首页> 外文会议>Detection of intrusions and malware, and vulnerability assessment. >Reverse Social Engineering Attacks in Online Social Networks
【24h】

Reverse Social Engineering Attacks in Online Social Networks

机译:在线社交网络中的反向社会工程学攻击

获取原文
获取原文并翻译 | 示例

摘要

Social networks are some of the largest and fastest growing online services today. Facebook, for example, has been ranked as the second most visited site on the Internet, and has been reporting growth rates as high as 3% per week. One of the key features of social networks is the support they provide for finding new friends. For example, social network sites may try to automatically identify which users know each other in order to propose friendship recommendations. Clearly, most social network sites are critical with respect to user's security and privacy due to the large amount of information available on them, as well as their very large user base. Previous research has shown that users of online social networks tend to exhibit a higher degree of trust in friend requests and messages sent by other users. Even though the problem of unsolicited messages in social networks (i.e., spam) has already been studied in detail, to date, reverse social engineering attacks in social networks have not received any attention. In a reverse social engineering attack, the attacker does not initiate contact with the victim. Rather, the victim is tricked into contacting the attacker herself. As a result, a high degree of trust is established between the victim and the attacker as the victim is the entity that established the relationship. In this paper, we present the first user study on reverse social engineering attacks in social networks. That is, we discuss and show how attackers, in practice, can abuse some of the friend-finding features that online social networks provide with the aim of launching reverse social engineering attacks. Our results demonstrate that reverse social engineering attacks are feasible and effective in practice.
机译:社交网络是当今一些最大,增长最快的在线服务。例如,Facebook已被评为互联网上访问量第二大的网站,并且报告的增长率高达每周3%。社交网络的主要功能之一是它们为寻找新朋友提供的支持。例如,社交网站可以尝试自动识别哪些用户彼此认识,以便提出友谊推荐。显然,由于社交网络站点上可用的大量信息以及庞大的用户群,因此它们对于用户的安全性和隐私至关重要。先前的研究表明,在线社交网络的用户倾向于对其他用户发送的朋友请求和消息表现出更高的信任度。即使已经详细研究了社交网络中不请自来的消息(即垃圾邮件)问题,但迄今为止,社交网络中的反向社会工程学攻击尚未引起任何注意。在反向社会工程学攻击中,攻击者不会启动与受害者的联系。相反,受骗者被诱骗自己与攻击者联系。结果,由于受害者是建立关系的实体,因此在受害者和攻击者之间建立了高度信任。在本文中,我们提出了关于反向社交工程攻击在社交网络中的第一个用户研究。也就是说,我们讨论并显示了攻击者在实践中如何能够滥用在线社交网络提供的某些友情发现功能,以发起反向社交工程攻击。我们的结果表明,反向社会工程学攻击在实践中是可行和有效的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号