Towards Detecting Compromised Accounts on Social Networks

Towards Detecting Compromised Accounts on Social Networks
复制标题

DOI:
10.1109/tdsc.2015.2479616
复制
发表时间:
2015-09
影响因子:
7.3
通讯作者:
Manuel Egele;G. Stringhini;C. Kruegel;Giovanni Vigna
Manuel Egele;G. Stringhini;C. Kruegel;Giovanni Vigna
中科院分区:
计算机科学2区
文献类型:
--
作者:
Manuel Egele;G. Stringhini;C. Kruegel;Giovanni Vigna

文献摘要

被引文献

相似文献

入侵社交网络账户已成为网络犯罪分子有利可图的行为。通过劫持对流行媒体或商业账户的控制,攻击者可以向大量用户分发他们的恶意消息或传播虚假信息。这些事件的影响范围从声誉受损到金融市场数十亿美元的货币损失。在我们之前的工作中,我们演示了如何检测常规在线社交网络用户的大规模妥协(即所谓的活动)。在这项工作中,我们展示了如何使用类似的技术来识别个人高知名度帐户的漏洞。备受瞩目的帐户通常有一个特征,使这种检测可靠-他们表现出一致的行为随着时间的推移。我们表明,如果部署我们的系统,将能够检测和阻止针对受欢迎的公司和新闻机构的三次现实世界攻击。此外,与流行媒体不同,我们的制度不会被一家美国连锁餐厅出于宣传原因煽动的阶段性妥协所迷惑。
Compromising social network accounts has become a profitable course of action for cybercriminals. By hijacking control of a popular media or business account, attackers can distribute their malicious messages or disseminate fake information to a large user base. The impacts of these incidents range from a tarnished reputation to multi-billion dollar monetary losses on financial markets. In our previous work, we demonstrated how we can detect large-scale compromises (i.e., so-called campaigns) of regular online social network users. In this work, we show how we can use similar techniques to identify compromises of individual high-profile accounts. High-profile accounts frequently have one characteristic that makes this detection reliable—they show consistent behavior over time. We show that our system, were it deployed, would have been able to detect and prevent three real-world attacks against popular companies and news agencies. Furthermore, our system, in contrast to popular media, would not have fallen for a staged compromise instigated by a US restaurant chain for publicity reasons.