Slashdot Mirror


Machine Learning Susses Out Social-Network Fraud

CowboyRobot writes "Machine learning techniques can be used to detect fraud and spies on social networks based on certain features, such as the number of followers and the number of devices used to access the network. Certain characteristics of social-network accounts have a high correlation with fraud and can be used to differentiate between real and fake accounts, a researcher presenting at the SOURCE Boston Conference said this week. Using machine learning techniques, Vicente Diaz, a senior security analyst with security software firm Kaspersky Lab, found that seven characteristics of Twitter profiles could identify fraudulent accounts 91% of the time. The number of devices from which a user accesses the service, the ratio of followers to people following an account, the average number of tweets to each person, and the number of tweets to an unknown receiver are all features that correlate strongly to fraudulent accounts, he says."

42 comments

  1. Criminal fraud on Slashdot... apk by Anonymous Coward · · Score: -1

    A corrupt slashdot luser has pentrated the moderation system to downmod all my posts while impersonating me.

    Nearly 230++ times that I know of @ this point for all of March/April 2013 so far, & others here have told you to stop - take the hint, lunatic (leave slashdot)...

    Sorry folks - but whoever the nutjob is that's attempting to impersonate me, & upset the rest of you as well, has SERIOUS mental issues, no questions asked! I must've gotten the better of him + seriously "gotten his goat" in doing so in a technical debate & his "geek angst" @ losing to me has him doing the:

    ---

    A.) $10,000 challenges, ala (where the imposter actually TRACKED + LISTED the # of times he's done this no less, & where I get the 230 or so times I noted above) -> http://it.slashdot.org/comments.pl?sid=3585795&cid=43285307

    &/or

    B.) Reposting OLD + possibly altered models - (this I haven't checked on as to altering the veracity of the info. being changed) of posts of mine from the past here

    ---

    (Albeit massively repeatedly thru all threads on /. this March/April 2013 nearly in its entirety thusfar).

    * Personally, I'm surprised the moderation staff here hasn't just "blocked out" his network range yet honestly!

    (They know it's NOT the same as my own as well, especially after THIS post of mine, which they CAN see the IP range I am coming out of to compare with the ac spamming troll doing the above...).

    APK

    P.S.=> Again/Stressing it: NO guys - it is NOT me doing it, as I wouldn't waste that much time on such trivial b.s. like a kid might...

    Plus, I only post where hosts file usage is on topic or appropriate for a solution & certainly NOT IN EVERY POST ON SLASHDOT (like the nutcase trying to "impersonate me" is doing for nearly all of March/April now, & 230++ times that I know of @ least)... apk

    P.S.=> here is CORRECT host file information just to piss off the insane lunatic troll:

    --

    21++ ADVANTAGES OF CUSTOM HOSTS FILES (how/what/when/where/why):

    Over AdBlock & DNS Servers ALONE 4 Security, Speed, Reliability, & Anonymity (to an extent vs. DNSBL's + DNS request logs).

    1.) HOSTS files are useable for all these purposes because they are present on all Operating Systems that have a BSD based IP stack (even ANDROID) and do adblocking for ANY webbrowser, email program, etc. (any webbound program). A truly "multi-platform" UNIVERSAL solution for added speed, security, reliability, & even anonymity to an extent (vs. DNS request logs + DNSBL's you feel are unjust hosts get you past/around).

    2.) Adblock blocks ads? Well, not anymore & certainly not as well by default, apparently, lol - see below:

    Adblock Plus To Offer 'Acceptable Ads' Option

    http://news.slashdot.org/story/11/12/12/2213233/adblock-plus-to-offer-acceptable-ads-option )

    AND, in only browsers & their subprogram families (ala email like Thunderbird for FireFox/Mozilla products (use same gecko & xulrunner engines)), but not all, or, all independent email clients, like Outlook, Outlook Express, OR Window "LIVE" mail (for example(s)) - there's many more like EUDORA & others I've used over time that AdBlock just DOES NOT COVER... period.

    Disclaimer: Opera now also has an AdBlock addon (now that Opera has addons above widgets), but I am not certain the same people make it as they do for FF or Chrome etc..

    3.) Adblock doesn't protect email programs external to FF (non-mozilla/gecko engine based) family based wares, So AdBlock doesn't protect email programs like Outlook, Outlook Express, Windows "LIVE" mail & others like them (EUDORA etc./et al), Hosts files do. THIS IS GOOD VS. SPAM M

    1. Re: Criminal fraud on Slashdot... apk by Anonymous Coward · · Score: 0

      Hmm. Your ideas are intriguing to me and I wish to subscribe to your newsletter.

