EDBT 2026 Demo / reviewers in the wild / expert
Damon McCoy
dblp:58/4016
· DBLP profile ↗
89ranked-venue papers
3as first author
23since 2021 · last 2026
0000-0001-7386-7260ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 56 · 3 first-author · 11 since 2021Computer networks · 13 · 2 since 2021Databases, data management, data science and information retrieval · 10 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 since 2021Human-computer interaction and ubiquitous computing · 9 · 7 since 2021Artificial intelligence and machine learning · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Caught in a Mafia Romance: How Users Explore Intimate Narratives with ChatbotsabstractAI chatbots, built using large language models, are increasingly integrated into society and mimic the patterns of human text exchanges. While previous research has raised concerns that humans may form romantic attachment to chatbots, the range of AI-mediated interactions that people wish to create for themselves or others with chatbots remains poorly understood, particularly given the fast evolving landscape of chatbots. We provide an empirical study of Character.AI (cAI), a popular chatbot platform that enables users to design and share character-based bots, and synthesize this with an analysis of Reddit posts from cAI users. Contrary to popular narratives, we identify that users want to: (1) engage in intimate role-play with young adult, masculine-presenting characters that place users in a position of inferior power in well-defined scenarios and (2) immerse themselves in boundless, fantasy settings. We further find that users problematize both the excessive and insufficient sexualized content in such interactions which warrants novel digital-safety features. Julia B. Kieserman, Cat Mai, Sara Lignell, Lucy Qin, Athanasios Andreou, Damon McCoy, Rosanna Bellini |
CHI | 6 |
| 2026 | Analyzing Social Media Claims regarding Youth Online Safety Features to Identify Problem Areas and Communication Gaps CSCW005abstractSocial media platforms have faced increasing scrutiny over whether and how they protect youth online. While online risks to children have been well-documented by prior research, how social media platforms communicate about these risks and their efforts to improve youth safety have not been holistically examined. To fill this gap, we analyzed N = 352 press releases and safety-related blogs published between 2019 and 2024 by four platforms popular among youth: YouTube, TikTok, Meta (Facebook and Instagram), and Snapchat. Leveraging both inductive and deductive qualitative approaches, we developed a comprehensive framework of seven problem areas where risks arise, and social media platforms claim to address these risks through various online safety features. Our analysis revealed uneven emphasis across problem areas, with most communications focused on Content Exposure and Interpersonal Communication, whereas less emphasis was placed on Content Creation, Data Access, and Platform Access. Additionally, we identified three problematic communication practices related to their described safety features, including discrepancies between feature implementation and availability, unclear or inconsistent explanations of safety feature operation, and a lack of evidence regarding the effectiveness of safety features in mitigating risks once implemented. Based on these findings, we discuss the communication gaps between risks and the described safety features, as well as the tensions in achieving transparency in platform communication. Our analysis of platform communication informs guidelines for responsibly communicating about youth safety features. Renkai Ma, Dominique Geißler, Stefan Feuerriegel, Tobias Lauinger, Damon McCoy, Pamela J. Wisniewski |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2025 | What's in a Label? Propaganda Labels and User Sharing Behavior on Social Media PlatformsabstractAuthentic information is vital for a society's ability to make rational decisions. Fabricated and manipulative information can be harmful to society as seen in cases of threatening events that were consequences of foreign propaganda and radical ideologies. While past research has studied dis- and misinformation on social media platforms, the study of propaganda has received much less attention. This study explores the sharing intentions of propaganda on social media platforms and develops an intervention to help detect it. In a randomized controlled trial setting, we added indicators to social media posts that used propaganda techniques to advance an agenda, including techniques that rely on fallacious reasoning, emotional rather than logical reasoning, etc. We then asked our participants (n=1,187) about their intention to engage with these posts. We found that participants were significantly (2.4 times) less likely to share these posts with indicators. We also found that participants’ political affiliation moderated their sharing intentions. We believe our findings provide valuable insights for the study of propaganda on social media platforms. Julia Jose, Chris Geeng, Kediel O. Morales, Damon McCoy, Rachel Greenstadt |
ICWSM | 4 |
| 2025 | Partnërka in Crime: Characterizing Deceptive Affiliate Marketing Offers
Victor Le Pochat, Cameron Ballard, Lieven Desmet, Wouter Joosen, Damon McCoy, Tobias Lauinger |
PAM | 5 |
| 2025 | Characterizing the Usability and Usefulness of U.S. Ad Transparency SystemsabstractOnline targeted ads are those shown only to certain users based on interests, demographics, or behaviors. Because targeted ads raise many privacy concerns, many platforms provide ad transparency systems (ATSs) to inform users about this practice. To better understand what current ATSs are communicating to users—and how—we first taxonomized the design and content of 22 of the most popular English-language websites' ATSs as presented to users in the United States. We found substantial differences across ATSs in both the prevalence of transparency-enhancing features (e.g., whether they show users what has been inferred about them) and the presentation of information (e.g., the terminology used, where settings are located). Across all platforms, however, we observed consistent ambiguity about what data is used to target ads and the actual impact of altering settings. To gauge how these different design choices impact users, we conducted an online user study in which 198 participants used their own account to explore the ATS of one of eight representative platforms. We found that many of the questions participants hoped the ATS would answer remained unanswered after exploring the ATS. More broadly, participants found current ATSs simultaneously complex and lacking key details. We pinpoint ATS design decisions that best support users. Kevin Bryson 0002, Arthur Borem, Phoebe Moh, Omer Akgul, Laura Edelson, Tobias Lauinger, Michelle L. Mazurek, Damon McCoy, Blase Ur |
SP | 8 |
| 2025 | 'It Would Be a Lot Harder for Them to Change Their Mind....They Grew Up in Like a Very Different Time and a Very Different Location': Barriers to Misinformation Corrections in Online Black and Latine Private SpacesabstractMisinformation disproportionately affects Black and Latine communities in the U.S., particularly spreading in private online groups where platform-based moderation and fact-checking are challenging. Close-tie corrections from family members and friends in online private spaces are crucial as they may be the primary form of correction within these communities. We conducted semi-structured interviews ( N =16) with participants to explore their barriers to correction and outcomes. Our findings illustrate various interpersonal and cultural barriers to successful correction, including family hierarchy, diaspora experiences, English as a second language, religion, racism, and sexism. Participants shared positive correction experiences, supported by shared cultural/community ties and lack of power difference between corrector and correctee. We connect our findings to Critical Race Theory and intersectionality, showing how misinformation correction experiences depend on a confluence of culture and identity relations. We offer recommendations for enhancing misinformation interventions to more effectively support the Black and Latine communities. Rafael Martinez, Chris Geeng, Damon McCoy |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2025 | Tracker Installations Are Not Created Equal: Understanding Tracker Configuration of Form Data CollectionabstractTargeted advertising is fueled by the comprehensive tracking of users' online activity. As a result, advertising companies, such as Google and Meta, encourage website administrators to not only install tracking scripts on their websites but configure them to automatically collect users' Personally Identifying Information (PII). In this study, we aim to characterize how Google and Meta's trackers can be configured to collect PII data from web forms. We first perform a qualitative analysis of how third parties present form data collection to website administrators in the documentation and user interface. We then perform a measurement study of 40,150 websites to quantify the prevalence and configuration of Google and Meta trackers. Our results reveal that both Meta and Google encourage the use of form data collection and include inaccurate statements about hashing PII as a privacy-preserving method. Additionally, we find that Meta includes configuring form data collection as part of the basic setup flow. Our large-scale measurement study reveals that while Google trackers are more prevalent than Meta trackers (72.6% vs. 28.2% of websites), Meta trackers are configured to collect form data more frequently (11.6% vs. 62.3%). Finally, we identify sensitive finance and health websites that have installed trackers that are likely configured to collect form data PII in violation of Meta and Google policies. Our study highlights how tracker documentation and interfaces can potentially play a role in users' privacy through the configuration choices made by the website administrators who install trackers. Julia B. Kieserman, Athanasios Andreou, Chris Geeng, Tobias Lauinger, Damon McCoy |
Proc. Priv. Enhancing Technol. | 5 |
