To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media

To Err.Is Human: Characterizing the Threat of Unintended URLs in Social Media
复制标题

DOI:
10.14722/ndss.2021.24322
复制
发表时间:
2021
期刊:
Proceedings 2021 Network and Distributed System Security Symposium
影响因子:
--
通讯作者:
Beliz Kaleli;Brian Kondracki;Manuel Egele;Nick Nikiforakis;G. Stringhini
Beliz Kaleli;Brian Kondracki;Manuel Egele;Nick Nikiforakis;G. Stringhini
中科院分区:
其他
文献类型:
--
作者:
Beliz Kaleli;Brian Kondracki;Manuel Egele;Nick Nikiforakis;G. Stringhini

文献摘要

相似文献

为了使其服务更加用户友好,在线社交媒体平台自动识别与URL对应的文本,并将其呈现为可点击的链接。在本文中,我们表明,这些服务所使用的技术来识别URL往往过于宽容,并可能导致意外的URL被显示在社交网络消息。其中,我们表明,如果用户忘记了句末句号后的空格,并且下一句的第一个单词恰好是有效的顶级域名,那么流行的平台(如Twitter)将文本呈现为可点击的URL。攻击者可以通过注册相应的域并将数百万Twitter用户暴露给任意恶意内容来利用这些意想不到的URL。为了描述非预期URL对社交媒体用户构成的威胁,我们对推文中的非预期URL进行了为期7个月的大规模研究。通过设计一个能够区分推文中发布的预期和非预期URL的分类器,我们发现了超过26000个由拥有数千万粉丝的账户发布的非预期URL。作为研究的一部分,我们还注册了45个非预期的域名,并量化了攻击者仅通过在正确的时间注册正确的域名就可以获得的流量。最后,由于我们发现的严重性,我们提出了一个轻量级的浏览器扩展,它可以分析用户撰写的推文,并提醒他们潜在的非预期URL,并发出警告,允许用户在发布推文之前修复他们的错误。
—To make their services more user friendly, online social media platforms automatically identify text that corresponds to URLs and render it as clickable links. In this paper, we show that the techniques used by such services to recognize URLs are often too permissive and can result in unintended URLs being displayed in social network messages. Among others, we show that popular platforms (such as Twitter) will render text as a clickable URL if a user forgets a space after a full stop at the end of a sentence, and the first word of the next sentence happens to be a valid Top Level Domain. Attackers can take advantage of these unintended URLs by registering the corresponding domains and exposing millions of Twitter users to arbitrary malicious content. To characterize the threat that unintended URLs pose to social media users, we perform a large-scale study of unintended URLs in tweets over a period of 7 months. By designing a classifier capable of differentiating between intended and unintended URLs posted in tweets, we find more than 26K unintended URLs posted by accounts with tens of millions of followers. As part of our study, we also register 45 unintended domains and quantify the traffic that attackers can get by merely registering the right domains at the right time. Finally, due to the severity of our findings, we propose a lightweight browser extension which can, on the fly, analyze the tweets that users compose and alert them of potentially unintended URLs and raise a warning, allowing users to fix their mistake before the tweet is posted.