Skip to main content
QUICK REVIEW

[논문 리뷰] Abusing Phone Numbers and Cross-Application Features for Crafting Targeted Attacks

Srishti Gupta, Payas Gupta|arXiv (Cornell University)|2015. 12. 23.
Spam and Phishing Detection참고 문헌 24인용 수 8
한 줄 요약

이 논문은 Truecaller 및 Facebook과 같은 서비스의 전화번호 및 응용 간 데이터를 악용하여 OTT 메시징 플랫폼에서 표적 지능형 피싱, 음성 피싱, 화이팅 공격을 가능하게 하는 확장성 있고 자동화된 시스템을 제시한다. 전화번호 열거 및 사회적 네트워크 관련 분석을 통해 저자들은 표적 지능형 피싱 공격 대상으로 180,000명, 음성 피싱 공격 대상으로 722,696명이 존재하며, 화이팅 공격 대상으로서 고가치 대상 91,487명이 확인되었다.

ABSTRACT

With the convergence of Internet and telephony, new applications (e.g., WhatsApp) have emerged as an important means of communication for billions of users. These applications are becoming an attractive medium for attackers to deliver spam and carry out more targeted attacks. Since such applications rely on phone numbers, we explore the feasibility, automation, and scalability of phishing attacks that can be carried out by abusing a phone number. We demonstrate a novel system that takes a potential victim's phone number as an input, leverages information from applications like Truecaller and Facebook about the victim and his / her social network, checks the presence of phone number's owner (victim) on the attack channels (over-the-top or OTT messaging applications, voice, e-mail, or SMS), and finally targets the victim on the chosen channel. As a proof of concept, we enumerate through a random pool of 1.16 million phone numbers. By using information provided by popular applications, we show that social and spear phishing attacks can be launched against 51,409 and 180,000 users respectively. Furthermore, voice phishing or vishing attacks can be launched against 722,696 users. We also found 91,487 highly attractive targets who can be attacked by crafting whaling attacks. We show the effectiveness of one of these attacks, phishing, by conducting an online roleplay user study. We found that social (69.2%) and spear (54.3%) phishing attacks are more successful than non-targeted phishing attacks (35.5%) on OTT messaging applications. Although similar results were found for other mediums like e-mail, we demonstrate that due to the significantly increased user engagement via new communication applications and the ease with which phone numbers allow collection of information necessary for these attacks, there is a clear need for better protection of OTT messaging applications.

연구 동기 및 목표

  • OTT 메시징, 음성, 이메일, SMS 등 다양한 플랫폼에서 전화번호를 고유 식별자로 사용하여 표적 침입 공격을 수행하는 데 있어 실현 가능성과 확장성을 조사한다.
  • Truecaller 및 Facebook과 같은 서비스의 응용 간 기능이 어떻게 악용되어 피해자의 프로파일 및 사회적 네트워크를 수집할 수 있는지 분석한다.
  • 현대의 통신 플랫폼인 WhatsApp와 같은 플랫폼에서 사회적, 표적 지능형, 비표적 피싱 공격의 효과성을 평가한다.
  • 전화번호 기반 프로파일링 및 사회적 네트워크 분석을 통해 화이팅 공격에 적합한 고가치 대상자를 식별한다.
  • OTT 메시징 및 전화번호 확인 응용 프로그램에서 사용자 데이터 남용과 전화번호 신뢰성 오용을 방지하기 위한 실질적인 방어 조치를 제안한다.

제안 방법

  • 공격 표면 분석을 위한 116만 개의 인도 모바일 번호 데이터셋 수집.
  • Truecaller의 역방향 검색 기능을 활용해 전화번호에서 피해자 이름 및 관련 정보 추출.
  • 피해자 데이터를 페이스북 프로필과 연계하여 사회적 네트워크 및 상호 연결 관계 재구성.
  • 각 피해자의 번호가 OTT 플랫폼(예: WhatsApp), 음성, 이메일, SMS 채널 등에 존재하는지 자동으로 확인.
  • 아마존 MTurk에서 역할극 기반 사용자 연구를 설계하고 실행하여 다양한 유형의 피싱 공격 성공률 측정.
  • 피싱 점수 시스템 및 콜러ID 앱에서 악성 번호를 탐지하기 위한 정합성 검증 메커니즘을 제안

실험 결과

연구 질문

  • RQ1다양한 응용 프로그램 간에 사용자를 프로파일링하는 데 있어 전화번호가 얼마나 확장성 있고 신뢰할 수 있는 식별자로 활용될 수 있는가?
  • RQ2비표적 피싱 공격에 비해 OTT 메시징 플랫폼에서 사회적 및 표적 지능형 피싱 공격의 효과성은 어떠한가?
  • RQ3Truecaller 및 Facebook의 응용 간 데이터를 활용할 경우 음성 피싱 및 화이팅 공격 표면의 규모는 어느 정도인가?
  • RQ4OTT 플랫폼에서의 사용자 참여 패턴이 기존 이메일에 비해 사회공학적 공격의 성공률을 얼마나 증폭시키는가?
  • RQ5전화번호 및 콜러ID 데이터 남용을 방지하기 위해 기술적 및 정책 수준에서 구현 가능한 방어 조치는 무엇인가?

주요 결과

  • 응용 간 데이터 유사성 분석을 통해 시스템은 표적 지능형 피싱 공격에 취약한 180,000명의 사용자를 성공적으로 식별했다.
  • 음성 피싱 공격는 722,696명의 사용자를 대상으로 수행 가능하며, 음성 채널에 막대한 공격 표면이 존재함을 시사한다.
  • 사회적 영향력과 네트워크 중심성 지표를 기반으로 총 91,487명의 고가치 대상자가 화이팅 공격 대상으로 확인되었다.
  • 역할극 연구에서 사회적 피싱은 OTT 플랫폼에서 69.2%의 성공률를 기록했으며, 비표적 피싱(35.5%)에 비해 현저히 높았다.
  • OTT 플랫폼에서의 표적 지능형 피싱은 54.3%의 성공률를 기록했으며, 개인화가 공격 효과성을 높임을 확인했다.
  • 본 연구는 이러한 공격의 빈도가 높고 탐지율이 낮아 OTT 및 콜러ID 응용 프로그램에서 보다 나은 보호 메커니즘이 시급히 필요하다고 강조한다.

더 나은 연구,지금 바로 시작하세요

논문 읽기부터 검토까지, 연구 시간을 획기적으로 줄여보세요.

카드 등록 없음 · 무료 플랜 제공

이 리뷰는 AI가 만들고, 인간 에디터가 검토했습니다.