Title
Characterizing Social Insider Attacks on Facebook.
Abstract
Facebook accounts are secured against unauthorized access through passwords and device-level security. Those defenses, however, may not be sufficient to prevent social insider attacks, where attackers know their victims, and gain access to a victim's account by interacting directly with their device. To characterize these attacks, we ran two MTurk studies. In the first (n = 1,308), using the list experiment method, we estimated that 24% of participants had perpetrated social insider attacks and that 21% had been victims (and knew about it). In the second study (n = 45), participants wrote stories detailing personal experiences with such attacks. Using thematic analysis, we typified attacks around five motivations (fun, curiosity, jealousy, animosity, and utility), and explored dimensions associated with each type. Our combined findings indicate that social insider attacks are common, often have serious emotional consequences, and have no simple mitigation.
Year
DOI
Venue
2017
10.1145/3025453.3025901
CHI
Keywords
Field
DocType
Usable security, privacy, insider attack, Facebook
Thematic analysis,Internet privacy,Personal experience,Curiosity,Computer science,Computer security,Insider attack,Insider,Jealousy,Password
Conference
Citations 
PageRank 
References 
2
0.36
10
Authors
6
Name
Order
Citations
PageRank
Wali Ahmed Usmani120.36
Diogo Marques2366.33
Ivan Beschastnikh366543.49
Konstantin Beznosov41521105.47
Tiago Guerreiro536645.90
Luís Carriço620.70