"Please don't send that bot anything": Mixed-methods Study of Personal Impersonation Attacks to Steal Digital Payments on Social Media
收藏资源简介:
This archive accompanies the paper “Please Don’t Send That Bot Anything: Mixed-Methods Study of Personal Impersonation Attacks to Steal Digital Payments on Social Media.” In keeping with open science guidelines, we are making all artifacts available for researchers. Note that this is a private repository that contains unanonymized raw data. Therefore, we restrict its access to security researchers to prevent abuse. If you need access to the public repository instead please refer to: https://doi.org/10.5281/zenodo.15611472 Below is a high‐level overview of each component and guidance on how to navigate and use them. Repository Structure X-AM_code/ browser_extension_code/ quantitative_analysis_code/ codebook_qualitative_analysis/ aggregated_dataset/ raw_data/ Contents X-AM_code/Contains the X-AM optimized real-time data collection and validation pipeline for PROSPER attacks. Refer to X-AM_code/README for detailed instructions on running and replicating our data collection. browser_extension_code/Holds the source code for the browser extension we used during historical data collection, which captures trigger‐tweet search results via a browser extension. quantitative_analysis_code/Contains the scripts for the quantitative analysis described in Section 3 of our paper. Refer to quantitative_analysis_code/README.md for instructions on running this script. codebook_qualitative_analysis/Includes the full codebook used for our Section 4 qualitative analysis. aggregated_dataset/Provides processed and anonymized data aggregated from our raw dataset, used for generation of our results in Section 3. raw_data/Includes raw data collected in our study, comprising non‐anonymized victim and attacker account IDs. For more details on the raw dataset, see raw_data/README.md.



