Íntegro: Leveraging victim prediction for robust fake account detection in large scale OSNs

Yazan Boshmaf*, Dionysios Logothetis, Georgos Siganos, Jorge Lería, Jose Lorenzo, Matei Ripeanu, Konstantin Beznosov, Hassan Halawa

*Corresponding author for this work

Research output: Contribution to journalArticlepeer-review

67 Citations (Scopus)

Abstract

Detecting fake accounts in online social networks (OSNs) protects both OSN operators and their users from various malicious activities. Most detection mechanisms attempt to classify user accounts as real (i.e., benign, honest) or fake (i.e., malicious, Sybil) by analyzing either user-level activities or graph-level structures. These mechanisms, however, are not robust against adversarial attacks in which fake accounts cloak their operation with patterns resembling real user behavior. In this article, we show that victims - real accounts whose users have accepted friend requests sent by fakes - form a distinct classification category that is useful for designing robust detection mechanisms. In particular, we present Íntegro - a robust and scalable defense system that leverages victim classification to rank most real accounts higher than fakes, so that OSN operators can take actions against low-ranking fake accounts. Íntegro starts by identifying potential victims from user-level activities using supervised machine learning. After that, it annotates the graph by assigning lower weights to edges incident to potential victims. Finally, Íntegro ranks user accounts based on the landing probability of a short random walk that starts from a known real account. As this walk is unlikely to traverse low-weight edges in a few steps and land on fakes, Íntegro achieves the desired ranking. We implemented Íntegro using widely-used, open-source distributed computing platforms, where it scaled nearly linearly. We evaluated Íntegro against SybilRank, which is the state-of-the-art in fake account detection, using real-world datasets and a large-scale deployment at Tuenti - the largest OSN in Spain with more than 15 million active users. We show that Íntegro significantly outperforms SybilRank in user ranking quality, with the only requirement that the employed victim classifier is better than random. Moreover, the deployment of Íntegro at Tuenti resulted in up to an order of magnitude higher precision in fake account detection, as compared to SybilRank.

Original languageEnglish
Pages (from-to)142-168
Number of pages27
JournalComputers and Security
Volume61
DOIs
Publication statusPublished - 1 Aug 2016

Keywords

  • Fake account detection
  • Online social networks
  • Social infiltration
  • Socialbots
  • Victim account prediction

Fingerprint

Dive into the research topics of 'Íntegro: Leveraging victim prediction for robust fake account detection in large scale OSNs'. Together they form a unique fingerprint.

Cite this