论文标题
在线广告安全:问题,分类法和未来方向
Online Advertising Security: Issues, Taxonomy, and Future Directions
论文作者
论文摘要
在线广告已通过彻底改变业务营销来成为互联网经济的骨干。它为广告商提供了一种简单有效的方式,可以向特定的个人用户展示其广告,并且在过去的几年中,为几家基于网络的业务的收入流爆炸了。例如,在2016年至2018年期间,Google的收入增长了51.6%,达到1368亿美元。广告收入中的这种指数增长促使欺诈者利用在线广告模型的弱点来赚钱,研究人员在模型中发现新的安全漏洞,提出对策并预测研究的未来趋势。在这些考虑因素上,本文对在线广告系统的安全威胁进行了全面审查。我们首先介绍在线广告系统的动机,解释它与传统广告网络的不同,引入术语并定义当前的在线广告体系结构。然后,我们设计了对在线广告的攻击的全面分类法,以提高研究人员对在线广告生态系统脆弱性的认识。我们讨论为保护广告生态系统中的实体免受这些攻击而开发的对策的局限性和有效性。为了完成我们的工作,我们确定了一些开放问题,并概述了一些可能的方向,以改善在线广告系统的安全方法。
Online advertising has become the backbone of the Internet economy by revolutionizing business marketing. It provides a simple and efficient way for advertisers to display their advertisements to specific individual users, and over the last couple of years has contributed to an explosion in the income stream for several web-based businesses. For example, Google's income from advertising grew 51.6% between 2016 and 2018, to $136.8 billion. This exponential growth in advertising revenue has motivated fraudsters to exploit the weaknesses of the online advertising model to make money, and researchers to discover new security vulnerabilities in the model, to propose countermeasures and to forecast future trends in research. Motivated by these considerations, this paper presents a comprehensive review of the security threats to online advertising systems. We begin by introducing the motivation for online advertising system, explain how it differs from traditional advertising networks, introduce terminology, and define the current online advertising architecture. We then devise a comprehensive taxonomy of attacks on online advertising to raise awareness among researchers about the vulnerabilities of online advertising ecosystem. We discuss the limitations and effectiveness of the countermeasures that have been developed to secure entities in the advertising ecosystem against these attacks. To complete our work, we identify some open issues and outline some possible directions for future research towards improving security methods for online advertising systems.