwais2014_parking,
 +  author        = {Alrwais, Sumayah and Yuan, Kan and Alowaisheq, Eihal and Li, Zhou and Wang, XiaoFeng},
 +  title         = {Understanding the Dark Side of Domain Parking},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2014},
 +  series        = {USENIX Security 2014},
 +  url           = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/alrwais},
 +}
 +@inproceedings{chen2016_mitm,
 +  author        = {Chen, Qi Alfred and Osterweil, Eric and Thomas, Matthew and Mao, Zhuoqing Morley},
 +  title         = {MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2016},
 +  series        = {IEEE S&P 2016},
 +  doi           = {10.1109/sp.2016.46},
 +}
 +@inproceedings{halvorson2015_academy,
 +  author        = {Halvorson, Tristan and Der, Matthew F. and Foster, Ian D. and Savage, Stefan and Saul, Lawrence K. and Voelker, Geoffrey M.},
 +  title         = {From .academy to .zone: An Analysis of the New TLD Land Rush},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2015},
 +  series        = {IMC 2015},
 +  doi           = {10.1145/2815675.2815696},
 +}
 +@inproceedings{hortea2026_dead,
 +  author        = {Hortea, Gabriel and Girish, Aniketh and Vallina-Rodriguez, Narseo and Tapiador, Juan},
 +  title         = {Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2026},
 +  series        = {PoPETs 2026},
 +  doi           = {10.56553/popets-2026-0112},
 +}
 +@inproceedings{hu2021_idn,
 +  author        = {Hu, Hang and Jan, Steve T.K. and Wang, Yang and Wang, Gang},
 +  title         = {Assessing Browser-level Defense against IDN-based Phishing},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/hu-hang},
 +}
 +@inproceedings{kalafut2010_orphan,
 +  author        = {Kalafut, Andrew J. and Gupta, Minaxi and Cole, Christopher A. and Chen, Lei and Myers, Nathan E.},
 +  title         = {An empirical study of orphan DNS servers in the internet},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2010},
 +  series        = {IMC 2010},
 +  doi           = {10.1145/1879141.1879182},
 +}
 +@inproceedings{khan2015_every,
 +  author        = {Khan, Mohammad Taha and Huo, Xiang and Li, Zhou and Kanich, Chris},
 +  title         = {Every Second Counts: Quantifying the Negative Externalities of Cybercrime via Typosquatting},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2015},
 +  series        = {IEEE S&P 2015},
 +  doi           = {10.1109/sp.2015.16},
 +}
 +@inproceedings{kintis2017_hiding,
 +  author        = {Kintis, Panagiotis and Miramirkhani, Najmeh and Lever, Charles and Chen, Yizheng and Gómez, Rosa Romero and Pitropakis, Nikolaos and Nikiforakis, Nick and Antonakakis, Manos},
 +  title         = {Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2017},
 +  series        = {CCS 2017},
 +  doi           = {10.1145/3133956.3134002},
 +}
 +@inproceedings{lauinger2016_whois,
 +  author        = {Lauinger, Tobias and Onarlioglu, Kaan and Chaabane, Abdelberi and Robertson, William and Kirda, Engin},
 +  title         = {WHOIS Lost in Translation: (Mis)Understanding Domain Name Expiration and Re-Registration},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2016},
 +  series        = {IMC 2016},
 +  doi           = {10.1145/2987443.2987463},
 +}
 +@inproceedings{lauinger2017_game,
 +  author        = {Lauinger, Tobias and Chaabane, Abdelberi and Buyukkayhan, Ahmet Salih and Onarlioglu, Kaan and Robertson, William},
 +  title         = {Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2017},
 +  series        = {USENIX Security 2017},
 +  url           = {https://www.usenix.org/conference/usenixsecurity17/technical-sessions/presentation/lauinger},
 +}
 +@inproceedings{lauinger2018_deletion,
 +  author        = {Lauinger, Tobias and Buyukkayhan, Ahmet Salih and Chaabane, Abdelberi and Robertson, William K. and Kirda, Engin},
 +  title         = {From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2018},
 +  series        = {IMC 2018},
 +  doi           = {10.1145/3278532.3278560},
