What You See is NOT What You Get: Discovering and Tracking Social Engineering Attack Campaigns

What You See is NOT What You Get: Discovering and Tracking Social Engineering Attack Campaigns
复制标题

所见非所得:发现和跟踪社会工程攻击活动

DOI:
--
复制
发表时间:
2019
期刊:
ACM/SIGCOMM Internet Measurement Conference
影响因子:
--
通讯作者:
R. Perdisci
R. Perdisci
中科院分区:
--
文献类型:
--
作者:
Phani Vadrevu;R. Perdisci

文献摘要

被引文献

相似文献

恶意广告通常使用社会工程(SE)策略诱使用户下载不需要的软件,购买假冒产品或服务,或放弃有价值的个人信息。这些广告通常由低层广告网络提供服务,这些网络可能没有技术手段(或只是意愿)来巡逻他们提供的广告内容,以减少滥用。在本文中,我们提出了一个大规模的自动发现和跟踪通过恶意广告(SEACMA)的SE攻击活动的系统。我们的系统旨在通用,使我们能够研究SEACMA广告分发问题,而不会偏向于特定类别的广告发布网站或SE攻击。从低层广告网络的种子开始,我们衡量这些网络中哪些最有可能分发恶意广告,并提出了一种机制来发现新的广告网络,这些网络也被用来支持SEACMA活动的分发。我们的研究结果旨在以多种方式发挥作用。例如,我们展示了SEACMA广告使用多种策略来成功规避URL黑名单和广告拦截器。通过跟踪SEACMA活动,我们的系统提供了一种机制,可以更主动地检测和阻止此类规避广告。因此,我们的研究结果提供了有价值的信息,可用于改善防御系统,以抵御社会工程攻击和恶意广告。
Malicious ads often use social engineering (SE) tactics to coax users into downloading unwanted software, purchasing fake products or services, or giving up valuable personal information. These ads are often served by low-tier ad networks that may not have the technical means (or simply the will) to patrol the ad content they serve to curtail abuse. In this paper, we propose a system for large-scale automatic discovery and tracking of SE Attack Campaigns delivered via Malicious Advertisements (SEACMA). Our system aims to be generic, allowing us to study the SEACMA ad distribution problem without being biased towards specific categories of ad-publishing websites or SE attacks. Starting with a seed of low-tier ad networks, we measure which of these networks are the most likely to distribute malicious ads and propose a mechanism to discover new ad networks that are also leveraged to support the distribution of SEACMA campaigns. The results of our study aim to be useful in a number of ways. For instance, we show that SEACMA ads use a number of tactics to successfully evade URL blacklists and ad blockers. By tracking SEACMA campaigns, our system provides a mechanism to more proactively detect and block such evasive ads. Therefore, our results provide valuable information that could be used to improve defense systems against social engineering attacks and malicious ads in general.