Detecting Organization-Targeted Socialbots by Monitoring Social Network Profiles

被引:2
作者
Paradise, Abigail [1 ]
Shabtai, Asaf [1 ]
Puzis, Rami [1 ]
机构
[1] Ben Gurion Univ Negev, Dept Software & Informat Syst Engn, Beer Sheva, Israel
关键词
Social network; Social network security; Reconnaissance; Socialbots; ATTACKS; DEFENSE; GRAPH;
D O I
10.1007/s11067-018-9406-1
中图分类号
C93 [管理学]; O22 [运筹学];
学科分类号
070105 ; 12 ; 1201 ; 1202 ; 120202 ;
摘要
Advanced attackers use online social networks in order to extract useful information about targeted organizations, including the names of the organization's members, their connections, affiliations, positions, etc. Using artificial profiles (socialbots) attackers connect to real members of the organization, thus establishing a foothold inside the organization and greatly increasing the amount of sensitive information they can collect. The connection methods used by attackers are versatile, ranging from random friend requests to carefully crafted, manually operated social engineering attempts. In this paper we provide an analysis of the cost-effectiveness of strategies used to monitor organizational social networks and detect the socialbots that penetrate a target organization. These strategies were evaluated against heterogeneous attackers with different levels of knowledge about the monitoring strategies, using simulation on actual social network data and data from a real scenario of socialbot intrusion. The results demonstrate the efficacy of the monitoring strategies in detecting less sophisticated attackers and slowing down attackers that deliberately avoid the monitored profiles.
引用
收藏
页码:731 / 761
页数:31
相关论文
共 67 条
[1]   Measuring the degree of corporate social media use [J].
Aichner, Thomas ;
Jacob, Frank .
INTERNATIONAL JOURNAL OF MARKET RESEARCH, 2015, 57 (02) :257-275
[2]  
Aiello L.M., 2012, Links, V697, P1
[3]  
An B., 2012, ANN ARBOR, V1001, P48109
[4]  
[Anonymous], INTRUDER WELCOME FRI
[5]  
[Anonymous], AXIOMS CENTRALITY SC
[6]  
[Anonymous], 2006, 12 INT S DYN GAM APP
[7]  
[Anonymous], 2012, ICDM
[8]  
[Anonymous], 2009, NDSS
[9]  
[Anonymous], 2008, P INT C COMP SUPP CO
[10]  
[Anonymous], CEAS