TrustBook:在线社交网络中基于信任的关系建立

Umara Noor, Z. Anwar, Y. Mehmood, Waseem Aslam
{"title":"TrustBook:在线社交网络中基于信任的关系建立","authors":"Umara Noor, Z. Anwar, Y. Mehmood, Waseem Aslam","doi":"10.1109/FIT.2013.48","DOIUrl":null,"url":null,"abstract":"Existing online social networks open the doors of socialization for their users by providing a few and easy steps towards user account creation. The major drawback of this feature is that current social network providers lack mechanisms of determining the authenticity of an account. A genuine user's account can be easily forged with fake profile information. There is simply no mechanism to assign or bind any unique identity with user's account that prevents its forged clone to be created on the same network or across multiple networks. One of the intentions of creating a forged account is to deceive the social circle of an individual and compromise their privacy. Accepting a friend's request from a forged account can badly compromise the privacy of an individual. All this can occur to the victim in a very short span of time before she discovers this attack and remove the fake identity holder from her friend's list. To tackle with the issue of identity theft and determining genuine user accounts in online social networks, we present in this paper a novel and real world's trust based approach for verifying the legitimacy of online social network accounts. We propose to use a verification process that utilizes the use of OpenPGP digital certificates and the web of trust consequently formed by them. We define two stages for our secure design. In the first stage, our approach requires digital certificates to be uploaded on the social network server at the time of user account creation. These digital certificates are verified to restrict forged account creation on the same network and across other social networks. In the second stage, to establish a new connection this digital certificate is sent along with the friend request to the recipient. The recipient verifies its authenticity based on the web of trust associated with that certificate. In order to implement our solution, we developed a social network prototype i.e. Trust Book. We conducted an experiment to evaluate the performance of our work against well know social networking site i.e. Face book by launching forged account attacks on both. There were three performance metrics used in the experiment i.e. applicability, reliability and usability. The observations showed that our approach is applicable to all kinds of interaction scenarios. Also it has a good resilience against profile cloning and other kinds of security attacks including session hijacking, replay and channel jamming.","PeriodicalId":179067,"journal":{"name":"2013 11th International Conference on Frontiers of Information Technology","volume":"60 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2013-12-16","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"5","resultStr":"{\"title\":\"TrustBook: Web of Trust Based Relationship Establishment in Online Social Networks\",\"authors\":\"Umara Noor, Z. Anwar, Y. Mehmood, Waseem Aslam\",\"doi\":\"10.1109/FIT.2013.48\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"Existing online social networks open the doors of socialization for their users by providing a few and easy steps towards user account creation. The major drawback of this feature is that current social network providers lack mechanisms of determining the authenticity of an account. A genuine user's account can be easily forged with fake profile information. There is simply no mechanism to assign or bind any unique identity with user's account that prevents its forged clone to be created on the same network or across multiple networks. One of the intentions of creating a forged account is to deceive the social circle of an individual and compromise their privacy. Accepting a friend's request from a forged account can badly compromise the privacy of an individual. All this can occur to the victim in a very short span of time before she discovers this attack and remove the fake identity holder from her friend's list. To tackle with the issue of identity theft and determining genuine user accounts in online social networks, we present in this paper a novel and real world's trust based approach for verifying the legitimacy of online social network accounts. We propose to use a verification process that utilizes the use of OpenPGP digital certificates and the web of trust consequently formed by them. We define two stages for our secure design. In the first stage, our approach requires digital certificates to be uploaded on the social network server at the time of user account creation. These digital certificates are verified to restrict forged account creation on the same network and across other social networks. In the second stage, to establish a new connection this digital certificate is sent along with the friend request to the recipient. The recipient verifies its authenticity based on the web of trust associated with that certificate. In order to implement our solution, we developed a social network prototype i.e. Trust Book. We conducted an experiment to evaluate the performance of our work against well know social networking site i.e. Face book by launching forged account attacks on both. There were three performance metrics used in the experiment i.e. applicability, reliability and usability. The observations showed that our approach is applicable to all kinds of interaction scenarios. Also it has a good resilience against profile cloning and other kinds of security attacks including session hijacking, replay and channel jamming.\",\"PeriodicalId\":179067,\"journal\":{\"name\":\"2013 11th International Conference on Frontiers of Information Technology\",\"volume\":\"60 1\",\"pages\":\"0\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2013-12-16\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"5\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"2013 11th International Conference on Frontiers of Information Technology\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.1109/FIT.2013.48\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"2013 11th International Conference on Frontiers of Information Technology","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/FIT.2013.48","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 5

