反欺诈能否让大规模攻击无利可图?
3 分•作者: jezzwar•12 天前
我希望获得有欺诈预防、安全、广告技术或滥用系统经验的人的反馈。
假设有一个平台,用户可以根据经过验证的真实活动获得某种形式的收益。一个主要担忧是,有组织的欺诈操作是否能够盈利地扩展。
一个普遍的假设是,攻击者总会找到绕过个体防御的方法。因此,与其试图让滥用变得不可能,不如采取增加滥用成本的方法:
* 设备声誉和指纹识别;
* IP/网络声誉;
* VPN/代理/数据中心检测;
* 行为分析;
* 账户随时间推移的声誉;
* 图分析以检测关联账户;
* 基于风险的限制和延迟支付;
* 人工审核和反馈循环。
这样做的目的是,欺诈者或许能够创建账户,但要大规模地维持盈利账户则变得困难。
问题是:
这是否真的能改变欺诈的经济学原理,还是说,老练的运营商总能找到保持盈利的方法?
例如,攻击者理论上可以使用虚拟机、代理、自动化和其他基础设施。但他们也有持续的成本:
* 基础设施;
* 获取和维护身份/账户;
* 运营开销;
* 适应检测系统;
* 账户和声誉的损失。
运营成本何时会超过预期回报?
我特别希望听到在欺诈的进攻方或防御方工作过的人的观点。您会期望这种方法存在哪些弱点?哪些信号实际上是有价值的,哪些更多是安全表演?
我寻求的是批评,而不是认可。
查看原文
I’m interested in feedback from people who have experience with fraud prevention, security, ad-tech, or abuse systems.<p>Let’s assume a platform where users receive some form of benefit based on verified real activity. A major concern is whether organized fraud operations can scale profitably.<p>A common assumption is that attackers will always find a way around individual defenses. So instead of trying to make abuse impossible, the approach is to increase the cost of abuse:<p>device reputation and fingerprinting;
IP/network reputation;
VPN/proxy/datacenter detection;
behavioral analysis;
account reputation over time;
graph analysis to detect connected accounts;
risk-based limits and delayed payouts;
manual review and feedback loops.<p>The idea is that a fraudster might be able to create accounts, but maintaining profitable accounts at scale becomes difficult.<p>The question:<p>Does this actually change the economics of fraud, or will sophisticated operators always find a way to stay profitable?<p>For example, attackers can theoretically use virtual machines, proxies, automation, and other infrastructure. But they also have ongoing costs:<p>infrastructure;
acquiring and maintaining identities/accounts;
operational overhead;
adapting to detection systems;
losing accounts and reputation.<p>At what point does the cost of running the operation exceed the expected return?<p>I’m especially interested in perspectives from people who have worked on the offensive or defensive side of fraud. What weaknesses would you expect in this approach? Which signals are actually valuable, and which are mostly security theater?<p>Looking for criticism, not validation.