{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T16:52:40Z","timestamp":1783097560542,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":37,"publisher":"ACM","license":[{"start":{"date-parts":[[2012,10,16]],"date-time":"2012-10-16T00:00:00Z","timestamp":1350345600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2012,10,16]]},"DOI":"10.1145\/2382196.2382267","type":"proceedings-article","created":{"date-parts":[[2012,10,15]],"date-time":"2012-10-15T17:13:12Z","timestamp":1350321192000},"page":"674-686","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":159,"title":["Knowing your enemy"],"prefix":"10.1145","author":[{"given":"Zhou","family":"Li","sequence":"first","affiliation":[{"name":"Indiana University at Bloomington, Bloomington, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Kehuan","family":"Zhang","sequence":"additional","affiliation":[{"name":"Indiana University at Bloomington, Bloomington, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yinglian","family":"Xie","sequence":"additional","affiliation":[{"name":"MSR Silicon Valley, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fang","family":"Yu","sequence":"additional","affiliation":[{"name":"MSR Silicon Valley, Mountain View, CA, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"XiaoFeng","family":"Wang","sequence":"additional","affiliation":[{"name":"Indiana University at Bloomington, Bloomington, IN, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2012,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"Adblock plus. http:\/\/adblockplus.org\/en\/.  Adblock plus. http:\/\/adblockplus.org\/en\/."},{"key":"e_1_3_2_1_2_1","unstructured":"Display network google ads. http:\/\/www.google.com\/ads\/displaynetwork\/.  Display network google ads. http:\/\/www.google.com\/ads\/displaynetwork\/."},{"key":"e_1_3_2_1_3_1","unstructured":"Wordpress blog tool publishing platform and cms. http:\/\/wordpress.org\/.  Wordpress blog tool publishing platform and cms. http:\/\/wordpress.org\/."},{"key":"e_1_3_2_1_4_1","unstructured":"Adobe. Adobe flash platform. http:\/\/www.adobe.com\/flashplatform 2011.  Adobe. Adobe flash platform. http:\/\/www.adobe.com\/flashplatform 2011."},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.5555\/176313.176316"},{"key":"e_1_3_2_1_6_1","first-page":"25","volume-title":"Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10","author":"Cha S. K.","year":"2010","unstructured":"S. K. Cha , I. Moraru , J. Jang , J. Truelove , D. Brumley , and D. G. Andersen . SplitScreen: enabling efficient, distributed malware detection . In Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10 , page 25 , Berkeley, CA, USA , 2010 . USENIX Association. S. K. Cha, I. Moraru, J. Jang, J. Truelove, D. Brumley, and D. G. Andersen. SplitScreen: enabling efficient, distributed malware detection. In Proceedings of the 7th USENIX conference on Networked systems design and implementation, NSDI'10, page 25, Berkeley, CA, USA, 2010. USENIX Association."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/1772690.1772720"},{"key":"e_1_3_2_1_8_1","unstructured":"D. Crockford. Adsafe. http:\/\/www.adsafe.org.  D. Crockford. Adsafe. http:\/\/www.adsafe.org."},{"key":"e_1_3_2_1_9_1","unstructured":"B. Edelman. Benjamin edelman - publications. http:\/\/www.benedelman.org\/publications\/ July 2012.  B. Edelman. Benjamin edelman - publications. http:\/\/www.benedelman.org\/publications\/ July 2012."},{"key":"e_1_3_2_1_10_1","volume-title":"Preventing capability leaks in secure javascript subsets","author":"Finifter M.","year":"2010","unstructured":"M. Finifter , J. Weinberger , and A. Barth . Preventing capability leaks in secure javascript subsets . In NDSS. The Internet Society , 2010 . M. Finifter, J. Weinberger, and A. Barth. Preventing capability leaks in secure javascript subsets. In NDSS. The Internet Society, 2010."},{"key":"e_1_3_2_1_11_1","unstructured":"D. Fisher. Google removes .co.cc subdomains over phishing spam concerns. http:\/\/threatpost.com\/en_us\/blogs\/google-removes-cocc-subdomainsover-phishing-spam-concerns-070611 2011.  