literature:bibliography
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| literature:bibliography [2026/09/24 21:44] – Append 19 entries for security:online_scams (online scams: fake shops, support scams, crypto scams). Authored by Claude karel.kubicek.claude | literature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude | ||
|---|---|---|---|
| Line 10281: | Line 10281: | ||
| series | series | ||
| url = {https:// | url = {https:// | ||
| + | } | ||
| + | @inproceedings{adjibi2025_guardians, | ||
| + | author | ||
| + | title = {The Guardians of Name Street: Studying the Defensive Registration Practices of the Fortune 500}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{adjibi2026_udrp, | ||
| + | author | ||
| + | title = {Repairing Trust in Domain Name Disputes Practices: Insights from a Quarter-Century’s Worth of Squabbles}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{akiwate2020_lame, | ||
| + | author | ||
| + | title = {Unresolved Issues: Prevalence, Persistence, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{akiwate2021_risky, | ||
| + | author | ||
| + | title = {Risky BIZness: risks derived from registrar name management}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{alhamdan2025_deno, | ||
| + | author | ||
| + | title = {Welcome to Jurassic Park: A Comprehensive Study of Security Risks in Deno and its Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{alowaisheq2019_cracking, | ||
| + | author | ||
| + | title = {Cracking the Wall of Confinement: | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{alowaisheq2020_zombie, | ||
| + | author | ||
| + | title = {Zombie Awakening: Stealthy Hijacking of Active Domains through DNS Hosting Referral}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{alrwais2014_parking, | ||
| + | author | ||
| + | title = {Understanding the Dark Side of Domain Parking}, | ||
| + | booktitle | ||
| + | year = {2014}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{chen2016_mitm, | ||
| + | author | ||
| + | title = {MitM Attack by Name Collision: Cause Analysis and Vulnerability Assessment in the New gTLD Era}, | ||
| + | booktitle | ||
| + | year = {2016}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | @inproceedings{halvorson2015_academy, | ||
| + | author | ||
| + | title = {From .academy to .zone: An Analysis of the New TLD Land Rush}, | ||
| + | booktitle | ||
| + | year = {2015}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{hortea2026_dead, | ||
| + | author | ||
| + | title = {Dead Domains, Living Data: A Privacy Risk Analysis of Domain Lifecycle in Android Apps}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.56553/ | ||
| + | } | ||
| + | @inproceedings{hu2021_idn, | ||
| + | author | ||
| + | title = {Assessing Browser-level Defense against IDN-based Phishing}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{kalafut2010_orphan, | ||
| + | author | ||
| + | title = {An empirical study of orphan DNS servers in the internet}, | ||
| + | booktitle | ||
| + | year = {2010}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{khan2015_every, | ||
| + | author | ||
| + | title = {Every Second Counts: Quantifying the Negative Externalities of Cybercrime via Typosquatting}, | ||
| + | booktitle | ||
| + | year = {2015}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | @inproceedings{kintis2017_hiding, | ||
| + | author | ||
| + | title = {Hiding in Plain Sight: A Longitudinal Study of Combosquatting Abuse}, | ||
| + | booktitle | ||
| + | year = {2017}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{lauinger2016_whois, | ||
| + | author | ||
| + | title = {WHOIS Lost in Translation: | ||
| + | booktitle | ||
| + | year = {2016}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{lauinger2017_game, | ||
| + | author | ||
| + | title = {Game of Registrars: An Empirical Analysis of Post-Expiration Domain Name Takeovers}, | ||
| + | booktitle | ||
| + | year = {2017}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{lauinger2018_deletion, | ||
| + | author | ||
| + | title = {From Deletion to Re-Registration in Zero Seconds: Domain Registrar Behaviour During the Drop}, | ||
| + | booktitle | ||
| + | year = {2018}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{lever2016_domainz, | ||
| + | author | ||
| + | title = {Domain-Z: 28 Registrations Later Measuring the Exploitation of Residual Trust in Domains}, | ||
| + | booktitle | ||
| + | year = {2016}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | @inproceedings{liu2015_whois, | ||
| + | author | ||
| + | title = {Who is .com?: Learning to Parse WHOIS Records}, | ||
| + | booktitle | ||
| + | year = {2015}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{liu2016_dangling, | ||
| + | author | ||
| + | title = {All Your DNS Records Point to Us: Understanding the Security Threats of Dangling DNS Records}, | ||
| + | booktitle | ||
| + | year = {2016}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{liu2022_container, | ||
| + | author | ||
| + | title = {Exploring the Unchartered Space of Container Registry Typosquatting}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{ma2023_stale, | ||
| + | author | ||
| + | title = {Stale TLS Certificates: | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{miramirkhani2018_panning, | ||