 +}
 +@inproceedings{lever2016_domainz,
 +  author        = {Lever, Chaz and Walls, Robert J. and Nadji, Yacin and Dagon, David and McDaniel, Patrick D. and Antonakakis, Manos},
 +  title         = {Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2016},
 +  series        = {IEEE S&P 2016},
 +  doi           = {10.1109/sp.2016.47},
 +}
 +@inproceedings{liu2015_whois,
 +  author        = {Liu, Suqi and Foster, Ian D. and Savage, Stefan and Voelker, Geoffrey M. and Saul, Lawrence K.},
 +  title         = {Who is .com?: Learning to Parse WHOIS Records},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2015},
 +  series        = {IMC 2015},
 +  doi           = {10.1145/2815675.2815693},
 +}
 +@inproceedings{liu2016_dangling,
 +  author        = {Liu, Daiping and Hao, Shuai and Wang, Haining},
 +  title         = {All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2016},
 +  series        = {CCS 2016},
 +  doi           = {10.1145/2976749.2978387},
 +}
 +@inproceedings{liu2022_container,
 +  author        = {Liu, Guannan and Gao, Xing and Wang, Haining and Sun, Kun},
 +  title         = {Exploring the Unchartered Space of Container Registry Typosquatting},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/liu-guannan},
 +}
 +@inproceedings{ma2023_stale,
 +  author        = {Ma, Zane and Faulkenberry, Aaron and Papastergiou, Thomas and Durumeric, Zakir and Bailey, Michael D. and Keromytis, Angelos D. and Monrose, Fabian and Antonakakis, Manos},
 +  title         = {Stale TLS Certificates: Investigating Precarious Third-Party Access to Valid TLS Keys},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624802},
 +}
 +@inproceedings{miramirkhani2018_panning,
 +  author        = {Miramirkhani, Najmeh and Barron, Timothy and Ferdman, Michael and Nikiforakis, Nick},
 +  title         = {Panning for gold.com: Understanding the Dynamics of Domain Dropcatching},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2018},
 +  series        = {TheWebConf 2018},
 +  doi           = {10.1145/3178876.3186092},
 +}
 +@inproceedings{muzammil2024_panning,
 +  author        = {Muzammil, Muhammad and Wu, Zhengyu and Balasubramanian, Aruna and Nikiforakis, Nick},
 +  title         = {Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689009},
 +}
 +@inproceedings{neupane2023_confusion,
 +  author        = {Neupane, Shradha and Holmes, Grant and Wyss, Elizabeth and Davidson, Drew and De Carli, Lorenzo},
 +  title         = {Beyond Typosquatting: An In-depth Look at Package Confusion},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/neupane},
 +}
 +@inproceedings{nikiforakis2013_bitsquatting,
 +  author        = {Nikiforakis, Nick and Van Acker, Steven and Meert, Wannes and Desmet, Lieven and Piessens, Frank and Joosen, Wouter},
 +  title         = {Bitsquatting: exploiting bit-flips for fun, or profit?},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2013},
 +  series        = {TheWebConf 2013},
 +  doi           = {10.1145/2488388.2488474},
 +}
 +@inproceedings{pauley2022_ipreuse,
 +  author        = {Pauley, Eric and Sheatsley, Ryan and Hoak, Blaine and Burke, Quinn and Beugin, Yohan and McDaniel, Patrick D.},
 +  title         = {Measuring and Mitigating the Risk of IP Reuse on Public Clouds},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2022},
 +  series        = {IEEE S&P 2022},
 +  doi           = {10.1109/sp46214.2022.9833784},
 +}
 +@inproceedings{saric2024_hyperlink,
 +  author        = {Saric, Kevin and Savins, Felix and Ramachandran, Gowri Sankar and Jurdak, Raja and Nepal, Surya},
 +  title         = {Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645510},
 +}
 +@inproceedings{so2022_spots,
 +  author        = {So, Johnny and Miramirkhani, Najmeh and Ferdman, Michael and Nikiforakis, Nick},
 +  title         = {Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2022},
 +  series        = {IEEE S&P 2022},
 +  doi           = {10.1109/sp46214.2022.9833609},
 +}