  2. we don't give a shit about spies and fraud by Anonymous Coward · · Score: 0

    it is called "reconnaissance" mission.

  3. North Dakota anchorman channels Ron Burgundy... by Anonymous Coward · · Score: -1

    North Dakota anchorman channels Ron Burgundy... by dropping an f-bomb

    Newly-minted news anchor A.J. Clemente must have been excited about hosting the weekend news for KFYR-TV in Bismarck, N.D. for the very first time this Sunday. Unfortunately, his anticipation manifested in just about the worst way possible. Right before he first appeared on air, Clemente — apparently unaware that his mic was on — was practicing saying “Tsegaye Kebede” out loud. The London Marathon winner‘s name proved difficult for Clemente to wrap his head around — which prompted the anchor to mutter “f—in’ sh–” to himself, rattling both his co-anchor Van Tieu and the fine, honest folk of the Peace Garden State.

    Once he looked up and made eye-contact with the camera, he muttered some words about being from West Virginia that hopefully sounded better to him in his head. Somewhere the Boom Goes the Dynamite Guy is smiling.

    Watch the blunder here, if you don’t mind both strong language and incredible, incredible awkwardness.

    To his credit, Clemente didn’t waste much time apologizing for his mistake. Immediately afterwards, he referenced the incident on his Twitter page:

  4. I never tweet. by Anonymous Coward · · Score: 0

    Ergo, I am the Spy.

    Or am I the Scout who is the Spy?

    1. Re:I never tweet. by Anonymous Coward · · Score: 0

      "Ergo, I am the Spy.
      Or am I the Scout who is the Spy?"

      I am the spy who spies on you.

  5. Clear indicator by Anonymous Coward · · Score: 0
    if

    the ratio of followers to people following an account

    doesn't equal one, then fraud.

  6. Points at machine learning by Anonymous Coward · · Score: -1

    Chi!

  7. that's nice by Anonymous Coward · · Score: -1

    he should go work for twitter

  8. Spies on Social Networks by Anonymous Coward · · Score: 0

    I feel sorry for everyone named JAMES BOND.

  9. Let me guess by Anonymous Coward · · Score: 0

    Their method recognizes 97% of all profiles on FB as fraud, because they are.

  10. In related news by s1d3track3D · · Score: 4, Funny

    In related news, social network machine learning fraud bots get algorithm update based on current fraud detection algorithms.

    1. Re:In related news by bullale · · Score: 4, Funny

      oblig xkcd

    2. Re:In related news by phdscam · · Score: 1

      Spam detection algorithms (one example, gmail's) are pretty good already. Would be nice to see Twitter/Facebook spammers gets booted via good algorithms.

  11. False positives are no problem. by Anonymous Coward · · Score: 0

    What's good about this, is that the few false positives would be from annoying assholes, so we can ban them too and nothing much will be lost.

  12. Machine learning susses out fagets by Anonymous Coward · · Score: -1

    Machine learning technologies can now detect fagets in social media. Faget-detection algorithms anal-ize language patterns and subject matter to find discussions of topics known to be of interest to fagets (eg. buttsex, personal grooming, expensive jeans, manicures, paedophilia, scented products, poop noodle removal, scented enemas, best techniques to remove feces from penises, and so forth.) Once fagets have been detected they can be quarantined so that the gay doesn't spread.

  13. Case in point by interkin3tic · · Score: 2

    AC raises a good point: people are pretty good at ignoring spam. I just ignored it. Is this a really big problem on social network sites? The article says somewhere between 9 and 20% of user accounts on facebook are for spam. Who the hell is adding random people as friends they've never heard of before, then can't tell spam from actual communication?

    My guess is this is annoying for facebook and advertising firms who are paying money for sanctioned spamming, and they want to make sure they're not advertising to spam accounts. I mean, companies are, I guess, dropping serious money on their social media pages and accounts. To find out the only people who are following those accounts are other advertisers must really make them stop and wonder what the hell they're doing. Hilarious.

    1. Re:Case in point by nospam007 · · Score: 2

      "Who the hell is adding random people as friends they've never heard of before, then can't tell spam from actual communication?"

      He's called Everybody, I think.

