Rotten Apples or Bad Harvest? What We Are Measuring When We Are Measuring Abuse

被引:5
|
作者
Tajalizadehkhoob, Samaneh [1 ]
Boehme, Rainer [2 ]
Ganan, Carlos [1 ]
Korczynski, Maciej [3 ,4 ]
van Eeten, Michel [1 ]
机构
[1] Delft Univ Technol, Dept Multiactor syst, Jaffalaan 5, NL-2628 BX Delft, Netherlands
[2] Univ Innsbruck, Secur & Privacy Lab, Tech Str 21A, A-6020 Innsbruck, Austria
[3] Delft Univ Technol, Delft, Netherlands
[4] Grenoble Inst Technol, LIG Lab, F-38401 St Martin Dheres, France
关键词
Statistical modeling; hosting providers; abuse concentrations; web security; measurement errors; OVERDISPERSION;
D O I
10.1145/3122985
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet security and technology policy research regularly uses technical indicators of abuse to identify culprits and to tailor mitigation strategies. As a major obstacle, current inferences from abuse data that aim to characterize providers with poor security practices often use a naive normalization of abuse (abuse counts divided by network size) and do not take into account other inherent or structural properties of providers. Even the size estimates are subject to measurement errors relating to attribution, aggregation, and various sources of heterogeneity. More precise indicators are costly to measure at Internet scale. We address these issues for the case of hosting providers with a statistical model of the abuse data generation process, using phishing sites in hosting networks as a case study. We decompose error sources and then estimate key parameters of the model, controlling for heterogeneity in size and business model. We find that 84% of the variation in abuse counts across 45,358 hosting providers can be explained with structural factors alone. Informed by the fitted model, we systematically select and enrich a subset of 105 homogeneous "statistical twins" with additional explanatory variables, unreasonable to collect for all hosting providers. We find that abuse is positively associated with the popularity of websites hosted and with the prevalence of popular content management systems. Moreover, hosting providers who charge higher prices (after controlling for level differences between countries) witness less abuse. These structural factors together explain a further 77% of the remaining variation. This calls into question premature inferences from raw abuse indicators about the security efforts of actors, and suggests the adoption of similar analysis frameworks in all domains where network measurement aims at informing technology policy.
引用
收藏
页数:25
相关论文
共 50 条
  • [1] What Are We Measuring When We Evaluate Journals ?
    Polonsky, Michael
    Whitelaw, Paul
    [J]. JOURNAL OF MARKETING EDUCATION, 2005, 27 (02) : 189 - 201
  • [2] What are we measuring when we measure the fear of crime
    Kury, H
    Lichtblau, A
    Neumaier, A
    [J]. KRIMINALISTIK, 2004, 58 (07): : 457 - 465
  • [3] What are we measuring when we measure task switch costs?
    Hazeltine, Eliot
    [J]. CURRENT OPINION IN BEHAVIORAL SCIENCES, 2024, 56
  • [4] What are we measuring?
    Rosenfeld, Jeffrey
    [J]. AMYOTROPHIC LATERAL SCLEROSIS AND FRONTOTEMPORAL DEGENERATION, 2013, 14 (03) : 161 - 161
  • [5] WHAT ARE WE MEASURING
    HAM, RE
    [J]. JOURNAL OF FLUENCY DISORDERS, 1989, 14 (04) : 231 - 243
  • [6] What are We Measuring When We Test Strain Differences in Anxiety in Mice?
    O'Leary, Timothy P.
    Gunn, Rhian K.
    Brown, Richard E.
    [J]. BEHAVIOR GENETICS, 2013, 43 (01) : 34 - 50
  • [7] What are We Measuring When We Test Strain Differences in Anxiety in Mice?
    Timothy P. O’Leary
    Rhian K. Gunn
    Richard E. Brown
    [J]. Behavior Genetics, 2013, 43 : 34 - 50
  • [8] Are we measuring what we need to measure?
    Wittink, Harriet
    Nicholas, Michael
    Kralik, Debbie
    Verbunt, Jeanine
    [J]. CLINICAL JOURNAL OF PAIN, 2008, 24 (04): : 316 - 324
  • [9] What are we measuring with PET?
    Morgan, AE
    Brodie, JD
    Dewey, SL
    [J]. QUARTERLY JOURNAL OF NUCLEAR MEDICINE, 1998, 42 (03): : 151 - 157
  • [10] BILIRUBIN - WHAT ARE WE MEASURING
    HICKS, JM
    IOSEFSOHN, M
    [J]. CLINICAL CHEMISTRY, 1985, 31 (06) : 987 - 987