2020/06/28 by Shehroze Farooqi, Maaz Musa, Maaz Bin Musa +6 · 1 voice · 2 citations
Computer Science · #Spam and Phishing Detection #Advanced Malware Detection Techniques #Internet Traffic Analysis and Secure E-voting
paper · pdf · doi:10.48550/arxiv.2006.15794
Online social networks support a vibrant ecosystem of third-party apps that\nget access to personal information of a large number of users. Despite several\nrecent high-profile incidents, methods to systematically detect data misuse by\nthird-party apps on online social networks are lacking. We propose CanaryTrap\nto detect misuse of data shared with third-party apps. CanaryTrap associates a\nhoneytoken to a user account and then monitors its unrecognized use via\ndifferent channels after sharing it with the third-party app. We design and\nimplement CanaryTrap to investigate misuse of data shared with third-party apps\non Facebook. Specifically, we share the email address associated with a\nFacebook account as a honeytoken by installing a third-party app. We then\nmonitor the received emails and use Facebook's ad transparency tool to detect\nany unrecognized use of the shared honeytoken. Our deployment of CanaryTrap to\nmonitor 1,024 Facebook apps has uncovered multiple cases of misuse of data\nshared with third-party apps on Facebook including ransomware, spam, and\ntargeted advertising.\n