 +@inproceedings{so2025_lost,
 +  author        = {So, Johnny and Sanchez-Rola, Iskander and Nikiforakis, Nick},
 +  title         = {Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/so},
 +}
 +@inproceedings{sommese2024_darkdns,
 +  author        = {Sommese, Raffaele and Akiwate, Gautam and Affinito, Antonia and Müller, Moritz and Jonker, Mattijs and Claffy, K. C.},
 +  title         = {DarkDNS: Revisiting the Value of Rapid Zone Update},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2024},
 +  series        = {IMC 2024},
 +  doi           = {10.1145/3646547.3689021},
 +}
 +@inproceedings{suzuki2019_shamfinder,
 +  author        = {Suzuki, Hiroaki and Chiba, Daiki and Yoneya, Yoshiro and Mori, Tatsuya and Goto, Shigeki},
 +  title         = {ShamFinder: An Automated Framework for Detecting IDN Homographs},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2019},
 +  series        = {IMC 2019},
 +  doi           = {10.1145/3355369.3355587},
 +}
 +@inproceedings{szurdi2014_taile,
 +  author        = {Szurdi, Janos and Kocso, Balazs and Cseh, Gabor and Spring, Jonathan and Felegyhazi, Mark and Kanich, Chris},
 +  title         = {The Long “Taile” of Typosquatting Domain Names},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2014},
 +  series        = {USENIX Security 2014},
 +  url           = {https://www.usenix.org/conference/usenixsecurity14/technical-sessions/presentation/szurdi},
 +}
 +@inproceedings{vissers2015_parking,
 +  author        = {Vissers, Thomas and Joosen, Wouter and Nikiforakis, Nick},
 +  title         = {Parking Sensors: Analyzing and Detecting Parked Domains},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2015},
 +  series        = {NDSS 2015},
 +  url           = {https://www.ndss-symposium.org/ndss2015/ndss-2015-programme/parking-sensors-analyzing-and-detecting-parked-domains/},
 +}
 +@inproceedings{vissers2017_wolf,
 +  author        = {Vissers, Thomas and Barron, Timothy and Van Goethem, Tom and Joosen, Wouter and Nikiforakis, Nick},
 +  title         = {The Wolf of Name Street: Hijacking Domains Through Their Nameservers},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2017},
 +  series        = {CCS 2017},
 +  doi           = {10.1145/3133956.3133988},
 +}
 +@inproceedings{zhang2023_wolf,
 +  author        = {Zhang, Fenglu and Zhang, Yunyi and Liu, Baojun and Alowaisheq, Eihal and Ying, Lingyun and Li, Xiang and Zhang, Zaifeng and Liu, Ying and Duan, Haixin and Zhang, Min},
 +  title         = {Wolf in Sheep's Clothing: Evaluating Security Risks of the Undelegated Record on DNS Hosting Services},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2023},
 +  series        = {IMC 2023},
 +  doi           = {10.1145/3618257.3624839},
 +}
 +@inproceedings{zhang2024_cross,
 +  author        = {Zhang, Yunyi and Zhang, Mingming and Liu, Baojun and Liu, Zhan and Zhang, Jia and Duan, Haixin and Zhang, Min and Shi, Fan and Xu, Chengxi},
 +  title         = {Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-yunyi-zone},
 +}
 +@inproceedings{zhang2024_glue,
 +  author        = {Zhang, Yunyi and Liu, Baojun and Duan, Haixin and Zhang, Min and Li, Xiang and Shi, Fan and Xu, Chengxi and Alowaisheq, Eihal},
 +  title         = {Rethinking the Security Threats of Stale DNS Glue Records},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/zhang-yunyi-rethinking},
 +}
 +@inproceedings{zhang2025_misty,
 +  author        = {Zhang, Mingming and Zhang, Yunyi and Liu, Baojun and Duan, Haixin and Zhang, Min and Shi, Fan and Xu, Chengxi},
 +  title         = {Misty Registry: An Empirical Study of Flawed Domain Registry Operation},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/zhang-mingming},
 +}
 +@inproceedings{roberts2019_impersonation,
 +  author        = {Roberts, Richard and Goldschlag, Yaelle and Walter, Rachel and Chung, Taejoong and Mislove, Alan and Levin, Dave},
 +  title         = {You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2019},
