首页> 外文期刊>Journal of web engineering >Automatic Detection and Analysis of the 'Game Hack' Scam
【24h】

Automatic Detection and Analysis of the 'Game Hack' Scam

机译:“游戏黑客”诈骗自动检测与分析

获取原文
获取原文并翻译 | 示例
       

摘要

The "Game Hack" Scam (GHS) is a mostly unreported cyberattack in which attackers attempt to convince victims that they will be provided with free, unlimited "resources" or other advantages for their favorite game. The endgame of the scammers ranges from monetizing for themselves the victims time and resources by having them click through endless "surveys", filing out "market research" forms, etc., to collecting personal information, getting the victims to subscribe to questionable services, up to installing questionable executable files on their machines. Other scams such as the "Technical Support Scam", the "Survey Scam", and the "Romance Scam" have been analyzed before but to the best of our knowledge, GHS has not been well studied so far and is indeed mostly unknown.In this paper, our aim is to investigate and gain more knowledge on this type of scam by following a data-driven approach; we formulate GHS-related search queries, and used multiple search engines to collect data about the websites to which GHS victims are directed when they search online for various game hacks and tricks. We analyze the collected data to provide new insight into GHS and research the extent of this scam. We show that despite its low profile, the click traffic generated by the scam is in the hundreds of millions. We also show that GHS attackers use social media, streaming sites, blogs, and even unrelated sites such as change.org or jeuxvideo.com to carry out their attacks and reach a large number of victims.Our data collection spans a year; in that time, we uncovered 65,905 different GHS URLs, mapped onto over 5,900 unique domains. We were able to link attacks to attackers and found that they routinely target a vast array of games. Furthermore, we find that GHS instances are on the rise, and so is the number of victims. Our low-end estimation is that these attacks have been clicked at least 150 million times in the last five years. Finally, in keeping with similar large-scale scam studies, we find that the current public blacklists are inadequate and suggest that our method is more effective at detecting these attacks.
机译:“游戏黑客”诈骗(GHS)是一个大多数未报告的网络攻击,其中攻击者试图说服受害者,他们将被免费提供,无限制的“资源”或其他优势的游戏。诈骗者的最终名称通过让他们点击无尽的“调查”,提交“市场研究”形式等,以收取“市场研究”形式等,以收集个人信息,让受害者订阅有质疑的服务,最终在其计算机上安装可疑的可执行文件。其他骗局,如“技术支持诈骗”,“调查诈骗”和“浪漫诈骗”和“浪漫诈骗”在我们的知识中已经分析,但到目前为止,GHS还没有很好地研究,并且确实大多是未知的。本文,我们的目的是通过遵循数据驱动方法来调查和提高对这种诈骗的了解;我们制定与GHS相关的搜索查询,并使用多个搜索引擎收集有关在线搜索各种游戏和技巧时针对的网站的数据。我们分析所收集的数据,为GHS提供新的洞察力,并研究该骗局的范围。我们表明,尽管它的较低,骗局生成的点击流量在数百万数亿中。我们还表明,GHS攻击者使用社交媒体,流媒体网站,博客甚至不相关的网站,如change.org或jeuxvideo.com,以实现他们的攻击并达到大量受害者。每年的数据收集跨度;在此时间,我们发现了65,905个不同的GHS URL,映射到超过5,900个独特的域。我们能够将攻击与攻击者联系起来,发现他们经常瞄准大量游戏。此外,我们发现GHS实例正在上升,因此受害者的数量也是如此。我们的低端估计是,在过去五年中,这些攻击已被点击至少有1.5亿倍。最后,在保持类似的大规模诈骗研究中,我们发现目前的公共黑名单不充分,并表明我们的方法在检测这些攻击方面更有效。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号