{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,9]],"date-time":"2026-07-09T15:22:21Z","timestamp":1783610541460,"version":"3.55.0"},"publisher-location":"New York, NY, USA","reference-count":53,"publisher":"ACM","license":[{"start":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T00:00:00Z","timestamp":1667779200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2022,11,7]]},"DOI":"10.1145\/3548606.3559377","type":"proceedings-article","created":{"date-parts":[[2022,11,7]],"date-time":"2022-11-07T11:41:28Z","timestamp":1667821288000},"page":"3049-3062","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["An Extensive Study of Residential Proxies in China"],"prefix":"10.1145","author":[{"given":"Mingshuo","family":"Yang","sequence":"first","affiliation":[{"name":"Shandong University, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunnan","family":"Yu","sequence":"additional","affiliation":[{"name":"University at Buffalo, Buffalo, NY, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xianghang","family":"Mi","sequence":"additional","affiliation":[{"name":"University of Science and Technology of China, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shujun","family":"Tang","sequence":"additional","affiliation":[{"name":"QI-ANXIN Technology Research Institute, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shanqing","family":"Guo","sequence":"additional","affiliation":[{"name":"Shandong University &amp; Quancheng Laboratory, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yilin","family":"Li","sequence":"additional","affiliation":[{"name":"Shandong University, Jinan, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaofeng","family":"Zheng","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; QI-ANXIN Technology Research Institute, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haixin","family":"Duan","sequence":"additional","affiliation":[{"name":"Tsinghua University &amp; QI-ANXIN Technology Research Institute, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,11,7]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"another botnet using dht. https:\/\/blog.netlab.360.com\/mozi-another-botnet-using-dht\/","author":"Mozi","year":"2019","unstructured":"Mozi , another botnet using dht. https:\/\/blog.netlab.360.com\/mozi-another-botnet-using-dht\/ , 2019 . Mozi, another botnet using dht. https:\/\/blog.netlab.360.com\/mozi-another-botnet-using-dht\/, 2019."},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1145\/1177080.1177086"},{"key":"e_1_3_2_1_3_1","first-page":"1093","volume-title":"26th {USENIX} security sym- posium ({USENIX} Security 17)","author":"Antonakakis Manos","year":"2017","unstructured":"Manos Antonakakis , Tim April , Michael Bailey , Matt Bernhard , Elie Bursztein , Jaime Cochran , Zakir Durumeric , J Alex Halderman , Luca Invernizzi , Michalis Kallitsis , Understanding the mirai botnet . In 26th {USENIX} security sym- posium ({USENIX} Security 17) , pages 1093 -- 1110 , 2017 . Manos Antonakakis, Tim April, Michael Bailey, Matt Bernhard, Elie Bursztein, Jaime Cochran, Zakir Durumeric, J Alex Halderman, Luca Invernizzi, Michalis Kallitsis, et al. Understanding the mirai botnet. In 26th {USENIX} security sym- posium ({USENIX} Security 17), pages 1093--1110, 2017."},{"key":"e_1_3_2_1_4_1","volume-title":"How to proactively defend against mozi iot botnet. https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/19\/ how-to-proactively-defend-against-mozi-iot-botnet\/","author":"Atch David Atch","year":"2021","unstructured":"David Atch Atch , Gil Regev , and Ross Bevington . How to proactively defend against mozi iot botnet. https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/19\/ how-to-proactively-defend-against-mozi-iot-botnet\/ , 2021 . David Atch Atch, Gil Regev, and Ross Bevington. How to proactively defend against mozi iot botnet. https:\/\/www.microsoft.com\/security\/blog\/2021\/08\/19\/ how-to-proactively-defend-against-mozi-iot-botnet\/, 2021."},{"key":"e_1_3_2_1_5_1","first-page":"1","volume-title":"Ndss","author":"Bilge Leyla","year":"2011","unstructured":"Leyla Bilge , Engin Kirda , Christopher Kruegel , and Marco Balduzzi . Exposure : Finding malicious domains using passive dns analysis . In Ndss , pages 1 -- 17 , 2011 . Leyla Bilge, Engin Kirda, Christopher Kruegel, and Marco Balduzzi. Exposure: Finding malicious domains using passive dns analysis. In Ndss, pages 1--17, 2011."