vix.ing · top · new · best · stats · spec

Rotten Apples or Bad Harvest? What We Are Measuring When We Are\n Measuring Abuse

2017/02/06 by Samaneh Tajalizadehkhoob, Tajalizadehkhoob, Samaneh, Rainer Böhme +7 · 1 citation
Computer Science · Social Sciences · #Cryptography and Security (cs.CR) #FOS: Computer and information sciences #Internet Traffic Analysis and Secure E-voting #Network Security and Intrusion Detection #Social Media and Politics #Spam and Phishing Detection

paper · pdf · doi:10.48550/arxiv.1702.01624

openalex publication_date 2017/02/06 · openalex created_date 2022/10/02 · openalex updated_date 2026/07/28

Abstract

Internet security and technology policy research regularly uses technical\nindicators of abuse in order to identify culprits and to tailor mitigation\nstrategies. As a major obstacle, readily available data are often misaligned\nwith actual information needs. They are subject to measurement errors relating\nto observation, aggregation, attribution, and various sources of heterogeneity.\nMore precise indicators such as size estimates are costly to measure at\nInternet scale. We address these issues for the case of hosting providers with\na statistical model of the abuse data generation process, using phishing sites\nin hosting networks as a case study. We decompose error sources and then\nestimate key parameters of the model, controlling for heterogeneity in size and\nbusiness model. We find that 84 , % of the variation in abuse counts across\n45,358 hosting providers can be explained with structural factors alone.\nInformed by the fitted model, we systematically select and enrich a subset of\n105 homogeneous "statistical twins" with additional explanatory variables,\nunreasonable to collect for \all hosting providers. We find that abuse is\npositively associated with the popularity of websites hosted and with the\nprevalence of popular content management systems. Moreover, hosting providers\nwho charge higher prices (after controlling for level differences between\ncountries) witness less abuse. These factors together explain a further 77 , %\nof the remaining variation, calling into question premature inferences from raw\nabuse indicators on security efforts of actors, and suggesting the adoption of\nsimilar analysis frameworks in all domains where network measurement aims at\ninforming technology policy.\n

Cited by

Related