| 2025 | More and Scammier Ads: The Perils of YouTube's Ad Privacy SettingsabstractWhen users disable online ad personalization, they might be anticipating to see fewer ads that are "relevant" to them as a trade-off for more privacy. In this paper, we show that the tradeoff can go much further than this intuition. We conducted controlled experiments on YouTube in Australia, Canada, Ireland, the United Kingdom, and the United States to investigate the impact of disabling ad personalization on the quantity and quality of ads that users receive. Through experiments where emulated users with different ad privacy settings watched sequences of 400 videos, we show that disabling ad personalization can lead to the user being shown as much as 1.30 times more pre-roll ads than the default (least private) setting. More concerning is that in our experiments, the proportion of predatory ads increased 2.69 times compared to the default setting, from 2.5% to 8.7% of ads. This result highlights that certain user demographics (in this case, privacy-conscious users) can be exposed to significantly higher rates of predatory ads, and suggests that the platform's efforts to curb such ads are still falling short. Cat Mai, Bruno Coelho, Julia B. Kieserman, Lexie Matsumoto, Kyle Spinelli, Eric Yang, Athanasios Andreou, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
Proc. Priv. Enhancing Technol. | 10 |
| 2024 | Stoking the Flames: Understanding Escalation in an Online Harassment CommunityabstractOnline harassment remains a prevalent problem for internet users. Its impact is made orders of magnitude worse when multiple harassers coordinate to conduct networked attacks. This paper presents an analysis of 231 threads in Kiwi Farms, a notorious online harassment community. We find that networked online harassment campaigns consists of three phases: target introduction, network decision, and network response. The first stage consists of the initial narrative elements, that are approved or not in stage two and expanded in stage three. Narrative building is a common element of all three stages. The network plays a key role in narrative building, adding elements to the narrative in at least 80 % of the threads, resulting in sustained harassment. This finding is central to our model of Continuous Narrative Escalation (CNE), that has two parts: (1) narrative continuation, the action of repeatedly adding new information to the existing narrative and (2) escalation, the aggravation of harassment that occurs as a consequence. In addition, we present insights from our analysis of 100 takedown requests threads, discussing received abuse reports. We find that these takedown requests are misused by the community and are used as elements to further fuel the narrative. We use our findings and framework to come up with a set of recommendations, that can inform harassment interventions and make online spaces safer. Kejsi Take, Victoria Zhong, Chris Geeng, Emmi Bevensee, Damon McCoy, Rachel Greenstadt |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2024 | What to Expect When You're Accessing: An Exploration of User Privacy Rights in People Search WebsitesabstractPeople Search Websites, a category of data brokers, collect, catalog, monetize and often publicly display individuals' personally identifiable information (PII). We present a study of user privacy rights in 20 such websites assessing the usability of data access and data removal mechanisms. We combine insights from these two processes to determine connections between sites, such as shared access mechanisms or removal effects. We find that data access requests are mostly unsuccessful. Instead, sites cite a variety of legal exceptions or misinterpret the nature of the requests. By purchasing reports, we find that only one set of connected sites provided access to the same report they sell to customers. We leverage a multiple step removal process to investigate removal effects between suspected connected sites. In general, data removal is more streamlined than data access, but not very transparent; questions about the scope of removal and reappearance of information remain. Confirming and expanding the connections observed in prior phases, we find that four main groups are behind 14 of the sites studied, indicating the need to further catalog these connections to simplify removal. Kejsi Take, Jordyn Young, Rasika Bhalerao, Kevin Gallagher 0001, Andrea Forte, Damon McCoy, Rachel Greenstadt |
Proc. Priv. Enhancing Technol. | 6 |
| 2023 | Propaganda Política Pagada: Exploring U.S. Political Facebook Ads en EspañolabstractIn 2021, the U.S. Hispanic population totaled 62.5 million people, 68% of whom spoke Spanish in their homes. To date, it is unclear which political advertisers address this audience in their preferred language, and whether they do so differently than for English-speaking audiences. In this work, we study differences between political Facebook ads in English and Spanish during 2020, the latest U.S. presidential election. Political advertisers spent $ 1.48 B in English, but only $ 28.8 M in Spanish, disproportionately little compared to the share of Spanish speakers in the population. We further find a lower proportion of election-related advertisers (which additionally are more liberal-leaning than in the English set), and a higher proportion of government agencies in the set of Spanish ads. We perform multilingual topic classification, finding that the most common ad topics in English were also present in Spanish, but to a different extent, and with a different composition of advertisers. Thus, Spanish speakers are served different types of ads from different types of advertisers than English speakers, and in lower amounts; these results raise the question of whether political communication through Facebook ads may be inequitable and effectively disadvantaging the sizeable minority of Spanish speakers in the U.S. population. Bruno Coelho, Tobias Lauinger, Laura Edelson, Ian Goldstein, Damon McCoy |
WWW | 5 |
| 2023 | No Privacy Among Spies: Assessing the Functionality and Insecurity of Consumer Android Spyware AppsabstractConsumer mobile spyware apps covertly monitor a user's activities (i.e., text messages, phone calls, e-mail, location, etc.) and transmit that information over the Internet to support remote surveillance. Unlike conceptually similar apps used for state espionage, so-called "stalkerware" apps are mass-marketed to consumers on a retail basis and expose a far broader range of victims to invasive monitoring. Today the market for such apps is large enough to support dozens of competitors, with individual vendors reportedly monitoring hundreds of thousands of phones. However, while the research community is well aware of the existence of such apps, our understanding of the mechanisms they use to operate remains ad hoc. In this work, we perform an in-depth technical analysis of 14 distinct leading mobile spyware apps targeting Android phones. We document the range of mechanisms used to monitor user activity of various kinds (e.g., photos, text messages, live microphone access) — primarily through the creative abuse of Android APIs. We also discover previously undocumented methods these apps use to hide from detection and to achieve persistence. Additionally, we document the measures taken by each app to protect the privacy of the sensitive data they collect, identifying a range of failings on the part of spyware vendors (including privacy-sensitive data sent in the clear or stored in the cloud with little or no protection). Enze Liu 0001, Sumanth Rao, Sam Havron, Grant Ho, Stefan Savage, Geoffrey M. Voelker, Damon McCoy |
Proc. Priv. Enhancing Technol. | 7 |
| 2022 | Cart-ology: Intercepting Targeted Advertising via Ad Network Identity EntanglementabstractTargeted advertising is a pervasive practice in the advertising ecosystem, with complex representations of user identity central to targeting. Ad networks are incentivized to tie ephemeral cookies across devices to lasting durable identifiers such as email addresses in order to develop comprehensive cross-device user profiles. Third-party ad networks typically do not have relationships with users and must rely on external parties such as merchant websites for durable identity information, introducing intricate trust relationships. We find attackers can exploit these trust relationships to confuse an ad network into linking an unprivileged attacker's browser to a victim's identity, thus "impersonating" the victim to the ad network. ChangSeok Oh, Chris Kanich, Damon McCoy, Paul Pearce |
CCS | 3 |
| 2022 | An Analysis of Terms of Service and Official Policies with Respect to Sex WorkabstractPolicymakers who design the rules that govern the internet and the technologists who implement them can often be disconnected from some of the populations affected by their products. In this study, we analyze the terms of service, community guidelines, privacy policies, and other documents officially issued by online platforms in the United States to discuss their implications with regards to a marginalized population of interest: workers in the sex industry, ranging in autonomy from sex workers with a high degree of autonomy to survivors of sex trafficking. While criminalized and stigmatized populations such as sex industry workers are underrepresented among technologists, we show how technological decision makers without subject matter knowledge or understanding of the motivations and effects on the population can unintentionally lead to harming sex industry workers. Our analysis is in line with sex industry worker-led movements to stop arresting sex industry workers, de-stigmatize sex work, and let sex industry workers remain and flourish in online life. We study over 100 online platforms from 13 platform types and discuss the laws, perceptions, and motivations behind their policies regarding the sex industry, and how these policies affect sex industry workers. We find that platforms generally view sex industry workers as either criminals, victims, spam, or entrepreneurs; we show how using the first three paradigms to characterize the entire industry can lead to stigmatization, overly general and restrictive rules, and decreased accessibility to online life. We use this study as an example to illustrate the need for a cultural shift in the technology community towards empathy and social education and provide concrete research directions towards a solution. Rasika Bhalerao, Damon McCoy |
ISTAS | 2 |
| 2022 | An Audit of Facebook's Political Ad Policy Enforcement
Victor Le Pochat, Laura Edelson, Tom van Goethem, Wouter Joosen, Damon McCoy, Tobias Lauinger |
USENIX Security Symposium | 5 |
