Skip to main content
QUICK REVIEW

[論文レビュー] Call Me MayBe: Understanding Nature and Risks of Sharing Mobile Numbers on Online Social Networks

Prachi Jain, Ponnurangam Kumaraguru|arXiv (Cornell University)|Dec 12, 2013
Privacy, Security, and Data Protection参考文献 27被引用数 6
ひとこと要約

本研究は、Twitter や Facebook などのオンラインソーシャルネットワーク(OSN)におけるインド発のモバイル番号共有の普及状況、動機、およびリスクを調査している。76,347件の公開投稿番号を用いた分析から、大多数のユーザーは緊急要請、マーケティング、介護サービスなど、個人的でない理由で番号を共有していることが判明した。一方、自らの番号を公開していることに気づいていなかったユーザーのうち38.3%は、自分自身が番号を投稿していた。研究では、データの統合によって暴露された番号が、選挙登録証やBBMピンなどの機微な個人情報と関連付けることができることを示しており、2,492人のユーザーにIVRを用いてリスクを伝える試みが行われ、広範な無知状態と、ボットによる詐欺的電話(vishing)攻撃へのさらなるリスクが明らかになった。

ABSTRACT

There is a great concern about the potential for people to leak private information on OSNs, but few quantitative studies on this. This research explores the activity of sharing mobile numbers on OSNs, via public profiles and posts. We attempt to understand the characteristics and risks of mobile numbers sharing behaviour on OSNs and focus on Indian mobile numbers. We collected 76,347 unique mobile numbers posted by 85905 users on Twitter and Facebook and analysed 2997 numbers, prefixed with +91. We observed, most users shared their own mobile numbers to spread urgent information; and to market products and escort business. Fewer female users shared mobile numbers on OSNs. Users utilized other OSN platforms and third party applications like Twitterfeed, to post mobile numbers on multiple OSNs. In contrast to the user's perception of numbers spreading quickly on OSN, we observed that except for emergency, most numbers did not diffuse deep. To assess risks associated with mobile numbers exposed on OSNs, we used numbers to gain sensitive information about their owners (e.g. name, Voter ID) by collating publicly available data from OSNs, Truecaller, OCEAN. On using the numbers on WhatApp, we obtained a myriad of sensitive details (relationship status, BBM pins) of the number owner. We communicated the observed risks to the owners by calling. Few users were surprised to know about the online presence of their number, while a few others intentionally posted it online for business purposes. We observed, 38.3% of users who were unaware of the online presence of their number have posted their number themselves on the social network. With these observations, we highlight that there is a need to monitor leakage of mobile numbers via profile and public posts. To the best of our knowledge, this is the first exploratory study to critically investigate the exposure of Indian mobile numbers on OSNs.

研究の動機と目的

  • インドのOSN(例:Twitter や Facebook)におけるモバイル番号共有の性質と動機を理解すること。
  • 公開されたモバイル番号に伴うプライバシーリスク、特に身元の再識別およびボットによる詐欺的電話(vishing)攻撃のリスクを評価すること。
  • ユーザーが自身のモバイル番号のオンライン存在にどれほど気づいているかを評価し、IVRベースのアプローチを用いてリスクを伝えること。
  • 番号共有における技術的および行動的パターン(例:集約ツールの使用、複数プラットフォームへの拡散)を同定すること。
  • モバイル番号の意図しない公開を防ぐための、ユーザーの意識向上と技術的対策の強化を提言すること。

提案手法

  • キーワードベースのクローリングと検証技術を用いて、公開されたTwitterおよびFacebook投稿から76,347件のインド発モバイル番号を収集した。
  • +91で始まる2,997件の番号を、OSN、Truecaller、OCEAN(オープン政府データ)、WhatsApp などの複数のデータソースを用いて検証した。
  • LIWCを用いた文脈およびジャンル分析と手動タグ付けを組み合わせ、番号共有の動機(例:緊急要請、マーケティング、個人的)を分類した。
  • Twitterにおける番号の拡散ネットワークを構築し、カバレッジと拡散の深さを評価した。
  • FreeSWITCH と Java を用いたIVRシステムを実装し、2,492人のユーザーにリスクを伝えるための連絡を実施した。
  • OSN、Truecaller、オープン政府リポジトリからの公開データを統合し、モバイル番号と機微な個人情報(例:選挙登録証、BBMピン)を関連付ける実験を実施した。

実験結果

リサーチクエスチョン

  • RQ1インドのユーザーがオンラインソーシャルネットワークで自身のモバイル番号を共有する主な動機は何ですか?
  • RQ2モバイル番号はOSN内でどの程度拡散され、状況(例:緊急要請、マーケティング)によってその拡散の度合いはどのように変化しますか?
  • RQ3公開されたモバイル番号が露出しているユーザーはどの程度脆弱であり、これらの番号を用いてどのような機微な個人情報が再識別可能ですか?
  • RQ4ユーザーは自身のモバイル番号がオンラインに存在することをどの程度認識しており、リスク通信に対してどのように反応しますか?
  • RQ5複数のプラットフォームやツールを通じた番号共有における技術的および行動的パターンはどのようなものですか?

主な発見

  • 自らの番号がオンラインに存在することに気づいていなかったユーザーのうち38.3%が、自分自身が番号を投稿していたことから、ユーザーの認識のギャップが顕著であることが示された。
  • 大多数の番号共有は個人的でない動機によるものであり、緊急要請が38.3%、マーケティング(例:ITサービス、占い)が25.6%、介護サービスが12.4%を占めた。
  • 個人的動機での共有は14.7%にとどまり、文脈に特化したキーワードが不足しているため、区別が困難な場合が多かった。
  • OSN、Truecaller、オープン政府リポジトリからのデータ統合によって、選挙登録証番号やBBMピンなどの機微な個人情報がモバイル番号と成功裏に関連付けられた。
  • IVRによるアプローチの結果、多くのユーザーが自身の番号がオンラインに存在することを驚いており、一部のユーザーはビジネス宣伝の目的で意図的に投稿していたと認めている。
  • 特にマーケターらはスパムや偽のリクエスト(例:Textastrophe経由)の標的となっており、意図的な共有であっても望ましくない結果を招く可能性があることが明らかになった。

より良い研究を、今すぐ始めましょう

論文の読解から最終レビューまで、研究時間を劇的に削減しましょう。

クレジットカード登録不要

このレビューはAIが作成し、人間の編集者が確認しました。