dissecting one click frauds

17
Dissecting One Click Frauds Authors: Nicolas Christin, Sally S. Yanagihara, Keisuke Kamataki Proceedings of the ACM CCS 2010 Reporter: Jing Chiu Advisor: Yuh-Jye Lee Email: [email protected] 111/06/2 0 1 Data Mining & Machine Learning Lab

Upload: elton

Post on 11-Jan-2016

39 views

Category:

Documents


0 download

DESCRIPTION

Dissecting One Click Frauds. Authors: Nicolas Christin, Sally S. Yanagihara, Keisuke Kamataki Proceedings of the ACM CCS 2010 Reporter: Jing Chiu Advisor: Yuh-Jye Lee Email: [email protected]. Outlines. Introduction One Click Fraud Data Collection Channel BBS - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Dissecting One Click Frauds

Dissecting One Click FraudsAuthors: Nicolas Christin, Sally S. Yanagihara, Keisuke KamatakiProceedings of the ACM CCS 2010Reporter: Jing ChiuAdvisor: Yuh-Jye LeeEmail: [email protected]

112/04/21 1Data Mining & Machine Learning Lab

Page 2: Dissecting One Click Frauds

Outlines• Introduction

▫ One Click Fraud• Data Collection

▫ Channel BBS▫ Koguma-neko Teikoku▫ Wan-Cli Zukan

• Data Analysis▫ Infrastructural loopholes▫ Grouping miscreants▫ Evidence of other illicit activities

• Economic Incentives▫ Cost-benefit analysis▫ Fraud profitability▫ Legal aspects▫ Field measurements

• Conclusions112/04/21 2Data Mining & Machine Learning Lab

Page 3: Dissecting One Click Frauds

•One Click Frauds

Introduction

112/04/21 Data Mining & Machine Learning Lab 3

Page 4: Dissecting One Click Frauds

•2 Channel BBS▫The largest bulletin board in Japan▫March 6, 2006 ~ October 26, 2009

•Koguma-neko Teikoku▫Privately owned website▫August 24, 2006 ~ August 14, 2009

•Wan-Cli Zukan▫Privately owned website▫September 6,2006 ~ October 26, 2009

Data Collection

112/04/21 Data Mining & Machine Learning Lab 4

Page 5: Dissecting One Click Frauds

•Data parsing•Extracted attributes•Store to MySQL database

Data Collection (cont.)

112/04/21 Data Mining & Machine Learning Lab 5

Page 6: Dissecting One Click Frauds

Data Collection (cont.)

112/04/21 Data Mining & Machine Learning Lab 6

Page 7: Dissecting One Click Frauds

• Infrastructural loopholes▫Phone numbers▫Bank▫DNS registrars▫DNS resellers

• Grouping miscreants▫Use undirected graph to represent the dataset▫Fraud distribution

• Evidence of other illicit activities▫Eight blacklisting services and Google Safe

Browsing

Data Analysis

112/04/21 Data Mining & Machine Learning Lab 7

Page 8: Dissecting One Click Frauds

•Cost-benefit analysis•Fraud profitability•Legal aspects•Field measurements

Economic Incentives

112/04/21 Data Mining & Machine Learning Lab 8

Page 9: Dissecting One Click Frauds

•Collect and analyze a corpus of over 2,000 reported One Click Fraud incidents

•Describe a number of potential vulnerabilities which be used for scam

•Shows an important reason for why scam flourish

Conclusions

112/04/21 Data Mining & Machine Learning Lab 9

Page 10: Dissecting One Click Frauds

•Questions?

Thanks for your attention

112/04/21 Data Mining & Machine Learning Lab 10

Page 11: Dissecting One Click Frauds

•Top 10 popular registrars vs. Top 11 in One Click Frauds

DNS Registrars

112/04/21 Data Mining & Machine Learning Lab 11

Page 12: Dissecting One Click Frauds

DNS Resellers

112/04/21 Data Mining & Machine Learning Lab 12

Page 13: Dissecting One Click Frauds

112/04/21 Data Mining & Machine Learning Lab 13

Page 14: Dissecting One Click Frauds

Fraud Distribution

112/04/21 Data Mining & Machine Learning Lab 14

Page 15: Dissecting One Click Frauds

Evidence of other illicit activities

112/04/21 Data Mining & Machine Learning Lab 15

Page 16: Dissecting One Click Frauds

Ten most common amounts of money requested

112/04/21 Data Mining & Machine Learning Lab 16

Page 17: Dissecting One Click Frauds

Press reports of One Click Fraud arrests

112/04/21 Data Mining & Machine Learning Lab 17