| 2022 | Conspiracy Brokers: Understanding the Monetization of YouTube Conspiracy TheoriesabstractConspiracy theories are increasingly a subject of research interest as society grapples with their rapid growth in areas such as politics or public health. Previous work has established YouTube as one of the most popular sites for people to host and discuss different theories. In this paper, we present an analysis of monetization methods of conspiracy theorist YouTube creators and the types of advertisers potentially targeting this content. We collect 184,218 ad impressions from 6,347 unique advertisers found on conspiracy-focused channels and mainstream YouTube content. We classify the ads into business categories and compare their prevalence between conspiracy and mainstream content. We also identify common offsite monetization methods. In comparison with mainstream content, conspiracy videos had similar levels of ads from well-known brands, but an almost eleven times higher prevalence of likely predatory or deceptive ads. Additionally, we found that conspiracy channels were more than twice as likely as mainstream channels to use offsite monetization methods, and 53% of the demonetized channels we observed were linking to third-party sites for alternative monetization opportunities. Our results indicate that conspiracy theorists on YouTube had many potential avenues to generate revenue, and that predatory ads were more frequently served for conspiracy videos. Cameron Ballard, Ian Goldstein, Pulak Mehta, Genesis Smothers, Kejsi Take, Victoria Zhong, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
WWW | 9 |
| 2022 | Ethics and Efficacy of Unsolicited Anti-Trafficking SMS OutreachabstractThe sex industry exists on a continuum based on the degree of work autonomy present in one's labor conditions: a high degree of autonomy exists on one side of the continuum where certain independent sex workers have a great deal of agency, while much less autonomy exists on the other side, where sex is traded under conditions of human trafficking. Various organizations across North America perform outreach to sex workers to offer assistance in the form of services (e.g., healthcare, financial assistance, housing) as well as prayer and intervention. Increasingly, technology is used to look for trafficking victims and/or facilitate the provision of assistance or services, for example through scraping and parsing sex industry workers' advertisements into a database of contact information that can be used by outreach organizations. However, little is known about the efficacy of anti-trafficking outreach technology, nor the potential risks of using such technology to identify and contact the highly stigmatized and marginalized population of those working in the sex industry. In this work, we investigate the use, context, benefits, and harms of an anti-trafficking technology platform via qualitative interviews with multiple stakeholders: the technology developers (n=6), organizations that use the technology (n=17), and sex industry workers who have been contacted or wish to be contacted (n=24). Our findings illustrate misalignment between developers, users of the platform, and sex industry workers they are attempting to assist. In their current state, anti-trafficking outreach tools such as the one we investigate are ineffective and, at best, serve as a mechanism for spam and, at worst, scale and exacerbate harm against the population they aim to serve. We conclude with a discussion of best practices -- and the feasibility of their implementation -- for technology-facilitated outreach efforts to minimize risk or harm to sex industry workers while efficiently providing needed services. Rasika Bhalerao, Nora McDonald, Hanna Barakat, Vaughn Hamilton, Damon McCoy, Elissa M. Redmiles |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2022 | "It Feels Like Whack-a-mole": User Experiences of Data Removal from People Search WebsitesabstractPeople Search Websites aggregate and publicize users’ Personal Identifiable Information (PII), previously sourced from data brokers. This paper presents a qualitative study of the perceptions and experiences of 18 participants who sought information removal by hiring a removal service or requesting removal from the sites. The users we interviewed were highly motivated and had sophisticated risk perceptions. We found that they encountered obstacles during the removal process, resulting in a high cost of removal, whether they requested it themselves or hired a service. Participants perceived that the successful monetization of users PII motivates data aggregators to make the removal more difficult. Overall, self management of privacy by attempting to keep information off the internet is difficult and its’ success is hard to evaluate. We provide recommendations to users, third parties, removal services and researchers aiming to improve the removal process. Kejsi Take, Kevin Gallagher 0001, Andrea Forte, Damon McCoy, Rachel Greenstadt |
Proc. Priv. Enhancing Technol. | 4 |
| 2021 | A large-scale characterization of online incitements to harassment across platformsabstractAttack strategies used by online harassers have evolved over time to inflict increasing harm to their targets. In addition to scaling harassment through incitement and coordination, online communities that commonly engage in harassment are likely a source of "innovation" for harassment attack strategies. We use the incitements or calls to harassment posted by members of these communities as a lens through which to holistically measure and understand this ecosystem. We create a filtering pipeline to discover 14,679 incitements to harassment within four large-scale data sets of messages and posts that span multiple platforms. Max Aliapoulios, Kejsi Take, Prashanth Ramakrishna, Daniel Borkan, Beth Goldberg, Jeffrey S. Sorensen, Anna Turner, Rachel Greenstadt, Tobias Lauinger, Damon McCoy |
Internet Measurement Conference | 10 |
| 2021 | Understanding engagement with U.S. (mis)information news sources on FacebookabstractFacebook has become an important platform for news publishers to promote their work and engage with their readers. Some news pages on Facebook have a reputation for consistently low factualness in their reporting, and there is concern that Facebook allows their misinformation to reach large audiences. To date, there is remarkably little empirical data about how often users "like," comment and share content from news pages on Facebook, how user engagement compares between sources that have a reputation for misinformation and those that do not, and how the political leaning of the source impacts the equation. In this work, we propose a methodology to generate a list of news publishers' official Facebook pages annotated with their partisanship and (mis)information status based on third-party evaluations, and collect engagement data for the 7.5 M posts that 2,551 U.S. news publishers made on their pages during the 2020 U.S. presidential election. We propose three metrics to study engagement (1) across the Facebook news ecosystem, (2) between (mis)information providers and their audiences, and (3) with individual pieces of content from (mis)information providers. Our results show that misinformation news sources receive widespread engagement on Facebook, accounting for 68.1% of all engagement with far-right news providers, followed by 37.7 % on the far left. Individual posts from misinformation news providers receive consistently higher median engagement than non-misinformation in every partisanship group. While most prevalent on the far right, misinformation appears to be an issue across the political spectrum. Laura Edelson, Minh-Kha Nguyen, Ian Goldstein, Oana Goga, Damon McCoy, Tobias Lauinger |
Internet Measurement Conference | 5 |
| 2021 | SoK: Hate, Harassment, and the Changing Landscape of Online AbuseabstractWe argue that existing security, privacy, and antiabuse protections fail to address the growing threat of online hate and harassment. In order for our community to understand and address this gap, we propose a taxonomy for reasoning about online hate and harassment. Our taxonomy draws on over 150 interdisciplinary research papers that cover disparate threats ranging from intimate partner violence to coordinated mobs. In the process, we identify seven classes of attacks—such as toxic content and surveillance—that each stem from different attacker capabilities and intents. We also provide longitudinal evidence from a three-year survey that hate and harassment is a pervasive, growing experience for online users, particularly for at-risk communities like young adults and people who identify as LGBTQ+. Responding to each class of hate and harassment requires a unique strategy and we highlight five such potential research directions that ultimately empower individuals, communities, and platforms to do so. Kurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh, Elie Bursztein, Sunny Consolvo, Nicola Dell, Zakir Durumeric, Patrick Gage Kelley, Deepak Kumar 0006, Damon McCoy, Sarah Meiklejohn, Thomas Ristenpart, Gianluca Stringhini |
SP | 11 |
| 2021 | Swiped: Analyzing Ground-truth Data of a Marketplace for Stolen Debit and Credit Cards
Max Aliapoulios, Cameron Ballard, Rasika Bhalerao, Tobias Lauinger, Damon McCoy |
USENIX Security Symposium | 5 |
| 2021 | "I'm a Professor, which isn't usually a dangerous job": Internet-facilitated Harassment and Its Impact on ResearchersabstractWhile the Internet has dramatically increased the exposure that research can receive, it has also facilitated harassment against scholars. To understand the impact that these attacks can have on the work of researchers, we perform a series of systematic interviews with researchers including academics, journalists, and activists, who have experienced targeted, Internet-facilitated harassment. We provide a framework for understanding the types of harassers that target researchers, the harassment that ensues, and the personal and professional impact on individuals and academic freedom. We then study preventative and remedial strategies available, and the institutions that prevent some of these strategies from being more effective. Finally, we discuss the ethical structures that could facilitate more equitable access to participating in research without serious personal suffering. Periwinkle Doerfler, Andrea Forte, Emiliano De Cristofaro, Gianluca Stringhini, Jeremy Blackburn, Damon McCoy |
Proc. ACM Hum. Comput. Interact. | 6 |
