{"id":"https://openalex.org/W4225727688","doi":"https://doi.org/10.1109/tifs.2022.3169923","title":"Hidden Path: Understanding the Intermediary in Malicious Redirections","display_name":"Hidden Path: Understanding the Intermediary in Malicious Redirections","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4225727688","doi":"https://doi.org/10.1109/tifs.2022.3169923"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2022.3169923","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3169923","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5068116051","display_name":"Yuwei Zeng","orcid":"https://orcid.org/0000-0002-4022-3634"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Yuwei Zeng","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]},{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100745766","display_name":"Zhicheng Liu","orcid":"https://orcid.org/0000-0002-1015-2759"},"institutions":[{"id":"https://openalex.org/I4210087772","display_name":"National Computer Network Emergency Response Technical Team/Coordination Center of Chinar","ror":"https://ror.org/00247dh76","country_code":"CN","type":"nonprofit","lineage":["https://openalex.org/I4210087772"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhicheng Liu","raw_affiliation_strings":["CNCERT/CC, Beijing, China"],"affiliations":[{"raw_affiliation_string":"CNCERT/CC, Beijing, China","institution_ids":["https://openalex.org/I4210087772"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5062771971","display_name":"Xunxun Chen","orcid":"https://orcid.org/0000-0002-9481-4819"},"institutions":[{"id":"https://openalex.org/I4210087772","display_name":"National Computer Network Emergency Response Technical Team/Coordination Center of Chinar","ror":"https://ror.org/00247dh76","country_code":"CN","type":"nonprofit","lineage":["https://openalex.org/I4210087772"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xunxun Chen","raw_affiliation_strings":["CNCERT/CC, Beijing, China"],"affiliations":[{"raw_affiliation_string":"CNCERT/CC, Beijing, China","institution_ids":["https://openalex.org/I4210087772"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5066426299","display_name":"Tianning Zang","orcid":"https://orcid.org/0000-0003-3583-6249"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I4210165038","display_name":"University of Chinese Academy of Sciences","ror":"https://ror.org/05qbk4x57","country_code":"CN","type":"education","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210165038"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tianning Zang","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]},{"raw_affiliation_string":"School of Cyber Security, University of Chinese Academy of Sciences, Beijing, China","institution_ids":["https://openalex.org/I4210165038"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5068116051"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210156404","https://openalex.org/I4210165038"],"apc_list":null,"apc_paid":null,"fwci":3.1846,"has_fulltext":false,"cited_by_count":10,"citation_normalized_percentile":{"value":0.92814288,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":"17","issue":null,"first_page":"1725","last_page":"1740"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8571869134902954},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6306600570678711},{"id":"https://openalex.org/keywords/javascript","display_name":"JavaScript","score":0.5509799122810364},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5356438159942627},{"id":"https://openalex.org/keywords/web-crawler","display_name":"Web crawler","score":0.5290837287902832},{"id":"https://openalex.org/keywords/information-leakage","display_name":"Information leakage","score":0.5262959599494934},{"id":"https://openalex.org/keywords/adversary","display_name":"Adversary","score":0.4950069785118103},{"id":"https://openalex.org/keywords/crawling","display_name":"Crawling","score":0.4353092610836029},{"id":"https://openalex.org/keywords/path","display_name":"Path (computing)","score":0.42707934975624084},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.3441835641860962},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.3142669200897217},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.11163592338562012}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8571869134902954},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6306600570678711},{"id":"https://openalex.org/C544833334","wikidata":"https://www.wikidata.org/wiki/Q2005","display_name":"JavaScript","level":2,"score":0.5509799122810364},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5356438159942627},{"id":"https://openalex.org/C13743948","wikidata":"https://www.wikidata.org/wiki/Q45842","display_name":"Web crawler","level":2,"score":0.5290837287902832},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.5262959599494934},{"id":"https://openalex.org/C41065033","wikidata":"https://www.wikidata.org/wiki/Q2825412","display_name":"Adversary","level":2,"score":0.4950069785118103},{"id":"https://openalex.org/C100368936","wikidata":"https://www.wikidata.org/wiki/Q1411725","display_name":"Crawling","level":2,"score":0.4353092610836029},{"id":"https://openalex.org/C2777735758","wikidata":"https://www.wikidata.org/wiki/Q817765","display_name":"Path (computing)","level":2,"score":0.42707934975624084},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.3441835641860962},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.3142669200897217},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.11163592338562012},{"id":"https://openalex.org/C105702510","wikidata":"https://www.wikidata.org/wiki/Q514","display_name":"Anatomy","level":1,"score":0.0},{"id":"https://openalex.org/C71924100","wikidata":"https://www.wikidata.org/wiki/Q11190","display_name":"Medicine","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/tifs.2022.3169923","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3169923","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7599999904632568,"display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G1329900568","display_name":null,"funder_award_id":"2016QY05X1002","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":40,"referenced_works":["https://openalex.org/W80155331","https://openalex.org/W1480813933","https://openalex.org/W1554293762","https://openalex.org/W1561983441","https://openalex.org/W1954903228","https://openalex.org/W1998843210","https://openalex.org/W2013269776","https://openalex.org/W2040424958","https://openalex.org/W2083391339","https://openalex.org/W2084835421","https://openalex.org/W2095610745","https://openalex.org/W2097470225","https://openalex.org/W2101678831","https://openalex.org/W2101737524","https://openalex.org/W2113167642","https://openalex.org/W2117202485","https://openalex.org/W2146729596","https://openalex.org/W2159710624","https://openalex.org/W2182421051","https://openalex.org/W2190286163","https://openalex.org/W2424402128","https://openalex.org/W2518248186","https://openalex.org/W2794855529","https://openalex.org/W2889547652","https://openalex.org/W2902942389","https://openalex.org/W2906701006","https://openalex.org/W2922410548","https://openalex.org/W2967483606","https://openalex.org/W2980770947","https://openalex.org/W2990296034","https://openalex.org/W2995774794","https://openalex.org/W3012755363","https://openalex.org/W3148501095","https://openalex.org/W6603260413","https://openalex.org/W6633578641","https://openalex.org/W6640663528","https://openalex.org/W6676915735","https://openalex.org/W6685992501","https://openalex.org/W6760491298","https://openalex.org/W6766914566"],"related_works":["https://openalex.org/W2566658409","https://openalex.org/W3119324922","https://openalex.org/W2352686120","https://openalex.org/W2372594123","https://openalex.org/W2358310581","https://openalex.org/W2964752624","https://openalex.org/W2026132847","https://openalex.org/W4385695127","https://openalex.org/W2137810919","https://openalex.org/W4255854114"],"abstract_inverted_index":{"URL":[0,29],"redirection":[1,30,91,102,131,133],"has":[2],"become":[3],"an":[4,46],"important":[5],"tool":[6],"for":[7,55,158],"adversaries":[8,27],"to":[9,31,50,66,138,162,173],"cover":[10],"up":[11],"their":[12],"malicious":[13,37,56,74,111,143],"campaigns.":[14],"In":[15],"this":[16,42],"paper,":[17],"we":[18,44,60,81,104,127],"conduct":[19,163],"the":[20,52,69,89,94,100,106,114,121,140,149,155],"first":[21],"large-scale":[22],"measurement":[23],"study":[24],"on":[25,99],"how":[26],"leverage":[28],"circumvent":[32],"security":[33],"checks":[34],"and":[35,87,117,119,169],"distribute":[36],"content":[38],"in":[39,73],"practice.":[40],"To":[41],"end,":[43],"design":[45],"iteratively":[47],"running":[48],"framework":[49],"mine":[51],"domains":[53,70,86],"used":[54],"redirections":[57,75],"constantly.":[58],"First,":[59],"use":[61],"a":[62,129],"bipartite":[63],"graph-based":[64],"method":[65],"dig":[67],"out":[68],"potentially":[71],"involved":[72],"from":[76,93],"real-world":[77],"DNS":[78],"traffic.":[79],"Then,":[80],"dynamically":[82],"crawl":[83],"these":[84],"suspicious":[85],"recover":[88],"corresponding":[90],"chains":[92],"crawler\u2019s":[95],"performance":[96],"log.":[97],"Based":[98],"collected":[101],"chains,":[103],"analyze":[105],"working":[107],"mechanism":[108],"of":[109,123,142],"various":[110],"redirections,":[112],"involving":[113],"abused":[115,137],"modes":[116],"methods,":[118],"highlight":[120],"pervasiveness":[122],"node":[124],"sharing.":[125],"Notably,":[126],"find":[128],"new":[130],"abuse,":[132],"fluxing,":[134],"which":[135],"is":[136],"enhance":[139],"concealment":[141],"sites":[144],"by":[145,166],"introducing":[146,167],"randomness":[147],"into":[148],"redirection.":[150],"Our":[151],"case":[152],"studies":[153],"reveal":[154],"adversary\u2019s":[156],"preference":[157],"abusing":[159],"JavaScript":[160],"methods":[161],"redirection,":[164],"even":[165],"time-delay":[168],"fabricating":[170],"user":[171],"clicks":[172],"simulate":[174],"normal":[175],"users.":[176]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":3},{"year":2023,"cited_by_count":2}],"updated_date":"2026-03-06T13:50:29.536080","created_date":"2025-10-10T00:00:00"}
