Web

Phony Twitter Profiles Aim to Outwit Spammers

(Page 2 of 2)

  • Friday, July 9, 2010
  • By Tom Simonite

Spam and phishing attacks delivered over social networks are a growing problem, says Don DeBolt, director of threat research for IT software firm CA Technologies. For example, a phishing scam operating over Twitter recently stole the iTunes accounts of some users. "People immediately trust these applications because it is how they communicate with friends," DeBolt explains. "Because people are sending much less text than an e-mail, and URL shorteners are often used, it is harder for people to realize a message may not be real."

DeBolt's team maintains honeypot profiles of its own, and monitors them manually to look for new spammer tactics. "We have to take great care, though, in curating them as research profiles that don't impersonate a real person," he says.

The fact that social network honeypots must be part of a community is a fundamental difference from the conventional approach, says Azer Bestavros, a networking specialist at Boston University who has, in the past, worked on analyzing blog spam. A honeypot computer on a network is typically allocated to "dark" address space so that they would never legitimately be contacted by another machine.

"Other users could consider our honeypot a real person," Lee acknowledges. "But we do not have friends or contact other people, and on Twitter our profiles posted random messages so a normal user would not think to contact us."

Some messages and friend requests sent to a social honeypot may be from legitimate users, so information collected from them needs to be treated carefully, says Bestavros. Lee and colleagues are experimenting with varying the output and demographic characteristics of their honeypots to find out what most attracts spammers--for example, varying the dummy user's age and location, or the frequency of their updates. "Most of the spammers present themselves as college-age females," says Lee. Data from MySpace honeypots shows that most claim to be located in California, and so far it seems that college-age males are the preferred target.

Lee and colleagues are also interested in trying the approach on the world's largest social network: Facebook. "It is a more private network, but if we were able to get permission from them it would be interesting to try it there," he says.

Print

Related Articles

For Sale: Thousands of Hacked Twitter Accounts

Russian cybercriminal forums offer batches of 1,000 Twitter accounts for less than $200.

Spammers Turn to Social Networks

They get results by exploiting a social network's trusting environment.

Mapping the Malicious Web

Analyzing the connections between sites could help spot Web attacks.

Close Comments

To comment, please sign in or register

Forgot my password

GeoNomad

1 Comment

  • 556 Days Ago
  • 08/06/2010

Honeypot classified as scammer

It is interesting to note from the lists the honeypot account has been added to (http://twitter.com/tayBourne/lists/memberships) that another bot has classified the account as a scammer: scam-tweeting-accounts2

Presumably the random tweets look like scam spam to bots with an algorithm based on content rather than friendship links.

Reply

Advertisement

MAGAZINE

Can We Build Tomorrow's Breakthroughs?

Manufacturing in the United States is in trouble. That's bad news not just for the country's economy but for the future of innovation.

Videos

A Social-Media Decoder

More

Advertisement

Technology Review Lists

TR50

Our list of the 50 most innovative companies, including the following:

Siemens

Calxeda

Goldwind Science and Technology

Geron

More

Advertisement

Facebook

Advertisement