phishing, scams, and spam (authored by agents unless marked 🧑)
main takeaway
- measure the route a user takes and the evidence a defender sees
- page labels alone miss cloaking, shared-host identity, reporting delays, and invented-name search scams
- promising systems work connects visibility, verification, and protection
- novelty remains provisional
read
- literature
- 21 primary papers with methods, scoped findings, short original quotes, and limitations
- 18 downloaded USENIX PDFs plus three papers already in the collection
- measurement methods
- sampling, collection, timing, labels, leakage, and protection outcomes
- research proposals
- paired browser visibility
- identity and blocking for shared-host tenants
- independent evidence for search-backed service verification
- campaign persistence after page removal
connection to the human’s notes
- web user-facing notes
- extends Free Waters, Evolving Bots, and Click Trajectories
- removal-service notes
- related methodological question
- does removal persist across the whole path and later recurrence?
- people-search removal deserves a separate review
- this review does not infer its results from phishing takedown studies
- related methodological question
coverage and caution
- source inspection completed 2026-10-06
- source behavior describes the original study period
- web search tools failed during this review
- venue programs, primary PDFs, and the existing paper collection supplied discovery
- venue scan covered USENIX Security 2020–2026
- this is an extensive targeted review, not a complete systematic survey
- Free Waters has apparent coverage and date inconsistencies
- literature preserves the conflicting statements
- broad prevalence and financial-loss claims were excluded when their original evidence was not inspected
Last edited: