<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE ArticleSet PUBLIC "-//NLM//DTD PubMed 2.7//EN" "https://dtd.nlm.nih.gov/ncbi/pubmed/in/PubMed.dtd">
<ArticleSet>
<Article>
<Journal>
				<PublisherName>Islamic Azad University, Khodabandeh Branch, Zanjan</PublisherName>
				<JournalTitle>Arman Process Journal (APJ)</JournalTitle>
				<Issn>2783-1361</Issn>
				<Volume>6</Volume>
				<Issue>4</Issue>
				<PubDate PubStatus="epublish">
					<Year>2026</Year>
					<Month>01</Month>
					<Day>21</Day>
				</PubDate>
			</Journal>
<ArticleTitle>Detect Redirect to the Malicious Web-Sites in ANDROID Devices</ArticleTitle>
<VernacularTitle>Detect Redirect to the Malicious Web-Sites in ANDROID Devices</VernacularTitle>
			<FirstPage>12</FirstPage>
			<LastPage>24</LastPage>
			<ELocationID EIdType="pii">735648</ELocationID>
			
<ELocationID EIdType="doi">10.22034/apj.2026.2079995.1061</ELocationID>
			
			<Language>FA</Language>
<AuthorList>
<Author>
					<FirstName>Seyed Mahmood</FirstName>
					<LastName>Hashemi</LastName>
<Affiliation>KAR Higher Educational Institute</Affiliation>

</Author>
</AuthorList>
				<PublicationType>Journal Article</PublicationType>
			<History>
				<PubDate PubStatus="received">
					<Year>2025</Year>
					<Month>12</Month>
					<Day>05</Day>
				</PubDate>
			</History>
		<Abstract>Background and Objectives: Website clicks that redirect Android phone users to malicious ‎websites with fake virus warnings or phishing attacks are increasing exponentially. Although a ‎Uniform Resource Locator (URL) blacklist is considered as a suitable countermeasure for such ‎attacks, it is difficult to efficiently identify malicious websites. To the best of our knowledge, no ‎research has focused on detecting attacks that redirect Android phone users to malicious ‎websites. Therefore, we propose a redirection detection method that focuses on the URL bar ‎change interval of the Android-based Google Chrome browser.‎&lt;br&gt;Methods: The proposed method, which can be easily installed as an Android application, uses ‎the Android Accessibility Service to detect unwanted redirects to malicious websites without ‎collecting information about these websites in advance. This paper describes the details of the ‎design, implementation, and evaluation results of the proposed application on a real Android ‎device. We set threshold values for the number of times the URL bar changes and the elapsed ‎time to detect redirects to malicious websites for the proposed method.‎&lt;br&gt;Finding: Based on the results, we investigated the causes of false positive detections of ‎redirects to safe websites and proposed solutions to manage them. We also present threshold ‎values that can minimize the false positive and negative rates, as well as the detection accuracy ‎of the proposed method based on these threshold values. In addition, we present evaluation ‎results based on access reports of real users participating in the WarpDrive project experiment, ‎which show that the proposed method minimizes false positives and successfully detects most ‎redirects to malicious websites.‎</Abstract>
			<OtherAbstract Language="FA">Background and Objectives: Website clicks that redirect Android phone users to malicious ‎websites with fake virus warnings or phishing attacks are increasing exponentially. Although a ‎Uniform Resource Locator (URL) blacklist is considered as a suitable countermeasure for such ‎attacks, it is difficult to efficiently identify malicious websites. To the best of our knowledge, no ‎research has focused on detecting attacks that redirect Android phone users to malicious ‎websites. Therefore, we propose a redirection detection method that focuses on the URL bar ‎change interval of the Android-based Google Chrome browser.‎&lt;br&gt;Methods: The proposed method, which can be easily installed as an Android application, uses ‎the Android Accessibility Service to detect unwanted redirects to malicious websites without ‎collecting information about these websites in advance. This paper describes the details of the ‎design, implementation, and evaluation results of the proposed application on a real Android ‎device. We set threshold values for the number of times the URL bar changes and the elapsed ‎time to detect redirects to malicious websites for the proposed method.‎&lt;br&gt;Finding: Based on the results, we investigated the causes of false positive detections of ‎redirects to safe websites and proposed solutions to manage them. We also present threshold ‎values that can minimize the false positive and negative rates, as well as the detection accuracy ‎of the proposed method based on these threshold values. In addition, we present evaluation ‎results based on access reports of real users participating in the WarpDrive project experiment, ‎which show that the proposed method minimizes false positives and successfully detects most ‎redirects to malicious websites.‎</OtherAbstract>
		<ObjectList>
			<Object Type="keyword">
			<Param Name="value">Android</Param>
			</Object>
			<Object Type="keyword">
			<Param Name="value">Redirect</Param>
			</Object>
		</ObjectList>
<ArchiveCopySource DocType="pdf">https://www.armanprocessjournal.ir/article_735648_04f1c006f7340e0ddda52ab394945086.pdf</ArchiveCopySource>
</Article>
</ArticleSet>