D. Fisher. Google removes .co.cc subdomains over phishing spam concerns. http:\/\/threatpost.com\/en_us\/blogs\/google-removes-cocc-subdomainsover-phishing-spam-concerns-070611 2011."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC.2009.41"},{"issue":"2","key":"e_1_3_2_1_13_1","article-title":"Badvertisements: Stealthy click-fraud with unwitting accessories","volume":"1","author":"Gandhi M.","year":"2006","unstructured":"M. Gandhi , M. Jakobsson , and J. Ratkiewicz . Badvertisements: Stealthy click-fraud with unwitting accessories . Journal of Digital Forensics Practice , 1 ( 2 ), 2006 . M. Gandhi, M. Jakobsson, and J. Ratkiewicz. Badvertisements: Stealthy click-fraud with unwitting accessories. Journal of Digital Forensics Practice, 1(2), 2006.","journal-title":"Journal of Digital Forensics Practice"},{"key":"e_1_3_2_1_14_1","unstructured":"Google. What is an ad tag? - doubleclick for publishers help. http:\/\/support.google.com\/dfp_premium\/bin\/answer.py?hl=en&answer=1131465.  Google. What is an ad tag? - doubleclick for publishers help. http:\/\/support.google.com\/dfp_premium\/bin\/answer.py?hl=en&answer=1131465."},{"key":"e_1_3_2_1_15_1","first-page":"101","volume-title":"Proceedings of the 18th conference on USENIX security symposium, SSYM'09","author":"Hao S.","year":"2009","unstructured":"S. Hao , N. A. Syed , N. Feamster , A. G. Gray , and S. Krasser . Detecting spammers with snare: spatio-temporal network-level automatic reputation engine . In Proceedings of the 18th conference on USENIX security symposium, SSYM'09 , pages 101 -- 118 , Berkeley, CA, USA , 2009 . USENIX Association. S. Hao, N. A. Syed, N. Feamster, A. G. Gray, and S. Krasser. Detecting spammers with snare: spatio-temporal network-level automatic reputation engine. In Proceedings of the 18th conference on USENIX security symposium, SSYM'09, pages 101--118, Berkeley, CA, USA, 2009. USENIX Association."},{"key":"e_1_3_2_1_16_1","first-page":"20","volume-title":"Proceedings of the 20th USENIX conference on Security, SEC'11","author":"John J. P.","year":"2011","unstructured":"J. P. John , F. Yu , Y. Xie , A. Krishnamurthy , and M. Abadi . deseo: combating search-result poisoning . In Proceedings of the 20th USENIX conference on Security, SEC'11 , pages 20 -- 20 , Berkeley, CA, USA , 2011 . USENIX Association. J. P. John, F. Yu, Y. Xie, A. Krishnamurthy, and M. Abadi. deseo: combating search-result poisoning. In Proceedings of the 20th USENIX conference on Security, SEC'11, pages 20--20, Berkeley, CA, USA, 2011. USENIX Association."},{"key":"e_1_3_2_1_17_1","unstructured":"C. Larsen. Busting a big malvertising \/ fake-av attack. http:\/\/www.bluecoat.com\/security\/security-archive\/2011-07-25\/busting-bigmalvertising-fake-av-attack-0 July 2011.  C. Larsen. Busting a big malvertising \/ fake-av attack. http:\/\/www.bluecoat.com\/security\/security-archive\/2011-07-25\/busting-bigmalvertising-fake-av-attack-0 July 2011."},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.24"},{"key":"e_1_3_2_1_19_1","first-page":"24","volume-title":"Proceedings of the 19th USENIX conference on Security, USENIX Security'10","author":"Louw M. T.","year":"2010","unstructured":"M. T. Louw , K. T. Ganesh , and V. N. Venkatakrishnan . Adjail: practical enforcement of confidentiality and integrity policies on web advertisements . In Proceedings of the 19th USENIX conference on Security, USENIX Security'10 , pages 24 -- 24 , Berkeley, CA, USA , 2010 . USENIX Association. M. T. Louw, K. T. Ganesh, and V. N. Venkatakrishnan. Adjail: practical enforcement of confidentiality and integrity policies on web advertisements. In Proceedings of the 19th USENIX conference on Security, USENIX Security'10, pages 24--24, Berkeley, CA, USA, 2010. USENIX Association."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/2046707.2046762"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866356"},{"key":"e_1_3_2_1_22_1","unstructured":"McAfee. Mcafee web gateway. http:\/\/www.mcafee.com\/us\/products\/webgateway.aspx#vtab-Benefits 2011.  McAfee. Mcafee web gateway. http:\/\/www.mcafee.com\/us\/products\/webgateway.aspx#vtab-Benefits 2011."