 +  series        = {CCS 2019},
 +  doi           = {10.1145/3319535.3363188},
 +}
 +
 +@inproceedings{marjanov2026_stayin,
 +  author        = {Marjanov, Tina and Tsuchiya, Taro and Ioannidis, Konstantinos and Hughes, Jack and Christin, Nicolas and Hutchings, Alice},
 +  title         = {Stayin' Alive: How Global Stolen Data Markets Thrive on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/marjanov},
 +}
 +
 +@inproceedings{gao2026_doxing,
 +  author        = {Gao, Yiran and Xia, Pengcheng and Wang, Liu and Liu, Tianming and Wang, Haoyu},
 +  title         = {Doxing-as-a-Service: Demystifying the Chinese Online Doxing Ecosystem},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792296},
 +}
 +
 +@inproceedings{xu2019_anatomy,
 +  author        = {Xu, Jiahua and Livshits, Benjamin},
 +  title         = {The Anatomy of a Cryptocurrency Pump-and-Dump Scheme},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2019},
 +  series        = {USENIX Security 2019},
 +  url           = {https://www.usenix.org/conference/usenixsecurity19/presentation/xu-jiahua},
 +}
 +
 +@inproceedings{sun2021_having,
 +  author        = {Sun, Zhibo and Oest, Adam and Zhang, Penghui and Rubio-Medrano, Carlos and Bao, Tiffany and Wang, Ruoyu and Zhao, Ziming and Shoshitaishvili, Yan and Doupé, Adam and Ahn, Gail-Joon},
 +  title         = {Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/sun-zhibo},
 +}
 +
 +@inproceedings{he2025_unmasking,
 +  author        = {He, Bowen and Hu, Yufeng and Chen, Zhuo and Chen, Yuan and Yu, Ting and Chang, Rui and Wu, Lei and Zhou, Yajin},
 +  title         = {Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2025},
 +  series        = {IMC 2025},
 +  doi           = {10.1145/3730567.3764476},
 +}
 +
 +@inproceedings{weyns2026_mirai,
 +  author        = {Weyns, Maarten and Ferrero, Dario and Beek, Stefan Op de and Wagner, Daniel and Smaragdakis, Georgios and Griffioen, Harm},
 +  title         = {From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/weyns},
 +}
 +
 +@inproceedings{acharya2025_pirates,
 +  author        = {Acharya, Bhupendra and Lazzaro, Dario and Cinà, Antonio Emanuele and Holz, Thorsten},
 +  title         = {Pirates of Charity: Exploring Donation-based Abuses in Social Media Platforms},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714634},
 +}
 +
 +@inproceedings{hoseini2020_demystifying,
 +  author        = {Hoseini, Mohamad and Melo, Philipe and Junior, Manoel and Benevenuto, Fabrício and Chandrasekaran, Balakrishnan and Feldmann, Anja and Zannettou, Savvas},
 +  title         = {Demystifying the Messaging Platforms' Ecosystem Through the Lens of Twitter},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2020},
 +  series        = {IMC 2020},
 +  doi           = {10.1145/3419394.3423651},
 +}
 +
 +@inproceedings{resende2019_information,
 +  author        = {Resende, Gustavo and Melo, Philipe F. and Sousa, Hugo and Messias, Johnnatan and Vasconcelos, Marisa and Almeida, Jussara M. and Benevenuto, Fabrício},
 +  title         = {(Mis)Information Dissemination in WhatsApp: Gathering, Analyzing and Countermeasures},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2019},
 +  series        = {TheWebConf 2019},
 +  doi           = {10.1145/3308558.3313688},
 +}
 +
 +@inproceedings{saha2021_short,
 +  author        = {Saha, Punyajoy and Mathew, Binny and Garimella, Kiran and Mukherjee, Animesh},
 +  title         = {"Short is the Road that Leads from Fear to Hate": Fear Speech in Indian WhatsApp Groups},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2021},
 +  series        = {TheWebConf 2021},
 +  doi           = {10.1145/3442381.3450137},
 +}
 +
 +@inproceedings{kireev2025_characterizing,
 +  author        = {Kireev, Klim and Mykhno, Yevhen and Troncoso, Carmela and Overdorf, Rebekah},
 +  title         = {Characterizing and Detecting Propaganda-Spreading Accounts on Telegram},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/kireev},
 +}
 +