| 2020 | Understanding Incentivized Mobile App Installs on Google Play Storeabstract"Incentivized" advertising platforms allow mobile app developers to acquire new users by directly paying users to install and engage with mobile apps (e.g., create an account, make in-app purchases). Incentivized installs are banned by the Apple App Store and discouraged by the Google Play Store because they can manipulate app store metrics (e.g., install counts, appearance in top charts). Yet, many organizations still offer incentivized install services for Android apps. In this paper, we present the first study to understand the ecosystem of incentivized mobile app install campaigns in Android and its broader ramifications through a series of measurements. We identify incentivized install campaigns that require users to install an app and perform in-app tasks targeting manipulation of a wide variety of user engagement metrics (e.g., daily active users, user session lengths) and revenue. Our results suggest that these artificially inflated metrics can be effective in improving app store metrics as well as helping mobile app developers to attract funding from venture capitalists. Our study also indicates lax enforcement of the Google Play Store's existing policies to prevent these behaviors. It further motivates the need for stricter policing of incentivized install campaigns. Our proposed measurements can also be leveraged by the Google Play Store to identify potential policy violations. Shehroze Farooqi, Álvaro Feal, Tobias Lauinger, Damon McCoy, Zubair Shafiq, Narseo Vallina-Rodriguez |
Internet Measurement Conference | 4 |
| 2020 | A Security Analysis of the Facebook Ad LibraryabstractActors engaged in election disinformation are using online advertising platforms to spread political messages. In response to this threat, online advertising networks have started making political advertising on their platforms more transparent in order to enable third parties to detect malicious advertisers. We present a set of methodologies and perform a security analysis of Facebook's U.S. Ad Library, which is their political advertising transparency product. Unfortunately, we find that there are several weaknesses that enable a malicious advertiser to avoid accurate disclosure of their political ads. We also propose a clustering-based method to detect advertisers engaged in undeclared coordinated activity. Our clustering method identified 16 clusters of likely inauthentic communities that spent a total of over four million dollars on political advertising. This supports the idea that transparency could be a promising tool for combating disinformation. Finally, based on our findings, we make recommendations for improving the security of advertising transparency on Facebook and other platforms. Laura Edelson, Tobias Lauinger, Damon McCoy |
SP | 3 |
| 2020 | The Many Kinds of Creepware Used for Interpersonal AttacksabstractTechnology increasingly facilitates interpersonal attacks such as stalking, abuse, and other forms of harassment. While prior studies have examined the ecosystem of software designed for stalking, there exists an unstudied, larger landscape of apps-what we call creepware-used for interpersonal attacks. In this paper, we initiate a study of creepware using access to a dataset detailing the mobile apps installed on over 50 million Android devices. We develop a new algorithm, CreepRank, that uses the principle of guilt by association to help surface previously unknown examples of creepware, which we then characterize through a combination of quantitative and qualitative methods. We discovered apps used for harassment, impersonation, fraud, information theft, concealment, and even apps that purport to defend victims against such threats. As a result of our work, the Google Play Store has already removed hundreds of apps for policy violations. More broadly, our findings and techniques improve understanding of the creepware ecosystem, and will inform future efforts that aim to mitigate interpersonal attacks. Kevin A. Roundy, Paula Barmaimon Mendelberg, Nicola Dell, Damon McCoy, Daniel Nissani, Thomas Ristenpart, Acar Tamersoy |
SP | 4 |
| 2020 | The Tools and Tactics Used in Intimate Partner Surveillance: An Analysis of Online Infidelity Forums
Emily Tseng, Rosanna Bellini, Nora McDonald, Matan Danos, Rachel Greenstadt, Damon McCoy, Nicola Dell, Thomas Ristenpart |
USENIX Security Symposium | 6 |
| 2020 | Dark Matter: Uncovering the DarkComet RAT EcosystemabstractRemote Access Trojans (RATs) are a persistent class of malware that give an attacker direct, interactive access to a victim’s personal computer, allowing the attacker to steal private data, spy on the victim in real-time using the camera and microphone, and verbally harass the victim through the speaker. To date, the users and victims of this pernicious form of malware have been challenging to observe in the wild due to the unobtrusive nature of infections. In this work, we report the results of a longitudinal study of the DarkComet RAT ecosystem. Using a known method for collecting victim log databases from DarkComet controllers, we present novel techniques for tracking RAT controllers across hostname changes and improve on established techniques for filtering spurious victim records caused by scanners and sandboxed malware executions. We downloaded 6,620 DarkComet databases from 1,029 unique controllers spanning over 5 years of operation. Our analysis shows that there have been at least 57,805 victims of DarkComet over this period, with 69 new victims infected every day; many of whose keystrokes have been captured, actions recorded, and webcams monitored during this time. Our methodologies for more precisely identifying campaigns and victims could potentially be useful for improving the efficiency and efficacy of victim cleanup efforts and prioritization of law enforcement investigations. Brown Farinholt, Mohammad Rezaeirad, Damon McCoy, Kirill Levchenko |
WWW | 3 |
| 2020 | The Pod People: Understanding Manipulation of Social Media Popularity via Reciprocity AbuseabstractOnline Social Network (OSN) Users’ demand to increase their account popularity has driven the creation of an underground ecosystem that provides services or techniques to help users manipulate content curation algorithms. One method of subversion that has recently emerged occurs when users form groups, called pods, to facilitate reciprocity abuse, where each member reciprocally interacts with content posted by other members of the group. We collect 1.8 million Instagram posts that were posted in pods hosted on Telegram. We first summarize the properties of these pods and how they are used, uncovering that they are easily discoverable by Google search and have a low barrier to entry. We then create two machine learning models for detecting Instagram posts that have gained interaction through two different kinds of pods, achieving 0.91 and 0.94 AUC, respectively. Finally, we find that pods are effective tools for increasing users’ Instagram popularity, we estimate that pod utilization leads to a significantly increased level of likely organic comment interaction on users’ subsequent posts. Janith Weerasinghe, Bailey Flanigan, Aviel J. Stein, Damon McCoy, Rachel Greenstadt |
WWW | 4 |
| 2020 | "So-called privacy breeds evil": Narrative Justifications for Intimate Partner Surveillance in Online ForumsabstractA growing body of research suggests that intimate partner abusers use digital technologies to surveil their partners, including by installing spyware apps, compromising devices and online accounts, and employing social engineering tactics. However, to date, this form of privacy violation, called intimate partner surveillance (IPS), has primarily been studied from the perspective of victim-survivors. We present a qualitative study of how potential perpetrators of IPS harness the emotive power of sharing personal narratives to validate and legitimise their abusive behaviours. We analysed 556 stories of IPS posted on publicly accessible online forums dedicated to the discussion of sexual infidelity. We found that many users share narrative posts describing IPS as they boast about their actions, advise others on how to perform IPS without detection, and seek suggestions for next steps to take. We identify a set of common thematic story structures, justifications for abuse, and outcomes within the stories that provide a window into how these individuals believe their behaviour to be justified. Using these stories, we develop a four-stage framework that captures the change in a potential perpetrator's approach to IPS. We use our findings and framework to guide a discussion of efforts to combat abuse, including how we can identify crucial moments where interventions might be safely applied to prevent or deescalate IPS. Rosanna Bellini, Emily Tseng, Nora McDonald, Rachel Greenstadt, Damon McCoy, Thomas Ristenpart, Nicola Dell |
Proc. ACM Hum. Comput. Interact. | 5 |
| 2019 | Clinical Computer Security for Victims of Intimate Partner Violence
Sam Havron, Diana Freed, Rahul Chatterjee 0001, Damon McCoy, Nicola Dell, Thomas Ristenpart |
USENIX Security Symposium | 4 |
| 2019 | Reading the Tea leaves: A Comparative Analysis of Threat Intelligence
Vector Guo Li, Matthew Dunn, Paul Pearce, Damon McCoy, Geoffrey M. Voelker, Stefan Savage |
USENIX Security Symposium | 4 |
| 2019 | Platforms in Everything: Analyzing Ground-Truth Data on the Anatomy and Economics of Bullet-Proof Hosting
Arman Noroozian, Jan Koenders, Eelco van Veldhuizen, Carlos Gañán, Sumayah A. Alrwais, Damon McCoy, Michel van Eeten |
USENIX Security Symposium | 6 |
| 2019 | Evaluating Login Challenges as aDefense Against Account TakeoverabstractIn this paper, we study the efficacy of login challenges at preventing account takeover, as well as evaluate the amount of friction these challenges create for normal users. These secondary authentication factors-presently deployed at Google, Microsoft, and other major identity providers as part of risk-aware authentication-trigger in response to a suspicious login or account recovery attempt. Using Google as a case study, we evaluate the effectiveness of fourteen device-based, delegation-based, knowledge-based, and resource-based challenges at preventing over 350,000 real-world hijacking attempts stemming from automated bots, phishers, and targeted attackers. We show that knowledge-based challenges prevent as few as 10% of hijacking attempts rooted in phishing and 73% of automated hijacking attempts. Device-based challenges provide the best protection, blocking over 94% of hijacking attempts rooted in phishing and 100% of automated hijacking attempts. We evaluate the usability limitations of each challenge based on a sample of 1.2M legitimate users. Our results illustrate that login challenges act as an important barrier to hijacking, but that friction in the process leads to 52% of legitimate users failing to sign-in-though 97% of users eventually access their account in a short period. Periwinkle Doerfler, Kurt Thomas, Maija Marincenko, Juri Ranieri, Angelique Moscicki, Damon McCoy |
