SearcharxivSearch

arXiv subjects

Richard Clayton

Publications and source records attributed to Richard Clayton.

4 recordsLinked to original sources

Assessing the Aftermath: the Effects of a Global Takedown against DDoS-for-hire Services

Law enforcement and private-sector partners have in recent years conducted various interventions to disrupt the DDoS-for-hire market. Drawing on multiple quantitative datasets, including web traffic and ground-truth visits to seized websites, millions of DDoS attack records from academic, industry, and self-reported statistics, along with chats on underground forums and Telegram channels, we assess the effects of an ongoing global intervention against DDoS-for-hire services since December 2022. This is the most extensive booter takedown to date conducted, combining targeting infrastructure with digital influence tactics in a concerted effort by law enforcement across several countries with two waves of website takedowns and the use of deceptive domains. We found over half of the seized sites in the first wave returned within a median of one day, while all booters seized in the second wave returned within a median of two days. Re-emerged booter domains, despite closely resembling old ones, struggled to attract visitors (80-90% traffic reduction). While the first wave cut the global DDoS attack volume by 20-40% with a statistically significant effect specifically on UDP-based DDoS attacks (commonly attributed to booters), the impact of the second wave appeared minimal. Underground discussions indicated a cumulative impact, leading to changes in user perceptions of safety and causing some operators to leave the market. Despite the extensive intervention efforts, all DDoS datasets consistently suggest that the illicit market is fairly resilient, with an overall short-lived effect on the global DDoS attack volume lasting for at most only around six weeks.

cs.CR

Getting Bored of Cyberwar: Exploring the Role of Low-level Cybercrime Actors in the Russia-Ukraine Conflict

There has been substantial commentary on the role of cyberattacks carried out by low-level cybercrime actors in the Russia-Ukraine conflict. We analyse 358k website defacement attacks, 1.7M UDP amplification DDoS attacks, 1764 posts made by 372 users on Hack Forums mentioning the two countries, and 441 Telegram announcements (with 58k replies) of a volunteer hacking group for two months before and four months after the invasion. We find the conflict briefly but notably caught the attention of low-level cybercrime actors, with significant increases in online discussion and both types of attacks targeting Russia and Ukraine. However, there was little evidence of high-profile actions; the role of these players in the ongoing hybrid warfare is minor, and they should be separated from persistent and motivated 'hacktivists' in state-sponsored operations. Their involvement in the conflict appears to have been short-lived and fleeting, with a clear loss of interest in discussing the situation and carrying out both website defacement and DDoS attacks against either Russia or Ukraine after just a few weeks.

cs.CR

Online Suicide Games: A Form of Digital Self-harm or A Myth?

Online suicide games are claimed to involve a series of challenges, ending in suicide. A whole succession of these such as the Blue Whale Challenge, Momo, the Fire Fairy and Doki Doki have appeared in recent years. The challenge culture is a deeply rooted online phenomenon, whether the challenge is dangerous or not, while social media particularly motivates youngsters to take part because of their desire for attention. Although there is no evidence that the suicide games are real, authorities around the world have reacted by releasing warnings and creating information campaigns to warn youngsters and parents. We interviewed teachers, child protection experts and NGOs, conducted a systematic review of historical news reports from 2015-2019 and searched police and other authority websites to identify relevant warning releases. We then synthesized the existing knowledge on the suicide games phenomenon. A key finding of our work is that media, social media and warning releases by authorities are mainly just serving to spread the challenge culture and exaggerate fears regarding online risk.

cs.CY

The gift of the gab: Are rental scammers skilled at the art of persuasion?

Rental scams are a type of advance fee fraud, in which the scammer tries to get a victim to pay a deposit to rent an apartment of which the scammer pretends to be the landlord. We specifically focused on fraudulent long-term rentals advertised in the UK on Craigslist. After a victim responds to the scammer's advertisement, the scammer attempts to persuade them to transfer money without having seen the property. We were interested in which persuasion techniques scammers use, and in assessing their skill at the art of persuasion. During a period of three weeks, we scraped 2112 letting advertisements, identified the fraudulent advertisements and had 44 conversations of around 4 or 5 emails each with the scammers. Our analysis indicates that Cialdini`s marketing-based social persuasion strategies, such as liking, appeal to authority, and the need for commitment and consistency are extensively implemented by rental scammers. Of Stajano and Wilson's scam-based persuasion strategies, an appeal to sympathy (i.e., kindness) and need for greed were commonly used. We identified two further social persuasion strategies: establishing credibility and removing objections. At a superficial level, rental scammers seem skilled at their job, because they mimic genuine landlords and use a range of effective persuasion techniques. However, when examining their emails more closely, we see they often use pre-scripted emails, their mimicry is often incompetent, and they have a lack of language skills and cultural knowledge that may tip people off. They appear to be the criminal equivalent of a boilerhouse sales operation, a modus operandi that has not previously been studied by cybercrime researchers.

cs.CY