An Inquiry into the Nature and Causes of the Wealth of Internet Miscreants
Published 1 January 2007
Jason Franklin, Vern Paxson, Adrian Perrig, Stefan Savage
Citations331
Generate an AI Snapshot to get a quick, structured summary of this paper.
Study Snapshot
ObjectiveStudy objective
MethodsResearch methodology
PopulationPopulation studied
Sample sizeSample sizes
OutcomesStudy outcomes here
ResultsStudy results comes here
LimitationsResearch study limitations comes here
A concise AI-generated summary of the paper will appear here once you click Generate AI Snapshot.
Abstract
This paper studies an active underground economy which specializes in the commoditization of activities such as credit car d fraud, identity theft, spamming, phishing, online credential the ft, and the sale of compromised hosts. Using a seven month trace of logs collected from an active underground market operating on public Internet chat networks, we measure how the shift from “hacking for fun” to “hacking for profit” has given birth to a societal subs trate mature enough to steal wealth into the millions of dollars in less than one year.
Keywords
Computer Science
The Quarterly Journal of EconomicsThe Market for "Lemons": Quality Uncertainty and the Market Mechanism
22,642 Citations1970George A. Akerlof
Lecture notes in computer scienceThe Sybil Attack
4,328 Citations2002John R. Douceur
It is shown that, without a logically centralized authority, Sybil attacks are always possible except under extreme and unrealistic assumptions of resource parity and coordination among entities.
A re-examination of text categorization methods
2,660 Citations1999Yiming Yang, Xin Liu
The results show that SVM, kNN and LLSF signi cantly outperform NNet and NB when the number of positive training instances per category are small, and that all the methods perform comparably when the categories are over 300 instances.
Why information security is hard - an economic perspective
813 Citations2005Ross Anderson
The author puts forward a contrary view: information insecurity is at least as much due to perverse incentives as it is due to technical measures.
ACM SIGCOMM Computer Communication ReviewSybilGuard
749 Citations2006Haifeng Yu, Michael Kaminsky +2 more
Internet Relay Chat Protocol
176 Citations1993J. Oikarinen, D. Reed
The IRC protocol was developed over the last 4 years since it was first implemented as a means for users on a BBS to chat amongst themselves, and is stringing to cope with growth.
IEEE Security & PrivacyToward econometric models of the security risk from remote attacks
100 Citations2005Stuart Schechter
This paper presents a meta-modelling framework that automates the very labor-intensive and therefore time-heavy and therefore expensive and expensive process of manually cataloging and evaluating the security of individual computer systems.
Bug Auctions: Vulnerability Markets Reconsidered
80 Citations2004Andy Ozment
This paper argues that a vulnerability market in which software producers receive a time-variable reward to free-market testers who identify vulnerabilities can best be considered as an auction; auction theory is used to tune the structure of this ‘bug auction’ forency and to better defend against attacks.
Quantitatively Differentiating System Security
49 Citations2002Stuart Schechter
It is asserted that the cost to break into a system is an effective metric, that this metric can be measured from the start of testing until product retirement, and that using this metric to differentiate products will provide developers with the competitive advantage needed to lead the industry to more secure systems.
The Knowledge Bank (The Ohio State University)The Real ID Act: Fixing Identity Documents with Duct Tape
6 Citations2006Serge Egelman, Lorrie Faith Cranor
This paper discusses new proposed regulations that aim to increase the security of both the passport and the driver’s license, the potential privacy and security problems, as well as policy conflicts between DMV regulations and applicable state and federal laws.
Feature Representation for Effective Action-Item Detection
3 Citations2005Paul N. Bennett, Jaime Carbonell
This paper reports on a new task: automated action-item detection, in order to flag emails that require responses, and to highlight the specific passage(s) indicating the request(S) for action.
