literature:bibliography
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| literature:bibliography [2026/09/25 02:37] – Add 40 entries for security:domain_abuse (squatting, parking, expired domains, dangling DNS). Duplicate-checked with bib_dedup_scan.py (0 definite). Authored by Claude. karel.kubicek.claude | literature:bibliography [2026/09/27 16:40] (current) – Add 2 Telegram Mini Apps preprints for design:mobile_and_app_measurement:mini_programs (review fix). Authored by Claude karel.kubicek.claude | ||
|---|---|---|---|
| Line 10602: | Line 10602: | ||
| url = {https:// | url = {https:// | ||
| } | } | ||
| + | @inproceedings{roberts2019_impersonation, | ||
| + | author | ||
| + | title = {You Are Who You Appear to Be: A Longitudinal Study of Domain Impersonation in TLS Certificates}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{marjanov2026_stayin, | ||
| + | author | ||
| + | title = {Stayin' | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{gao2026_doxing, | ||
| + | author | ||
| + | title = {Doxing-as-a-Service: | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{xu2019_anatomy, | ||
| + | author | ||
| + | title = {The Anatomy of a Cryptocurrency Pump-and-Dump Scheme}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{sun2021_having, | ||
| + | author | ||
| + | title = {Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{he2025_unmasking, | ||
| + | author | ||
| + | title = {Unmasking the Shadow Economy: A Deep Dive into Drainer-as-a-Service Phishing on Ethereum}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{weyns2026_mirai, | ||
| + | author | ||
| + | title = {From Mirai to Gorilla: Deep Dive into a Long-Lasting DDoS-for-Hire Botnet}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{acharya2025_pirates, | ||
| + | author | ||
| + | title = {Pirates of Charity: Exploring Donation-based Abuses in Social Media Platforms}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{hoseini2020_demystifying, | ||
| + | author | ||
| + | title = {Demystifying the Messaging Platforms' | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{resende2019_information, | ||
| + | author | ||
| + | title = {(Mis)Information Dissemination in WhatsApp: Gathering, Analyzing and Countermeasures}, | ||
| + | booktitle | ||
| + | year = {2019}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{saha2021_short, | ||
| + | author | ||
| + | title = {" | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{kireev2025_characterizing, | ||
| + | author | ||
| + | title = {Characterizing and Detecting Propaganda-Spreading Accounts on Telegram}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{vu2024_easy, | ||
| + | author | ||
| + | title = {No Easy Way Out: the Effectiveness of Deplatforming an Extremist Forum to Suppress Hate and Harassment}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{vu2024_getting, | ||
| + | author | ||
| + | title = {Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{vafa2025_learning, | ||
| + | author | ||
| + | title = {Learning from Censored Experiences: | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{recabarren2023_strategies, | ||
| + | author | ||
| + | title = {Strategies and Vulnerabilities of Participants in Venezuelan Influence Operations}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{aliapoulios2021_characterization, | ||
| + | author | ||
| + | title = {A large-scale characterization of online incitements to harassment across platforms}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{bahramali2020_practical, | ||
| + | author | ||
| + | title = {Practical Traffic Analysis Attacks on Secure Messaging Applications}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{weerasinghe2020_people, | ||
| + | author | ||
| + | title = {The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity Abuse}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{shen2024_anything, | ||
| + | author | ||
| + | title = {"Do Anything Now": Characterizing and Evaluating In-The-Wild Jailbreak Prompts on Large Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yu2024_listen, | ||
| + | author | ||
| + | title = {Don't Listen To Me: Understanding and Exploring Jailbreak Prompts of Large Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{guo2024_moderating, | ||
| + | author | ||
| + | title = {Moderating Illicit Online Image Promotion for Unsafe User Generated Content Games Using Large Vision-Language Models}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{schrittwieser2012_guess, | ||
| + | author | ||
| + | title = {Guess Who’s Texting You? Evaluating the Security of Smartphone Messaging Applications}, | ||
| + | booktitle | ||
| + | year = {2012}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{li2025_investigating, | ||
| + | author | ||
| + | title = {Investigating the Impact of Online Community Involvement on Safety Practices and Perceived Risks Among People Who Use Drugs}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{albrecht2021_collective, | ||
| + | author | ||
| + | title = {Collective Information Security in Large-Scale Urban Protests: the Case of Hong Kong}, | ||
| + | booktitle | ||
| + | year = {2021}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{arunasalam2024_security, | ||
| + | author | ||
| + | title = {Understanding the Security and Privacy Implications of Online Toxic Content on Refugees}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{chou2025_bots, | ||
| + | author | ||
| + | title = {Bots can Snoop: Uncovering and Mitigating Privacy Risks of Bots in Group Chats}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2025_detecting, | ||