},{"key":"e_1_3_2_1_6_1","volume-title":"Exposure: A passive dns analysis service to detect and report malicious domains. ACM Transactions on Information and System Security (TISSEC), 16(4):1--28","author":"Bilge Leyla","year":"2014","unstructured":"Leyla Bilge , Sevil Sen , Davide Balzarotti , Engin Kirda , and Christopher Kruegel . Exposure: A passive dns analysis service to detect and report malicious domains. ACM Transactions on Information and System Security (TISSEC), 16(4):1--28 , 2014 . Leyla Bilge, Sevil Sen, Davide Balzarotti, Engin Kirda, and Christopher Kruegel. Exposure: A passive dns analysis service to detect and report malicious domains. ACM Transactions on Information and System Security (TISSEC), 16(4):1--28, 2014."},{"key":"e_1_3_2_1_7_1","first-page":"433","volume-title":"29th {USENIX} Security Symposium ({USENIX} Security","author":"Bouwman Xander","year":"2020","unstructured":"Xander Bouwman , Harm Griffioen , Jelle Egbers , Christian Doerr , Bram Klievink , and Michel van Eeten . A different cup of {TI}? the added value of commercial threat intelligence . In 29th {USENIX} Security Symposium ({USENIX} Security , pages 433 -- 450 , 2020 . Xander Bouwman, Harm Griffioen, Jelle Egbers, Christian Doerr, Bram Klievink, and Michel van Eeten. A different cup of {TI}? the added value of commercial threat intelligence. In 29th {USENIX} Security Symposium ({USENIX} Security, pages 433--450, 2020."},{"key":"e_1_3_2_1_8_1","volume-title":"ACM","author":"Chung Taejoong","year":"2016","unstructured":"Taejoong Chung , David Choffnes , and Alan Mislove . Tunneling for transparency: A large-scale analysis of end-to-end violations in the internet. In Pro- ceedings of the 2016 Internet Measurement Conference, pages 199--213 . ACM , 2016 . Taejoong Chung, David Choffnes, and Alan Mislove. Tunneling for transparency: A large-scale analysis of end-to-end violations in the internet. In Pro- ceedings of the 2016 Internet Measurement Conference, pages 199--213. ACM, 2016."},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1298306.1298319"},{"key":"e_1_3_2_1_10_1","volume-title":"the government wants that to stop. https:\/\/web.archive.org\/save\/https:\/\/www.cnn.com\/2021\/05\/24\/investing\/ bitcoin-mining-china-crackdown-intl-hnk\/index.html","author":"China","year":"2021","unstructured":"China mines more bitcoin than anywhere else. the government wants that to stop. https:\/\/web.archive.org\/save\/https:\/\/www.cnn.com\/2021\/05\/24\/investing\/ bitcoin-mining-china-crackdown-intl-hnk\/index.html , 2021 . China mines more bitcoin than anywhere else. the government wants that to stop. https:\/\/web.archive.org\/save\/https:\/\/www.cnn.com\/2021\/05\/24\/investing\/ bitcoin-mining-china-crackdown-intl-hnk\/index.html, 2021."},{"key":"e_1_3_2_1_11_1","volume-title":"crypto investors. https:\/\/web.archive.org\/web\/20220407090458\/https:\/\/www.cnbc.com\/2021\/09\/24\/what-investors-should- know-about-chinas-cryptocurrency-crackdown.html","author":"China","year":"2021","unstructured":"China is cracking down on crypto again -here's what that actually means, and how it affects u.s. crypto investors. https:\/\/web.archive.org\/web\/20220407090458\/https:\/\/www.cnbc.com\/2021\/09\/24\/what-investors-should- know-about-chinas-cryptocurrency-crackdown.html , 2021 . China is cracking down on crypto again -here's what that actually means, and how it affects u.s. crypto investors. https:\/\/web.archive.org\/web\/20220407090458\/https:\/\/www.cnbc.com\/2021\/09\/24\/what-investors-should- know-about-chinas-cryptocurrency-crackdown.html, 2021."},{"key":"e_1_3_2_1_12_1","volume-title":"https:\/\/blog-netlab-360-com.translate.goog\/msraminer-uipdates-in-72-hours-after- disclose\/?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp","author":"Updates","year":"2018","unstructured":"Updates within 72 hours of msraminer being exposed. https:\/\/blog-netlab-360-com.translate.goog\/msraminer-uipdates-in-72-hours-after- disclose\/?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp , 2018 . Updates within 72 hours of msraminer being exposed. https:\/\/blog-netlab-360-com.translate.goog\/msraminer-uipdates-in-72-hours-after- disclose\/?_x_tr_sl=zh-CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp, 2018."},{"key":"e_1_3_2_1_13_1","volume-title":"https:\/\/howtofix.guide\/trojan-ddostf-s8420\/","year":"2021","unstructured":"Trojan.ddostf.s8420. https:\/\/howtofix.guide\/trojan-ddostf-s8420\/ , 2021 . Trojan.ddostf.s8420. https:\/\/howtofix.guide\/trojan-ddostf-s8420\/, 2021."