首页> 外文学位 >A Comprehensive Approach to Undermining Search Result Poisoning.
【24h】

A Comprehensive Approach to Undermining Search Result Poisoning.

机译:破坏搜索结果中毒的一种综合方法。

获取原文
获取原文并翻译 | 示例

摘要

Black hat search engine optimization (SEO), the practice of manipulating search results, has long been used by attackers to abuse search engines. In one such instance, search result poisoning, attackers siphon off large volumes of user traffic from organic search through organized efforts called SEO campaigns, and monetize the resulting traffic through scams ranging from sales of illicit goods to malware distributions. Entire ecosystems exist, each consisting of multiple campaigns poisoning on behalf of the same type of funding scam (e.g., counterfeit luxury goods).;These campaigns are supported by two low-level mechanisms: poisoned search results (PSRs) and an SEO botnet. Disguised as a typical search result, PSRs in reality entrap unsuspecting users and direct them to scams. To prolifically generate PSRs, campaigns use an SEO botnet of compromised sites.;Although interventions designed to disrupt search poisoning exist (e.g., demoting PSRs, seizing domain names), they tend to treat individual symptoms rather than address root causes. Thus, these reactive approaches are expensive and offer marginal benefit, leading to impractical and limited defenses.;In this dissertation, I present a framework to understand and address the root causes of search result poisoning. In support, I analyze search poisoning from three perspectives: PSRs, SEO botnets, and an ecosystem. Additionally, I synthesize insights acquired while examining lower-level mechanisms (PSRs, SEO botnets) into a comprehensive understanding capable of impacting the attacker's high level operation -- their SEO campaign.;From the point-of-view of PSRs, I explore modern cloaking to characterize the role of this black hat SEO technique in supporting PSRs. Then, by infiltrating an SEO botnet, I characterize the composition of an SEO botnet and how attackers generate PSRs at large scale. Lastly, I evaluate the effectiveness of current interventions in disrupting SEO campaigns found in the counterfeit luxury goods ecosystem.;In the end, I present a "bottom-up" approach to understanding and addressing the root causes of search result poisoning. Using a framework constructed from my analyses of lower-level mechanisms, I provide a methodology for identifying campaigns and their infrastructure that provides the improved targeting required for more robust, comprehensive, and systematic intervention.
机译:黑帽搜索引擎优化(SEO)是操纵搜索结果的一种做法,攻击者长期以来一直在滥用搜索引擎。在一种这样的情况下,即搜索结果中毒,攻击者通过有组织的称为SEO活动的努力从有机搜索中窃取了大量用户流量,并通过从非法商品销售到恶意软件分发的骗局将所得流量货币化。存在整个生态系统,每个生态系统由代表同一类型的资金骗局(例如假冒奢侈品)的多个活动中毒组成;这些活动由两个低级机制支持:中毒搜索结果(PSR)和SEO僵尸网络。伪装成典型的搜索结果,实际上,PSR会诱骗毫无戒心的用户,并将他们引导到骗局。为了有效地生成PSR,竞选活动使用了受感染网站的SEO僵尸网络。;尽管存在旨在破坏搜索中毒的干预措施(例如,降级PSR,抢占域名),但它们倾向于对待单个症状而不是解决根本原因。因此,这些反应性方法昂贵且提供了边际收益,导致了不切实际和有限的防御。;在本文中,我提出了一个框架来理解和解决搜索结果中毒的根本原因。作为支持,我从三个角度分析了搜索中毒:PSR,SEO僵尸网络和生态系统。此外,我将检查低级机制(PSR,SEO僵尸网络)时获得的见解进行综合,以形成能够影响攻击者的高级操作的全面理解-他们的SEO活动。;从PSR的角度出发,我探索了现代伪装以表征此黑帽SEO技术在支持PSR中的作用。然后,通过渗透SEO僵尸网络,我描述了SEO僵尸网络的组成以及攻击者如何大规模生成PSR。最后,我评估了当前干预措施对破坏假冒奢侈品生态系统中的SEO活动的有效性。最后,我提出了一种“自下而上”的方法来理解和解决搜索结果中毒的根本原因。使用从我对低级机制的分析中构建的框架,我提供了一种用于识别运动及其基础结构的方法,该方法可以提供更强大,更全面,系统地进行干预所需的改进目标。

著录项

  • 作者

    Wang, David Yi-Chen.;

  • 作者单位

    University of California, San Diego.;

  • 授予单位 University of California, San Diego.;
  • 学科 Computer Science.
  • 学位 Ph.D.
  • 年度 2014
  • 页码 162 p.
  • 总页数 162
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

  • 入库时间 2022-08-17 11:53:59

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号