Abuse Reporting and the Fight Against Cybercrime

被引:19
|
作者
Jhaveri, Mohammad Hanif [1 ,4 ]
Cetin, Orcun [2 ,5 ]
Ganan, Carlos [2 ,5 ]
Moore, Tyler [3 ]
Van Eeten, Michel [2 ,5 ]
机构
[1] Southern Methodist Univ, Dallas, TX 75275 USA
[2] Delft Univ Technol, Delft, Netherlands
[3] Univ Tulsa, Tandy Sch Comp Sci, 800 S Tucker Dr, Tulsa, OK 74114 USA
[4] 5601 Rock Valley Dr, Ft Worth, TX 76244 USA
[5] Delft Univ Technol, Fac TBM, Jaffalaan 5, NL-2628 BX Delft, Netherlands
关键词
Measurement; Security; Economics; Cybercrime; abuse reporting; internet security; security economics;
D O I
10.1145/3003147
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Cybercriminal activity has exploded in the past decade, with diverse threats ranging from phishing attacks to botnets and drive-by-downloads afflicting millions of computers worldwide. In response, a volunteer defense has emerged, led by security companies, infrastructure operators, and vigilantes. This reactionary force does not concern itself with making proactive upgrades to the cyber infrastructure. Instead, it operates on the front lines by remediating infections as they appear. We construct a model of the abuse reporting infrastructure in order to explain how voluntary action against cybercrime functions today, in hopes of improving our understanding of what works and how to make remediation more effective in the future. We examine the incentives to participate among data contributors, affected resource owners, and intermediaries. Finally, we present a series of key attributes that differ among voluntary actions to investigate further through experimentation, pointing toward a research agenda that could establish causality between interventions and outcomes.
引用
收藏
页数:27
相关论文
共 50 条