Social Honeypots are tools deployed in Online Social Networks (OSN) to attract malevolent activities performed by spammers and bots. To this end, their content is designed to be of maximum interest to malicious users. However, by choosing an appropriate content topic, this attractive mechanism could be extended to any OSN users, rather than only luring malicious actors. As a result, honeypots can be used to attract individuals interested in a wide range of topics, from sports and hobbies to more sensitive subjects like political views and conspiracies. With all these individuals gathered in one place, honeypot owners can conduct many analyses, from social to marketing studies. In this work, we introduce a novel concept of social honeypot for attracting OSN users interested in a generic target topic. We propose a framework based on fully-automated content generation strategies and engagement plans to mimic legit Instagram pages. To validate our framework, we created 21 self-managed social honeypots (i.e., pages) on Instagram, covering three topics, four content generation strategies, and three engaging plans. In nine weeks, our honeypots gathered a total of 753 followers, 5387 comments, and 15739 likes. These results demonstrate the validity of our approach, and through statistical analysis, we examine the characteristics of effective social honeypots.
翻译:社交蜜罐是部署在在线社交网络中的工具,旨在吸引垃圾邮件发送者和机器人进行的恶意活动。为此,其内容被设计为对恶意用户具有最大吸引力。然而,通过选择适当的内容主题,这种吸引机制可扩展到所有社交网络用户,而不仅仅引诱恶意行为者。因此,蜜罐可用于吸引对广泛话题感兴趣的个人,从体育、爱好到政治观点、阴谋论等更敏感的主题。当这些个体聚集在一处时,蜜罐所有者可进行从社会研究到市场调研等多种分析。本研究提出了一种新颖的社交蜜罐概念,用于吸引对特定目标话题感兴趣的社交网络用户。我们基于全自动内容生成策略和互动计划构建了一个框架,以模拟真实的Instagram页面。为验证该框架,我们在Instagram上创建了21个自主管理的社交蜜罐(即页面),涵盖三个话题、四种内容生成策略和三种互动计划。在九周内,我们的蜜罐共吸引了753名关注者、5387条评论和15739个点赞。这些结果证明了方法的有效性,并通过统计分析,我们探究了高效社交蜜罐的特征。