Skip to main content
QUICK REVIEW

[论文解读] Characterizing Cryptocurrency Exchange Scams

Pengcheng Xia, Bowen Zhang|arXiv (Cornell University)|Mar 16, 2020
Spam and Phishing Detection参考文献 22被引用 7
一句话总结

本文首次系统性地研究了加密货币交易所诈骗,通过结合已知报告与自动化拼写错误劫持检测的混合方法,识别出1,595个诈骗域名和323款假冒应用。研究发现,94个诈骗域名家族和30个假冒应用家族由少数攻击者团体控制,导致至少52万美元的经济损失,并表明假冒应用已渗透至Google Play等主要应用市场,成功规避了现有安全检测。

ABSTRACT

As the indispensable trading platforms of the ecosystem, hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. While, it also attracts the attentions of attackers. A number of scam attacks were reported targeting cryptocurrency exchanges, leading to a huge mount of financial loss. However, no previous work in our research community has systematically studied this problem. In this paper, we make the first effort to identify and characterize the cryptocurrency exchange scams. We first identify over 1,500 scam domains and over 300 fake apps, by collecting existing reports and using typosquatting generation techniques. Then we investigate the relationship between them, and identify 94 scam domain families and 30 fake app families. We further characterize the impacts of such scams, and reveal that these scams have incurred financial loss of 520k US dollars at least. We further observe that the fake apps have been sneaked to major app markets (including Google Play) to infect unsuspicious users. Our findings demonstrate the urgency to identify and prevent cryptocurrency exchange scams. To facilitate future research, we have publicly released all the identified scam domains and fake apps to the community.

研究动机与目标

  • 系统性地识别并描述加密货币交易所诈骗,尽管其造成的财务影响持续扩大,但该领域仍缺乏充分研究。
  • 揭示针对加密货币交易所的诈骗域名和假冒应用的规模、结构及运作模式。
  • 通过区块链地址追踪分析这些诈骗的真实世界财务影响。
  • 揭示假冒应用如何绕过安全检查并渗透至Google Play等主要应用市场。
  • 发布一个全面且公开可用的诈骗域名与应用数据集,以支持未来的研究与检测工作。

提出的方法

  • 收集现有的诈骗报告,并利用自动化拼写错误生成技术,发现此前未知的诈骗域名。
  • 从Koodous平台获取假冒应用,并与主要应用仓库(Janus和Androzoo)交叉比对,检测其是否存在于官方市场中。
  • 基于结构与行为相似性,将诈骗域名和假冒应用聚类为家族,以识别攻击者团体。
  • 追踪与诈骗域名和应用相关的区块链地址,分析资金流动并估算财务影响。
  • 通过人工分析与启发式规则验证并分类诈骗样本,包括域名相似性与应用元数据。
  • 在https://cryptoexchangescam.github.io/ScamDataset/发布一个全面的诈骗域名与假冒应用数据集,供社区使用。

实验结果

研究问题

  • RQ1加密货币交易所诈骗的真实规模与结构如何,包括诈骗域名和假冒应用?
  • RQ2诈骗域名与假冒应用之间有何关联?背后是由哪些攻击者团体操控?
  • RQ3假冒应用在Google Play等主要应用市场中的渗透程度如何?现有安全机制的有效性如何?
  • RQ4这些诈骗的真实世界财务影响是什么?资金是如何洗钱或隐藏的?
  • RQ5社区如何利用此数据提升未来对交易所诈骗的检测与防范能力?

主要发现

  • 本研究识别出1,595个诈骗域名,其中超过60%此前未被公众所知。
  • 共发现323款假冒交易所应用,其中66款(20.4%)存在于主要应用市场,包括60款在Google Play上。
  • 诈骗基础设施由94个诈骗域名家族和30个假冒应用家族构成,表明由少数攻击者团体集中控制。
  • 受害者遭受的经济损失至少达52万美元,与诈骗活动相关的区块链地址共183个。
  • 攻击者使用多个资金转账地址及混币服务,以掩盖资金流动路径,使追踪变得困难。
  • 现有应用市场安全机制未能检测并阻止大量假冒应用,暴露了用户面临广泛的风险。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。