[论文解读] Abusing Phone Numbers and Cross-Application Features for Crafting Targeted Attacks
该论文展示了一套可扩展的自动化系统,通过滥用Truecaller和Facebook等服务的电话号码及跨应用数据,针对OTT即时通讯平台发起针对性的网络钓鱼、语音网络钓鱼和高价值目标网络钓鱼攻击。通过利用电话号码枚举和社交图谱关联技术,作者发现有180,000名用户易受精准网络钓鱼攻击,722,696名用户易受语音网络钓鱼攻击,另有91,487名高价值目标可用于高级网络钓鱼活动。
With the convergence of Internet and telephony, new applications (e.g., WhatsApp) have emerged as an important means of communication for billions of users. These applications are becoming an attractive medium for attackers to deliver spam and carry out more targeted attacks. Since such applications rely on phone numbers, we explore the feasibility, automation, and scalability of phishing attacks that can be carried out by abusing a phone number. We demonstrate a novel system that takes a potential victim's phone number as an input, leverages information from applications like Truecaller and Facebook about the victim and his / her social network, checks the presence of phone number's owner (victim) on the attack channels (over-the-top or OTT messaging applications, voice, e-mail, or SMS), and finally targets the victim on the chosen channel. As a proof of concept, we enumerate through a random pool of 1.16 million phone numbers. By using information provided by popular applications, we show that social and spear phishing attacks can be launched against 51,409 and 180,000 users respectively. Furthermore, voice phishing or vishing attacks can be launched against 722,696 users. We also found 91,487 highly attractive targets who can be attacked by crafting whaling attacks. We show the effectiveness of one of these attacks, phishing, by conducting an online roleplay user study. We found that social (69.2%) and spear (54.3%) phishing attacks are more successful than non-targeted phishing attacks (35.5%) on OTT messaging applications. Although similar results were found for other mediums like e-mail, we demonstrate that due to the significantly increased user engagement via new communication applications and the ease with which phone numbers allow collection of information necessary for these attacks, there is a clear need for better protection of OTT messaging applications.
研究动机与目标
- 调查并评估利用电话号码作为唯一标识符,在OTT即时通讯、语音、电子邮件和短信平台中发起针对性网络攻击的可行性与可扩展性。
- 分析Truecaller和Facebook等服务的跨应用功能如何被滥用以收集受害者资料与社交网络信息。
- 评估社交网络钓鱼、精准网络钓鱼和非针对性网络钓鱼攻击在WhatsApp等现代通信平台上的有效性。
- 基于电话号码的资料分析与社交图谱研究,识别可用于高级网络钓鱼攻击的高价值目标。
- 为OTT即时通讯和来电显示应用程序提出可操作的防御措施,以减轻用户数据与电话号码信任机制被滥用的风险
提出的方法
- 收集包含116万名印度手机号码的数据集,用于枚举与攻击面分析。
- 利用Truecaller的反向查询功能,从电话号码中提取受害者姓名及相关详细信息。
- 将受害者数据与Facebook个人资料关联,重建社交网络与共同联系人关系。
- 自动检测每位受害者在OTT平台(如WhatsApp)、语音、电子邮件和短信渠道中的存在情况。
- 在Amazon MTurk上设计并执行基于角色扮演的用户研究,以测量不同攻击类型下的网络钓鱼成功率。
- 提出一种基于众包的网络钓鱼评分系统及完整性验证机制,用于来电显示应用程序以检测恶意号码
实验结果
研究问题
- RQ1在多个应用程序之间,电话号码在多大程度上可作为可扩展且可靠的用户画像标识符?
- RQ2与非针对性网络钓鱼相比,社交网络钓鱼和精准网络钓鱼在OTT即时通讯平台上的有效性如何?
- RQ3当结合Truecaller和Facebook的跨应用数据时,语音网络钓鱼和高级网络钓鱼的攻击面规模如何?
- RQ4与传统电子邮件相比,OTT平台上的用户参与模式如何放大社交工程攻击的成功率?
- RQ5在技术与政策层面,可实施哪些防御措施以减少电话号码与来电显示数据在恶意攻击链中的滥用?
主要发现
- 该系统通过跨应用数据关联,成功识别出180,000名易受精准网络钓鱼攻击的用户。
- 语音网络钓鱼可针对722,696名用户发起,表明语音渠道存在巨大的攻击面。
- 基于社交影响力与网络中心性指标,共识别出91,487名可用于高级网络钓鱼攻击的高价值目标。
- 在角色扮演研究中,社交网络钓鱼在OTT平台上的成功率高达69.2%,显著高于非针对性网络钓鱼的35.5%。
- 在OTT平台上,精准网络钓鱼的成功率为54.3%,证实个性化内容可显著提升攻击效果。
- 本研究凸显了OTT平台与来电显示应用亟需更完善的保护机制,以应对此类攻击数量庞大且检测率低的问题
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。