| + | author | ||
| + | title = {Panning for gold.com: Understanding the Dynamics of Domain Dropcatching}, | ||
| + | booktitle | ||
| + | year = {2018}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{muzammil2024_panning, | ||
| + | author | ||
| + | title = {Panning for gold.eth: Understanding and Analyzing ENS Domain Dropcatching}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{neupane2023_confusion, | ||
| + | author | ||
| + | title = {Beyond Typosquatting: | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{nikiforakis2013_bitsquatting, | ||
| + | author | ||
| + | title = {Bitsquatting: | ||
| + | booktitle | ||
| + | year = {2013}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{pauley2022_ipreuse, | ||
| + | author | ||
| + | title = {Measuring and Mitigating the Risk of IP Reuse on Public Clouds}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | @inproceedings{saric2024_hyperlink, | ||
| + | author | ||
| + | title = {Hyperlink Hijacking: Exploiting Erroneous URL Links to Phantom Domains}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{so2022_spots, | ||
| + | author | ||
| + | title = {Domains Do Change Their Spots: Quantifying Potential Abuse of Residual Trust}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | @inproceedings{so2025_lost, | ||
| + | author | ||
| + | title = {Lost in the Mists of Time: Expirations in DNS Footprints of Mobile Apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{sommese2024_darkdns, | ||
| + | author | ||
| + | title = {DarkDNS: Revisiting the Value of Rapid Zone Update}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{suzuki2019_shamfinder, | ||
| + | author | ||
| + | title = {ShamFinder: | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{szurdi2014_taile, | ||
| + | author | ||
| + | title = {The Long “Taile” of Typosquatting Domain Names}, | ||
| + | booktitle | ||
| + | year = {2014}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{vissers2015_parking, | ||
| + | author | ||
| + | title = {Parking Sensors: Analyzing and Detecting Parked Domains}, | ||
| + | booktitle | ||
| + | year = {2015}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{vissers2017_wolf, | ||
| + | author | ||
| + | title = {The Wolf of Name Street: Hijacking Domains Through Their Nameservers}, | ||
| + | booktitle | ||
| + | year = {2017}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{zhang2023_wolf, | ||
| + | author | ||
| + | title = {Wolf in Sheep' | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{zhang2024_cross, | ||
| + | author | ||
| + | title = {Cross the Zone: Toward a Covert Domain Hijacking via Shared DNS Infrastructure}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{zhang2024_glue, | ||
| + | author | ||
| + | title = {Rethinking the Security Threats of Stale DNS Glue Records}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{zhang2025_misty, | ||
| + | author | ||
| + | title = {Misty Registry: An Empirical Study of Flawed Domain Registry Operation}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | @inproceedings{roberts2019_impersonation, | ||
| + | author | ||
| + | title = {You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{marjanov2026_stayin, | ||
| + | author | ||
| + | title = {Stayin' | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{gao2026_doxing, | ||
| + | author | ||
| + | title = {Doxing-as-a-Service: | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{xu2019_anatomy, | ||
| + | author | ||
| + | title = {The Anatomy of a Cryptocurrency Pump-and-Dump Scheme}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{sun2021_having, | ||
| + | author | ||
| + | title = {Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{he2025_unmasking, | ||
| + | author | ||
| + | title = {Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{weyns2026_mirai, | ||
| + | author | ||
| + | title = {From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{acharya2025_pirates, | ||
| + | author | ||
| + | title = {Pirates of Charity: Exploring Donation-based Abuses in Social Media Platforms}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{hoseini2020_demystifying, | ||
| + | author | ||
| + | title = {Demystifying the Messaging Platforms' | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{resende2019_information, | ||
| + | author | ||
| + | title = {(Mis)Information Dissemination in WhatsApp: Gathering, Analyzing and Countermeasures}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{saha2021_short, | ||
| + | author | ||
| + | title = {" | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{kireev2025_characterizing, | ||
| + | author | ||
| + | title = {Characterizing and Detecting Propaganda-Spreading Accounts on Telegram}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{vu2024_easy, | ||
| + | author | ||
| + | title = {No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{vu2024_getting, | ||
| + | author | ||
| + | title = {Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{vafa2025_learning, | ||
| + | author | ||
| + | title = {Learning from Censored Experiences: | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{recabarren2023_strategies, | ||
| + | author | ||
| + | title = {Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{aliapoulios2021_characterization, | ||