},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/345508.345593"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW.2018.00014"},{"key":"e_1_3_2_1_16_1","volume-title":"Detecting phishing web","author":"Fu Anthony Y","year":"2006","unstructured":"Anthony Y Fu , Liu Wenyin , and Xiaotie Deng . Detecting phishing web pages with visual similarity assessment based on earth mover's distance (emd). IEEE transactions on dependable and secure computing, 3(4):301--311, 2006 . Anthony Y Fu, Liu Wenyin, and Xiaotie Deng. Detecting phishing web pages with visual similarity assessment based on earth mover's distance (emd). IEEE transactions on dependable and secure computing, 3(4):301--311, 2006."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23488"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243840"},{"key":"e_1_3_2_1_19_1","unstructured":"IPinfo. https:\/\/ipinfo.io\/developers.  IPinfo. https:\/\/ipinfo.io\/developers."},{"key":"e_1_3_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132866"},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1145\/1879141.1879173"},{"key":"e_1_3_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978315"},{"key":"e_1_3_2_1_23_1","unstructured":"We were luminati. now we're bright data. http:\/\/web.archive.org\/web\/20220114011818\/https:\/\/brightdata.com\/luminati 2021.  We were luminati. now we're bright data. http:\/\/web.archive.org\/web\/20220114011818\/https:\/\/brightdata.com\/luminati 2021."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274711"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00011"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24008"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2013.0202"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24444"},{"key":"e_1_3_2_1_29_1","volume-title":"https:\/\/en.wikipedia.org\/wiki\/Nitol_botnet","author":"Nitol","year":"2021","unstructured":"Nitol botnet. https:\/\/en.wikipedia.org\/wiki\/Nitol_botnet , 2021 . Nitol botnet. https:\/\/en.wikipedia.org\/wiki\/Nitol_botnet, 2021."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISI.2016.7745435"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2987443.2987488"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/IJCNN48605.2020.9207707"},{"key":"e_1_3_2_1_33_1","volume-title":"Proceedings of the 2018 World Wide Web Conference, pages 197--206. International World Wide Web Conferences Steering Committee","author":"Perino Diego","year":"2018","unstructured":"Diego Perino , Matteo Varvello , and Claudio Soriente . Proxytorrent : Untangling the free http (s) proxy ecosystem . In Proceedings of the 2018 World Wide Web Conference, pages 197--206. International World Wide Web Conferences Steering Committee , 2018 . Diego Perino, Matteo Varvello, and Claudio Soriente. Proxytorrent: Untangling the free http (s) proxy ecosystem. In Proceedings of the 2018 World Wide Web Conference, pages 197--206. International World Wide Web Conferences Steering Committee, 2018."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23386"},{"key":"e_1_3_2_1_35_1","volume-title":"http:\/\/web.archive.org\/web\/ 20220114043524\/https:\/\/www.proxyrack.com\/premium-geo-residential\/","author":"Premium","year":"2021","unstructured":"Premium residential proxies from proxyrack. http:\/\/web.archive.org\/web\/ 20220114043524\/https:\/\/www.proxyrack.com\/premium-geo-residential\/ , 2021 . Premium residential proxies from proxyrack. http:\/\/web.archive.org\/web\/ 20220114043524\/https:\/\/www.proxyrack.com\/premium-geo-residential\/, 2021."},{"key":"e_1_3_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.5555\/576628"},{"key":"e_1_3_2_1_37_1","volume-title":"https:\/\/www.selenium.dev\/","year":"2021","unstructured":"Selenium. https:\/\/www.selenium.dev\/ , 2021 . Selenium. https:\/\/www.selenium.dev\/, 2021."},{"key":"e_1_3_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1145\/1008992.1009035"},{"key":"e_1_3_2_1_39_1","volume-title":"https:\/\/www-banyuetan-org.translate.goog\/jrt\/detail\/20220120\/ 1000200033134991642405015323600477_1.html?_x_tr_sch=http&_x_tr_sl=zh- CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp","author":"Services","year":"2022","unstructured":"Services of \"switch ip in seconds\" have become the fundamental infrastructure for cybercrime. https:\/\/www-banyuetan-org.translate.goog\/jrt\/detail\/20220120\/ 1000200033134991642405015323600477_1.html?_x_tr_sch=http&_x_tr_sl=zh- CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp , 2022 . Services of \"switch ip in seconds\" have become the fundamental infrastructure for cybercrime. https:\/\/www-banyuetan-org.translate.goog\/jrt\/detail\/20220120\/ 1000200033134991642405015323600477_1.html?