surveying the landscape of threats facing users in the social web

28
Surveying The Landscape of Threats Facing Users In The Social Web Steve Webb, Ph.D. Emory Guest Lecture April 16, 2009

Upload: rhian

Post on 06-Jan-2016

26 views

Category:

Documents


3 download

DESCRIPTION

Surveying The Landscape of Threats Facing Users In The Social Web. Steve Webb, Ph.D. Emory Guest Lecture April 16, 2009. Introduction. The World Wide Web is evolving into a “social Web” World’s top Web destinations are now dominated by social environments. Introduction (cont.). - PowerPoint PPT Presentation

TRANSCRIPT

Page 1: Surveying The Landscape of Threats Facing Users In The Social Web

Surveying The Landscape of Threats Facing Users In The Social Web

Steve Webb, Ph.D.

Emory Guest Lecture

April 16, 2009

Page 2: Surveying The Landscape of Threats Facing Users In The Social Web

Introduction

The World Wide Web is evolving into a “social Web”

World’s top Web destinations are now dominated by social environments

Page 3: Surveying The Landscape of Threats Facing Users In The Social Web

Introduction (cont.)

New and exciting ways to connect with others

Wildly popular 200 million active

Facebook users

100 million YouTube videos

1.5 million SecondLife residents

Page 4: Surveying The Landscape of Threats Facing Users In The Social Web

Introduction (cont.)

And as always... attackers love crashing big parties

Threat categories Traditional Attacks

Socially Enhanced Attacks

Social Web-specific Attacks

Let’s take a closer look…

Page 5: Surveying The Landscape of Threats Facing Users In The Social Web

Traditional Attacks

Social environment characteristics Large and very distributed

Numerous communication mechanisms

Relatively naïve user bases

That seems like a paradise for attackers…

Page 6: Surveying The Landscape of Threats Facing Users In The Social Web

Malware Propagation

Worms Samy Mikeyy

Spyware Ad networks Rogue apps

Adware Zango

Page 7: Surveying The Landscape of Threats Facing Users In The Social Web

Spam

Comment spam

Bulletin spam

Message spam

Page 8: Surveying The Landscape of Threats Facing Users In The Social Web

Phishing

Fraudulent login display

Grants access to resources outside of the community

Compromised accounts used to launch additional attacks

Page 9: Surveying The Landscape of Threats Facing Users In The Social Web

Research Challenges

Same problems… new and more challenging environment

More information available… but it’s a double-edged sword

Page 10: Surveying The Landscape of Threats Facing Users In The Social Web

Research Challenges

How can we adapt existing techniques to these environments?

What new approaches are necessary?

Page 11: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks

Obviously, social environments are vulnerable to traditional attacks

But that’s just the beginning…

Page 12: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

Key barrier for attackers has been private information

Generic attacks against the masses

Page 13: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

What if attackers knew private information about their victims?

Oh, wait! Isn’t that what social environments provide?!?!

Page 14: Surveying The Landscape of Threats Facing Users In The Social Web
Page 15: Surveying The Landscape of Threats Facing Users In The Social Web

What’s The Big Deal?

Name, Age, Gender, and Location Friends Relationship Status Interests and Favorite Things Education/Employment History Etc., Etc., Etc.

Page 16: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

ORIGINAL

From: Bellusci Thresa <[email protected]> Subject: Jessica Alba's hot scene

If your powder is damped and gun can't fire: We know the spark you need! http://yqazqvot.com/

Page 17: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

SOCIALLY ENHANCED

From: Li Xiong <[email protected]> Subject: Jessica Alba's hot scene

Steve,

Check out this link: http://yqazqvot.com/

-Li

Page 18: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

Scary, right?!

Not isolated to spamMalware

propagation and phishing attacks benefit too

Page 19: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

Page 20: Surveying The Landscape of Threats Facing Users In The Social Web

Socially Enhanced Attacks (cont.)

SOCIALLY ENHANCED

From: Li Xiong <[email protected]> Subject: Check out this auction…

Steve,

I think you might like this Kevin Smith auction… http://url.com/

-Li

Page 21: Surveying The Landscape of Threats Facing Users In The Social Web

Research Challenges

How can we protect users without killing the fun of these environments?

How do you identify a needle in a stack of needles?

Page 22: Surveying The Landscape of Threats Facing Users In The Social Web

Social Web-specific Attacks

Phishing revisitedQuestionably more

dangerous than “old school phishing”

Creates a new set of problems…

Page 23: Surveying The Landscape of Threats Facing Users In The Social Web

Social Identity Theft

“Bryan NEEDS HELP URGENTLY!!!”

Twitter fail

Page 24: Surveying The Landscape of Threats Facing Users In The Social Web

Fake Profiles

“Fakesters”

Impersonators

Thin line between fun and slander

Page 25: Surveying The Landscape of Threats Facing Users In The Social Web

Fake Profiles (cont.)

The next generation of spam

The next generation of malware propagation

Page 26: Surveying The Landscape of Threats Facing Users In The Social Web

Research Questions

How do we collect examples of these new attacks? Social Honeypots

(CEAS 2008)

More importantly, how do we protect users…

Page 27: Surveying The Landscape of Threats Facing Users In The Social Web

Purewire Trust Demo

http://www.purewiretrust.org

Page 28: Surveying The Landscape of Threats Facing Users In The Social Web

Questions