论文标题
电子邮件欺诈的主动对策
Active Countermeasures for Email Fraud
论文作者
论文摘要
作为在线犯罪的主要组成部分,基于电子邮件的欺诈是一种威胁,每年都会造成巨大的经济损失。为了抵消这些诈骗者,志愿者称骗子扮演受害者的角色,对骗子的回复,并试图通过长时间且无效的对话浪费时间和注意力。为了遏制电子邮件欺诈并扩大骗局诱饵的有效性,我们开发并部署了可扩展的骗局诱饵邮件服务器,可以自动进行骗局诱饵活动。我们使用三个不同的模型实施了三种答复策略,并进行了一个月的实验,在此期间,我们从130个不同的骗子中引起了150条消息。我们比较每种策略在吸引和引起诈骗者的注意,找到人写和自动生成的响应策略之间的权衡方面的表现。我们还证明,骗子可以通过在第二个实验中部署这些策略的多个服务器同时参与,该实验使用两个服务器实例在12天内与92个不同的骗子联系。我们同时发布了我们的平台和一个包含自动骗局和真实人类骗子对话的数据集,以支持预防在线欺诈方面的未来工作。
As a major component of online crime, email-based fraud is a threat that causes substantial economic losses every year. To counteract these scammers, volunteers called scam-baiters play the roles of victims, reply to scammers, and try to waste their time and attention with long and unproductive conversations. To curb email fraud and magnify the effectiveness of scam-baiting, we developed and deployed an expandable scam-baiting mailserver that can conduct scam-baiting activities automatically. We implemented three reply strategies using three different models and conducted a one-month-long experiment during which we elicited 150 messages from 130 different scammers. We compare the performance of each strategy at attracting and holding the attention of scammers, finding tradeoffs between human-written and automatically-generated response strategies. We also demonstrate that scammers can be engaged concurrently by multiple servers deploying these strategies in a second experiment, which used two server instances to contact 92 different scammers over 12 days. We release both our platform and a dataset containing conversations between our automatic scam-baiters and real human scammers, to support future work in preventing online fraud.