WWW | 7 |
| 2018 | Peeling the Onion's User Experience Layer: Examining Naturalistic Use of the Tor BrowserabstractThe strength of an anonymity system depends on the number of users. Therefore, User eXperience (UX) and usability of these systems is of critical importance for boosting adoption and use. To this end, we carried out a study with 19 non-expert participants to investigate how users experience routine Web browsing via the Tor Browser, focusing particularly on encountered problems and frustrations. Using a mixed-methods quantitative and qualitative approach to study one week of naturalistic use of the Tor Browser, we uncovered a variety of UX issues, such as broken Web sites, latency, lack of common browsing conveniences, differential treatment of Tor traffic, incorrect geolocation, operational opacity, etc. We applied this insight to suggest a number of UX improvements that could mitigate the issues and reduce user frustration when using the Tor Browser. Kevin Gallagher 0001, Sameer Patil 0001, Brendan Dolan-Gavitt, Damon McCoy, Nasir Memon |
CCS | 4 |
| 2018 | The Spyware Used in Intimate Partner ViolenceabstractSurvivors of intimate partner violence increasingly report that abusers install spyware on devices to track their location, monitor communications, and cause emotional and physical harm. To date there has been only cursory investigation into the spyware used in such intimate partner surveillance (IPS). We provide the first in-depth study of the IPS spyware ecosystem. We design, implement, and evaluate a measurement pipeline that combines web and app store crawling with machine learning to find and label apps that are potentially dangerous in IPS contexts. Ultimately we identify several hundred such IPS-relevant apps. While we find dozens of overt spyware tools, the majority are "dual-use" apps - they have a legitimate purpose (e.g., child safety or anti-theft), but are easily and effectively repurposed for spying on a partner. We document that a wealth of online resources are available to educate abusers about exploiting apps for IPS. We also show how some dual-use app developers are encouraging their use in IPS via advertisements, blogs, and customer support services. We analyze existing anti-virus and anti-spyware tools, which universally fail to identify dual-use apps as a threat. Rahul Chatterjee 0001, Periwinkle Doerfler, Hadas Orgad, Sam Havron, Jackeline Palmer, Diana Freed, Karen Levy, Nicola Dell, Damon McCoy, Thomas Ristenpart |
IEEE Symposium on Security and Privacy | 9 |
| 2018 | Tracking Ransomware End-to-endabstractRansomware is a type of malware that encrypts the files of infected hosts and demands payment, often in a crypto-currency like Bitcoin. In this paper, we create a measurement framework that we use to perform a large-scale, two-year, end-to-end measurement of ransomware payments, victims, and operators. By combining an array of data sources, including ransomware binaries, seed ransom payments, victim telemetry from infections, and a large database of bitcoin addresses annotated with their owners, we sketch the outlines of this burgeoning ecosystem and associated third-party infrastructure. In particular, we are able to trace the financial transactions, from the acquisition of bitcoins by victims, through the payment of ransoms, to the cash out of bitcoins by the ransomware operators. We find that many ransomware operators cashed out using BTC-e, a now-defunct Bitcoin exchange. In total we are able to track over $16 million USD in likely ransom payments made by 19,750 potential victims during a two-year period. While our study focuses on ransomware, our methods are potentially applicable to other cybercriminal operations that have similarly adopted Bitcoin as their payment channel. Danny Yuxing Huang, Max Aliapoulios, Vector Guo Li, Luca Invernizzi, Elie Bursztein, Kylie McRoberts, Kirill Levchenko, Alex C. Snoeren, Damon McCoy |
IEEE Symposium on Security and Privacy | 10 |
| 2018 | Schrödinger's RAT: Profiling the Stakeholders in the Remote Access Trojan Ecosystem
Mohammad Rezaeirad, Brown Farinholt, Hitesh Dharmdasani, Paul Pearce, Kirill Levchenko, Damon McCoy |
USENIX Security Symposium | 6 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2018 | Editors' Introduction
Rachel Greenstadt, Damon McCoy, Carmela Troncoso |
Proc. Priv. Enhancing Technol. | 2 |
| 2017 | Identifying Products in Online Cybercrime Marketplaces: A Dataset for Fine-grained Domain AdaptationabstractGreg Durrett, Jonathan K. Kummerfeld, Taylor Berg-Kirkpatrick, Rebecca Portnoff, Sadia Afroz, Damon McCoy, Kirill Levchenko, Vern Paxson. Proceedings of the 2017 Conference on Empirical Methods in Natural Language Processing. 2017. Greg Durrett, Jonathan K. Kummerfeld, Taylor Berg-Kirkpatrick, Rebecca S. Portnoff, Sadia Afroz 0001, Damon McCoy, Kirill Levchenko, Vern Paxson |
EMNLP | 6 |
| 2017 | Fifteen minutes of unwanted fame: detecting and characterizing doxingabstractDoxing is online abuse where a malicious party harms another by releasing identifying or sensitive information. Motivations for doxing include personal, competitive, and political reasons, and web users of all ages, genders and internet experience have been targeted. Existing research on doxing is primarily qualitative. This work improves our understanding of doxing by being the first to take a quantitative approach. We do so by designing and deploying a tool which can detect dox files and measure the frequency, content, targets, and effects of doxing on popular dox-posting sites. Peter Snyder, Periwinkle Doerfler, Chris Kanich, Damon McCoy |
Internet Measurement Conference | 4 |
| 2017 | Backpage and Bitcoin: Uncovering Human TraffickersabstractSites for online classified ads selling sex are widely used by human traffickers to support their pernicious business. The sheer quantity of ads makes manual exploration and analysis unscalable. In addition, discerning whether an ad is advertising a trafficked victim or an independent sex worker is a very difficult task. Very little concrete ground truth (i.e., ads definitively known to be posted by a trafficker) exists in this space. In this work, we develop tools and techniques that can be used separately and in conjunction to group sex ads by their true owner (and not the claimed author in the ad). Specifically, we develop a machine learning classifier that uses stylometry to distinguish between ads posted by the same vs. different authors with 90% TPR and 1% FPR. We also design a linking technique that takes advantage of leakages from the Bitcoin mempool, blockchain and sex ad site, to link a subset of sex ads to Bitcoin public wallets and transactions. Finally, we demonstrate via a 4-week proof of concept using Backpage as the sex ad site, how an analyst can use these automated approaches to potentially find human traffickers. Rebecca S. Portnoff, Danny Yuxing Huang, Periwinkle Doerfler, Sadia Afroz 0001, Damon McCoy |
KDD | 5 |
| 2017 | Linking Amplification DDoS Attacks to Booter Services
Johannes Krupp, Mohammad Karami, Christian Rossow, Damon McCoy, Michael Backes 0001 |
RAID | 4 |
| 2017 | Under the Shadow of Sunshine: Understanding and Detecting Bulletproof Hosting on Legitimate Service Provider NetworksabstractBulletProof Hosting (BPH) services provide criminal actors with technical infrastructure that is resilient to complaints of illicit activities, which serves as a basic building block for streamlining numerous types of attacks. Anecdotal reports have highlighted an emerging trend of these BPH services reselling infrastructure from lower end service providers (hosting ISPs, cloud hosting, and CDNs) instead of from monolithic BPH providers. This has rendered many of the prior methods of detecting BPH less effective, since instead of the infrastructure being highly concentrated within a few malicious Autonomous Systems (ASes) it is now agile and dispersed across a larger set of providers that have a mixture of benign and malicious clients. In this paper, we present the first systematic study on this new trend of BPH services. By collecting and analyzing a large amount of data (25 snapshots of the entire Whois IPv4 address space, 1.5 TB of passive DNS data, and longitudinal data from several blacklist feeds), we are able to identify a set of new features that uniquely characterizes BPH on sub-allocations and that are costly to evade. Based upon these features, we train a classifier for detecting malicious sub-allocated network blocks, achieving a 98% recall and 1.5% false discovery rates according to our evaluation. Using a conservatively trained version of our classifier, we scan the whole IPv4 address space and detect 39K malicious network blocks. This allows us to perform a large-scale study of the BPH service ecosystem, which sheds light on this underground business strategy, including patterns of network blocks being recycled and malicious clients being migrated to different network blocks, in an effort to evade IP address based blacklisting. Our study highlights the trend of agile BPH services and points to potential methods of detecting and mitigating this emerging threat. Sumayah A. Alrwais, Xiaojing Liao, Xianghang Mi, Peng Wang 0088, XiaoFeng Wang 0001, Feng Qian 0001, Raheem A. Beyah, Damon McCoy |
IEEE Symposium on Security and Privacy | 8 |
| 2017 | To Catch a Ratter: Monitoring the Behavior of Amateur DarkComet RAT Operators in the WildabstractRemote Access Trojans (RATs) give remote attackers interactive control over a compromised machine. Unlike large-scale malware such as botnets, a RAT is controlled individually by a human operator interacting with the compromised machine remotely. The versatility of RATs makes them attractive to actors of all levels of sophistication: they've been used for espionage, information theft, voyeurism and extortion. Despite their increasing use, there are still major gaps in our understanding of RATs and their operators, including motives, intentions, procedures, and weak points where defenses might be most effective. In this work we study the use of DarkComet, a popular commercial RAT. We collected 19,109 samples of DarkComet malware found in the wild, and in the course of two, several-week-long experiments, ran as many samples as possible in our honeypot environment. By monitoring a sample's behavior in our system, we are able to reconstruct the sequence of operator actions, giving us a unique view into operator behavior. We report on the results of 2,747 interactive sessions captured in the course of the experiment. During these sessions operators frequently attempted to interact with victims via remote desktop, to capture video, audio, and keystrokes, and to exfiltrate files and credentials. To our knowledge, we are the first large-scale systematic study of RAT use. Brown Farinholt, Mohammad Rezaeirad, Paul Pearce, Hitesh Dharmdasani, Haikuo Yin, Stevens Le Blond, Damon McCoy, Kirill Levchenko |
