Twitter, RSS and Facebook logos

  Connect with Security Magazine!
     Follow us on Twitter and Facebook or subscribe to our newsletters or RSS feeds.

Security Newswire

Study says Gaming Applications Increase Spam and Phishing in Social Networks

In order to reach high scores, social entertainment applications require users to gather a considerable number of friends and supporters to play the same game, leading to player-development of social gaming channels, groups and fan pages to facilitate player interaction, says a study on the subject by BitDefender.
 
Spammers and phishers exploit the increasing trend of social gaming with fake profiles and bots that send spam messages to groups, as the study shows. Unlike the regular social networking spam, when the users are enticed to add the spammer in their circle of friends, the social gaming-related phony profiles are willingly added by the users as an immediate consequence of their interest in enlarging the supportive players' community. This makes it almost impossible for the bogus accounts to be automatically suspended, since the spammers' action does not constitute an abuse.
 
The study also demonstrates that the most successful fake accounts are those miming real profiles, which hold plenty of details and pictures of the "user." In an acceptance experiment, BitDefender researchers created three honeypot profiles -- one without any picture and holding few details, another with an image and limited information and a third with a large amount of data and photos. All three profiles where subscribed to general interest groups. One hour after adding people to each profile, the circle of friends enlarged with 23 connections for the first profile, 47 for the second profile and 53 for the third profile. After joining social games groups, the volume of users willing to add unknown people drastically increased. Within 24 hours, 85 users accepted a request from the first profile, 108 from the second and 111 from the third.
 
"Users are more likely to accept spammers in their friends list when they are in a social network than in any other online communication environment," said George Petre, BitDefender threat intelligence team leader and author of the case study.
 
The security implications are numerous, ranging from the consolidation and increase of the spamming power, data and ID theft, accounts hijacking to malware dissemination. A shortened URL posted without any explanation on each honeypot profile was followed by 24 percent of the friends from the three accounts, even if they did not know who posted it and where it was going.
 
"This fact brings spam and social engineering schemes closer to the user than any e-mail spam or online scam. Moreover, we have seen that in a social applications environment, users can easily be tricked to add spammers to their profile. Thus, we recommend social gaming aficionados use extreme caution before enlarging their circle of friends," Petre added.
 
The complete case study is available at http://download.bitdefender.com/resources/files/Main/file/fb-another_breach_in_the_wall.pdf
You must register or login in order to post comments.

Multimedia

Videos

Image Galleries

Stanley Customer Appreciation Event at ASIS 2011

Customers enjoyed the annual Stanley customer appreciation event during ASIS 2011 in Orlando.

Podcasts

The New Age of Video Surveillance
In this podcast, Bill Lawrence, director of Service Solutions and Platforms for ADT Security Services, explains the growing interest in video surveillance by both government agencies as well as businesses of every stripe. He discusses what any organization should consider before investing heavily in the technology. Lawrence is a 25-year veteran of both the information technology and physical security industries, with extensive experience in network video surveillance and physical security convergence.
More Podcasts

Your Time

On a daily basis, how much work time do you estimate that you spend addressing an emergency or crisis within your organization?
See Poll Results Poll Archive

THE SECURITY STORE

comptiahighriseproductphoto
CompTIA Security+ Certification Study Guide
CompTIA's Security+ certification is a globally-recognized, vendor neutral exam that has helped over 60,000 IT professionals reach further and higher in their careers. The current Security+ exam (SY0-201) focuses more on being able to deal with security issues rather than just identifying them.
More Products

Clear Seas Research

Clear Seas ResearchWith access to over one million professionals and more than 60 industry-specific publications,Clear Seas Research offers relevant insights from those who know your industry best. Let us customize a market research solution that exceeds your marketing goals.

Vertical Sector Focus: Critical Infrastructures

criticalhomepagethumbFrom terrorism to vandalism, it’s preparedness, response, training and partnerships. Learn about some of the critical security issues facing this sector.

Visit the Critical Infrastructure page to read more.  

STAY CONNECTED

facebooklogo twitterlogo  linkedinlogo  YouTube icon