SaTC: CORE: Small: Securing Web-to-Mobile Interface Through Characterization and Detection of Malicious Deep Links
SaTC: CORE: Small: Securing Web-to-Mobile Interface Through Characterization and Detection of Malicious Deep Links
批准号:
1717028
负责人:
Danfeng Yao
金额:
$50.0万
依托单位国家:
美国
项目类别:
Standard Grant
财政年份:
2017
资助国家:
美国
项目状态:
已结题
起止时间:
2017-08-01 至 2021-07-31
中文摘要
随着移动设备的广泛采用,移动网站和应用程序(App)已成为访问在线内容的主要界面。移动深度链接是索引移动内容的关键机制,已被广泛用于使用户能够在网站、搜索引擎和移动应用程序之间导航,并成为改善用户在线体验的工具。不幸的是,移动Deeplink在设计时没有考虑到安全性,它允许恶意应用程序或网站发起秘密攻击,以劫持用户点击、窃取敏感信息和执行网络钓鱼攻击。随着每天都有更多的应用程序和网站深度链接,这对广大互联网人口来说是一个新的安全威胁。该项目正在开发方法和可用的工具来测量、分析和保护当今移动网络生态系统中的移动深度链接。为了首先了解新出现的安全威胁,研究人员正在开发新的测量框架,通过自动从市场规模的应用程序中提取移动深度链接来绘制移动应用程序和网络之间的经验联系。此外,研究人员正在研究自动化技术,以检测基于深度链接的滥用行为,而不需要依赖大规模的地面事实数据。一个目标方法是为应用程序和网站构建深度链接图,并使用半监督学习和信任比例分配方案探索检测技术。最后,研究人员正在开发分析工具,从移动深度链接中提取上下文信息,以使智能警报系统能够保护深度链接的使用。研究人员正在研究安全性和可用性之间的权衡,以设计在不牺牲可用性的情况下使用Deeplink的更安全的方式。
英文摘要
With the wide adoption of mobile devices, mobile websites and applications (apps) have become the primary interfaces to access online content. Mobile deep-linking, a key mechanism to index mobile content, has been widely used to enable users to navigate across websites, search engines and mobile apps and become instrumental to improving users' online experience. Unfortunately, mobile deeplinks are designed without security in mind, which allows malicious apps or websites to launch stealthy attacks to hijack user clicks, steal sensitive information and perform phishing attacks. With more apps and websites deep-linked every day, this becomes an emerging security threat to a broad Internet population. This project is developing methodologies and usable tools to measure, analyze and secure mobile deeplinks in today's mobile-web ecosystem.To first understand the emerging security threat, the researchers are developing novel measurement frameworks to map out the empirical connections between mobile apps and the web by automatically extracting mobile deeplinks from the market-scale apps. In addition, the researchers are investigating automated techniques to detect deeplink-based abuse without relying on large-scale ground-truth data. One target approach is to construct deeplink graphs for apps and websites and explore detection techniques using semi-supervised learning and trust prorogation schemes. Finally, the researchers are developing analytics tools to extract context information from mobile deeplinks to enable intelligent alert systems to safeguard the deeplink usage. The researchers are investigating the tradeoffs between security and usability to design safer ways of using deeplinks without sacrificing the usability.
期刊论文(28)
专著(0)
科研奖励(0)
会议论文
登录
查看更多内容
DOI:
10.1109/tnet.2018.2818073
发表时间:
2018-06-01
期刊:
IEEE-ACM TRANSACTIONS ON NETWORKING
影响因子:
3.7
作者:
[Wang, Gang, Wang, Bolun, Zhao, Ben Y.]
通讯作者:
Zhao, Ben Y.
