- Did Pete Buttigieg seriously just rip-off a famous Obama speech? 4 Years Ago
- The most dangerous TikTok challenges we’ve seen—so far 4 Years Ago
- PewDiePie wants Bernie Sanders to host meme review Today 1:44 PM
- Hilary Duff records confrontation with ‘creep’ taking photos of kids Today 1:08 PM
- BTS may have used Twitch streamer’s voice in song without permission Today 12:15 PM
- Gigi Hadid absolutely obliterates Jake Paul over Zayn Malik diss Today 10:26 AM
- People really want Chris Matthews fired after he compared Sanders’ Nevada win to Nazi invasion of France Today 9:35 AM
- Bernie Sanders wins Nevada Caucuses Saturday 6:54 PM
- MSNBC is out of its mind over Sanders leading Nevada Saturday 5:20 PM
- Kim Kardashian dragged for using makeup to darken her hands Saturday 4:13 PM
- TikTok users show how they turned their vehicles into incredible tiny homes Saturday 3:44 PM
- Woman iconically pranks man who sent her an unsolicited d*ck pic Saturday 2:25 PM
- ‘Terrifying’ deepfake puts Jeff Bezos and Elon Musk in ‘Star Trek’ Saturday 1:06 PM
- A 36-year-old called the cops after being booted from parents’ phone plan Saturday 12:16 PM
- People think novelist Dean Koontz predicted the coronavirus in 1981 thriller Saturday 10:22 AM
New system automatically detects when your Twitter or Facebook account gets hacked
Social networks are a battlefield.
If that sounds strange, remember the 2013 hack against the Associated Press’s Twitter account that claimed a terror attack on the White House. Thanks to a single tweet from the AP account, which was shared thousands of times, the U.S. stock market instantly plummeted $136 billion before Twitter flagged the account as hacked. Or consider the last four years of Syrian Electronic Army attacks against major Western social media accounts and websites (including this one).
Given this vulnerability, a key question has arisen: How do you sniff out the hackers aiming for social media accounts that have become such impressively important and trusted megaphones?
A new system called COMPA quickly identifies compromised social network accounts by checking old habits against sudden changes, a significantly reliable way to detect hacked accounts, according to new research from American and British academics posted at Cornell University’s arXiv.
“COMPA is based on a simple observation: social network users develop habits over time, and these habits are fairly stable,” the researchers wrote.
“A typical social network user, for example, might consistently check her posts in the morning from her phone, and during the lunch break from her desktop computer. Furthermore, interaction will likely be limited to a moderate number of social network contacts (i.e., friends). Conversely, if the account falls under the control of an adversary, the messages that the attacker sends will likely show anomalies compared to the typical behavior of the user.”
COMPA builds a behavioral profile of each user based on a few pertinent questions—When do they post? How do they access the social network? What language do they write in? What kind of links do they send? Who are they connecting with?—and then watches for aberrations like an out-of-character tweet or a strange Facebook message that doesn’t match up.
When an action deviates from the behavioral profile, COMPA flags the account as potentially compromised.
One bizarre caveat originates in 2013, when the American restaurant Chipotle faked a social media hack as a publicity stunt. The hack fooled a lot of people—Chipotle’s Twitter account gained 1,600 percent more followers in a single day—but COMPA recognized the fraud, researchers boasted, because the fake hack actually matched previous behavior.
You can read the research below:
The research paper was written by Manuel Egele of Boston University, Gianluca Stringhini of University College London, as well as Christopher Kruegel and Giovanni Vigna of UC Santa Barbara.
Illustration by Max Fleishman
Patrick Howell O'Neill is a notable cybersecurity reporter whose work has focused on the dark net, national security, and law enforcement. A former senior writer at the Daily Dot, O'Neill joined CyberScoop in October 2016. I am a cybersecurity journalist at CyberScoop. I cover the security industry, national security and law enforcement.