SocialHEISTing: Understanding Stolen Facebook Accounts
Jeremiah Onaolapo, Nektarios Leontiadis, Despoina Magka, Gianluca Stringhini
摘要
Online social network (OSN) accounts are often more usercentric than other types of online accounts (e.g., email accounts) because they present a number of demographic attributes such as age, gender, location, and occupation. While these attributes allow for more meaningful online interactions, they can also be used by malicious parties to craft various types of abuse. To understand the effects of demographic attributes on attacker behavior in stolen social accounts, we devised a method to instrument and monitor such accounts. We then created, instrumented, and deployed more than 1000 Facebook accounts, and exposed them to criminals. Our results confirm that victim demographic traits indeed influence the way cybercriminals abuse their accounts. For example, we find that cybercriminals that access teen accounts write messages and posts more than the ones accessing adult accounts, and attackers that compromise male accounts perform disruptive activities such as changing some of their profile information more than the ones that access female accounts. This knowledge could potentially help online services develop new models to characterize benign and malicious activity across various demographic attributes, and thus automatically classify future activity. We created 1008 Facebook test accounts in total, comprising equal numbers of female adult, male adult, female teen, and male teen accounts. In this section, we describe how we created, instrumented, and deployed them.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper4
- Care Infrastructures for Digital Security in Intimate Partner ViolenceEmily Tseng, Mehrnaz Sabet, Rosanna Bellini, Harkiran Kaur Sodhi 等CHI 2022 · 被引用 77 次
- SoK: Digging into the Digital Underworld of Stolen Data MarketsTina Marjanov, Alice HutchingsS&P 2025
- Hidden in Plain Bytes: Investigating Interpersonal Account Compromise with Data ExportsJulia Nonnenkamp, Naman Gupta, Abhimanyu Dev Gupta, Rahul ChatterjeeCCS 2025
- Predictive Response Optimization: Using Reinforcement Learning to Fight Online Social Network AbuseGarrett Wilson, Geoffrey Goh, Yan Jiang, Ajay Gupta 等USENIX Security 2025
它引用的顶会 Paper3
- Targeted Online Password Guessing: An Underestimated ThreatDing Wang, Zijian Zhang, Ping Wang, Jeff Yan 等CCS 2016 · 被引用 385 次
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh 等S&P 2021 · 被引用 175 次
- PhishEye: Live Monitoring of Sandboxed Phishing KitsXiao Han, Nizar Kheir, Davide BalzarottiCCS 2016 · 被引用 118 次
相关 Paper
- The Chameleon Attack: Manipulating Content Display in Online Social MediaAviad Elyashar, Sagi Uziel, Abigail Paradise, Rami PuzisWWW 2020 · 被引用 7 次
- Deep Entity Classification: Abusive Account Detection for Online Social NetworksTeng Xu, Gerard Goossen, Huseyin Kerem Cevahir, Sara Khodeir 等USENIX Security 2021 · 被引用 41 次
- Know Your Cybercriminal: Evaluating Attacker Preferences by Measuring Profile Sales on an Active, Leading Criminal Market for User Impersonation at ScaleMichele Campobasso, Luca AllodiUSENIX Security 2023
- You Are Who You Know and How You Behave: Attribute Inference Attacks via Users' Social Friends and BehaviorsNeil Zhenqiang Gong, Bin LiuUSENIX Security 2016 · 被引用 156 次
- "Should I Worry?" A Cross-Cultural Examination of Account Security Incident ResponseElissa M. RedmilesS&P 2019 · 被引用 53 次
