• DocumentCode
    3423064
  • Title

    Analysis and Detection of Modern Spam Techniques on Social Networking Sites

  • Author

    Krishna Chaitanya, T. ; Ponnapalli, H. ; Herts, D. ; Pablo, Juan

  • Author_Institution
    Security & Privacy Res. Lab., Infosys Labs. Infosys Ltd., Hyderabad, India
  • fYear
    2012
  • fDate
    12-15 Dec. 2012
  • Firstpage
    147
  • Lastpage
    152
  • Abstract
    The modern Web has become a collaboration and communications platform with the advent of social networks. Apart from attracting millions of users, the popularity of social networking communities has also attracted spammers who can abuse and misuse the rich information in these sites using sophisticated attack techniques. In this paper we have described four popular modern techniques used by attackers to spam social networking sites: clickjacking [1], malicious browser extensions via drive-by-downloads [2], URL shorteners [3] and socially engineered script injection [4]. We have analyzed click-jacking and malicious browser extensions in detail, evaluating existing solutions to detect/prevent them. We observed that the existing solutions for clickjacking fail in some common use case scenarios. Therefore, we proposed enhancements that help detecting clickjacking attacks in those failed scenarios. We also proposed a declarative security policy to prevent malicious browser extension attacks. We implemented chrome extensions to validate both of our proposals in a test bed social network, which we have setup using an open source social networking engine. We believe our proposals are helpful to strengthen the security of social networks in general and the Web platform as a whole.
  • Keywords
    Internet; invasive software; online front-ends; public domain software; search engines; social networking (online); URL shortener attacks; chrome extensions; clickjacking attack detection; declarative security policy; drive-by-downloads; malicious browser extension attack prevention; open source social networking community engine; social networking sites; socially engineered script injection attacks; spam technique analysis; spam technique detection; test bed social network security; Browsers; Facebook; Logic gates; Proposals; Security; Web pages; attacks; browsers; clickjacking; drive-by-downloads; javascript; security; social networking sites; spam; web 2.0;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Services in Emerging Markets (ICSEM), 2012 Third International Conference on
  • Conference_Location
    Mysore
  • Print_ISBN
    978-1-4673-5729-6
  • Type

    conf

  • DOI
    10.1109/ICSEM.2012.28
  • Filename
    6468192