<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName></PublisherName>
				<JournalTitle>فصلنامه تخصصی آرمان پردازش</JournalTitle>
				<Issn>2783-1361</Issn>
				<Volume>6</Volume>
				<Issue>4</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>01</Month>
					<Day>21</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Detect Redirect to the Malicious Web-Sites in ANDROID Devices</ArticleTitle>
<VernacularTitle>شناسایی هدایت مجدد به وب سایتهای مخرب در وسایل اندروید</VernacularTitle>
			<FirstPage>12</FirstPage>
			<LastPage>24</LastPage>
			<ELocationID EIdType="pii">735648</ELocationID>
			
<ELocationID EIdType="doi">10.22034/apj.2026.2079995.1061</ELocationID>
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>سید محمود</FirstName>
					<LastName>هاشمی</LastName>
<Affiliation>موسسه آموزش عالی کار</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2025</Year>
					<Month>12</Month>
					<Day>05</Day>
				</PubDate>
			</History>
		<Abstract>Background and Objectives: Website clicks that redirect Android phone users to malicious ‎websites with fake virus warnings or phishing attacks are increasing exponentially. Although a ‎Uniform Resource Locator (URL) blacklist is considered as a suitable countermeasure for such ‎attacks, it is difficult to efficiently identify malicious websites. To the best of our knowledge, no ‎research has focused on detecting attacks that redirect Android phone users to malicious ‎websites. Therefore, we propose a redirection detection method that focuses on the URL bar ‎change interval of the Android-based Google Chrome browser.‎&lt;br&gt;Methods: The proposed method, which can be easily installed as an Android application, uses ‎the Android Accessibility Service to detect unwanted redirects to malicious websites without ‎collecting information about these websites in advance. This paper describes the details of the ‎design, implementation, and evaluation results of the proposed application on a real Android ‎device. We set threshold values for the number of times the URL bar changes and the elapsed ‎time to detect redirects to malicious websites for the proposed method.‎&lt;br&gt;Finding: Based on the results, we investigated the causes of false positive detections of ‎redirects to safe websites and proposed solutions to manage them. We also present threshold ‎values that can minimize the false positive and negative rates, as well as the detection accuracy ‎of the proposed method based on these threshold values. In addition, we present evaluation ‎results based on access reports of real users participating in the WarpDrive project experiment, ‎which show that the proposed method minimizes false positives and successfully detects most ‎redirects to malicious websites.‎</Abstract>
			<OtherAbstract Language="FA">پیشینه و اهداف: کلیک‌های وب‌سایت که کاربران تلفن‌های اندروید را به وب‌سایت‌های مخرب با هشدارهای ‏جعلی ویروس یا حملات فیشینگ هدایت می‌کنند، به صورت تصاعدی در حال افزایش هستند. اگرچه یک ‏لیست سیاه مکان‌یاب منبع یکنواخت‎ (URL) ‎به عنوان یک اقدام متقابل مناسب برای چنین حملاتی در نظر ‏گرفته می‌شود، اما شناسایی کارآمد وب‌سایت‌های مخرب دشوار است. تا آنجا که ما می‌دانیم، هیچ تحقیقی بر ‏تشخیص حملاتی که کاربران تلفن‌های اندروید را به وب‌سایت‌های مخرب هدایت می‌کنند، متمرکز نشده است. ‏بنابراین، ما یک روش تشخیص تغییر مسیر را پیشنهاد می‌کنیم که بر فاصله زمانی تغییر نوار‎ URL ‎مرورگر ‏گوگل کروم مبتنی بر اندروید تمرکز دارد.‏&lt;br&gt;روشها: روش پیشنهادی، که به راحتی به عنوان یک برنامه اندروید قابل نصب است، از سرویس دسترسی ‏اندروید برای شناسایی تغییر مسیرهای ناخواسته به وب‌سایت‌های مخرب بدون جمع‌آوری اطلاعات در مورد ‏این وب‌سایت‌ها از قبل استفاده می‌کند. این مقاله جزئیات طراحی، پیاده‌سازی و نتایج ارزیابی برنامه پیشنهادی ‏را بر روی یک دستگاه اندروید واقعی شرح می‌دهد‎. ‎ما مقادیر آستانه برای تعداد دفعات تغییر نوار‎ URL ‎و زمان ‏سپری شده برای تعیین تغییر مسیرها به وب‌سایت‌های مخرب را برای روش پیشنهادی تعیین کردیم.‏&lt;br&gt;یافته ها: بر اساس نتایج، ما علل تشخیص‌های مثبت کاذبِ تغییر مسیرها به وب‌سایت‌های بی‌خطر را بررسی ‏کردیم و راه‌حل‌هایی برای مدیریت آنها ارائه دادیم‎.‎‏ همچنین مقادیر آستانه‌ای که می‌توانند نرخ‌های مثبت و ‏منفی کاذب را به حداقل برسانند، و همچنین دقت تشخیص روش پیشنهادی بر اساس این مقادیر آستانه را ‏ارائه می‌دهیم. علاوه بر این، نتایج ارزیابی‌ها را بر اساس گزارش‌های دسترسی کاربران واقعی شرکت‌کننده در ‏آزمایش پروژه‎ WarpDrive ‎ارائه می‌دهیم که نشان می‌دهد روش پیشنهادی، موارد مثبت کاذب را به حداقل ‏می‌رساند و اکثر تغییر مسیرها به وب‌سایت‌های مخرب را با موفقیت تشخیص می‌دهد</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">اندروید</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">هدایت مجدد</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.armanprocessjournal.ir/article_735648_04f1c006f7340e0ddda52ab394945086.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
