Targeted cyber-attacks: Unveiling target reconnaissance strategy via Social Networks

Hung T. Nguyen, Thang N. Dinh · 2016

The massive explosion of Online Social Networks (OSNs) has brought both great opportunities and security threats. As one of the richest sources on personal information, intelligent attackers have actively used OSNs for target reconnaissance in which sensitive information of specific users and organizations are gathered for later attacks. Modeling and investigating the attackers' techniques is crucial for prevention and countermeasure of cyber-targeted attacks. In this paper, we rigorously model the target reconnaissance in closed-wall OSNs (e.g. Facebook) using probabilistic graphs. In our model, the attackers need to send friend requests smartly to gather as much information from targeted users as possible while avoiding being detected by the services operators. We formulate the attacker's task as the Adaptive Targeted Crawling Maximization problem which is shown to be NP-hard. Further, we use adaptive submodularity theory to show that there exists a simple greedy strategy that the attackers may deploy to guarantee a near-optimal effectiveness. Simulations on real-world social networks also confirms the effectiveness of the strategy in comparison with other naive node-ranking methods. Our work is a first step towards a theoretical foundation to analyze behaviors of intelligent attackers and the susceptibility of organizational social networks.

Read the paper · More papers on PaperTik