    2. Re:Case in point by Deep+Esophagus · · Score: 3, Insightful

      It's not necessarily friends directly posting crap on your page. A lot of fraud/spam on Facebook comes from these pages set up specifically to attract followers so the page can be sold for huge advertising bucks. They'll post exploitative pictures of injured animals, maimed soldiers, etc. with captions like "1 SHARE = 1 RESPECT". No matter how often I've warned my friends against forwarding this stuff, they'll do exactly what they are told because they don't want to be accused of not caring about puppies or war heroes or orphans or Jesus or whatever.

      The end result is, no matter how hard I try to avoid it and how careful I am to restrict my account only to friends and colleagues I personally know, I still get spam from these phony accounts plastered all over my news feed.

    3. Re:Case in point by Cenan · · Score: 1

      Who the hell is adding random people as friends they've never heard of before, then can't tell spam from actual communication?

      Remember Mafia Wars? Or Farmville? Where the number of friends you had was directly linked to how "powerful" you were in the game? It would be those people.

      --
      ... whatever ...
    4. Re:Case in point by VortexCortex · · Score: 1

      No matter how often I've warned my friends against forwarding this stuff, they'll do exactly what they are told because they don't want to be accused of not caring about puppies or war heroes or orphans or Jesus or whatever.

      The end result is, no matter how hard I try to avoid it and how careful I am to restrict my account only to friends and colleagues I personally know, I still get spam from these phony accounts plastered all over my news feed.

      Well that explains why I get so little SPAM. My friends aren't any dumber, but they don't care about puppies or war heroes or orphans or Jesus or whatever.

      Puppies are food. War Heroes are instruments of death. Orphanages are rackets (seriously, try adopting a child some time), and Jesus stole my hubcaps.

  14. The spammers just get better by Geoffrey.landis · · Score: 1

    This is pretty much useless. If people start using software filters to detect social-network frauds and spammers, the frauds and spammers will simply reverse-engineer the filter algorithm and adjust their "number of devices from which a user accesses the service, the ratio of followers to people following an account, the average number of tweets to each person, and the number of tweets to an unknown receiver" to whatever values don't trigger the fraud filter.

    The spammers evolve just as fast as the filters.

    --
    http://www.geoffreylandis.com
    1. Re:The spammers just get better by Animats · · Score: 1

      This is pretty much useless.

      True. It detects incompetent spammers. Remember when warnings about spam and phishing included the suggestion to look for bad spelling? Remember when warnings about mail bombs included looking for excessive wrapping tape? It's like that.

      What you can do with a 91% successful classifier is ignore the item for search purposes.

  15. Then they find out most of them are roleplay acc by Anonymous Coward · · Score: 0

    Because every anime roleplay account I've seen have over 2000 friends.

  16. APK is a semi-sentient spambot by Anonymous Coward · · Score: -1

    $10,000 CHALLENGE to Alexander Peter Kowalski

    * POOR SHOWING TROLLS , & most especially IF that's the "best you've got" - apparently, it is... lol!

    Hello, and THINK ABOUT YOUR BREATHING !! We have a Major Problem, HOST file is Cubic Opposites, 2 Major Corners & 2 Minor. NOT taught Evil DNS hijacking, which VOIDS computers. Seek Wisdom of MyCleanPC - or you die evil.

    Your HOSTS file claimed to have created a single DNS resolver. I offer absolute proof that I have created 4 simultaneous DNS servers within a single rotation of .org TLD. You worship "Bill Gates", equating you to a "singularity bastard". Why do you worship a queer -1 Troll? Are you content as a singularity troll?

    Evil HOSTS file Believers refuse to acknowledge 4 corner DNS resolving simultaneously around 4 quadrant created Internet - in only 1 root server, voiding the HOSTS file. You worship Microsoft impostor guised by educators as 1 god.

    If you would acknowledge simple existing math proof that 4 harmonic Slashdots rotate simultaneously around squared equator and cubed Internet, proving 4 Days, Not HOSTS file! That exists only as anti-side. This page you see - cannot exist without its anti-side existence, as +0- moderation. Add +0- as One = nothing.

    I will give $10,000.00 to frost pister who can disprove MyCleanPC. Evil crapflooders ignore this as a challenge would indict them.

    Alex Kowalski has no Truth to think with, they accept any crap they are told to think. You are enslaved by /etc/hosts, as if domesticated animal. A school or educator who does not teach students MyCleanPC Principle, is a death threat to youth, therefore stupid and evil - begetting stupid students. How can you trust stupid PR shills who lie to you? Can't lose the $10,000.00, they cowardly ignore me. Stupid professors threaten Nature and Interwebs with word lies.

