反欺诈措施能否使大规模攻击变得无利可图?

3 分•作者: jezzwar•2 个月前•原帖
我对那些在欺诈预防、安全、广告技术或滥用系统方面有经验的人士的反馈很感兴趣。 假设有一个平台,用户根据经过验证的真实活动获得某种形式的收益。一个主要的担忧是,组织化的欺诈操作是否能够盈利并扩展规模。 一个常见的假设是,攻击者总会找到绕过个别防御措施的方法。因此,与其试图让滥用行为变得不可能,不如采取提高滥用成本的策略: - 设备声誉和指纹识别; - IP/网络声誉; - VPN/代理/数据中心检测; - 行为分析; - 随时间推移的账户声誉; - 图形分析以检测关联账户; - 基于风险的限制和延迟支付; - 手动审核和反馈循环。 这个想法是,欺诈者可能能够创建账户,但在规模上维持盈利账户将变得困难。 问题是: 这是否真的改变了欺诈的经济学,还是说复杂的操作者总能找到保持盈利的方法? 例如,攻击者理论上可以使用虚拟机、代理、自动化和其他基础设施。但他们也有持续的成本: - 基础设施; - 获取和维护身份/账户; - 操作开销; - 适应检测系统; - 失去账户和声誉。 在什么情况下,运营的成本会超过预期的收益? 我特别希望听到那些在欺诈的进攻或防守方面工作过的人的看法。您认为这种方法存在哪些弱点?哪些信号实际上是有价值的,哪些只是安全表演? 我寻求的是批评,而不是验证。
查看原文
I’m interested in feedback from people who have experience with fraud prevention, security, ad-tech, or abuse systems.<p>Let’s assume a platform where users receive some form of benefit based on verified real activity. A major concern is whether organized fraud operations can scale profitably.<p>A common assumption is that attackers will always find a way around individual defenses. So instead of trying to make abuse impossible, the approach is to increase the cost of abuse:<p>device reputation and fingerprinting; IP&#x2F;network reputation; VPN&#x2F;proxy&#x2F;datacenter detection; behavioral analysis; account reputation over time; graph analysis to detect connected accounts; risk-based limits and delayed payouts; manual review and feedback loops.<p>The idea is that a fraudster might be able to create accounts, but maintaining profitable accounts at scale becomes difficult.<p>The question:<p>Does this actually change the economics of fraud, or will sophisticated operators always find a way to stay profitable?<p>For example, attackers can theoretically use virtual machines, proxies, automation, and other infrastructure. But they also have ongoing costs:<p>infrastructure; acquiring and maintaining identities&#x2F;accounts; operational overhead; adapting to detection systems; losing accounts and reputation.<p>At what point does the cost of running the operation exceed the expected return?<p>I’m especially interested in perspectives from people who have worked on the offensive or defensive side of fraud. What weaknesses would you expect in this approach? Which signals are actually valuable, and which are mostly security theater?<p>Looking for criticism, not validation.