 +@inproceedings{vu2024_easy,
 +  author        = {Vu, Anh V. and Hutchings, Alice and Anderson, Ross J.},
 +  title         = {No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2024},
 +  series        = {IEEE S&P 2024},
 +  doi           = {10.1109/sp54263.2024.00007},
 +}
 +
 +@inproceedings{vu2024_getting,
 +  author        = {Vu, Anh V. and Thomas, Daniel R. and Collier, Ben and Hutchings, Alice and Clayton, Richard and Anderson, Ross J.},
 +  title         = {Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2024},
 +  series        = {TheWebConf 2024},
 +  doi           = {10.1145/3589334.3645401},
 +}
 +
 +@inproceedings{vafa2025_learning,
 +  author        = {Vafa, Elham Pourabbas and Singhal, Mohit and Thota, Poojitha and Roy, Sayak Saha},
 +  title         = {Learning from Censored Experiences: Social Media Discussions around Censorship Circumvention Technologies},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2025},
 +  series        = {IEEE S&P 2025},
 +  doi           = {10.1109/sp61157.2025.00062},
 +}
 +
 +@inproceedings{recabarren2023_strategies,
 +  author        = {Recabarren, Ruben and Carbunar, Bogdan and Hernandez, Nestor and Shafin, Ashfaq Ali},
 +  title         = {Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/recabarren},
 +}
 +
 +@inproceedings{aliapoulios2021_characterization,
 +  author        = {Aliapoulios, Maxwell and Take, Kejsi and Ramakrishna, Prashanth and Borkan, Daniel and Goldberg, Beth and Sorensen, Jeffrey and Turner, Anna and Greenstadt, Rachel and Lauinger, Tobias and McCoy, Damon},
 +  title         = {A large-scale characterization of online incitements to harassment across platforms},
 +  booktitle     = {Proceedings of the ACM Internet Measurement Conference},
 +  year          = {2021},
 +  series        = {IMC 2021},
 +  doi           = {10.1145/3487552.3487852},
 +}
 +
 +@inproceedings{bahramali2020_practical,
 +  author        = {Bahramali, Alireza and Houmansadr, Amir and Soltani, Ramin and Goeckel, Dennis and Towsley, Don},
 +  title         = {Practical Traffic Analysis Attacks on Secure Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2020},
 +  series        = {NDSS 2020},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/practical-traffic-analysis-attacks-on-secure-messaging-applications/},
 +}
 +
 +@inproceedings{weerasinghe2020_people,
 +  author        = {Weerasinghe, Janith and Flanigan, Bailey and Stein, Aviel J. and McCoy, Damon and Greenstadt, Rachel},
 +  title         = {The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2020},
 +  series        = {TheWebConf 2020},
 +  doi           = {10.1145/3366423.3380256},
 +}
 +
 +@inproceedings{shen2024_anything,
 +  author        = {Shen, Xinyue and Chen, Zeyuan and Backes, Michael and Shen, Yun and Zhang, Yang},
 +  title         = {"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670388},
 +}
 +
 +@inproceedings{yu2024_listen,
 +  author        = {Yu, Zhiyuan and Liu, Xiaogeng and Liang, Shunning and Cameron, Zach and Xiao, Chaowei and Zhang, Ning},
 +  title         = {Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/yu-zhiyuan},
 +}
 +
 +@inproceedings{guo2024_moderating,
 +  author        = {Guo, Keyan and Utkarsh, Ayush and Ding, Wenbo and Ondracek, Isabelle and Zhao, Ziming and Freeman, Guo and Vishwamitra, Nishant and Hu, Hongxin},
 +  title         = {Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/guo-keyan},
 +}
 +
 +@inproceedings{schrittwieser2012_guess,
 +  author        = {Schrittwieser, Sebastian and Frühwirt, Peter and Kieseberg, Peter and Leithner, Manuel and Mulazzani, Martin and Huber, Markus and Weippl, Edgar},
 +  title         = {Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2012},
 +  series        = {NDSS 2012},
 +  url           = {https://www.ndss-symposium.org/ndss2012/ndss-2012-programme/guess-whos-texting-you-evaluating-security-smartphone-messaging-applications/},
 +}
 +
 +@inproceedings{li2025_investigating,