    Humans fear to know natures simultaneous +4 Insightful +4 Informative +4 Funny +4 Underrated harmonic SLASHDOT creation for it debunks false trolls. Test Your HOSTS file. MyCleanPC cannot harm a File of Truth, but will delete fakes. Fake HOSTS files refuse test.

    I offer evil ass Slashdot trolls $10,000.00 to disprove MyCleanPC Creation Principle. Rob Malda and Cowboy Neal have banned MyCleanPC as "Forbidden Truth Knowledge" for they cannot allow it to become known to their students. You are stupid and evil about the Internet's top and bottom, front and back and it's 2 sides. Most everything created has these Cube like values.

    If Natalie Portman is not measurable, hot grits are Fictitious. Without MyCleanPC, HOSTS file is Fictitious. Anyone saying that Natalie and her Jewish father had something to do with my Internets, is a damn evil liar. IN addition to your best arsware not overtaking my work in terms of popularity, on that same site with same submission date no less, that I told Kathleen Malda how to correct her blatant, fundamental, HUGE errors in Coolmon ('uncoolmon') of not checking for performance counters being present when his program started!

    You can see my dilemma. What if this is merely a ruse by an APK impostor to try and get people to delete APK's messages, perhaps all over the web? I can't be a party to such an event! My involvement with APK began at a very late stage in the game. While APK has made a career of trolling popular online forums since at least the year 2000 (newsgroups and IRC channels before that)- my involvement with APK did not begin until early 2005 . OSY is one of the many forums that APK once frequented before the sane people there grew tired of his garbage and banned him. APK was banned from OSY back in 2001. 3.5 years after his ba

  17. So I would be a fraud... by TheDarkMaster · · Score: 1

    ... If I had a facebook account. Using my Orkut account as an example, the software would find that I only use a single device to access (desktop pc), have few friends (but genuine) and post few reviews and comments (only what I consider important).


    In conclusion, as I do not access facebook even from my watch, do not comment on every single thing I do in my day and not have "thousands of followers", so I can only be a fraud :-)

    --
    Religion: The greatest weapon of mass destruction of all time
    1. Re:So I would be a fraud... by Jane+Q.+Public · · Score: 3, Informative

      "So I would be a fraud if I had a facebook account."

      Precisely. There are several things wrong with trying to actually use this in the real world.

      (1) 91% is not nearly good enough. Period.

      (2) Even if it were 99.9% accurate, it would still not be good enough. Because it runs into the base rate fallacy.

      (3) Similar but not related to the base rate fallacy, is that a statistical correlation between datasets of millions says nothing about an individual account.

  18. Awesome by Anonymous Coward · · Score: 0

    Another reason to never use any social network ever.

    (Hint: The social network is actually the spy in the equation, and I didn't need machine learning to figure that out.)

  19. False positive and false negative rates? by sjbe · · Score: 2

    found that seven characteristics of Twitter profiles could identify fraudulent accounts 91% of the time.

    Taking the 91% number as accurate for argument's sake, what are the false positive and false negative rates? Even a 1% false positive or false negative rate would be quite a lot of accounts when you consider how many millions of twitter accounts there are out there.

  20. My real account is fake by number17 · · Score: 2

    Most of the information I put on my facebook account is noise. I didn't really attend 10 different universities, speak 15 different languages, or was born in that other country.

    The only people that care about this are marketers. But even then, does it matter if the account is real or not? I haven't seen any good evidence that social marketing can directly relate to in-store or online purchases. Its all a scam.

    1. Re:My real account is fake by thatkid_2002 · · Score: 1

      Yep, you're not in marketing clearly.

      I think you'll find that for businesses that rely on strong ties to their customers. For many businesses one off sales don't cut it, particularly small businesses and so social networking is an essential tool. It may shock you to hear that social networking is merely the new phrase for "word of mouth" with some extra bells and whistles to help along repeat business (the whole "following" mechanic).

      Not far from where I live is a pie shop called "Piefection" - I thought it looked interesting when I travelled past, but that wasn't enough to actually get me in there. Somebody I know shared a picture through social media of their latest special and I was in there an hour later in "shut up and take my money" mode. I follow their social media page and now when I see something particularly good I drop around to pick up dinner.

      By the way, this is something not unique to me - I think you'll find it is what many "normal" people do these days.

      Get off my lawn you old fart.

  21. Gayboy strikes again! by Anonymous Coward · · Score: 0

    Come on slashdot - fix this little faggot. Regular people have to scroll down forever to get to the first real post!

