{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T00:29:02Z","timestamp":1766449742674,"version":"3.41.0"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2018,10,15]],"date-time":"2018-10-15T00:00:00Z","timestamp":1539561600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2018,10,15]]},"DOI":"10.1145\/3243734.3243778","type":"proceedings-article","created":{"date-parts":[[2018,10,16]],"date-time":"2018-10-16T17:38:33Z","timestamp":1539711513000},"page":"1788-1801","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":42,"title":["Phishing Attacks on Modern Android"],"prefix":"10.1145","author":[{"given":"Simone","family":"Aonzo","sequence":"first","affiliation":[{"name":"University of Genoa, Genoa, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alessio","family":"Merlo","sequence":"additional","affiliation":[{"name":"University of Genoa, Genoa, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Giulio","family":"Tavella","sequence":"additional","affiliation":[{"name":"University of Genoa, Genoa, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yanick","family":"Fratantonio","sequence":"additional","affiliation":[{"name":"EURECOM, Biot, France"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2018,10,15]]},"reference":[{"key":"e_1_3_2_2_1_1","doi-asserted-by":"crossref","unstructured":"Efthimios Alepis and Constantinos Patsakis. 2017. Trapped by the UI: The Android Case. In RAID.  Efthimios Alepis and Constantinos Patsakis. 2017. Trapped by the UI: The Android Case. In RAID.","DOI":"10.1007\/978-3-319-66332-6_15"},{"key":"e_1_3_2_2_2_1","unstructured":"Yair Amit. 2016. 95.4 Percent of All Android Devices Are Susceptible to Accessibility Clickjacking Exploits. https:\/\/www.skycure.com\/blog\/95--4-android-devices-susceptible-accessibility-clickjacking-exploits\/. (2016).  Yair Amit. 2016. 95.4 Percent of All Android Devices Are Susceptible to Accessibility Clickjacking Exploits. https:\/\/www.skycure.com\/blog\/95--4-android-devices-susceptible-accessibility-clickjacking-exploits\/. (2016)."},{"key":"e_1_3_2_2_3_1","unstructured":"Yair Amit. 2016. \"Accessibility Clickjacking\" -- The Next Evolution in Android Malware that Impacts More Than 500 Million Devices. https:\/\/www.skycure.com\/blog\/accessibility-clickjacking\/. (2016).  Yair Amit. 2016. \"Accessibility Clickjacking\" -- The Next Evolution in Android Malware that Impacts More Than 500 Million Devices. https:\/\/www.skycure.com\/blog\/accessibility-clickjacking\/. (2016)."},{"key":"e_1_3_2_2_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/3098243.3098247"},{"key":"e_1_3_2_2_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2015.62"},{"volume-title":"Peeking Into Your App Without Actually Seeing It: UI State Inference and Novel Android Attacks Proc. of the USENIX Security Symposium.","year":"2014","author":"Chen Qi Alfred","key":"e_1_3_2_2_6_1"},{"key":"e_1_3_2_2_7_1","unstructured":"N. Chou R. Ledesma Y. Teraguchi D. Boneh and J. C. Mitchell. 2004. Client-side defense against web-based identity theft Proceedings of the 11th Annual Network and Distributed System Security Symposium (NDSS).  N. Chou R. Ledesma Y. Teraguchi D. Boneh and J. C. Mitchell. 2004. Client-side defense against web-based identity theft Proceedings of the 11th Annual Network and Distributed System Security Symposium (NDSS)."},{"key":"e_1_3_2_2_8_1","doi-asserted-by":"publisher","DOI":"10.1145\/1073001.1073009"},{"key":"e_1_3_2_2_9_1","unstructured":"Artyom Dogtiev. 2018. Facebook Revenue and Usage Statistics. http:\/\/www.businessofapps.com\/data\/facebook-statistics\/. (2018).  Artyom Dogtiev. 2018. Facebook Revenue and Usage Statistics. http:\/\/www.businessofapps.com\/data\/facebook-statistics\/. (2018)."