},{"key":"e_1_3_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.5555\/2026647.2026661"},{"key":"e_1_3_2_1_24_1","volume-title":"In Proceeding of the Network and Distributed System Security Symposium (NDSS'07)","author":"Nentwich F.","year":"2007","unstructured":"F. Nentwich , N. Jovanovic , E. Kirda , C. Kruegel , and G. Vigna . Cross-site scripting prevention with dynamic data tainting and static analysis . In In Proceeding of the Network and Distributed System Security Symposium (NDSS'07) , 2007 . F. Nentwich, N. Jovanovic, E. Kirda, C. Kruegel, and G. Vigna. Cross-site scripting prevention with dynamic data tainting and static analysis. In In Proceeding of the Network and Distributed System Security Symposium (NDSS'07), 2007."},{"key":"e_1_3_2_1_25_1","unstructured":"A. NS. Blackhole exploit kit 1.0.2. http:\/\/www.airdemon.net\/blackhole.html 2011.  A. NS. Blackhole exploit kit 1.0.2. http:\/\/www.airdemon.net\/blackhole.html 2011."},{"key":"e_1_3_2_1_26_1","unstructured":"R. Petnel. The official easylist web site. http:\/\/easylist.adblockplus.org\/en\/.  R. Petnel. The official easylist web site. http:\/\/easylist.adblockplus.org\/en\/."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.5555\/1496711.1496712"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/2068816.2068843"},{"key":"e_1_3_2_1_29_1","unstructured":"Sucuri. Mass infection of wordpress sites due to timthumb. http:\/\/blog.sucuri.net\/2011\/08\/massinfection-of-wordpress-sites-counterwordpress-com.html 2011.  Sucuri. Mass infection of wordpress sites due to timthumb. http:\/\/blog.sucuri.net\/2011\/08\/massinfection-of-wordpress-sites-counterwordpress-com.html 2011."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2011.25"},{"key":"e_1_3_2_1_31_1","unstructured":"TrendLabs. Follow the money trail. http:\/\/blog.trendmicro.com\/follow-themoney-trail\/ March 2012.  TrendLabs. Follow the money trail. http:\/\/blog.trendmicro.com\/follow-themoney-trail\/ March 2012."},{"key":"e_1_3_2_1_32_1","unstructured":"A. VANCE. Times web ads show security breach. http:\/\/www.nytimes.com\/2009\/09\/15\/technology\/internet\/15adco.html 2009.  A. VANCE. Times web ads show security breach. http:\/\/www.nytimes.com\/2009\/09\/15\/technology\/internet\/15adco.html 2009."},{"key":"e_1_3_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2011.10"},{"key":"e_1_3_2_1_34_1","unstructured":"Whois.net. Whois lookup - domain names search registration & availability. http:\/\/www.whois.net\/ 2011.  Whois.net. Whois lookup - domain names search registration & availability. http:\/\/www.whois.net\/ 2011."},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/1402958.1402979"},{"key":"e_1_3_2_1_36_1","unstructured":"ZenithOptimedia. Global ad expenditure to return to pre-recession peak level this year. http:\/\/www.zenithoptimedia.com\/files\/media\/image\/news\/Press%20Release%20files\/2011\/July\/Adspend%20forecasts%20July%202011.pdf 2011.  ZenithOptimedia. Global ad expenditure to return to pre-recession peak level this year. http:\/\/www.zenithoptimedia.com\/files\/media\/image\/news\/Press%20Release%20files\/2011\/July\/Adspend%20forecasts%20July%202011.pdf 2011."},{"key":"e_1_3_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1145\/1963405.1963435"}],"event":{"name":"CCS'12: the ACM Conference on Computer and Communications Security","location":"Raleigh North Carolina USA","acronym":"CCS'12","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2012 ACM conference on Computer and communications security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382196.2382267","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2382196.2382267","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T09:34:48Z","timestamp":1750239288000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2382196.2382267"}},"subtitle":["understanding and detecting malicious web advertising"],"short-title":[],"issued":{"date-parts":[[2012,10,16]]},"references-count":37,"alternative-id":["10.1145\/2382196.2382267","10.1145\/2382196"],"URL":"https:\/\/doi.org\/10.1145\/2382196.2382267","relation":{},"subject":[],"published":{"date-parts":[[2012,10,16]]},"assertion":[{"value":"2012-10-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}