摘要

现有的在线社交网络通过提供几个简单的步骤来创建用户帐户,为用户打开了社交的大门。此功能的主要缺点是,当前的社交网络提供商缺乏确定帐户真实性的机制。一个真实用户的账户可以很容易地被伪造的个人资料信息所伪造。没有任何机制可以为用户的帐户分配或绑定任何唯一的身份,以防止在同一网络或跨多个网络上创建其伪造的克隆。创建虚假账户的目的之一是欺骗个人的社交圈,损害他们的隐私。接受来自伪造账户的好友请求会严重损害个人隐私。所有这一切都可能发生在受害者身上,在她发现这个攻击并从她的朋友列表中删除假身份持有人之前的很短的时间内。为了解决在线社交网络中身份盗窃和确定真实用户帐户的问题,我们在本文中提出了一种新颖的基于现实世界信任的方法来验证在线社交网络帐户的合法性。我们建议使用使用OpenPGP数字证书和由此形成的信任网络的验证过程。我们为安全设计定义了两个阶段。在第一阶段,我们的方法要求在创建用户帐户时将数字证书上传到社交网络服务器上。这些数字证书经过验证,以限制在同一网络和其他社交网络上创建伪造帐户。在第二阶段,为了建立新的连接,将此数字证书与好友请求一起发送给接收方。接收方根据与该证书关联的信任网络验证其真实性。为了实现我们的解决方案,我们开发了一个社交网络原型,即Trust Book。我们进行了一项实验,通过对知名社交网站(如facebook)发起虚假账户攻击来评估我们的工作表现。实验中使用了三个性能指标,即适用性、可靠性和可用性。观察结果表明,我们的方法适用于各种交互场景。此外,它对配置文件克隆和其他类型的安全攻击(包括会话劫持、重播和信道干扰)具有良好的弹性。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
TrustBook: Web of Trust Based Relationship Establishment in Online Social Networks
Existing online social networks open the doors of socialization for their users by providing a few and easy steps towards user account creation. The major drawback of this feature is that current social network providers lack mechanisms of determining the authenticity of an account. A genuine user's account can be easily forged with fake profile information. There is simply no mechanism to assign or bind any unique identity with user's account that prevents its forged clone to be created on the same network or across multiple networks. One of the intentions of creating a forged account is to deceive the social circle of an individual and compromise their privacy. Accepting a friend's request from a forged account can badly compromise the privacy of an individual. All this can occur to the victim in a very short span of time before she discovers this attack and remove the fake identity holder from her friend's list. To tackle with the issue of identity theft and determining genuine user accounts in online social networks, we present in this paper a novel and real world's trust based approach for verifying the legitimacy of online social network accounts. We propose to use a verification process that utilizes the use of OpenPGP digital certificates and the web of trust consequently formed by them. We define two stages for our secure design. In the first stage, our approach requires digital certificates to be uploaded on the social network server at the time of user account creation. These digital certificates are verified to restrict forged account creation on the same network and across other social networks. In the second stage, to establish a new connection this digital certificate is sent along with the friend request to the recipient. The recipient verifies its authenticity based on the web of trust associated with that certificate. In order to implement our solution, we developed a social network prototype i.e. Trust Book. We conducted an experiment to evaluate the performance of our work against well know social networking site i.e. Face book by launching forged account attacks on both. There were three performance metrics used in the experiment i.e. applicability, reliability and usability. The observations showed that our approach is applicable to all kinds of interaction scenarios. Also it has a good resilience against profile cloning and other kinds of security attacks including session hijacking, replay and channel jamming.
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信