论文标题
表征加密货币交换骗局
Characterizing Cryptocurrency Exchange Scams
论文作者
论文摘要
随着生态系统必不可少的交易平台,数百个加密货币交易所正在促进数字资产的交易。而这也吸引了攻击者的注意。据报道,许多骗局袭击针对加密货币交流,导致了大量的财务损失。但是,我们的研究社区以前没有研究这个问题。在本文中,我们首先努力识别和表征加密货币交换骗局。我们首先通过收集现有报告并使用打字机生成技术来确定1,500多个骗局域和300多个假应用程序。然后,我们研究了它们之间的关系,并确定94个骗局家庭和30个假应用程序家庭。我们进一步描述了此类骗局的影响,并揭示了这些骗局至少损失了520亿美元。我们进一步观察到,假应用程序已被潜入主要的应用程序市场(包括Google Play),以感染不可思议的用户。我们的发现表明了识别和防止加密货币交换骗局的紧迫性。为了促进未来的研究,我们已将所有已确定的骗局域和假应用程序公开发布给社区。
As the indispensable trading platforms of the ecosystem, hundreds of cryptocurrency exchanges are emerging to facilitate the trading of digital assets. While, it also attracts the attentions of attackers. A number of scam attacks were reported targeting cryptocurrency exchanges, leading to a huge mount of financial loss. However, no previous work in our research community has systematically studied this problem. In this paper, we make the first effort to identify and characterize the cryptocurrency exchange scams. We first identify over 1,500 scam domains and over 300 fake apps, by collecting existing reports and using typosquatting generation techniques. Then we investigate the relationship between them, and identify 94 scam domain families and 30 fake app families. We further characterize the impacts of such scams, and reveal that these scams have incurred financial loss of 520k US dollars at least. We further observe that the fake apps have been sneaked to major app markets (including Google Play) to infect unsuspicious users. Our findings demonstrate the urgency to identify and prevent cryptocurrency exchange scams. To facilitate future research, we have publicly released all the identified scam domains and fake apps to the community.