ProGuard: Detecting Malicious Accounts in Social-Network-Based Online Promotions


Online social networks (OSNs) gradually integrate financial capabilities by enabling the use of real and virtual currency. They serve as new platforms for hosting a variety of business activities, such as online promotion events, where by participating in such events, users can possibly get virtual currency as rewards. Both OSNs and business partners are significantly concerned when attackers use a set of accounts to collect virtual currency from these events, making these events ineffective and resulting in significant financial loss. It becomes of great importance to proactively detecting these malicious accounts before the online promotion activities and subsequently decreases their priority to be rewarded. We conducted extensive experiments based on data collected from the Tencent QQ.



In particular, a user commonly represented by their OSN account can receive a virtual currency reward through participating in online promotion activities run by business entities. She can then use such a reward in various ways, such as online shopping, transfer it to others and even exchange it for real currency. Such an online promotion model enabled by virtual currency enables enormous outreach, provides direct financial stimuli to end users, while minimizing interactions between business entities and financial institutions. As a result, this model showed great promise and rapidly gained enormous international prevalence.

However, it faces a significant threat: attackers can control a large number of accounts, either by registering new accounts or compromising existing accounts, to participate in virtual currency online promotion events.Such malicious activities will fundamentally undermine the effectiveness of promotional activities, immediately voiding the effectiveness of business entities ‘ promotional investment and meanwhile damaging the reputation of ONSs.

The detection of accounts controlled by assailants in online development is therefore essential. We use malicious accounts as part of the following discussions. Effective detection of malicious accounts allows both OSNs and business entities to take mitigation actions such as banning these accounts or decreasing the possibility of rewarding these accounts.