Escolar Documentos
Profissional Documentos
Cultura Documentos
ZEROFOX RESEARCH
//
TABLE OF CONTENTS
ZEROFOX RESEARCH
//
BY THE NUMBERS:
2M
80%
INSTAGRAM POSTS
ANALYZED BY ZEROFOX
SCAMS CREATED
FOR EVERY 1 TAKEN DOWN
4,574
37
23
1,386
98.74%
$420M
ACCURACY OF THE
PREDICTIVE MODEL
ZEROFOX RESEARCH
//
2. INTRODUCTION
2.1 SCAMS IN THE DIGITAL AGE
ZEROFOX RESEARCH
//
ZEROFOX RESEARCH
//
ZEROFOX RESEARCH
//
FIGURE 2.
FIGURE 3.
ZEROFOX RESEARCH
//
Training
Lable Data
Benign
Raw Instagram Data
Malicious
Predictive Model
Predicitng
ZeroFOX 2016 All Rights Reserved
10
ZEROFOX RESEARCH
//
FIGURE 4.*
FIGURE 5.
FIGURE 6.*
ZEROFOX RESEARCH
//
FIGURE 7.
FIGURE 8.
n order to further refine the performance of our model, we also took into account
behavioral and engagement metrics such as number of likes, comments, hashtags
and more. We found high separability between the number of hashtags in scam
posts as compared to benign posts, meaning the number of hashtags was a
powerful predictor to determine whether a post was a scam or not (Figure 10).
Furthemore, we found that scam posts demonstrated a lower number of likes
compared to their benign counterparts (Figure 11).
FIGURE 9.
FIGURE 10.
FIGURE 11.
12
ZEROFOX RESEARCH
//
o gain deeper insights into the most commonly cooccurring features, cluster analysis was performed on
the data with normalization based on the number of scams
per hashtag. Military-centric institutions are clustered
together. We conclude from this that military members are
specifically targeted by scammers.
For further evidence of this conclusion, topic models
were built to uncover thematic structures within the
data. A topic model is a probabilistic model that clusters
topics by choosing the strongest hypothesis for how the
documents in the dataset were created (Figure 12). Topic
model showed that military-related keywords are clustered
together in intertopic distance space (Figure 12A),
providing further evidence that military members may be
specific targets of scam campaigns on Instagram.
The data also showed that location-related terms (Figure
12B) and holiday-related terms formed clusters, which
sheds light on some other tactics employed by scammers.
They may be trying to gain trust based on an individuals
location or use a victims desperation around the holidays
to propagate their attacks.
FIGURE 12.
FIGURE 12A.*
FIGURE 12B.
13
ZEROFOX RESEARCH
//
FIGURE 13.
14
ZEROFOX RESEARCH
//
FIGURE 14.
FIGURE 15.
FIGURE 16.
15
ZEROFOX RESEARCH
//
FIGURE 18
FIGURE 17
16
ZEROFOX RESEARCH
//
17
ZEROFOX RESEARCH
//
EQUATION 2.
EQUATION 1.
18
ZEROFOX RESEARCH
//
$200
$300
$400
$500
26,500,000
52,500,000
78,750,000
105,000,000
131,250,000
.5
52,500,000
105,000,000
157,500,000
210,000,000
262,500,000
105,000,000
210,000,000
315,000,000
420,000,000
525,000,000
ZeroFOX Estimate
210,000,000
420,000,000
630,000,000
840,000,000
1,050,000,000
420,000,000
840,000,000
1,260,000,000
1,680,000,000
2,100,000,000
FIGURE 19.
Potential outcomes estimate the annual cost over the course of a year to financial institutions and/or their customers, or
in other words C as a function of the 2 variables r and c as defined by Eq 2. Highlighted cell represents the most likely
scenaio considering all available data.
19
ZEROFOX RESEARCH
//
AFFECTED ORGANIZATIONS
NEED TO TAKE AN
AUTOMATED, DATA-DRIVE
APPROACH TO IDENTIFYING
AND REMEDIATING SOCIAL
MEDIA THREATS, INCLUDING
MONEY FLIPPING SCAMS ON
INSTAGRAM
20
ZEROFOX RESEARCH
//
ABOUT ZEROFOX
ZeroFOX, the innovator of social media security, protects
modern organizations from the dynamic risks of social
media and digital channels. Each day, ZeroFOXs cloudbased, SaaS platform processes millions of posts
and accounts across the social landscape, spanning
Facebook, LinkedIn, Twitter, Instagram, Google+, YouTube
and more. Using targeted data collection, intelligent
analysis and automated remediation, ZeroFOX protects
businesses and government agencies around the world
against phishing attacks, information loss, account
compromise, fraud, compliance violations and financial
loss.
Led by a team of information security and high-growth
start-up veterans, ZeroFOX has raised over $40M in
funding from NEA, Highland Capital and others, and
has collected top industry awards such as the SINET16
Champion, DarkReadings Top Security Startups to
Watch, Tech Council of Marylands Technology Company
of the Year, and the Security Tech Trailblazer of the Year.
21
ZEROFOX RESEARCH
//
8. REFERENCES
1.
2.
3.
4.
5.
http://www.aba.com/tools/function/cyber/pages/card-cracking.aspx
http://wspa.com/2015/07/23/flipping-money-scam-growing-on-social-media/
http://www.cleveland.com/broadview-heights/index.ssf/2013/11/instagram_fraud_scams_woman_ou.html
http://www.fraud.org/component/content/article/2-uncategorised/80
http://www.omaha.com/news/metro/instagram-bank-scam-costs-omaha-woman/article_4743b3e8-a5e1-5e68-901ee9fce9291803.html
6. http://www.cisco.com/c/dam/assets/offers/pdfs/cisco-asr-2016.pdf
7. https://www.fbi.gov/news/news_blog/2014-ic3-annual-report
8. http://www.mcafee.com/us/resources/reports/rp-six-trends-security.pdf
9. http://www.fraud.org/component/content/article/2-uncategorised/71-flipping-money-scammers-lurking-in-social-media
10. http://www.bbb.org/blog/2015/08/spot-a-money-flipping-scam-on-instagram/
11. http://blogs.wf.com/news/2015/09/two-common-social-media-scams-avoid/
12. https://www.westernunion.com/us/en/fraudawareness/fraud-types.html
13. https://communities.usaa.com/t5/USAA-News/Insta-Scam-Fraudsters-Target-USAA-Members-with-Card-Cracking/bap/64486
14. https://www.navyfederal.org/life-money/managing-your-money/articles/security/social-media-scams.php
15. https://www.midwestone.com/customer-service/privacy-and-security/fraud-info/avoid-card-cracking-scam
16. https://www.bethpagefcu.com/advice-planning/fraud-protection/social-media-fraud.aspx
17. https://www.veridiancu.org/news/advice/common-scams-and-how-to-avoid-them.aspx
18. http://blog.nasafcu.com/2015/09/instagram-money-scam-involves-your-debit-card-and-pin/
19. http://www.thevictorybank.com/Banking/Online/Card%20Cracking%20Alert-5-19-15.pdf
20. http://www.pwc.com/gx/en/financial-services/pdf/Banking-banana-skins-2015-final.pdf
21. https://www.instagram.com/press/
22
ZEROFOX RESEARCH
//
23