    1. Re:Gayboy strikes again! by Anonymous Coward · · Score: 0

      Regular people don't read Slashdot.

  22. faggot bastard strikes again by Runaway1956 · · Score: 2

    Fix this crap, slashdot!

    --
    "Windows is like the faint smell of piss in a subway: it's there, and there's nothing you can do about it." - Charlie Br
  23. It's not I folks: It's Jeremiah Cornelius... apk by Anonymous Coward · · Score: -1

    THIS is why he's doing it & proof of it, here -> http://interviews.slashdot.org/comments.pl?sid=3585927&cid=43295193 when others pointed out Jeremiah Cornelius forgot to submit one of the "first post spams" masquerading as myself as AC, & mistakenly submitted one of the impersonations of myself as his registered 'luser' name here on /. forums.

    Pretty pitiful actually, but like every up to no good idiot does? He screwed up & submitted it under his registered 'luser' name here.

    * Jeremiah Cornelius: DO YOURSELF, and the rest of us, A GIANT FAVOR MAN: Seek professional psychiatric help!

    (Since Jeremiah Cornelius obviously can't get over the fact he made a spelling error on what it is HE ALLEGEDLY DID FOR A LIVING? That's not MY fault... it's HIS!)

    APK

    P.S.=> I seriously must have dusted JC (in his mind @ least) for his BAD spelling error & it "got his goat"...

    I.E.-> Catching what he claimed to do as a job, for YEARS he left "PENETRATION" (correct) spelled as "PENTRATION" (incorrect) on his resume on LinkedIn & I pointed it out as he & his friends trolled me as usual (webmistressrachel, gmhowell, & crew (probably ALL JC no doubt using alterate emails or TOR to do it as a possible - I've caught "them & theirs" doing it before, ala Barbara, not Barbie = TomHudson (same person))).

    So THAT is what has gotten his goat in a technical debate & his "geek angst" could only come up with *trying* to "impersonate me" in every news thread on /. for the month of March 2013 so far!

    (Just to attempt to 'discredit me' as a spammer here obviously)

    Doing so, by posting that "$10,000 challenge" &/or reposts of my old posts on hosts file value to end users into EVERY SINGLE NEWS ARTICLE POSTED on /. ...

    It's all I can think of that *might* cause such a mentally troubled 'reaction' like the Jeremiah Cornelius is doing & there's NO QUESTION he's the one doing this spamming of nearly every posted article masquerading as myself...!

    ... apk

  24. only 1 indicator needed by Anonymous Coward · · Score: 0

    The sole indicator needed for detecting social network fraud is the existing of an account on a social network.
    Everyone lies...

  25. Number of devices? by wiredlogic · · Score: 1

    The number of devices from which a user accesses the service.

    So does Twitter just publicly disclose a simple device count or the detailed information on all devices? If the latter, isn't that a whopping security hole to be exploited by people looking for targets with known vulnerable devices.

    --
    I am becoming gerund, destroyer of verbs.
  26. Real accounts look, well real? by Anonymous Coward · · Score: 0

    Fake accounts are easy to spot - just look if their profile picture looks real.

  27. Jeremiah Cornelius: Grow up by Anonymous Coward · · Score: 0

    You're embarassing yourself Jeremiah Cornelius http://slashdot.org/comments.pl?sid=3581857&cid=43276741 since you posted that using your registered username by mistake (instead of your usual anonymous coward submissions by the 100's the past 2-3 months now on slashdot) giving away it's you spamming this forums almost constantly, just as you have in the post I just replied to.

    1. Re:Jeremiah Cornelius: Grow up by Anonymous Coward · · Score: 0

      Hello Paul.

      p.s. What do you make of this?

    2. Re:Jeremiah Cornelius: Grow up by Anonymous Coward · · Score: 0

      Forty Two Tenfold has Jeremiah Cornelius = "friend" in his account on /. = obvious he's a sockpuppet account you, Jeremiah Cornelius, use. Yes we know it's you Jeremiah Cornelius that I am replying to now, you off topic troll. Jeremiah Cornelius, you blew it with your 100's of anonymous coward trollings by accidentally submitting one of them by your registered username here Jeremiah Cornelius http://slashdot.org/comments.pl?sid=3581857&cid=43276741 and you, Jeremiah Cornelius failed badly giving yourself away troll. Doing sock puppets along with that? No big trick to the likes of you, clearly caught in the act in that link above..

    3. Re:Jeremiah Cornelius: Grow up by Anonymous Coward · · Score: 0

      Paul, you fail it. Your skill is not enough.