The Art and Craft of Fraudulent App Promotion in Google Play

The Art and Craft of Fraudulent App Promotion in Google Play
复制标题

DOI:
10.1145/3319535.3345658
复制
发表时间:
2019-11
期刊:
Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security
影响因子:
--
通讯作者:
Mizanur Rahman;Nestor Hernandez;Ruben Recabarren;Syed Ishtiaque Ahmed;Bogdan Carbunar
Mizanur Rahman;Nestor Hernandez;Ruben Recabarren;Syed Ishtiaque Ahmed;Bogdan Carbunar
中科院分区:
其他
文献类型:
--
作者:
Mizanur Rahman;Nestor Hernandez;Ruben Recabarren;Syed Ishtiaque Ahmed;Bogdan Carbunar

文献摘要

被引文献

相似文献

以虚假评论和马甲帐户形式出现的黑帽应用搜索优化 (ASO) 在同行意见网站(例如应用商店)中普遍存在,对其用户的数字生活和现实生活产生负面影响。为了检测和过滤欺诈,越来越多的研究提供了对欺诈发布活动各个方面的见解,并根据在线数据对欺诈者的工作流程做出了假设。然而,此类假设往往缺乏来自实际欺诈实施者的经验证据。为了解决这个问题,在本文中,我们介绍了对从 5 个自由职业网站招募的 18 名 ASO 工作人员进行的定性研究结果,涉及他们在 Google Play 上进行的活动,以及对从其他 39 名 ASO 工作人员收集的欺诈相关数据进行的定量调查。我们揭示了有关 ASO 员工能力和行为各个方面的发现,包括对其工作模式的新颖见解,以及支持几个现有假设的证据。此外,我们发现并报告了参与者公开的绕过谷歌强制验证的技术、避免检测的具体策略,甚至利用欺诈检测来提高欺诈效率的策略。我们报告了一个 Google 网站漏洞,该漏洞使我们能够推断出用于在 Google Play 中发布超过 1.98 亿条评论的移动设备型号,其中包括 9,942 条虚假评论。我们讨论了我们的研究结果的更深层含义,包括它们在开发下一代欺诈检测和预防系统方面的潜在用途。
Black Hat App Search Optimization (ASO) in the form of fake reviews and sockpuppet accounts, is prevalent in peer-opinion sites, e.g., app stores, with negative implications on the digital and real lives of their users. To detect and filter fraud, a growing body of research has provided insights into various aspects of fraud posting activities, and made assumptions about the working procedures of the fraudsters from online data. However, such assumptions often lack empirical evidence from the actual fraud perpetrators. To address this problem, in this paper, we present results of both a qualitative study with 18 ASO workers we recruited from 5 freelancing sites, concerning activities they performed on Google Play, and a quantitative investigation with fraud-related data collected from other 39 ASO workers. We reveal findings concerning various aspects of ASO worker capabilities and behaviors, including novel insights into their working patterns, and supporting evidence for several existing assumptions. Further, we found and report participant-revealed techniques to bypass Google-imposed verifications, concrete strategies to avoid detection, and even strategies that leverage fraud detection to enhance fraud efficacy. We report a Google site vulnerability that enabled us to infer the mobile device models used to post more than 198 million reviews in Google Play, including 9,942 fake reviews. We discuss the deeper implications of our findings, including their potential use to develop the next generation fraud detection and prevention systems.