Measuring and Mitigating OAuth Access Token Abuse by Collusion Networks.

We uncovered a thriving ecosystem of large-scale reputation manipulation services on Facebook that leverage the principle of collusion. Collusion networks collect OAuth access tokens from colluding members and abuse them to provide fake likes or comments to their members. We carried out a comprehens...

Descripción completa

Detalles Bibliográficos
Publicado en:Communications of the ACM Vol. 63; no. 5; pp. 103 - 112
Autores principales: Farooqi, Shehroze, Zaffar, Fareed, Leontiadis, Nektarios, Shafiq, Zubair
Formato: Artículo
Publicado: Association for Computing Machinery May2020
Materias:
Acceso en línea:Ver este registro en EBSCOhost
Descripción
Sumario:We uncovered a thriving ecosystem of large-scale reputation manipulation services on Facebook that leverage the principle of collusion. Collusion networks collect OAuth access tokens from colluding members and abuse them to provide fake likes or comments to their members. We carried out a comprehensive measurement study to understand how these collusion networks exploited popular third-party Facebook applications with weak security settings to retrieve OAuth access tokens. We infiltrated popular collusion networks using honeypots and identified more than one million colluding Facebook accounts by "milking" these collusion networks. We disclosed our findings to Facebook and collaborated with them to implement a series of countermeasures that mitigated OAuth access token abuse without sacrificing application platform usability for third-party developers.