IEEE Symposium on Security and Privacy | 7 |
| 2017 | Tools for Automated Analysis of Cybercriminal MarketsabstractUnderground forums are widely used by criminals to buy and sell a host of stolen items, datasets, resources, and criminal services. These forums contain important resources for understanding cybercrime. However, the number of forums, their size, and the domain expertise required to understand the markets makes manual exploration of these forums unscalable. In this work, we propose an automated, top-down approach for analyzing underground forums. Our approach uses natural language processing and machine learning to automatically generate high-level information about underground forums, first identifying posts related to transactions, and then extracting products and prices. We also demonstrate, via a pair of case studies, how an analyst can use these automated approaches to investigate other categories of products and transactions. We use eight distinct forums to assess our tools: Antichat, Blackhat World, Carders, Darkode, Hack Forums, Hell, L33tCrew and Nulled. Our automated approach is fast and accurate, achieving over 80% accuracy in detecting post category, product, and prices. Rebecca S. Portnoff, Sadia Afroz 0001, Greg Durrett, Jonathan K. Kummerfeld, Taylor Berg-Kirkpatrick, Damon McCoy, Kirill Levchenko, Vern Paxson |
WWW | 6 |
| 2017 | Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy |
Proc. Priv. Enhancing Technol. | 3 |
| 2017 | Editors' Introduction
Claudia Díaz, Rachel Greenstadt, Damon McCoy |
Proc. Priv. Enhancing Technol. | 3 |
| 2016 | Do You See What I See? Differential Treatment of Anonymous Users
Sheharbano Khattak, David Fifield, Sadia Afroz 0001, Mobin Javed, Srikanth Sundaresan, Damon McCoy, Vern Paxson, Steven J. Murdoch |
NDSS | 6 |
| 2016 | You've Got Vulnerability: Exploring Effective Vulnerability Notifications
Frank Li 0001, Zakir Durumeric, Jakub Czyz, Mohammad Karami, Michael D. Bailey, Damon McCoy, Stefan Savage, Vern Paxson |
USENIX Security Symposium | 6 |
| 2016 | Investigating Commercial Pay-Per-Install and the Distribution of Unwanted Software
Kurt Thomas, Juan A. Elices Crespo, Ryan Rasti, Jean-Michel Picod, Cait Phillips, Marc-André Decoste, Chris Sharp, Fabio Tirelo, Ali Tofigh, Marc-Antoine Courteau, Lucas Ballard, Robert Shield, Nav Jagpal, Moheeb Abu Rajab, Panayiotis Mavrommatis, Niels Provos, Elie Bursztein, Damon McCoy |
USENIX Security Symposium | 18 |
| 2016 | Stress Testing the Booters: Understanding and Undermining the Business of DDoS ServicesabstractDDoS-for-hire services, also known as booters, have commoditized DDoS attacks and enabled abusive subscribers of these services to cheaply extort, harass and intimidate businesses and people by taking them offline. However, due to the underground nature of these booters, little is known about their underlying technical and business structure. In this paper, we empirically measure many facets of their technical and payment infrastructure. We also perform an analysis of leaked and scraped data from three major booters---Asylum Stresser, Lizard Stresser and VDO---which provides us with an in-depth view of their customers and victims. Finally, we conduct a large-scale payment intervention in collaboration with PayPal and evaluate its effectiveness as a deterrent to their operations. Based on our analysis, we show that these booters are responsible for hundreds of thousands of DDoS attacks and identify potentially promising methods to undermine these services by increasing their costs of operation. Mohammad Karami, Youngsam Park, Damon McCoy |
WWW | 3 |
| 2016 | Characterizing Long-tail SEO Spam on Cloud Web Hosting ServicesabstractThe popularity of long-tail search engine optimization (SEO) brings with new security challenges: incidents of long-tail keyword poisoning to lower competition and increase revenue have been reported. The emergence of cloud web hosting services provides a new and effective platform for long-tail SEO spam attacks. There is growing evidence that large-scale long-tail SEO campaigns are being carried out on cloud hosting platforms because they offer low-cost, high-speed hosting services. In this paper, we take the first step toward understanding how long-tail SEO spam is implemented on cloud hosting platforms. After identifying 3,186 cloud directories and 318,470 doorway pages on the leading cloud platforms for long-tail SEO spam, we characterize their abusive behavior. One highlight of our findings is the effectiveness of the cloud-based long-tail SEO spam, with 6% of the doorway pages successfully appearing in the top 10 search results of the poisoned long-tail keywords. Xiaojing Liao, Chang Liu 0021, Damon McCoy, Elaine Shi, Shuang Hao 0001, Raheem A. Beyah |
WWW | 3 |
| 2015 | "I Saw Images I Didn't Even Know I Had": Understanding User Perceptions of Cloud Storage PrivacyabstractBillions of people use cloud-based storage for personal files. While many are likely aware of the extent to which they store information in the cloud, it is unclear whether users are fully aware of what they are storing online. We recruited 30 research subjects from Craigslist to investigate how users interact with and understand the privacy issues of cloud storage. We studied this phenomenon through surveys, an interview, and custom software which lets users see and delete their photos stored in the cloud. We found that a majority of users stored private photos in the cloud that they did not intend to upload, and a large portion also chose to permanently delete some of the offending images. We believe our study highlights a mismatch between user expectation and reality. As cloud storage is plentiful and ubiquitous, effective tools for enabling risk self-assessment are necessary to protect users' privacy. Jason W. Clark, Peter Snyder, Damon McCoy, Chris Kanich |
CHI | 3 |
| 2015 | Ad Injection at Scale: Assessing Deceptive Advertisement ModificationsabstractToday, web injection manifests in many forms, but fundamentally occurs when malicious and unwanted actors tamper directly with browser sessions for their own profit. In this work we illuminate the scope and negative impact of one of these forms, ad injection, in which users have ads imposed on them in addition to, or different from, those that websites originally sent them. We develop a multi-staged pipeline that identifies ad injection in the wild and captures its distribution and revenue chains. We find that ad injection has entrenched itself as a cross-browser monetization platform impacting more than 5% of unique daily IP addresses accessing Google -- tens of millions of users around the globe. Injected ads arrive on a client's machine through multiple vectors: our measurements identify 50,870 Chrome extensions and 34,407 Windows binaries, 38% and 17% of which are explicitly malicious. A small number of software developers support the vast majority of these injectors who in turn syndicate from the larger ad ecosystem. We have contacted the Chrome Web Store and the advertisers targeted by ad injectors to alert each of the deceptive practices involved. Kurt Thomas, Elie Bursztein, Chris Grier, Grant Ho, Nav Jagpal, Alexandros Kapravelos, Damon McCoy, Antonio Nappa, Vern Paxson, Paul Pearce, Niels Provos, Moheeb Abu Rajab |
IEEE Symposium on Security and Privacy | 7 |
| 2014 | Characterizing Large-Scale Click Fraud in ZeroAccessabstractClick fraud is a scam that hits a criminal sweet spot by both tapping into the vast wealth of online advertising and exploiting that ecosystem's complex structure to obfuscate the flow of money to its perpetrators. In this work, we illuminate the intricate nature of this activity through the lens of ZeroAccess--one of the largest click fraud botnets in operation. Using a broad range of data sources, including peer-to-peer measurements, command-and-control telemetry, and contemporaneous click data from one of the top ad networks, we construct a view into the scale and complexity of modern click fraud operations. By leveraging the dynamics associated with Microsoft's attempted takedown of ZeroAccess in December 2013, we employ this coordinated view to identify "ad units" whose traffic (and hence revenue) primarily derived from ZeroAccess. While it proves highly challenging to extrapolate from our direct observations to a truly global view, by anchoring our analysis in the data for these ad units we estimate that the botnet's fraudulent activities plausibly induced advertising losses on the order of $100,000 per day. Paul Pearce, Vacha Dave, Chris Grier, Kirill Levchenko, Saikat Guha 0002, Damon McCoy, Vern Paxson, Stefan Savage, Geoffrey M. Voelker |
CCS | 6 |
| 2014 | Dialing Back Abuse on Phone Verified AccountsabstractIn the past decade the increase of for-profit cybercrime has given rise to an entire underground ecosystem supporting large-scale abuse, a facet of which encompasses the bulk registration of fraudulent accounts. In this paper, we present a 10 month logitudinal study of the underlying technical and financial capabilities of criminals who register phone verified accounts (PVA). To carry out our study, we purchase 4,695 Google PVA as well as acquire a random sample of 300,000 Google PVA through a collaboration with Google. We find that miscreants rampantly abuse free VOIP services to circumvent the intended cost of acquiring phone numbers, in effect undermining phone verification. Combined with short lived phone numbers from India and Indonesia that we suspect are tied to human verification farms, this confluence of factors correlates with a market-wide price drop of 30--40% for Google PVA until Google penalized verifications from frequently abused carriers. We distill our findings into a set of recommendations for any services performing phone verification as well as highlight open challenges related to PVA abuse moving forward. Kurt Thomas, Dmytro Iatskiv, Elie Bursztein, Tadek Pietraszek, Chris Grier, Damon McCoy |
CCS | 6 |
