Strengthening Weak Identities Through Inter-Domain Trust Transfer
Giridhari ¡Venkatadri, ¡Oana ¡Goga, ¡Changtao ¡Zhong, ¡Bimal ¡ Viswanath, ¡Nishanth ¡Sastry, ¡Krishna ¡Gummadi ¡ ¡
Strengthening Weak Identities Through Inter-Domain Trust Transfer - - PowerPoint PPT Presentation
Strengthening Weak Identities Through Inter-Domain Trust Transfer Giridhari Venkatadri, Oana Goga , Changtao Zhong, Bimal Viswanath, Nishanth Sastry, Krishna Gummadi Online
Giridhari ¡Venkatadri, ¡Oana ¡Goga, ¡Changtao ¡Zhong, ¡Bimal ¡ Viswanath, ¡Nishanth ¡Sastry, ¡Krishna ¡Gummadi ¡ ¡
2
Trusted certificate
weak identity-infrastructure
Trusted certificate
strong identity-infrastructure
2
Accountability Anonymity Adoption Resistance to fake identity attacks
Trusted certificate
weak identity-infrastructure
Trusted certificate
strong identity-infrastructure
2
Accountability Anonymity Adoption Resistance to fake identity attacks
Trusted certificate
weak identity-infrastructure
Trusted certificate
strong identity-infrastructure
Up to 40% of newly created identities on Twitter are malicious!!
2
Accountability Anonymity Adoption Resistance to fake identity attacks
Trusted certificate
weak identity-infrastructure
Trusted certificate
strong identity-infrastructure
Up to 40% of newly created identities on Twitter are malicious!!
Current techniques: Based on the past activity of each identity within the domain Limitation: Domains need to observe the behavior of weak identities over time (time lag)
(e.g., Reddit posting quotas)
3
4
Trusted certificate
4
Trusted certificate
external trust certificates
and they already interconnect their identities (e.g., social login)
for newer domains
5
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
6
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
6
Can activity signals from Facebook and Twitter help Pinterest reason about trustworthiness better? Dataset
matching identities on Facebook and Twitter
Twitter and Facebook (e.g., account age, # followers, suspension)
7
8
(untrustworthiness on Pinterest) activity signal
8
Correlation between untrustworthiness on Pinterest and the choice of the source domain! (untrustworthiness on Pinterest) activity signal
9
0.1 0.2 0.3 0.4 0.5 0.6 >0.2 0.05 0.1 0.15
Fraction of identities suspended Fraction of blocked pins
Facebook Twitter
(untrustworthiness on Pinterest) activity signal
9
0.1 0.2 0.3 0.4 0.5 0.6 >0.2 0.05 0.1 0.15
Fraction of identities suspended Fraction of blocked pins
Facebook Twitter
Untrustworthy Pinterest identities are more likely to be suspended on Twitter (but not on Facebook!) (untrustworthiness on Pinterest) activity signal
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
10
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
10
11
Target domain Source domains Sn S2 S1
11
Target domain Source domains Sn S2 S1
What are the challenges?
12
Target domain Source domains Sn S2 S1
12
Target domain Source domains Sn S2 S1
12
Target domain Source domains Sn S2 S1
Solution: single sign-on protocols
12
Target domain Source domains Sn S2 S1
this can be done in an anonymous way as well! Solution: single sign-on protocols
13
Target domain Source domains Sn S2 S1
13
Target domain Source domains Sn S2 S1
Inf( )
13
Target domain Source domains Sn S2 S1
Ideal information:
Inf( )
13
Target domain Source domains Sn S2 S1
Ideal information:
Inf( ) Solution:
permission of the user (e.g., OAuth)
coarse grain information
14
Inf( ) Inf( ) 100 followers 1000 likes
14
Inf( ) Inf( ) 100 followers 1000 likes Solution: Target domain needs to do a calibration step (e.g. using a classifier and all available activity signals)
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
15
1. Potential for inter-domain trust transfer 2. Inter-domain trust transfer framework 3. Leverage inter-domain trust transfer for identity curation
15
Curated set of identities: a set of identities with high probability to be trustworthy Why curate? I. Early access to elevated privileges
Question: Can activity signals from Facebook/Twitter help Pinterest:
16
17
0.93 0.94 0.95 0.96 0.97 0.98 0.99 10 20 30 40 50 60 70 80 90 100
Purity level Coverage
All signals Pinterest signals Random
17
0.93 0.94 0.95 0.96 0.97 0.98 0.99 10 20 30 40 50 60 70 80 90 100
Purity level Coverage
All signals Pinterest signals Random
0.975
17
0.93 0.94 0.95 0.96 0.97 0.98 0.99 10 20 30 40 50 60 70 80 90 100
Purity level Coverage
All signals Pinterest signals Random
Trust transfer allows to curate more than twice as many identities !!
0.975
18
0.2 0.4 0.6 0.8 1
5 10 15 20 25 30
CDF of identities Age in months on Pinterest
Pinterest curated Additionally curated
18
0.2 0.4 0.6 0.8 1
5 10 15 20 25 30
CDF of identities Age in months on Pinterest
Pinterest curated Additionally curated
18
0.2 0.4 0.6 0.8 1
5 10 15 20 25 30
CDF of identities Age in months on Pinterest
Pinterest curated Additionally curated
Trust transfer allows to curate identities up to 15 months in advance !!
be mitigated by user’s weak identities on other domains
19