Putting Out a HIT: Crowdsourcing Malware Installs
نویسندگان
چکیده
Today, several actors within the Internet’s burgeoning underground economy specialize in providing services to like-minded criminals. At the same time, gray and white markets exist for services on the Internet providing reasonably similar products. In this paper we explore a hypothetical arbitrage between these two markets by purchasing “Human Intelligence” on Amazon’s Mechanical Turk service, determining the vulnerability of and cost to compromise the computers being used by the humans to provide this service, and estimating the underground value of the computers which are vulnerable to exploitation. We show that it is economically feasible for an attacker to purchase access to high value hosts via Mechanical Turk, compromise the subset with unpatched, vulnerable browser plugins, and sell access to these hosts via Pay-Per-Install programs for a tidy profit. We also present supplementary statistics gathered regarding Mechanical Turk workers’ browser security, antivirus usage, and willingness to run arbitrary programs in exchange for a small monetary reward.
منابع مشابه
In-HIT Example-Guided Annotation Aid for Crowdsourcing UI Components
This paper presents an approach to crowdsourcing annotations of UI components from images. Using the “Find-Draw-Verify” task design, an in-HIT exampleguided annotation aid is proposed to facilitate workers thereby improving the result quality.
متن کاملWord Sense Inventories by Non-Experts
In this paper, we explore different strategies for implementing a crowdsourcing methodology for a single-step construction of an empirically-derived sense inventory and the corresponding sense-annotated corpus. We report on the crowdsourcing experiments using implementation strategies with different HIT costs, worker qualification testing, and locale restrictions. We describe multiple adjustmen...
متن کاملOpportunities for Crowdsourcing Research on Amazon Mechanical Turk
Many crowdsourcing studies have been conducted that utilize Amazon Mechanical Turk, a crowdsourcing marketplace platform. The Amazon Mechanical Turk team proposes that comprehensive studies in the areas of HIT design, workflow and reviewing methodologies, and compensation strategies will benefit the crowdsourcing field by establishing a standard library of repeatable patterns and protocols. Author
متن کاملImpact of HIT Design on Crowdsourcing Relevance
In this paper we investigate the design and implementation of effective crowdsourcing tasks in the context of book search evaluation. We observe the impact of aspects of the Human Intelligence Task (HIT) design on the quality of relevance labels provided by the crowd. We assess the output in terms of label agreement with a gold standard data set and observe the effect of the crowdsourced releva...
متن کاملAppSachet: Distributed App Delivery from the Edge Cloud
With total app installs touching 100 Billion in 2015, the increasing number of active devices that support apps are posed to result in 200 billion downloads by 2017. Data center based App stores offering users convenient app access, however, cause congestion in the last mile of the Internet, despite use of content delivery networks (CDNs) or ISP-based caching. This paper explores the new paradi...
متن کامل