| 2014 | Search + Seizure: The Effectiveness of Interventions on SEO CampaignsabstractBlack hat search engine optimization (SEO), the practice of abusively manipulating search results, is an enticing method to acquire targeted user traffic. In turn, a range of interventions--from modifying search results to seizing domains--are used to combat this activity. In this paper, we examine the effectiveness of these interventions in the context of an understudied market niche, counterfeit luxury goods. Using eight months of empirical crawled data, we identify 52 distinct SEO campaigns, document how well they are able to place search results for sixteen luxury brands, how this capability impacts the dynamics of their order volumes and how well existing interventions undermine this business when employed. David Y. Wang, Matthew F. Der, Mohammad Karami, Lawrence K. Saul, Damon McCoy, Stefan Savage, Geoffrey M. Voelker |
Internet Measurement Conference | 5 |
| 2014 | Botcoin: Monetizing Stolen Cycles
Danny Yuxing Huang, Hitesh Dharmdasani, Sarah Meiklejohn, Vacha Dave, Chris Grier, Damon McCoy, Stefan Savage, Nicholas Weaver, Alex C. Snoeren, Kirill Levchenko |
NDSS | 6 |
| 2014 | Scambaiter: Understanding Targeted Nigerian Scams on Craigslist
Youngsam Park, Jackie Jones, Damon McCoy, Elaine Shi, Markus Jakobsson |
NDSS | 3 |
| 2014 | Doppelgänger Finder: Taking Stylometry to the UndergroundabstractStylometry is a method for identifying anonymous authors of anonymous texts by analyzing their writing style. While stylometric methods have produced impressive results in previous experiments, we wanted to explore their performance on a challenging dataset of particular interest to the security research community. Analysis of underground forums can provide key information about who controls a given bot network or sells a service, and the size and scope of the cybercrime underworld. Previous analyses have been accomplished primarily through analysis of limited structured metadata and painstaking manual analysis. However, the key challenge is to automate this process, since this labor intensive manual approach clearly does not scale. We consider two scenarios. The first involves text written by an unknown cybercriminal and a set of potential suspects. This is standard, supervised stylometry problem made more difficult by multilingual forums that mix l33t-speak conversations with data dumps. In the second scenario, you want to feed a forum into an analysis engine and have it output possible doppelgangers, or users with multiple accounts. While other researchers have explored this problem, we propose a method that produces good results on actual separate accounts, as opposed to data sets created by artificially splitting authors into multiple identities. For scenario 1, we achieve 77% to 84% accuracy on private messages. For scenario 2, we achieve 94% recall with 90% precision on blogs and 85.18% precision with 82.14% recall for underground forum users. We demonstrate the utility of our approach with a case study that includes applying our technique to the Carders forum and manual analysis to validate the results, enabling the discovery of previously undetected doppelganger accounts. Sadia Afroz 0001, Aylin Caliskan, Ariel Stolerman, Rachel Greenstadt, Damon McCoy |
IEEE Symposium on Security and Privacy | 5 |
| 2013 | A fistful of bitcoins: characterizing payments among men with no namesabstractBitcoin is a purely online virtual currency, unbacked by either physical commodities or sovereign obligation; instead, it relies on a combination of cryptographic protection and a peer-to-peer protocol for witnessing settlements. Consequently, Bitcoin has the unintuitive property that while the ownership of money is implicitly anonymous, its flow is globally visible. In this paper we explore this unique characteristic further, using heuristic clustering to group Bitcoin wallets based on evidence of shared authority, and then using re-identification attacks (i.e., empirical purchasing of goods and services) to classify the operators of those clusters. From this analysis, we characterize longitudinal changes in the Bitcoin market, the stresses these changes are placing on the system, and the challenges for those seeking to use Bitcoin for criminal or fraudulent purposes at scale. Sarah Meiklejohn, Marjori Pomarole, Grant Jordan, Kirill Levchenko, Damon McCoy, Geoffrey M. Voelker, Stefan Savage |
Internet Measurement Conference | 5 |
| 2013 | Trafficking Fraudulent Accounts: The Role of the Underground Market in Twitter Spam and Abuse
Kurt Thomas, Damon McCoy, Chris Grier, Alek Kolcz, Vern Paxson |
USENIX Security Symposium | 2 |
| 2012 | Manufacturing compromise: the emergence of exploit-as-a-serviceabstractWe investigate the emergence of the exploit-as-a-service model for driveby browser compromise. In this regime, attackers pay for an exploit kit or service to do the "dirty work" of exploiting a victim's browser, decoupling the complexities of browser and plugin vulnerabilities from the challenges of generating traffic to a website under the attacker's control. Upon a successful exploit, these kits load and execute a binary provided by the attacker, effectively transferring control of a victim's machine to the attacker. Chris Grier, Lucas Ballard, Juan Caballero, Neha Chachra, Christian Dietrich 0005, Kirill Levchenko, Panayiotis Mavrommatis, Damon McCoy, Antonio Nappa, Andreas Pitsillidis, Niels Provos, M. Zubair Rafique, Moheeb Abu Rajab, Christian Rossow, Kurt Thomas, Vern Paxson, Stefan Savage, Geoffrey M. Voelker |
CCS | 8 |
| 2012 | Priceless: the role of payments in abuse-advertised goodsabstractLarge-scale abusive advertising is a profit-driven endeavor. Without consumers purchasing spam-advertised Viagra, search-advertised counterfeit software or malware-advertised fake anti-virus, these campaigns could not be economically justified. Thus, in addition to the numerous efforts focused on identifying and blocking individual abusive advertising mechanisms, a parallel research direction has emerged focused on undermining the associated means of monetization: payment networks. In this paper we explain the complex role of payment processing in monetizing the modern affiliate program ecosystem and characterize the dynamics of these banking relationships over two years within the counterfeit pharmaceutical and software sectors. By opportunistically combining our own active purchasing data with contemporary disruption efforts by brand-holders and payment card networks, we gather the first empirical dataset concerning this approach. We discuss how well such payment interventions work, how abusive merchants respond in kind and the role that the payments ecosystem is likely to play in the future. Damon McCoy, Hitesh Dharmdasani, Christian Kreibich, Geoffrey M. Voelker, Stefan Savage |
CCS | 1 |
| 2012 | PharmaLeaks: Understanding the Business of Online Pharmaceutical Affiliate Programs
Damon McCoy, Andreas Pitsillidis, Grant Jordan, Nicholas Weaver, Christian Kreibich, Brian Krebs, Geoffrey M. Voelker, Stefan Savage, Kirill Levchenko |
USENIX Security Symposium | 1 |
| 2011 | An analysis of underground forumsabstractUnderground forums, where participants exchange information on abusive tactics and engage in the sale of illegal goods and services, are a form of online social network (OSN). However, unlike traditional OSNs such as Facebook, in underground forums the pattern of communications does not simply encode pre-existing social relationships, but instead captures the dynamic trust relationships forged between mutually distrustful parties. In this paper, we empirically characterize six different underground forums --- BlackHatWorld, Carders, HackSector, HackE1ite, Freehack, and L33tCrew --- examining the properties of the social networks formed within, the content of the goods and services being exchanged, and lastly, how individuals gain and lose trust in this setting. Marti Motoyama, Damon McCoy, Kirill Levchenko, Stefan Savage, Geoffrey M. Voelker |
Internet Measurement Conference | 2 |
| 2011 | DefenestraTor: Throwing Out Windows in Tor
Mashael Al Sabah, Kevin S. Bauer, Ian Goldberg 0001, Dirk Grunwald, Damon McCoy, Stefan Savage, Geoffrey M. Voelker |
PETS | 5 |
| 2011 | Click Trajectories: End-to-End Analysis of the Spam Value ChainabstractSpam-based advertising is a business. While it has engendered both widespread antipathy and a multi-billion dollar anti-spam industry, it continues to exist because it fuels a profitable enterprise. We lack, however, a solid understanding of this enterprise's full structure, and thus most anti-Spam interventions focus on only one facet of the overall spam value chain (e.g., spam filtering, URL blacklisting, site takedown).In this paper we present a holistic analysis that quantifies the full set of resources employed to monetize spam email -- including naming, hosting, payment and fulfillment -- using extensive measurements of three months of diverse spam data, broad crawling of naming and hosting infrastructures, and over 100 purchases from spam-advertised sites. We relate these resources to the organizations who administer them and then use this data to characterize the relative prospects for defensive interventions at each link in the spam value chain. In particular, we provide the first strong evidence of payment bottlenecks in the spam value chain, 95% of spam-advertised pharmaceutical, replica and software products are monetized using merchant services from just a handful of banks. Kirill Levchenko, Andreas Pitsillidis, Neha Chachra, Brandon Enright, Márk Félegyházi, Chris Grier, Tristan Halvorson, Chris Kanich, Christian Kreibich, Damon McCoy, Nicholas Weaver, Vern Paxson, Geoffrey M. Voelker, Stefan Savage |
IEEE Symposium on Security and Privacy | 11 |
| 2011 | Comprehensive Experimental Analyses of Automotive Attack Surfaces
Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage, Karl Koscher, Alexei Czeskis, Franziska Roesner, Tadayoshi Kohno |
USENIX Security Symposium | 2 |
| 2011 | Show Me the Money: Characterizing Spam-advertised Revenue
Chris Kanich, Nicholas Weaver, Damon McCoy, Tristan Halvorson, Christian Kreibich, Kirill Levchenko, Vern Paxson, Geoffrey M. Voelker, Stefan Savage |
USENIX Security Symposium | 3 |
| 2011 | Dirty Jobs: The Role of Freelance Labor in Web Service Abuse
Marti Motoyama, Damon McCoy, Kirill Levchenko, Stefan Savage, Geoffrey M. Voelker |
USENIX Security Symposium | 2 |