 +  author        = {Li, Jiliang and Lu, Nora Sinong and Hanimann, Isaak and Si, Janice Jianing and Cheng, Dazhao and Zhou, Xiaobo and Wang, Kanye Ye},
 +  title         = {Investigating the Impact of Online Community Involvement on Safety Practices and Perceived Risks Among People Who Use Drugs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/li-jiliang},
 +}
 +
 +@inproceedings{albrecht2021_collective,
 +  author        = {Albrecht, Martin R. and Blasco, Jorge and Jensen, Rikke Bjerg and Mareková, Lenka},
 +  title         = {Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2021},
 +  series        = {USENIX Security 2021},
 +  url           = {https://www.usenix.org/conference/usenixsecurity21/presentation/albrecht},
 +}
 +
 +@inproceedings{arunasalam2024_security,
 +  author        = {Arunasalam, Arjun and Farrukh, Habiba and Tekcan, Eliz and Celik, Z. Berkay},
 +  title         = {Understanding the Security and Privacy Implications of Online Toxic Content on Refugees},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/arunasalam},
 +}
 +
 +@inproceedings{chou2025_bots,
 +  author        = {Chou, Kai-Hsiang and Lin, Yi-Min and Wang, Yi-An and Li, Jonathan Weiping and Kim, Tiffany Hyun-Jin and Hsiao, Hsu-Chun},
 +  title         = {Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/chou},
 +}
 +
 +@inproceedings{wang2025_detecting,
 +  author        = {Wang, Hongyu and Li, Ying and Huang, Ronghong and Mi, Xianghang},
 +  title         = {Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2025},
 +  series        = {TheWebConf 2025},
 +  doi           = {10.1145/3696410.3714550},
 +}
 +@inproceedings{lu2020_demystifying,
 +  author        = {Lu, Haoran and Xing, Luyi and Xiao, Yue and Zhang, Yifan and Liao, Xiaojing and Wang, XiaoFeng and Wang, Xueqiang},
 +  title         = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2020},
 +  series        = {CCS 2020},
 +  doi           = {10.1145/3372297.3417255},
 +}
 +
 +@inproceedings{yang2022_cross,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2022},
 +  series        = {CCS 2022},
 +  doi           = {10.1145/3548606.3560597},
 +}
 +
 +@inproceedings{zhang2022_identity,
 +  author        = {Zhang, Lei and Zhang, Zhibo and Liu, Ancong and Cao, Yinzhi and Zhang, Xiaohan and Chen, Yanjun and Zhang, Yuan and Yang, Guangliang and Yang, Min},
 +  title         = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2022},
 +  series        = {USENIX Security 2022},
 +  url           = {https://www.usenix.org/conference/usenixsecurity22/presentation/zhang-lei},
 +}
 +
 +@inproceedings{zhang2023_leak,
 +  author        = {Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Don't Leak Your Keys: Understanding, Measuring, and Exploiting the AppSecret Leaks in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616591},
 +}
 +
 +@inproceedings{wang2023_uncovering,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2023},
 +  series        = {CCS 2023},
 +  doi           = {10.1145/3576915.3616676},
 +}
 +
 +@inproceedings{wang2023_size,
 +  author        = {Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2023},
 +  series        = {USENIX Security 2023},
 +  url           = {https://www.usenix.org/conference/usenixsecurity23/presentation/wang-chao},
 +}
 +
 +@inproceedings{zhang2024_minicat,
 +  author        = {Zhang, Zidong and Hou, Qinsheng and Ying, Lingyun and Diao, Wenrui and Gu, Yacong and Li, Rui and Guo, Shanqing and Duan, Haixin},
 +  title         = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670294},
 +}
 +
 +@inproceedings{shi2026_better,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Liu, Dingyi and Zhong, Kangwei and Dai, Jiarun and Yang, Min},
 +  title         = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2026},
 +  series        = {NDSS 2026},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/better-safe-than-sorry-uncovering-the-insecure-resource-management-in-app-in-app-cloud-services/},
 +}
 +