| + | author | ||
| + | title = {Detecting and Understanding the Promotion of Illicit Goods and Services on Twitter}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | @inproceedings{lu2020_demystifying, | ||
| + | author | ||
| + | title = {Demystifying Resource Management Risks in Emerging Mobile App-in-App Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2020}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2022_cross, | ||
| + | author | ||
| + | title = {Cross Miniapp Request Forgery: Root Causes, Attacks, and Vulnerability Detection}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2022_identity, | ||
| + | author | ||
| + | title = {Identity Confusion in WebView-based Mobile App-in-app Ecosystems}, | ||
| + | booktitle | ||
| + | year = {2022}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2023_leak, | ||
| + | author | ||
| + | title = {Don't Leak Your Keys: Understanding, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_uncovering, | ||
| + | author | ||
| + | title = {Uncovering and Exploiting Hidden APIs in Mobile Super Apps}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_size, | ||
| + | author | ||
| + | title = {One Size Does Not Fit All: Uncovering and Exploiting Cross Platform Discrepant APIs in WeChat}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{zhang2024_minicat, | ||
| + | author | ||
| + | title = {MiniCAT: Understanding and Detecting Cross-Page Request Forgery Vulnerabilities in Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_better, | ||
| + | author | ||
| + | title = {Better Safe than Sorry: Uncovering the Insecure Resource Management in App-in-App Cloud Services}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{cai2025_tell, | ||
| + | author | ||
| + | title = {I Can Tell Your Secrets: Inferring Privacy Attributes from Mini-app Interaction History in Super-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{chen2026_minigames, | ||
| + | author | ||
| + | title = {When Fun Turns Toxic: A First Look at Aggressive Advertising in Mini-games}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2025_miniapp, | ||
| + | author | ||
| + | title = {Understanding Miniapp Malware: Identification, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2025_skeleton, | ||
| + | author | ||
| + | title = {The Skeleton Keys: A Large Scale Analysis of Credential Leakage in Mini-apps}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{he2024_demystifying, | ||
| + | author | ||
| + | title = {Demystifying the Security Implications in IoT Device Rental Services}, | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{liu2024_riotfuzzer, | ||
| + | author | ||
| + | title = {RIoTFuzzer: | ||
| + | booktitle | ||
| + | year = {2024}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{lee2025_deep, | ||
| + | author | ||
| + | title = {Deep Dive into In-app Browsers: Uncovering Hidden Pitfalls in Certificate Validation}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wei2026_raising, | ||
| + | author | ||
| + | title = {Raising the Flag: Detecting Missing Permission Controls in Mini-Program APIs}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @inproceedings{shi2026_convenience, | ||
| + | author | ||
| + | title = {Convenience at a Cost: the Security Risks of Template-Based Development in the App-in-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{yang2026_real, | ||
| + | author | ||
| + | title = {Real or Rogue? Detecting Malicious Miniapps with Deceptive Reporting Interface}, | ||
| + | booktitle | ||
| + | year = {2026}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2025_wechat, | ||
| + | author | ||
| + | title = {What WeChat Knows: Pervasive First-Party Tracking in a Billion-User Super-App Ecosystem}, | ||
| + | booktitle | ||
| + | year = {2025}, | ||
| + | series | ||
| + | doi = {10.56553/ | ||
| + | } | ||
| + | |||
| + | @article{zhang2021_measurement, | ||
| + | author | ||
| + | title = {A Measurement Study of {WeChat} Mini-Apps}, | ||
| + | journal | ||
| + | volume | ||
| + | number | ||
| + | year = {2021}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{baskaran2023_measuring, | ||
| + | author | ||
| + | title = {Measuring the Leakage and Exploitability of Authentication Secrets in Super-apps: The {WeChat} Case}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1145/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{wang2023_taintmini, | ||
| + | author | ||
| + | title = {{TaintMini}: | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @inproceedings{meng2023_wemint, | ||
| + | author | ||
| + | title = {{WeMinT}: Tainting Sensitive Data Leaks in {WeChat} Mini-Programs}, | ||
| + | booktitle | ||
| + | year = {2023}, | ||
| + | series | ||
| + | doi = {10.1109/ | ||
| + | } | ||
| + | |||
| + | @misc{yang2023_sok, | ||
| + | author | ||
| + | title = {{SoK}: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in {OS}-alike Apps}, | ||
| + | year = {2023}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{zhang2026_oauth, | ||
| + | author | ||
| + | title = {Mini-Programs, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ciccotelli2026_tenet, | ||
| + | author | ||
| + | title = {{TENET}: Telegram Mini App (in)security}, | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| + | @misc{ferrari2026_telegapper, | ||
| + | author | ||
| + | title = {{TeleGapper}: | ||
| + | year = {2026}, | ||
| + | howpublished | ||
| + | url = {https:// | ||
| + | } | ||
| + | |||
| </ | </ | ||
literature/bibliography.1790303826.txt.gz · Last modified: by karel.kubicek.claude
