Skip to main content
QUICK REVIEW

[论文解读] Call Me MayBe: Understanding Nature and Risks of Sharing Mobile Numbers on Online Social Networks

Prachi Jain, Ponnurangam Kumaraguru|arXiv (Cornell University)|Dec 12, 2013
Privacy, Security, and Data Protection参考文献 27被引用 6
一句话总结

本研究调查了印度移动号码在Twitter和Facebook等在线社交网络(OSNs)上共享的普遍性、动机及风险。基于从76,347条公开发布的号码中收集的数据,作者发现大多数用户出于非个人原因(如紧急求助、营销或接送服务)共享号码,而仅有38.3%的不知情用户曾自行发布过自己的号码。研究显示,通过数据聚合,暴露的号码可与敏感个人信息(如选民身份证、BBM个人识别码)关联起来;此外,通过IVR系统联系了2,492名用户以传达风险,揭示了用户普遍缺乏意识且面临语音网络钓鱼(vishing)威胁。

ABSTRACT

There is a great concern about the potential for people to leak private information on OSNs, but few quantitative studies on this. This research explores the activity of sharing mobile numbers on OSNs, via public profiles and posts. We attempt to understand the characteristics and risks of mobile numbers sharing behaviour on OSNs and focus on Indian mobile numbers. We collected 76,347 unique mobile numbers posted by 85905 users on Twitter and Facebook and analysed 2997 numbers, prefixed with +91. We observed, most users shared their own mobile numbers to spread urgent information; and to market products and escort business. Fewer female users shared mobile numbers on OSNs. Users utilized other OSN platforms and third party applications like Twitterfeed, to post mobile numbers on multiple OSNs. In contrast to the user's perception of numbers spreading quickly on OSN, we observed that except for emergency, most numbers did not diffuse deep. To assess risks associated with mobile numbers exposed on OSNs, we used numbers to gain sensitive information about their owners (e.g. name, Voter ID) by collating publicly available data from OSNs, Truecaller, OCEAN. On using the numbers on WhatApp, we obtained a myriad of sensitive details (relationship status, BBM pins) of the number owner. We communicated the observed risks to the owners by calling. Few users were surprised to know about the online presence of their number, while a few others intentionally posted it online for business purposes. We observed, 38.3% of users who were unaware of the online presence of their number have posted their number themselves on the social network. With these observations, we highlight that there is a need to monitor leakage of mobile numbers via profile and public posts. To the best of our knowledge, this is the first exploratory study to critically investigate the exposure of Indian mobile numbers on OSNs.

研究动机与目标

  • 理解印度OSNs(如Twitter和Facebook)上移动号码共享的性质与动机。
  • 评估公开暴露的移动号码所关联的隐私风险,包括身份重新识别和语音网络钓鱼攻击。
  • 评估用户对移动号码暴露的认知程度,并通过基于IVR的推广系统传达风险。
  • 识别号码共享中的技术和行为模式,包括聚合工具的使用和跨平台传播。
  • 倡导提升用户意识并加强技术防护措施,以防止OSNs上移动号码的意外暴露。

提出的方法

  • 使用基于关键词的爬取和验证技术,从Twitter和Facebook的公开帖子中收集76,347个印度移动号码。
  • 利用多个数据源(OSNs、Truecaller、OCEAN(开放政府数据)、WhatsApp)对2,997个以+91开头的号码进行验证。
  • 使用LIWC和人工标注进行上下文与文体分析,以分类号码共享的动机(如紧急情况、营销、个人用途)。
  • 通过网络分析研究Twitter上号码传播的扩散路径,评估其传播范围和深度。
  • 使用FreeSWITCH和Java实现IVR系统,联系2,492名用户并传达隐私风险。
  • 开展数据聚合实验,从公开可获取的来源(如OSNs、Truecaller和开放政府存储库)将移动号码与敏感个人信息(如选民身份证、BBM个人识别码)关联起来。

实验结果

研究问题

  • RQ1印度用户在在线社交网络上共享其移动号码的主要动机是什么?
  • RQ2移动号码在OSNs中的传播程度如何?其传播模式在不同语境(如紧急情况、营销)下有何差异?
  • RQ3公开暴露的移动号码用户有多脆弱?能否利用这些号码重新识别出敏感个人信息?
  • RQ4用户对其移动号码在线存在的认知程度如何?他们对风险沟通的反应是什么?
  • RQ5在跨平台和工具中,移动号码传播的技术与行为模式是什么?

主要发现

  • 38.3%的用户在不知情的情况下自行发布了其号码,表明用户意识存在显著缺口。
  • 大多数号码共享出于非个人原因:38.3%用于紧急求助,25.6%用于营销(如IT服务、占卜),12.4%用于接送服务。
  • 仅14.7%的用户出于个人原因共享号码,且由于缺乏特定语境关键词,这些帖子往往难以区分。
  • 通过OSNs、Truecaller和开放政府存储库的数据聚合,成功将选民身份证号码和BBM个人识别码等敏感信息与移动号码关联起来。
  • IVR推广结果显示,许多用户对其号码的在线存在感到惊讶,而另一些用户则承认为商业推广而故意发布。
  • 大量用户(尤其是营销人员)遭受垃圾信息或虚假请求(如通过Textastrophe)的攻击,表明即使有意共享也可能导致不良后果。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。