Rotten Apples or Bad Harvest? What We Are Measuring When We Are Measuring Abuse

被引:5
|
作者
Tajalizadehkhoob, Samaneh [1 ]
Boehme, Rainer [2 ]
Ganan, Carlos [1 ]
Korczynski, Maciej [3 ,4 ]
van Eeten, Michel [1 ]
机构
[1] Delft Univ Technol, Dept Multiactor syst, Jaffalaan 5, NL-2628 BX Delft, Netherlands
[2] Univ Innsbruck, Secur & Privacy Lab, Tech Str 21A, A-6020 Innsbruck, Austria
[3] Delft Univ Technol, Delft, Netherlands
[4] Grenoble Inst Technol, LIG Lab, F-38401 St Martin Dheres, France
关键词
Statistical modeling; hosting providers; abuse concentrations; web security; measurement errors; OVERDISPERSION;
D O I
10.1145/3122985
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Internet security and technology policy research regularly uses technical indicators of abuse to identify culprits and to tailor mitigation strategies. As a major obstacle, current inferences from abuse data that aim to characterize providers with poor security practices often use a naive normalization of abuse (abuse counts divided by network size) and do not take into account other inherent or structural properties of providers. Even the size estimates are subject to measurement errors relating to attribution, aggregation, and various sources of heterogeneity. More precise indicators are costly to measure at Internet scale. We address these issues for the case of hosting providers with a statistical model of the abuse data generation process, using phishing sites in hosting networks as a case study. We decompose error sources and then estimate key parameters of the model, controlling for heterogeneity in size and business model. We find that 84% of the variation in abuse counts across 45,358 hosting providers can be explained with structural factors alone. Informed by the fitted model, we systematically select and enrich a subset of 105 homogeneous "statistical twins" with additional explanatory variables, unreasonable to collect for all hosting providers. We find that abuse is positively associated with the popularity of websites hosted and with the prevalence of popular content management systems. Moreover, hosting providers who charge higher prices (after controlling for level differences between countries) witness less abuse. These structural factors together explain a further 77% of the remaining variation. This calls into question premature inferences from raw abuse indicators about the security efforts of actors, and suggests the adoption of similar analysis frameworks in all domains where network measurement aims at informing technology policy.
引用
收藏
页数:25
相关论文
共 50 条
  • [31] IQ PUZZLE - WHAT ARE WE MEASURING
    KAGAN, J
    [J]. SOCIAL EDUCATION, 1974, 38 (03): : 260 - 266
  • [32] Are We Measuring What Really Counts?
    Thoma, Achilleas
    Hassan, Yusuf
    Santos, Jenny
    [J]. AESTHETIC SURGERY JOURNAL, 2019, 39 (07) : 777 - 785
  • [33] Multicultural competencies: What are we measuring?
    Drinane, Joanna M.
    Owen, Jesse
    Adelson, Jill L.
    Rodolfa, Emil
    [J]. PSYCHOTHERAPY RESEARCH, 2016, 26 (03) : 342 - 351
  • [34] Variation and selection -: what are we measuring?
    Björklund, M
    [J]. ANNALES ZOOLOGICI FENNICI, 2003, 40 (05) : 387 - 394
  • [35] Are We Making the Correct Inferences Based on What We Are Measuring?
    Fulk, George
    [J]. JOURNAL OF NEUROLOGIC PHYSICAL THERAPY, 2021, 45 (04): : 243 - 245
  • [36] Validity of polygenic risk scores: are we measuring what we think we are?
    Janssens, A. Cecile J. W.
    [J]. HUMAN MOLECULAR GENETICS, 2019, 28 (R2) : R143 - R150
  • [37] The List Experiment for Measuring Abortion: What We Know and What We Need
    Moseson, Heidi
    Treleaven, Emily
    Gerdts, Caitlin
    Diamond-Smith, Nadia
    [J]. STUDIES IN FAMILY PLANNING, 2017, 48 (04) : 397 - 405
  • [38] MEASURING THE CREATIVE CLASS: DO WE KNOW IT WHEN WE SEE IT?
    Reese, Laura A.
    Faist, Jessica M.
    Sands, Gary
    [J]. JOURNAL OF URBAN AFFAIRS, 2010, 32 (03) : 345 - 366
  • [39] Describing the burden of malaria on child development: What should we be measuring and how should we be measuring it?
    Holding, PA
    Kitsao-Wekulo, PK
    [J]. AMERICAN JOURNAL OF TROPICAL MEDICINE AND HYGIENE, 2004, 71 (02): : 71 - 79
  • [40] Are We Really Measuring What We Think We're Measuring? Assessing Attitudes towards Destinations with the Implicit Association Test
    Kim, Dae-Young
    Chen, Zhijian
    Hwang, Yeong-Hyeon
    [J]. INTERNATIONAL JOURNAL OF TOURISM RESEARCH, 2011, 13 (05) : 468 - 481