论文标题

变色龙攻击:在线社交媒体中操纵内容显示

The Chameleon Attack: Manipulating Content Display in Online Social Media

论文作者

Elyashar, Aviad, Uziel, Sagi, Paradise, Abigail, Puzis, Rami

论文摘要

在线社交网络(OSN)无处不在,吸引了世界各地数百万用户。作为流行的通信媒体OSN,在各种网络攻击中被利用。在本文中,我们讨论了变色龙攻击技术,这是一种新型的基于OSN的骗局,恶意帖子和个人资料会改变向OSN用户显示的方式,以在攻击之前隐藏或避免检测。使用这种技术,例如,对手可以在要检查时掩盖真实内容来避免审查制度;获得社会资本以促进新内容的同时,同时背负了一个趋势;通过欺骗受害者的样子,转发或评论他通常不会在OSN中没有任何迹象表明他通常不会做的信息,从而造成尴尬和严重的声誉损害。通过封闭的Facebook体育迷进行的实验表明,(1)Chameleon页面可以通过更改显示帖子的显示方式,并且(2)主持人不会区分常规页面和变色龙页面。我们列出了促进变色龙攻击的OSN弱点,并提出了一套缓解指南。

Online social networks (OSNs) are ubiquitous attracting millions of users all over the world. Being a popular communication media OSNs are exploited in a variety of cyber attacks. In this article, we discuss the Chameleon attack technique, a new type of OSN-based trickery where malicious posts and profiles change the way they are displayed to OSN users to conceal themselves before the attack or avoid detection. Using this technique, adversaries can, for example, avoid censorship by concealing true content when it is about to be inspected; acquire social capital to promote new content while piggybacking a trending one; cause embarrassment and serious reputation damage by tricking a victim to like, retweet, or comment a message that he wouldn't normally do without any indication for the trickery within the OSN. An experiment performed with closed Facebook groups of sports fans shows that (1) Chameleon pages can pass by the moderation filters by changing the way their posts are displayed and (2) moderators do not distinguish between regular and Chameleon pages. We list the OSN weaknesses that facilitate the Chameleon attack and propose a set of mitigation guidelines.

扫码加入交流群

加入微信交流群

微信交流群二维码

扫码加入学术交流群,获取更多资源