Author_Institution :
Dept. of Comput. Eng., King Monkut´´s Univ. of Technol., Bangkok, Thailand
Abstract :
Online Social Network (OSN), such as Facebook, Linkedln, Twitter, is today´s one of the most popular platform on the internet where millions of users sign on daily to share personal information with friends and colleagues. On many of these services, users are able to share photos, videos, stories, send and receive messages, locations and play games. However, many OSNs have weak user to user authentication mechanism, mostly based on information such as displayed name, photo, and a set of common social links. This result in easy to exploit identity cloning attack to establish fake social link. In this paper, we develop a model to exploit OSN weak trust model and maintain authenticity of the fake online identity established by identity cloning attack to harvest more private information, and discuss how the attack can be thwarted and avoided by the users and developers of OSN. We develop an attack methodology to take advantage of a cloned fake profiles and carry authentic conversation between the exploited users. We also experiment with injecting various fake messages to harvest more information. Our experimental results show that the attack is feasible.
Keywords :
Internet; security of data; social networking (online); Facebook; Linkedln; OSN; Twitter; authentication mechanism; automating persistent identity clone model; online social network; personal information; private information; Cloning; Facebook; Monitoring; Prototypes; Relays; Twitter; Identity; Privacy; Social Network; Trust;
Conference_Titel :
Trust, Security and Privacy in Computing and Communications (TrustCom), 2011 IEEE 10th International Conference on