As a social platform with a large number of users, Weibo has attracted the attention of attackers because of its significant influence and openness. Attackers will utilize anomaly accounts for cybercrime. One of preserving social network security methods is detecting anomaly accounts. Based on attackers’ routine behavior and benign users’ behavior features, this paper proposes a method to detect compromised accounts. In this paper, we use six features to analyze users’ behaviors and propose the abnormal scores to evaluate the degree of violation. To verify the effectiveness of our method, the public Weibo dataset provided by Fudan University is used in the experiment and the results show that the precision of our method for detecting compromised accounts can achieve 97.5% when using the decision tree classifier.
社交网络[1] 被定义为基于 Web 的服务,这种服务允许用户进行如下操作:1)在系统内创建公开或半公开的个人资料;2)展示与其保有联系的用户列表;3)浏览或查看自己和他人的联系列表。随着 Web 技术的快速发展,社交网络成为人们生活、工作交流的重要平台。然而,社交网络为人们带来便利的同时也带来了安全隐患。微博作为国内用户数量较多、影响力较大的开放性社交网络,其中的异常账户占了不小的比例,攻击者会利用异常账户进行网络犯罪,因此维护微博环境变得极为重要。
发布时间特征为用户发布消息的确切时间。本文假设多数用户在一天中的某些相对固定的时间段内较为活跃,而在其他时间段内较为平静,如果用户在最不可能的时间发布消息,本文方法将其判定为异常。本文统计11 000个实验验本(详见2.1节)中用户在各个时间段内的消息总数, 得到用户活跃时间段的累积分布函数(cumulative distribution function,CDF)(图2)。本文将活跃时间段定义为:一个用户在这些时间段内发布消息的数量超过其一天中发布消息的总数量的一半。由图2可以看出,约75%的用户每天活跃的时间不大于7个小时,因此在下文的正常阈值设定中,我们选择用户最为活跃的7个时间段作为正常阈值。当一个用户在其活跃的时间段内发布消息,则认为是该行为是正常的;如果用户在其最不活跃的时间段内突然活跃,则认为其所发消息有一定的概率是异常的。
ELLISONN B. Social network sites: Definition, history, and scholarship[J]. Journal of Computer-Mediated Communication, 2007, 13(1): 210-230. DOI: 10.1111/j.1083-6101.2007.00393.x .
ZHANGY Q, LÜS Q, FAND. Anomaly detection in online social networks [J]. Chinese Journal of Computers,2015,38(10):2011-2027. DOI: 10.11987/SP.J.1016.2015.02011(Ch).
[4]
DAVISC A, VAROLO, FERRARAE, et al. BotOrNot: A system to evaluate social bots[C]// WWW’16 Companion Proceedings of the 25th International Conference Companion on World Wide Web. New York: ACM Press, 2016:273-274.
EGELEM, GIANLUCAS, CHIRSTOPHERK, et al. COMPA: Detecting Compromised Accounts on Social Networks [EB/OL]. [2019-03-02].
[9]
ADEWOLEK S, NOR B A, AMIRRUDINK, et al. Malicious accounts: Dark of the social networks [J]. Journal of Network and Computer Applications, 2017, 79(11): 41-67. DOI: 10.1016/j.jnca.2016.11.030 .
[10]
DINHS, AZEBAT, FORTINF, et al. Spam campaign detection, analysis, and investigation [J]. Digital Investigation, 2015, 12(1):12-21. DOI:10.1016/j.diin.2015.01.006 .
[11]
YUH F, KAMINSKYM, GIBBONSP B, et al. SybilGuard: Defending against Sybil attacks via social networks [J]. IEEE/ACM Transactions on Networking, 2008, 16(3): 576-589. DOI: 10.1109/TNET.2008.923723 .
[12]
WANGB H, ZHANGL, GONGN. Z. SybilSCAR: Sybil detection in online social networks via local rule based propagation [C]//IEEE INFOCOM 2017⁃IEEE Conference on Computer Communications. New York :IEEE Press, 2017:1-9.DOI:10.1109/infocom.2017.8057066 .
[13]
WANGB H, ZHANGL, GONGN Z. SybilBlind: Detecting fake users in online social networks without manual labels [C]//International Symposium on Research in Attacks, Intrusions, and Defenses (LNCS 11050). Heidelberg: Springer⁃Verlag, 2018: 228-249.DOI: 10.1007/978-3-030-00470-5_11 .
[14]
WANGB H, JIAJ, ZHANGL, et al. Structure-based Sybil detection in social networks via local rule-based propagation [J]. IEEE Transactions on Network Science and Engineering, 2019, 6(3): 523-537. DOI: 10.1109/TNSE.2018.2813672 .