| + | author | ||
| + | title = {A large-scale characterization of online incitements to harassment across platforms}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{bahramali2020_practical, | ||
| + | author | ||
| + | title = {Practical Traffic Analysis Attacks on Secure Messaging Applications}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{weerasinghe2020_people, | ||
| + | author | ||
| + | title = {The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{shen2024_anything, | ||
| + | author | ||
| + | title = {"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yu2024_listen, | ||
| + | author | ||
| + | title = {Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{guo2024_moderating, | ||
| + | author | ||
| + | title = {Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{schrittwieser2012_guess, | ||
| + | author | ||
| + | title = {Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications}, | ||
| + | booktitle | ||
| + | year = {2012}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{li2025_investigating, | ||
| + | author | ||
| + | title = {Investigating the Impact of Online Community Involvement on Safety Practices and Perceived Risks Among People Who Use Drugs}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{albrecht2021_collective, | ||
| + | author | ||
| + | title = {Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{arunasalam2024_security, | ||
| + | author | ||
| + | title = {Understanding the Security and Privacy Implications of Online Toxic Content on Refugees}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{chou2025_bots, | ||
| + | author | ||
| + | title = {Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2025_detecting, | ||
| + | author | ||
| + | title = {Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{lu2020_demystifying, | ||
| + | author | ||
| + | title = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2022_cross, | ||
| + | author | ||
| + | title = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2022_identity, | ||
| + | author | ||
| + | title = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2023_leak, | ||
| + | author | ||
| + | title = {Don't Leak Your Keys: Understanding, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_uncovering, | ||
| + | author | ||
| + | title = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_size, | ||
| + | author | ||
| + | title = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2024_minicat, | ||
| + | author | ||
| + | title = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_better, | ||
| + | author | ||
| + | title = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{cai2025_tell, | ||
| + | author | ||
| + | title = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{chen2026_minigames, | ||
| + | author | ||
| + | title = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2025_miniapp, | ||
| + | author | ||
| + | title = {Understanding Miniapp Malware: Identification, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2025_skeleton, | ||
| + | author | ||
| + | title = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{he2024_demystifying, | ||
| + | author | ||
| + | title = {Demystifying the Security Implications in IoT Device Rental Services}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{liu2024_riotfuzzer, | ||
| + | author | ||
| + | title = {RIoTFuzzer: | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{lee2025_deep, | ||
| + | author | ||
| + | title = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wei2026_raising, | ||
| + | author | ||
| + | title = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_convenience, | ||
| + | author | ||
| + | title = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2026_real, | ||
| + | author | ||
| + | title = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2025_wechat, | ||
| + | author | ||
| + | title = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.56553/ | ||
| + | } | ||
| + | |||
| + | @article{zhang2021_measurement, | ||
| + | author | ||
| + | title = {A Measurement Study of {WeChat} Mini-Apps}, | ||
| + | journal | ||
| + | volume | ||
| + | number | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{baskaran2023_measuring, | ||
| + | author | ||
| + | title = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_taintmini, | ||
| + | author | ||
| + | title = {{TaintMini}: | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{meng2023_wemint, | ||
| + | author | ||
| + | title = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @misc{yang2023_sok, | ||
| + | author | ||
| + | title = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps}, | ||
| + | year = {2023}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{zhang2026_oauth, | ||
| + | author | ||
| + | title = {Mini-Programs, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ciccotelli2026_tenet, | ||
| + | author | ||
| + | title = {{TENET}: Telegram Mini App (in)security}, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ferrari2026_telegapper, | ||
| + | author | ||
| + | title = {{TeleGapper}: | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| } | } | ||
literature/bibliography.1790286292.txt.gz · Last modified: by karel.kubicek.claude