},{"key":"e_1_3_2_2_10_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-39884-1_12"},{"volume-title":"Proc. of IEEE Workshop on Web 2.0 Security & Privacy (W2SP).","year":"2011","author":"Felt Adrienne Porter","key":"e_1_3_2_2_11_1"},{"volume-title":"Android UI Deception Revisited: Attacks and Defenses Proc. of Financial Cryptography and Data Security (FC).","year":"2016","author":"Fernandes Earlence","key":"e_1_3_2_2_12_1"},{"key":"e_1_3_2_2_13_1","doi-asserted-by":"crossref","unstructured":"Yanick Fratantonio Chenxiong Qian Pak Chung and Wenke Lee. 2017. Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop Proceedings of the IEEE Symposium on Security and Privacy (S&P).  Yanick Fratantonio Chenxiong Qian Pak Chung and Wenke Lee. 2017. Cloak and Dagger: From Two Permissions to Complete Control of the UI Feedback Loop Proceedings of the IEEE Symposium on Security and Privacy (S&P).","DOI":"10.1109\/SP.2017.39"},{"key":"e_1_3_2_2_14_1","unstructured":"Google. 2017. Digital Asset Links. https:\/\/developers.google.com\/digital-asset-links\/v1\/getting-started. (2017).  Google. 2017. Digital Asset Links. https:\/\/developers.google.com\/digital-asset-links\/v1\/getting-started. (2017)."},{"key":"e_1_3_2_2_15_1","unstructured":"Google. 2017. OpenYOLO for Android. https:\/\/openid.net\/specs\/openyolo-android-03.html. (2017).  Google. 2017. OpenYOLO for Android. https:\/\/openid.net\/specs\/openyolo-android-03.html. (2017)."},{"key":"e_1_3_2_2_16_1","unstructured":"Google. 2018. Accessiblity Service. https:\/\/developer.android.com\/guide\/topics\/ui\/accessibility\/services. (2018).  Google. 2018. Accessiblity Service. https:\/\/developer.android.com\/guide\/topics\/ui\/accessibility\/services. (2018)."},{"key":"e_1_3_2_2_17_1","unstructured":"Google. 2018. Autofill Framework. https:\/\/developer.android.com\/guide\/topics\/text\/autofill. (2018).  Google. 2018. Autofill Framework. https:\/\/developer.android.com\/guide\/topics\/text\/autofill. (2018)."},{"key":"e_1_3_2_2_18_1","unstructured":"Google. 2018. Enable automatic sign-in across apps and websites. https:\/\/developers.google.com\/identity\/smartlock-passwords\/android\/associate-apps-and-sites\/. (2018).  Google. 2018. Enable automatic sign-in across apps and websites. https:\/\/developers.google.com\/identity\/smartlock-passwords\/android\/associate-apps-and-sites\/. (2018)."},{"key":"e_1_3_2_2_19_1","unstructured":"Google. 2018. Google Smart Lock. https:\/\/get.google.com\/smartlock\/. (2018).  Google. 2018. Google Smart Lock. https:\/\/get.google.com\/smartlock\/. (2018)."},{"key":"e_1_3_2_2_20_1","unstructured":"Google. 2018. Google Smart Lock - Associate apps and sites. https:\/\/developers.google.com\/identity\/smartlock-passwords\/android\/associate-apps-and-sites. (2018).  Google. 2018. Google Smart Lock - Associate apps and sites. https:\/\/developers.google.com\/identity\/smartlock-passwords\/android\/associate-apps-and-sites. (2018)."},{"key":"e_1_3_2_2_21_1","unstructured":"Google. 2018. Keeper. https:\/\/keepersecurity.com\/. (2018).  Google. 2018. Keeper. https:\/\/keepersecurity.com\/. (2018)."},{"key":"e_1_3_2_2_22_1","unstructured":"Google. 2018. Safe Browsing. http:\/\/www.google.com\/transparencyreport\/safebrowsing\/. (2018).  Google. 2018. Safe Browsing. http:\/\/www.google.com\/transparencyreport\/safebrowsing\/. (2018)."},{"key":"e_1_3_2_2_23_1","unstructured":"Google. 2018. Smart Lock for Passwords affiliation form. https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLSc3FCn8ccGpgXd1jtLBVRlNJ6EhWQK50hNO5jT_9nuqHI79pg\/viewform. (2018).  Google. 2018. Smart Lock for Passwords affiliation form. https:\/\/docs.google.com\/forms\/d\/e\/1FAIpQLSc3FCn8ccGpgXd1jtLBVRlNJ6EhWQK50hNO5jT_9nuqHI79pg\/viewform. (2018)."