Title :
Analysis and Detection of Modern Spam Techniques on Social Networking Sites
Author :
Krishna Chaitanya, T. ; Ponnapalli, H. ; Herts, D. ; Pablo, Juan
Author_Institution :
Security & Privacy Res. Lab., Infosys Labs. Infosys Ltd., Hyderabad, India
Abstract :
The modern Web has become a collaboration and communications platform with the advent of social networks. Apart from attracting millions of users, the popularity of social networking communities has also attracted spammers who can abuse and misuse the rich information in these sites using sophisticated attack techniques. In this paper we have described four popular modern techniques used by attackers to spam social networking sites: clickjacking [1], malicious browser extensions via drive-by-downloads [2], URL shorteners [3] and socially engineered script injection [4]. We have analyzed click-jacking and malicious browser extensions in detail, evaluating existing solutions to detect/prevent them. We observed that the existing solutions for clickjacking fail in some common use case scenarios. Therefore, we proposed enhancements that help detecting clickjacking attacks in those failed scenarios. We also proposed a declarative security policy to prevent malicious browser extension attacks. We implemented chrome extensions to validate both of our proposals in a test bed social network, which we have setup using an open source social networking engine. We believe our proposals are helpful to strengthen the security of social networks in general and the Web platform as a whole.
Keywords :
Internet; invasive software; online front-ends; public domain software; search engines; social networking (online); URL shortener attacks; chrome extensions; clickjacking attack detection; declarative security policy; drive-by-downloads; malicious browser extension attack prevention; open source social networking community engine; social networking sites; socially engineered script injection attacks; spam technique analysis; spam technique detection; test bed social network security; Browsers; Facebook; Logic gates; Proposals; Security; Web pages; attacks; browsers; clickjacking; drive-by-downloads; javascript; security; social networking sites; spam; web 2.0;
Conference_Titel :
Services in Emerging Markets (ICSEM), 2012 Third International Conference on
Conference_Location :
Mysore
Print_ISBN :
978-1-4673-5729-6
DOI :
10.1109/ICSEM.2012.28