[论文解读] Tracing Cryptocurrency Scams: Clustering Replicated Advance-Fee and Phishing Websites
本文提出一种基于DBSCAN的聚类方法,用于识别针对加密货币用户的复制型预付费诈骗和钓鱼网站。通过分析网站内容、基础设施和区块链交易模式,研究发现诈骗分子运营多个相似的网站,并伪造区块链活动以制造合法假象,受害者通常通过法币兑换交易所入口注入资金,而收益则通过交易所、赌博网站和混币器进行洗钱。
Over the past few years, there has been a growth in activity, public knowledge, and awareness of cryptocurrencies and related blockchain technology. As the industry has grown, there has also been an increase in scams looking to steal unsuspecting individuals cryptocurrency. Many of the scams operate on visually similar but seemingly unconnected websites, advertised by malicious social media accounts, which either attempt an advance-fee scam or operate as phishing websites. This paper analyses public online and blockchain-based data to provide a deeper understanding of these cryptocurrency scams. The clustering technique DBSCAN is applied to the content of scam websites to discover a typology of advance-fee and phishing scams. It is found that the same entities are running multiple instances of similar scams, revealed by their online infrastructure and blockchain activity. The entities also manufacture public blockchain activity to create the appearance that their scams are genuine. Through source and destination of funds analysis, it is observed that victims usually send funds from fiat-accepting exchanges. The entities running these scams cash-out or launder their proceeds using a variety of avenues including exchanges, gambling sites, and mixers.
研究动机与目标
- 理解涉及预付费和钓鱼网站的加密货币诈骗的规模与结构。
- 识别诈骗网站在互联网上的复制模式及其底层基础设施特征。
- 分析区块链交易模式,以检测诈骗分子为制造合法假象而制造的合成活动。
- 追踪资金从受害者到洗钱渠道(包括交易所、混币器和赌博平台)的流动路径。
- 为执法机构和安全研究人员提供可操作的见解,以破坏诈骗活动。
提出的方法
- 将DBSCAN聚类算法应用于诈骗网站的文本和结构内容,以将视觉相似但逻辑上不同的网站分组。
- 提取并比较网站特征,如HTML结构、域名注册信息和托管基础设施,以检测复制行为。
- 分析区块链交易数据,以检测伪造活动的模式,包括快速、循环转账和高频交互。
- 通过链上交易追踪,绘制资金从法币入金通道(如交易所)到最终变现目的地的流动路径。
- 将网站聚类与区块链地址相关联,以识别多个诈骗实例背后的共同运营者。
实验结果
研究问题
- RQ1诈骗分子如何在保持运营一致性的前提下,在互联网上复制和分发预付费和钓鱼网站?
- RQ2诈骗分子在多大程度上模拟真实区块链活动以增强可信度?
- RQ3诈骗分子主要通过哪些路径对被盗的加密货币收益进行洗钱或变现?
- RQ4聚类技术(如DBSCAN)如何用于检测和分组地理上和结构上分散的诈骗网站?
- RQ5受害者资金来源和资金流动的哪些模式揭示了诈骗网络的运营结构?
主要发现
- 诈骗分子使用共享基础设施运营多个视觉上相似的网站,表明存在协调一致的大规模运作。
- 同一实体负责多个基于内容相似性聚类的诈骗网站,证实了运营资源的重复使用。
- 诈骗分子通过创建人工交易模式来伪造区块链活动,以模拟合法性和获取受害者信任。
- 受害者主要通过接受法币的交易所为诈骗提供资金,这些交易所是被盗资金的主要入金通道。
- 诈骗收益通过加密货币交易所、赌博网站和混币器的组合进行洗钱,以掩盖资金的来源和去向。
- 网站聚类与区块链分析的结合,能够识别出完整的诈骗网络,揭示了分布式网站存在背后的集中控制。
更好的研究,从现在开始
从阅读论文到最终审阅,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。