Having Your Cake and Eating It: An Analysis of Concession-Abuse-as-a-Service
Zhibo Sun, Adam Oest, Penghui Zhang, Carlos E. Rubio-Medrano, Tiffany Bao, Ruoyu Wang, Ziming Zhao, Yan Shoshitaishvili, Adam Doupé, Gail-Joon Ahn
摘要
Concession Abuse as a Service (CAaaS) is a growing scam service in underground forums that defrauds online retailers through the systematic abuse of their return policies (via social engineering) and the exploitation of loopholes in company protocols. Timely detection of such scams is difficult as they are fueled by an extensive suite of criminal services, such as credential theft, document forgery, and fake shipments. Ultimately, the scam enables malicious actors to steal arbitrary goods from merchants with minimal investment. In this paper, we perform in-depth manual and automated analysis of public and private messages from four large underground forums to identify the malicious actors involved in CAaaS, carefully study the operation of the scam, and define attributes to fingerprint the scam and inform mitigation strategies. Additionally, we surveyed users to evaluate their attitudes toward these mitigations and understand the factors that merchants should consider before implementing these strategies. We find that the scam is easy to scale-and can bypass traditional anti-fraud efforts-and thus poses a notable threat to online retailers.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper5
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren 等CCS 2023 · 被引用 19 次
- All Your Shops Are Belong to Us: Security Weaknesses in E-commerce PlatformsRohan Pagey, Mohammad Mannan, Amr M. YoussefWWW 2023 · 被引用 10 次
- Understanding and Analyzing Appraisal Systems in the Underground MarketplacesZhengyi Li, Xiaojing LiaoNDSS 2024
- The Dark Side of E-Commerce: Dropshipping Abuse as a Business ModelArjun Arunasalam, Andrew Chu, Muslum Ozgur Ozmen, Habiba Farrukh 等NDSS 2024
- SoK: A Privacy Framework for Security Research Using Social Media DataKyle Beadle, Kieron Ivy Turk, Aliai Eusebi, Mindy Tran 等S&P 2025
它引用的顶会 Paper8
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri 等USENIX Security 2016 · 被引用 331 次
- Data Breaches, Phishing, or Malware?: Understanding the Risks of Stolen CredentialsKurt Thomas, Frank Li, Ali Zand, Jacob Barrett 等CCS 2017 · 被引用 248 次
- PhishFarm: A Scalable Framework for Measuring the Effectiveness of Evasion Techniques against Browser Phishing BlacklistsAdam Oest, Yeganeh Safaei, Adam Doupé, Gail-Joon Ahn 等S&P 2019 · 被引用 129 次
- Resident Evil: Understanding Residential IP Proxy as a Dark ServiceXianghang Mi, Xuan Feng, Xiaojing Liao, Baojun Liu 等S&P 2019 · 被引用 80 次
- Towards Measuring and Mitigating Social Engineering Software Download AttacksTerry Nelms, Roberto Perdisci, Manos Antonakakis, Mustaque AhamadUSENIX Security 2016 · 被引用 70 次
相关 Paper
- Impersonation-as-a-Service: Characterizing the Emerging Criminal Infrastructure for User Impersonation at ScaleMichele Campobasso, Luca AllodiCCS 2020 · 被引用 24 次
- Doxing-as-a-Service: Demystifying the Chinese Online Doxing EcosystemYiran Gao, Pengcheng Xia, Liu Wang, Tianming Liu 等WWW 2026
- Scalable Detection of Promotional Website Defacements in Black Hat SEO CampaignsRonghai Yang, Xianbo Wang, Cheng Chi, Dawei Wang 等USENIX Security 2021 · 被引用 27 次
- WARDEN: Multi-Directional Backdoor Watermarks for Embedding-as-a-Service Copyright ProtectionAnudeex Shetty, Yue Teng, Ke He, Qiongkai XuACL 2024
- Lurking Malice in the Cloud: Understanding and Detecting Cloud Repository as a Malicious ServiceXiaojing Liao, Sumayah A. Alrwais, Kan Yuan, Luyi Xing 等CCS 2016 · 被引用 16 次