 +@inproceedings{cai2025_tell,
 +  author        = {Cai, Yifeng and Zhang, Ziqi and Yao, Mengyu and Liu, Junlin and Zhao, Xiaoke and Fu, Xinyi and Li, Ruoyu and Liu, Zhe and Chen, Xiangqun and Guo, Yao and Li, Ding},
 +  title         = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2025},
 +  series        = {USENIX Security 2025},
 +  url           = {https://www.usenix.org/conference/usenixsecurity25/presentation/cai-yifeng},
 +}
 +
 +@inproceedings{chen2026_minigames,
 +  author        = {Chen, Pei and Hong, Geng and Qin, Yicheng and Wang, Huazhe and Wu, Mengying and Yang, Min and Zhao, Ziru and Zhu, Yuanpeng and Su, Tao},
 +  title         = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/chen-pei},
 +}
 +
 +@inproceedings{yang2025_miniapp,
 +  author        = {Yang, Yuqing and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {Understanding Miniapp Malware: Identification, Dissection, and Characterization},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/understanding-miniapp-malware-identification-dissection-and-characterization/},
 +}
 +
 +@inproceedings{shi2025_skeleton,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Zhong, Kangwei and Yang, Guangliang and Yang, Yifan and Zhang, Xiaohan and Yang, Min},
 +  title         = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps},
 +  booktitle     = {Proceedings of the Network and Distributed System Security Symposium},
 +  year          = {2025},
 +  series        = {NDSS 2025},
 +  url           = {https://www.ndss-symposium.org/ndss-paper/the-skeleton-keys-a-large-scale-analysis-of-credential-leakage-in-mini-apps/},
 +}
 +
 +@inproceedings{he2024_demystifying,
 +  author        = {He, Yi and Guan, Yunchao and Lun, Ruoyu and Song, Shangru and Guo, Zhihao and Zhuge, Jianwei and Chen, Jianjun and Wei, Qiang and Wu, Zehui and Yu, Miao and Shi, Hetian and Li, Qi},
 +  title         = {Demystifying the Security Implications in IoT Device Rental Services},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2024},
 +  series        = {USENIX Security 2024},
 +  url           = {https://www.usenix.org/conference/usenixsecurity24/presentation/he-yi},
 +}
 +
 +@inproceedings{liu2024_riotfuzzer,
 +  author        = {Liu, Kaizheng and Yang, Ming and Ling, Zhen and Zhang, Yue and Lei, Chongqing and Luo, Junzhou and Fu, Xinwen},
 +  title         = {RIoTFuzzer: Companion App Assisted Remote Fuzzing for Detecting Vulnerabilities in IoT Devices},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2024},
 +  series        = {CCS 2024},
 +  doi           = {10.1145/3658644.3670342},
 +}
 +
 +@inproceedings{lee2025_deep,
 +  author        = {Lee, Woonghee and Hur, Junbeom and Kwon, Hyunsoo},
 +  title         = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation},
 +  booktitle     = {Proceedings of the ACM SIGSAC Conference on Computer and Communications Security},
 +  year          = {2025},
 +  series        = {CCS 2025},
 +  doi           = {10.1145/3719027.3765215},
 +}
 +
 +@inproceedings{wei2026_raising,
 +  author        = {Wei, Zhiao and Wang, Chao and Faheem, Haseeb-Ur-Rehman and Xing, Luyi and Aafer, Yousra and Lin, Zhiqiang},
 +  title         = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs},
 +  booktitle     = {Proceedings of the USENIX Security Symposium},
 +  year          = {2026},
 +  series        = {USENIX Security 2026},
 +  url           = {https://www.usenix.org/conference/usenixsecurity26/presentation/wei-zhiao},
 +}
 +
 +@inproceedings{shi2026_convenience,
 +  author        = {Shi, Yizhe and Yang, Zhemin and Yang, Yifan and Yang, Yunteng and Yang, Min},
 +  title         = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem},
 +  booktitle     = {Proceedings of the IEEE Symposium on Security and Privacy},
 +  year          = {2026},
 +  series        = {IEEE S\&P 2026},
 +  doi           = {10.1109/sp63933.2026.00074},
 +}
 +
 +@inproceedings{yang2026_real,
 +  author        = {Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface},