| 2010 | Practical Defenses for Evil Twin Attacks in 802.11abstractOpen-access 802.11 wireless networks are commonly deployed in cafes, bookstores, and other public spaces to provide free Internet connectivity. These networks are convenient to deploy, requiring no out-of-band key exchange or prior trust relationships. However, such networks are vulnerable to a variety of threats including the evil twin attack where an adversary clones a client's previously-used access point for a variety of malicious purposes including malware injection or identity theft. We propose defenses that aim to maintain the simplicity, convenience, and usability of open-access networks while offering increased protection from evil twin attacks. First, we present an evil twin detection strategy called context-leashing that constrains access point trust by location. Second, we propose that wireless networks be identified by uncertified public keys and design an SSH-style authentication and session key establishment protocol that fits into the 802.1X standard. Lastly, to mitigate the pitfalls of SSH-style authentication, we present a crowd-sourcing-based reporting protocol that provides historical information for access point public keys while preserving the location privacy of users who contribute reports. Harold Gonzales, Kevin S. Bauer, Janne Lindqvist, Damon McCoy, Douglas C. Sicker |
GLOBECOM | 4 |
| 2010 | Experimental Security Analysis of a Modern AutomobileabstractModern automobiles are no longer mere mechanical devices; they are pervasively monitored and controlled by dozens of digital computers coordinated via internal vehicular networks. While this transformation has driven major advancements in efficiency and safety, it has also introduced a range of new potential risks. In this paper we experimentally evaluate these issues on a modern automobile and demonstrate the fragility of the underlying system structure. We demonstrate that an attacker who is able to infiltrate virtually any Electronic Control Unit (ECU) can leverage this ability to completely circumvent a broad array of safety-critical systems. Over a range of experiments, both in the lab and in road tests, we demonstrate the ability to adversarially control a wide range of automotive functions and completely ignore driver input\dash including disabling the brakes, selectively braking individual wheels on demand, stopping the engine, and so on. We find that it is possible to bypass rudimentary network security protections within the car, such as maliciously bridging between our car's two internal subnets. We also present composite attacks that leverage individual weaknesses, including an attack that embeds malicious code in a car's telematics unit and that will completely erase any evidence of its presence after a crash. Looking forward, we discuss the complex challenges in addressing these vulnerabilities while considering the existing automotive ecosystem. Karl Koscher, Alexei Czeskis, Franziska Roesner, Shwetak N. Patel, Tadayoshi Kohno, Stephen Checkoway, Damon McCoy, Brian Kantor, Danny Anderson, Hovav Shacham, Stefan Savage |
IEEE Symposium on Security and Privacy | 7 |
| 2010 | Re: CAPTCHAs-Understanding CAPTCHA-Solving Services in an Economic Context
Marti Motoyama, Kirill Levchenko, Chris Kanich, Damon McCoy, Geoffrey M. Voelker, Stefan Savage |
USENIX Security Symposium | 4 |
| 2010 | Wifi-Reports: Improving Wireless Network Selection with CollaborationabstractWi-Fi clients can obtain much better performance at some commercial hot spots than others. Unfortunately, there is currently no way for users to determine which hot spot access points (APs) will be sufficient to run their applications before purchasing access. To address this problem, this paper presents Wifi-Reports, a collaborative service that provides Wi-Fi clients with historical information about AP performance and application support. The key research challenge in Wifi-Reports is to obtain accurate user-submitted reports. This is challenging because two conflicting goals must be addressed in a practical system: preserving the privacy of users' reports and limiting fraudulent reports. We introduce a practical cryptographic protocol that achieves both goals, and address the important engineering challenges in building Wifi-Reports. Using a measurement study of APs in a busy commercial district, we show that Wifi-Reports would improve the performance over previous AP selection approaches in 30-60 percent of locations. Jeffrey Pang, Ben Greenstein, Michael Kaminsky, Damon McCoy, Srinivasan Seshan |
IEEE Trans. Mob. Comput. | 4 |
| 2009 | The Directional Attack on Wireless Localization -or- How to Spoof Your Location with a Tin Canabstract802.11 localization algorithms provide the ability to accurately position and track wireless clients thereby enabling location-based services and applications. However, we show that these localization techniques are vulnerable to non-cryptographic attacks where an adversary uses a low-cost directional antenna to appear from the localization algorithm's perspective to be in another arbitrary location of their choosing. The attacker's ability to actively influence where they are positioned is a key distinguishing feature of the directional attack relative to prior localization attacks that use transmit power control to introduce localization errors. We implement a representative set of received signal strength-based localization algorithms and evaluate the attack in a real office building environment. To mitigate the attack's effectiveness, we develop and evaluate an attack detection scheme that offers a high detection rate with few false positives. Kevin S. Bauer, Damon McCoy, Eric Anderson 0002, Markus Breitenbach, Gregory Z. Grudic, Dirk Grunwald, Douglas C. Sicker |
GLOBECOM | 2 |
| 2009 | Wifi-reports: improving wireless network selection with collaborationabstractWi-Fi clients can obtain much better performance at some commercial hotspots than at others. Unfortunately, there is currently no way for users to determine which hotspot access points (APs) will be sufficient to run their applications before purchasing access. To address this problem, this paper presents Wifi-Reports, a collaborative service that provides Wi-Fi clients with historical information about AP performance and application support. The key research challenge in Wifi-Reports is to obtain accurate user-submitted reports. This is challenging because two conflicting goals must be addressed in a practical system: preserving the privacy of users' reports and limiting fraudulent reports. We introduce a practical cryptographic protocol that achieves both goals, and we address the important engineering challenges in building Wifi-Reports. Using a measurement study of commercial APs in Seattle, we show that Wifi-Reports would improve performance over previous AP selection approaches in 30%-60% of locations. Jeffrey Pang, Ben Greenstein, Michael Kaminsky, Damon McCoy, Srinivasan Seshan |
MobiSys | 4 |
| 2009 | Physical Layer Attacks on Unlinkability in Wireless LANs
Kevin S. Bauer, Damon McCoy, Ben Greenstein, Dirk Grunwald, Douglas C. Sicker |
Privacy Enhancing Technologies | 2 |
| 2008 | Mitigating Evil Twin Attacks in 802.11abstractDue to the prevalence of insecure open 802.11 access points, it is currently easy for a malicious party to launch a variety of attacks such as eavesdropping and data injection. In this paper, we consider a particular threat called the evil twin attack, which occurs when an adversary clones an open access point and exploits common automatic access point selection techniques to trick a wireless client into associating with the malicious access point. We propose two lines of defense against this attack. First, we present an evil twin detection strategy called context-leashing based upon recording the nearby access points when first associating with an access point. Using this contextual information, the client determines if an adversary has setup an evil twin access point at a different location. Next, we propose an SSH-style authentication method called EAP-SWAT to perform one-way access point authentication that fits into the extensible authentication protocol (EAP) framework. Kevin S. Bauer, Harold Gonzales, Damon McCoy |
IPCCC | 3 |
| 2008 | Improving wireless privacy with an identifier-free link layer protocolabstractWe present the design and evaluation of an 802.11-like wireless link layer protocol that obfuscates all transmitted bits to increase privacy. This includes explicit identifiers such as MAC addresses, the contents of management messages, and other protocol fields that the existing 802.11 protocol relies on to be sent in the clear. By obscuring these fields, we greatly increase the difficulty of identifying or profiling users from their transmissions in ways that are otherwise straightforward. Our design, called SlyFi, is nearly as efficient as existing schemes such as WPA for discovery, link setup, and data delivery despite its heightened protections; transmission requires only symmetric key encryption and reception requires a table lookup followed by symmetric key decryption. Experiments using our implementation on Atheros 802.11 drivers show that SlyFi can discover and associate with networks faster than 802.11 using WPA-PSK. The overhead SlyFi introduces in packet delivery is only slightly higher than that added by WPA-CCMP encryption (10% vs. 3% decrease in throughput). Ben Greenstein, Damon McCoy, Jeffrey Pang, Tadayoshi Kohno, Srinivasan Seshan, David Wetherall |
MobiSys | 2 |
| 2008 | Shining Light in Dark Places: Understanding the Tor Network
Damon McCoy, Kevin S. Bauer, Dirk Grunwald, Tadayoshi Kohno, Douglas C. Sicker |
Privacy Enhancing Technologies | 1 |
| 2008 | BitBlender: Light-Weight Anonymity for BitTorrentabstractWe present BitBlender, an efficient protocol that provides an anonymity layer for BitTorrent traffic. BitBlender works by creating an ad-hoc multi-hop network consisting of special peers called "relay peers" that proxy requests and replies on behalf of other peers. To understand the effect of introducing relay peers into the BitTorrent system architecture, we provide an analysis of the expected path lengths as the ratio of relay peers to normal peers varies. A prototype is implemented and experiments are conducted on Planetlab to quantify the performance overhead associated with the protocol. We also propose protocol extensions to add confidentiality and access control mechanisms, countermeasures against traffic analysis attacks, and selective caching policies that simultaneously increase both anonymity and performance. We finally discuss the potential legal obstacles to deploying an anonymous file sharing protocol. This work is among the first to propose a privacy enhancing system that is designed specifically for a particular class of peer-to-peer traffic. Kevin S. Bauer, Damon McCoy, Dirk Grunwald, Douglas C. Sicker |
SecureComm | 2 |
| 2006 | Passive Data Link Layer 802.11 Wireless Device Driver Fingerprinting
Jason Franklin, Damon McCoy |
USENIX Security Symposium | 2 |