_x_tr_sch=http&_x_tr_sl=zh- CN&_x_tr_tl=en&_x_tr_hl=en&_x_tr_pto=wapp, 2022."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1653662.1653738"},{"key":"e_1_3_2_1_41_1","doi-asserted-by":"publisher","DOI":"10.1145\/584931.584952"},{"key":"e_1_3_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23244"},{"key":"e_1_3_2_1_43_1","volume-title":"Russian hackers used home networks to evade detection. https:\/\/www.bloomberg.com\/news\/articles\/2021-10-26\/suspected-russian- hackers-use-home-networks-to-evade-detection","author":"Turton William","year":"2021","unstructured":"William Turton . Russian hackers used home networks to evade detection. https:\/\/www.bloomberg.com\/news\/articles\/2021-10-26\/suspected-russian- hackers-use-home-networks-to-evade-detection , 2021 . William Turton. Russian hackers used home networks to evade detection. https:\/\/www.bloomberg.com\/news\/articles\/2021-10-26\/suspected-russian- hackers-use-home-networks-to-evade-detection, 2021."},{"key":"e_1_3_2_1_44_1","unstructured":"UPnProxy: Blackhat Proxies via NAT Injections. https:\/\/www.akamai.com\/content\/dam\/site\/en\/documents\/research-paper\/upnproxy-blackhat-proxies-via-nat-injections-white-paper.pdf.  UPnProxy: Blackhat Proxies via NAT Injections. https:\/\/www.akamai.com\/content\/dam\/site\/en\/documents\/research-paper\/upnproxy-blackhat-proxies-via-nat-injections-white-paper.pdf."},{"key":"e_1_3_2_1_45_1","unstructured":"VirusTotal APIs. https:\/\/developers.virustotal.com\/reference.  VirusTotal APIs. https:\/\/developers.virustotal.com\/reference."},{"key":"e_1_3_2_1_46_1","volume-title":"https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ","author":"Wannamine","year":"2018","unstructured":"Wannamine --new cryptocurrency malware exposes failings of traditional anti-virus tools. https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ , 2018 . Wannamine --new cryptocurrency malware exposes failings of traditional anti-virus tools. https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ, 2018."},{"key":"e_1_3_2_1_47_1","volume-title":"https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ","author":"New","year":"2020","unstructured":"New wannamine campaign spreading through smart jscript backdoor. https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ , 2020 . New wannamine campaign spreading through smart jscript backdoor. https:\/\/twitter.com\/_CPResearch_\/status\/1318461422247051264's=20&t=jrLyWANNfSWdRq4XOxTUlQ, 2020."},{"key":"e_1_3_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-04918-2_18"},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/1062745.1062868"},{"key":"e_1_3_2_1_50_1","volume-title":"Large-scale automatic classifi- cation of phishing pages","author":"Whittaker Colin","year":"2010","unstructured":"Colin Whittaker , Brian Ryner , and Marria Nazif . Large-scale automatic classifi- cation of phishing pages . 2010 . Colin Whittaker, Brian Ryner, and Marria Nazif. Large-scale automatic classifi- cation of phishing pages. 2010."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1145\/1526709.1526786"},{"key":"e_1_3_2_1_52_1","first-page":"184","volume-title":"USENIX Security Symposium","volume":"171","author":"Zhang Yin","year":"2000","unstructured":"Yin Zhang and Vern Paxson . Detecting stepping stones . In USENIX Security Symposium , volume 171 , page 184 , 2000 . Yin Zhang and Vern Paxson. Detecting stepping stones. In USENIX Security Symposium, volume 171, page 184, 2000."},{"key":"e_1_3_2_1_53_1","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2018.00039"}],"event":{"name":"CCS '22: 2022 ACM SIGSAC Conference on Computer and Communications Security","location":"Los Angeles CA USA","acronym":"CCS '22","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 2022 ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3559377","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3548606.3559377","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T17:50:57Z","timestamp":1750182657000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3548606.3559377"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,11,7]]},"references-count":53,"alternative-id":["10.1145\/3548606.3559377","10.1145\/3548606"],"URL":"https:\/\/doi.org\/10.1145\/3548606.3559377","relation":{},"subject":[],"published":{"date-parts":[[2022,11,7]]},"assertion":[{"value":"2022-11-07","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}