},{"key":"e_1_3_2_2_24_1","unstructured":"Google. 2018. Verify Android App Links. https:\/\/developer.android.com\/training\/app-links\/verify-site-associations\/. (2018).  Google. 2018. Verify Android App Links. https:\/\/developer.android.com\/training\/app-links\/verify-site-associations\/. (2018)."},{"volume-title":"SUPOR: Precise and Scalable Sensitive User Input Detection for Android Apps USENIX Security Symposium.","year":"2015","author":"Huang Jianjun","key":"e_1_3_2_2_25_1"},{"key":"e_1_3_2_2_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/2660267.2660295"},{"key":"e_1_3_2_2_27_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2005.126"},{"key":"e_1_3_2_2_28_1","doi-asserted-by":"publisher","DOI":"10.5555\/2671225.2671255"},{"key":"e_1_3_2_2_29_1","unstructured":"Lookout. 2015. Trojanized adware family abuses accessibility service to install whatever apps it wants. https:\/\/blog.lookout.com\/blog\/2015\/11\/19\/shedun-trojanized-adware\/. (2015).  Lookout. 2015. Trojanized adware family abuses accessibility service to install whatever apps it wants. https:\/\/blog.lookout.com\/blog\/2015\/11\/19\/shedun-trojanized-adware\/. (2015)."},{"key":"e_1_3_2_2_30_1","unstructured":"Spandas Lui. 2016. Accessibility Service Helps Malware Bypass Android's Beefed Up Security. http:\/\/www.lifehacker.com.au\/2016\/05\/accessibility-service-helps-malware-bypass-androids-beefed-up-security\/. (2016).  Spandas Lui. 2016. Accessibility Service Helps Malware Bypass Android's Beefed Up Security. http:\/\/www.lifehacker.com.au\/2016\/05\/accessibility-service-helps-malware-bypass-androids-beefed-up-security\/. (2016)."},{"volume-title":"UIPicker: User-Input Privacy Identification in Mobile Applications USENIX Security Symposium.","year":"2015","author":"Nan Yuhong","key":"e_1_3_2_2_31_1"},{"volume-title":"UI Redressing Attacks on Android devices. Black Hat Abu Dhabi","year":"2012","author":"Niemietz Marcus","key":"e_1_3_2_2_32_1"},{"volume-title":"Towards Discovering and Understanding Task Hijacking in Android Proc. of USENIX Security Symposium.","year":"2015","author":"Ren Chuangang","key":"e_1_3_2_2_33_1"},{"volume-title":"Percentage of all global web","year":"2009","key":"e_1_3_2_2_34_1"},{"key":"e_1_3_2_2_35_1","unstructured":"Dinesh Venkatesan. 2016. Malware may abuse Android's accessibility service to bypass security enhancements. http:\/\/www.symantec.com\/connect\/blogs\/malware-may-abuse-android-s-accessibility-service-bypass-security- enhancements. (2016).  Dinesh Venkatesan. 2016. Malware may abuse Android's accessibility service to bypass security enhancements. http:\/\/www.symantec.com\/connect\/blogs\/malware-may-abuse-android-s-accessibility-service-bypass-security- enhancements. (2016)."},{"key":"e_1_3_2_2_36_1","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2016.7860470"}],"event":{"name":"CCS '18: 2018 ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Toronto Canada","acronym":"CCS '18"},"container-title":["Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3243734.3243778","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3243734.3243778","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T02:08:18Z","timestamp":1750212498000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3243734.3243778"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018,10,15]]},"references-count":36,"alternative-id":["10.1145\/3243734.3243778","10.1145\/3243734"],"URL":"https:\/\/doi.org\/10.1145\/3243734.3243778","relation":{},"subject":[],"published":{"date-parts":[[2018,10,15]]},"assertion":[{"value":"2018-10-15","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}