[15]
GONGN Z, FRANKM, MITTALP. SybilBelief: A semi-supervised learning approach for structure-based Sybil detection [J]. IEEE Transactions on Information Forensics and Security, 2014, 9(6): 976-987. DOI: 10.1109/TIFS.2014.2316975 .
MOHDF, ABULAISHM. A hybrid approach for detecting automated spammers in Twitter [J]. IEEE Transactions on Information Forensics and Security, 2018, 13(11): 2707-2719. DOI: 10.1109/TIFS.2018.2825958 .
[18]
RUANX, WUZ, WANGH, et al. Profiling online social behaviors for compromised account detection[J]. IEEE Transactions on Information Forensics and Security, 2015, 11(1): 176-187. DOI: 10.1109/TIFS.2015.2482465 .
[19]
SEYLERD, LIL N, ZHAIC X. Identifying Compromised Accounts on Social Media Using Statistical Text Analysis [EB/OL]. [2019-03-02].
[20]
BENEVENUTOF, MAGNOG, RODRIGUEST, et al. Detecting spammers on Twitter[C]//Collaboration, Electronic Messaging, Anti⁃Abuse and Spam Conference. Berlin: Springer⁃Verlag, 2010: 55–65.DOI: 10.1.1.297.5340 .
[21]
YANGC, HARKREADERR, GUG. Empirical evaluation and new design for fighting evolving twitter spammers [J]. IEEE Transactions on Information Forensics and Security, 2013, 8(8): 1280-1293. DOI: 10.1109/TIFS.2013.2267732 .
[22]
EGELEM, STRINGHINIG, KRUEGELC, et al. Towards detecting compromised accounts on social networks [J]. IEEE Transactions on Dependable and Secure Computing, 2017, 14(4): 447-460. DOI: 10.1109/TDSC.2015.2479616 .
[23]
AMLESHWARAMA A, REDDYN, YADAVS, et al. Cats: Characterizing automation of Twitter spammers[C]//2013 Fifth International Conference on Communication Systems and Networks (COMSNETS). New York: IEEE Press, 2013: 1-10.DOI:/10.1109/COMSNETS.2013.6465541 .
[24]
STRINGHINIG, KRUEGELC, VIGNAG. Detecting spammers on social networks[C]//Proceedings of the 26th Annual Computer Security Applications Conference. New York: ACM Press, 2010: 1-9.DOI:10.1145/1920261.1920263 .
[25]
LEE S, KIMJ. WarningBird: Detecting Suspicious URLs in Twitter Stream [EB/OL]. [2019-02-01].
[26]
THOMASK, GRIERC, MAJ, et al. Design and evaluation of a real-time URL spam filtering service [C]//2011 IEEE Symposium on Security and Privacy. New York: IEEE Press, 2011: 447-462.DOI: 10.1109/SP.2011.25 .
[27]
THOMASK, LIF, GRIERC, et al. Consequences of connectivity: Characterizing account hijacking on Twitter[C]//Proceedings of the 2014 ACM SIGSAC Conference on Computer and Communications Security. New York: ACM Press, 2014: 489-500.DOI: 10.1145/2660267.2660282 .
[28]
LEE K, CAVERLEEJ, WEBBS. Uncovering social spammers: Social honeypots+ machine learning[C]//Proceedings of the 33rd International ACM SIGIR Conference on Research and Development in Information Retrieval. New York: ACM Press, 2010: 435-442.DOI:10.1145/1835449.1835522 .
[29]
GAOH, HUJ, WILSONC, et al. Detecting and characterizing social spam campaigns[C]//Proceedings of the 10th ACM SIGCOMM Conference on Internet Measurement. New York: ACM Press, 2010: 35-47.DOI:10.1145/1879141.1879147 .
[30]
GRIERC, THOMASK, PAXSONV, et al. @spam: The underground on 140 characters or less [C]//Proceedings of the 17th ACM Conference on Computer and Communications Security. New York: ACM Press, 2010: 27-37.DOI: 10.1145/1866307.1866311 .
[31]
GILKSW R, RICHARDSONS, SPIEGELHALTERD J. Introducing Markov Chain Monte Carlo [EB/OL]. [2019-04-01].
[32]
CHUZ, GIANVECHIOS, WANGH, et al. Who is tweeting on Twitter: Human, bot, or cyborg? [C]//Proceedings of the 26th Annual Computer Security Applications Conference. New York: ACM Press. DOI: 10.1145/1920261.1920265.