Understanding the role of sender reputation in abuse reporting and cleanup

Journal Article (2016)
Authors

Orcun Cetin (TU Delft - Organisation & Governance)

Mohammad Hanif Jhaveri (Southern Methodist University)

Carlos Hernandez Ganan (TU Delft - Organisation & Governance)

Michel Van Van Eeten (TU Delft - Organisation & Governance)

Tyler Moore (Southern Methodist University)

Research Group
Organisation & Governance
Copyright
© 2016 F.O. Çetin, Mohammad Hanif Jhaveri, C. Hernandez Ganan, M.J.G. van Eeten, Tyler Moore
To reference this document use:
https://doi.org/10.1093/cybsec/tyw005
More Info
expand_more
Publication Year
2016
Language
English
Copyright
© 2016 F.O. Çetin, Mohammad Hanif Jhaveri, C. Hernandez Ganan, M.J.G. van Eeten, Tyler Moore
Research Group
Organisation & Governance
Issue number
1
Volume number
2
Pages (from-to)
83-98
DOI:
https://doi.org/10.1093/cybsec/tyw005
Reuse Rights

Other than for strictly personal use, it is not permitted to download, forward or distribute the text or part of it, without the consent of the author(s) and/or copyright holder(s), unless the work is under an open content license such as Creative Commons.

Abstract

Motivation: Participants on the front lines of abuse reporting have a variety of options to notify intermediaries and resource owners about abuse of their systems and services. These can include emails to personal messages to blacklists to machine-generated feeds. Recipients of these reports have to voluntarily act on this information. We know remarkably little about the factors that drive higher response rates to abuse reports. One such factor is the reputation of the sender. In this article, we present the first randomized controlled experiment into sender reputation. We used a private datafeed of Asprox-infected websites to issue notifications from three senders with different reputations: an individual, a university and an established anti-malware organization.

Results: We find that our detailed abuse reports significantly increase cleanup rates. Surprisingly, we find no evidence that sender reputation improves cleanup. We do see that the evasiveness of the attacker in hiding compromise can substantially hamper cleanup efforts. Furthermore, we find that the minority of hosting providers who viewed our cleanup advice webpage were much more likely to remediate infections than those who did not, but that website owners who viewed the advice fared no better.

Files

Tyw005.pdf
(pdf | 1.16 Mb)
License info not available