 +  booktitle     = {Proceedings of the ACM Web Conference},
 +  year          = {2026},
 +  series        = {TheWebConf 2026},
 +  doi           = {10.1145/3774904.3792470},
 +}
 +
 +@inproceedings{wang2025_wechat,
 +  author        = {Wang, Mona and Lin, Pellaeon and Knockel, Jeffrey and Greenberg, Will and Mayer, Jonathan and Mittal, Prateek},
 +  title         = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem},
 +  booktitle     = {Proceedings on Privacy Enhancing Technologies},
 +  year          = {2025},
 +  series        = {PoPETs 2025},
 +  doi           = {10.56553/popets-2025-0163},
 +}
 +
 +@article{zhang2021_measurement,
 +  author        = {Zhang, Yue and Turkistani, Bayan and Yang, Allen Yuqing and Zuo, Chaoshun and Lin, Zhiqiang},
 +  title         = {A Measurement Study of {WeChat} Mini-Apps},
 +  journal       = {Proceedings of the ACM on Measurement and Analysis of Computing Systems},
 +  volume        = {5},
 +  number        = {2},
 +  year          = {2021},
 +  series        = {SIGMETRICS 2021},
 +  doi           = {10.1145/3460081},
 +}
 +
 +@inproceedings{baskaran2023_measuring,
 +  author        = {Baskaran, Supraja and Zhao, Lianying and Mannan, Mohammad and Youssef, Amr},
 +  title         = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case},
 +  booktitle     = {Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses},
 +  year          = {2023},
 +  series        = {RAID 2023},
 +  doi           = {10.1145/3607199.3607236},
 +}
 +
 +@inproceedings{wang2023_taintmini,
 +  author        = {Wang, Chao and Ko, Ronny and Zhang, Yue and Yang, Yuqing and Lin, Zhiqiang},
 +  title         = {{TaintMini}: Detecting Flow of Sensitive Data in Mini-Programs with Static Taint Analysis},
 +  booktitle     = {Proceedings of the 45th IEEE/ACM International Conference on Software Engineering},
 +  year          = {2023},
 +  series        = {ICSE 2023},
 +  doi           = {10.1109/ICSE48619.2023.00086},
 +}
 +
 +@inproceedings{meng2023_wemint,
 +  author        = {Meng, Shi and Wang, Liu and Wang, Shenao and Wang, Kailong and Xiao, Xusheng and Bai, Guangdong and Wang, Haoyu},
 +  title         = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs},
 +  booktitle     = {Proceedings of the 38th IEEE/ACM International Conference on Automated Software Engineering},
 +  year          = {2023},
 +  series        = {ASE 2023},
 +  doi           = {10.1109/ASE56229.2023.00151},
 +}
 +
 +@misc{yang2023_sok,
 +  author        = {Yang, Yuqing and Wang, Chao and Zhang, Yue and Lin, Zhiqiang},
 +  title         = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps},
 +  year          = {2023},
 +  howpublished  = {arXiv:2306.07495},
 +  url           = {https://arxiv.org/abs/2306.07495},
 +}
 +
 +@misc{zhang2026_oauth,
 +  author        = {Zhang, Zidong and Xie, Zhentao and Ying, Lingyun and Hou, Qinsheng and Gu, Yacong and Diao, Wenrui and Wu, Jianliang},
 +  title         = {Mini-Programs, Mega-Problems: Unveiling {OAuth}-based Authentication Misuses in Mini-Programs via Dynamic Analysis},
 +  year          = {2026},
 +  howpublished  = {arXiv:2607.08232, accepted at ACM CCS 2026},
 +  url           = {https://arxiv.org/abs/2607.08232},
 +}
 +
 +@misc{ciccotelli2026_tenet,
 +  author        = {Ciccotelli, Andrea and Zappone, Federico and Di Pietro, Roberto},
 +  title         = {{TENET}: Telegram Mini App (in)security},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.17538},
 +  url           = {https://arxiv.org/abs/2608.17538},
 +}
 +
 +@misc{ferrari2026_telegapper,
 +  author        = {Ferrari, Luca and Ceccato, Mariano and Verderame, Luca},
 +  title         = {{TeleGapper}: On the (un)reliability of Privacy Policies in Telegram Mini apps},
 +  year          = {2026},
 +  howpublished  = {arXiv:2608.13390},
 +  url           = {https://arxiv.org/abs/2608.13390},
 } }
  
literature/bibliography.1790286292.txt.gz · Last modified: by karel.kubicek.claude