首页> 外文期刊>Neurocomputing >Payment-Guard: Detecting fraudulent in-app purchases in iOS system
【24h】

Payment-Guard: Detecting fraudulent in-app purchases in iOS system

机译:付款 - 保护 - 检测IOS系统中的欺诈性内部购买

获取原文
获取原文并翻译 | 示例

摘要

As a successful business model, "in-app purchase" has been adopted by massive applications (Apps) gradually. Users can purchase various virtual goods in different kinds of Apps, such as the license to download movies or songs. In-app purchase helps App operators gain huge income, and meanwhile provides users with flexibility in using Apps. Recently, iOS Apps have suffered the attack of fraudulent purchase. Attackers leverage the vulnerabilities in iOS payment system to purchase virtual goods at zero or low cost. More seriously, unscrupulous attackers solicit customers publicly and provide purchasing services, which has caused huge financial loss to business entities. It becomes of great importance to detect the fraudulent in-app purchases in iOS Apps, and then take measures such as confiscating goods to minimize profit loss. In this paper, we propose a system called Payment-Guard to achieve this objective, which designs various features to characterize a purchase from four perspectives including App account behavior, device behavior, IP behavior and union behavior of (App account, device, IP), then conducts detection based on the features. We perform comprehensive experiments based on data collected from "Honor of Kings" App, which is one of the most famous MOBA games in China and allows players to recharge App accounts for virtual currency. Experimental results demonstrated that Payment-Guard can detect 92.2% malicious in-app purchases and with only 2% false positive rate. (C) 2020 Elsevier B.V. All rights reserved.
机译:作为一个成功的商业模式,大规模应用程序(应用程序)采用了“应用程序购买”逐步采用。用户可以在不同类型的应用程序中购买各种虚拟商品,例如下载电影或歌曲的许可证。应用程序内购买有助于应用程序运营商获得巨额收入,同时为用户提供使用应用程序的灵活性。最近,iOS应用程序遭受了欺诈性购买的攻击。攻击者利用IOS支付系统的漏洞,以零或低成本购买虚拟商品。更认真地,肆无忌惮的攻击者公开招揽客户并提供购买服务,这导致了商业实体的巨额财务流失。在iOS应用中检测欺诈性的应用程序购买是非常重视,然后采取措施,例如没收货物以尽量减少损益。在本文中,我们提出了一个称为支付保护的系统,以实现这一目标,该目标设计了各种功能,以从包含应用帐户行为,设备行为,IP行为和联盟行为(App帐户,设备,IP)的四个角度来表征购买的各种功能然后,基于特征进行检测。我们根据“国王”应用程序所收集的数据进行全面的实验,该应用是中国最着名的Moba游戏之一,并允许玩家为虚拟货币充值应用帐户。实验结果表明,支付后卫可以检测92.2%的恶意应用内购买,只有2%的假阳性率。 (c)2020 Elsevier B.v.保留所有权利。

著录项

  • 来源
    《Neurocomputing》 |2021年第21期|263-276|共14页
  • 作者单位

    Xi An Jiao Tong Univ Fac Elect & Informat Engn Minist Educ Key Lab Intelligent Networks & Network Secur Xian 710049 Shaanxi Peoples R China;

    Xi An Jiao Tong Univ Fac Elect & Informat Engn Minist Educ Key Lab Intelligent Networks & Network Secur Xian 710049 Shaanxi Peoples R China;

    Xi An Jiao Tong Univ Fac Elect & Informat Engn Minist Educ Key Lab Intelligent Networks & Network Secur Xian 710049 Shaanxi Peoples R China;

    Xi An Jiao Tong Univ Fac Elect & Informat Engn Minist Educ Key Lab Intelligent Networks & Network Secur Xian 710049 Shaanxi Peoples R China;

    Natl Comp network Emergency Response tech Team Beijing Peoples R China;

    Xi An Jiao Tong Univ Fac Elect & Informat Engn Minist Educ Key Lab Intelligent Networks & Network Secur Xian 710049 Shaanxi Peoples R China;

  • 收录信息 美国《科学引文索引》(SCI);美国《工程索引》(EI);
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

    In-app purchase; Fraud detection; iOS payment vulnerability; Micropayment security; Learning system;

    机译:应用内购买;欺诈检测;iOS支付漏洞;微挖掘安全;学习系统;

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号