DOI:
10.1145/3319535.3363195
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
作者:
[Sazzadur Rahaman;Gang Wang;D. Yao]
通讯作者:
Sazzadur Rahaman;Gang Wang;D. Yao
DOI:
--
发表时间:
2020
期刊:
影响因子:
--
作者:
[Shuofei Zhu;J. Shi;Limin Yang;Boqin Qin;Ziyi Zhang;Linhai Song;Gang Wang]
通讯作者:
Shuofei Zhu;J. Shi;Limin Yang;Boqin Qin;Ziyi Zhang;Linhai Song;Gang Wang
Analyzing Payment-Driven Targeted Q8A Systems
分析支付驱动的定向 Q8A 系统
DOI:
10.1145/3281449
发表时间:
2018
期刊:
ACM Transactions on Social Computing
影响因子:
--
作者:
[Jan, Steve T., Wang, Chun, Zhang, Qing, Wang, Gang]
通讯作者:
Wang, Gang
DOI:
--
发表时间:
2018
期刊:
影响因子:
--
作者:
[Hang Hu;G. Wang]
通讯作者:
Hang Hu;G. Wang
共 23 条
iMentor Workshop at the ACM CCS Conference 2020-2022
-
批准号:1946295
-
项目类别:Standard Grant
-
资助金额:$15.0万
-
财政年份:2020
-
负责人:Danfeng Yao
-
依托单位:
SaTC: TTP: Medium: Collaborative: Deployment-quality and Accessible Solutions for Cryptography Code Development
-
批准号:1929701
-
项目类别:Standard Grant
-
资助金额:$70.0万
-
财政年份:2019
-
负责人:Danfeng Yao
-
依托单位:
EAGER: Collaborative Research: Privacy-enhancing CrowdPCR for Early Epidemic Detection
-
批准号:1645121
-
项目类别:Standard Grant
-
资助金额:$5.0万
-
财政年份:2016
-
负责人:Danfeng Yao
-
依托单位:
CAREER: Human-Behavior Driven Malware Detection
-
批准号:0953638
-
项目类别:Continuing Grant
-
资助金额:$53.0万
-
财政年份:2010
-
负责人:Danfeng Yao
-
依托单位:
国内基金
海外基金
登录
查看更多内容
胆固醇羟化酶CH25H非酶活依赖性促进乙型肝炎病毒蛋白Core及Pre-core降解的分子机制研究
-
批准号:82371765
-
项目类别:面上项目
-
资助金额:50万元
-
批准年份:2023
-
负责人:谭广云
-
依托单位:
锕系元素5f-in-core的GTH赝势和基组的开发
-
批准号:22303037
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2023
-
负责人:鲁俊波
-
依托单位:
基于合成致死策略搭建Core-matched前药共组装体克服肿瘤耐药的机制研究
-
批准号:--
-
项目类别:--
-
资助金额:52万元
-
批准年份:2022
-
负责人:孙丙军
-
依托单位:
鼠伤寒沙门氏菌LPS core经由CD209/SphK1促进树突状细胞迁移加重炎症性肠病的机制研究
-
批准号:--
-
项目类别:青年科学基金项目
-
资助金额:30万元
-
批准年份:2022
-
负责人:叶成林
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:--
-
项目类别:--
-
资助金额:55万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
基于外泌体精准调控的“核-壳”(core-shell)同步血管化骨组织工程策略的应用与机制探讨
-
批准号:82072415
-
项目类别:面上项目
-
资助金额:55.0万元
-
批准年份:2020
-
负责人:张智勇
-
依托单位:
肌营养不良蛋白聚糖Core M3型甘露糖肽的精确制备及功能探索
-
批准号:92053110
-
项目类别:重大研究计划
-
资助金额:70.0万元
-
批准年份:2020
-
负责人:彭鹏
-
依托单位:
Core-1-O型聚糖黏蛋白缺陷诱导胃炎发生并介导慢性胃炎向胃癌转化的分子机制研究
-
批准号:81902805
-
项目类别:青年科学基金项目
-
资助金额:20.5万元
-
批准年份:2019
-
负责人:刘菲
-
依托单位:
原始地球增生晚期的Core-merging大碰撞事件:地核增生、核幔平衡与核幔边界结构的新认识
-
批准号:41973063
-
项目类别:面上项目
-
资助金额:65.0万元
-
批准年份:2019
-
负责人:周游
-
依托单位:
CORDEX-CORE区域气候模拟与预估研讨会
-
批准号:41981240365
-
项目类别:国际(地区)合作与交流项目
-
资助金额:1.5万元
-
批准年份:2019
-
负责人:陈威霖
-
依托单位: