<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>The Dark Side of Open Data</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Matteo Mauri</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Alessio Mulas</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Davide Ariu</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>DIEE, University of Cagliari</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>We present a poster about a possible cyber-crime attack scenario based on data sciences, social engineering and open data. We want to raise awareness about dangers associated with the use of knowledge discovery techniques applied to open data by cyber-criminals. We hope this poster will spark interest in the topic.</p>
      </abstract>
      <kwd-group>
        <kwd>Knowledge Discovery</kwd>
        <kwd>Social Engineering</kwd>
        <kwd>Cyber-Crime</kwd>
        <kwd>Open Data</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>
        Humanity's streets are paved with data and as society moves forward we seem
to generate an ever larger amount of them. Data is a necessary \fuel" not just
for scienti c progress (e.g. gene mapping, LHC,etc.) but also for communication,
leisure activities (e.g. online gaming, multimedia streaming) or more important
sectors (e.g. government, military, transport and enterprises). Large amounts of
data would be unusable without the aid of powerful computers, as a consequence
we require data to be machine readable. Western world countries are adopting
a governing doctrine which holds that citizens have the right to access
government's documents and proceedings to allow for an e ective public oversight [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ].
While transparency can help citizens controlling their governments (i.e. reducing
corruption and bribery) [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ] it also comes with a prize: a loss in terms of privacy.
All this data is also surely useful, if not invaluable, for each kind of scam and
illicit activity based on social engineering (from now onward simply SE) [
        <xref ref-type="bibr" rid="ref3 ref4">3, 4</xref>
        ].
What happens if we combine open data and SE with disciplines such as data
analysis, knowledge discovery and data visualization (from now onward
collectively indicated as KD)? Can we foresee a scenario where these three elements
become the key of large cyber-criminal campaigns? The purpose of this paper is
to demonstrate that this hypothesis is a realistic one and to provide an example
of attack scenario.
      </p>
    </sec>
    <sec id="sec-2">
      <title>Open Data Vs. OSINT</title>
      <p>
        The rise of Internet and World Wide Web has caused an increase popularity of
\open data": the idea that some data should be free to use, distribute and share
by everyone without any restrictions or copyright [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ]. Despite being usually
associated with positive values such as \freedom", \innovation" or \opportunity",
open data (from now onward simply OD) should raise some privacy concerns
couple with a doubt: how much the average man or country's \decision
makers" know about subjects such as data, privacy and security? From a military
and government point of view there is no doubt, OD are an invaluable asset.
Open Source Intelligence (OSINT) is often able to turn apparently trivial data
into critical information. A famous early example is the story of how during
World War II the price of oranges in Paris was successfully used as an
indicator of whether railroad bridges had been bombed by Axis forces. The fact that
OD and transparency are broadly perceived by people as a source of innovation
and a more honest government while OSINT are associated with the world of
espionage and warfare should give an hint of how much confusion or lack of
knowledge there is about the subject.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>The evolution of Cyber Crime</title>
      <p>
        Open Data by themselves are already an interesting security topic but they
become even more important once we take into account how cyber-crime has
evolved in these last years. Long gone are the times of the lonesome nerdy
looking hacker, citizen of the BBS, frantically pressing keys while burning the
midnight oil over some co ee stained RFCs. These days cyber criminals are not
alone anymore [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], they are organized, they are bad and they only care for one
thing: pro t.
      </p>
      <p>
        Some examples: Stoyanov (Kaspersky Lab), describes Russian underground
cyber-crime organizations as well structured and similar to enterprises [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ]. Kharouni
(Trend Micro) describes a more distributed, less structured but equally
\business oriented" African cyber-crime [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ]. Among the new skill-sets required by
modern cyber-criminals, psychology and \data sciences" are in high demand.
Psychological principles are useful to devise better scams. Cialdini's work on the
psychology of in uence and persuasion [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ] has been already proven to be correct
even if applied to computer mediated forms of communication such as emails or
chat [
        <xref ref-type="bibr" rid="ref8">8</xref>
        ]. Data sciences can help criminals in several ways: nding victims (e.g.
search engine misuse, Black SEO, etc.), providing support in the creation of fake
web sites and social network pro les (e.g. web scraping, text analysis for chat,
etc.), etc.
4
      </p>
    </sec>
    <sec id="sec-4">
      <title>Social Engineering &amp; Knowledge Discovery</title>
      <p>
        Mitnick describes a generic SE driven attack as composed of four phases:
research, developing rapport and trust, exploiting trust, utilize information [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ].
It's interesting to analyse the usefulness of SE and KD applied to each one of
the four phases:
{ Research { according to Mitnick this phase should focus on open sources of
information. OD are structured and machine readable making KD extremely
useful for criminals. Information on a large number of victims can be
collected from several sources, combined and ltered according to a desired
criteria (e.g. age, gender, etc.).
{ Developing rapport and trust. This phase is strongly based on SE. In
order to gain the trust of the victim, every details is fundamental. A good
message leveraging the right SE principles, sent on the best medium (e.g.
chat, email, etc.) and using the best fake persona (e.g. gender, age, etc.) is
bound to succeed. SE skills allow criminals to psychologically pro le victims
using information collected from social networks and OD. Once a victim
is pro led, the criminal can easily decide what is the best strategy for the
attack. SE skills can also help eliciting information from victims. KD can
help the criminal solve the technical problems and automatize the process.
{ Exploit trust. It's during this phase that the attacker asks the victim to
share some knowledge or perform some action (e.g. clicking on a link, opening
an attached le). KD's role in this phase is minimum, SE skills, on the other
hand, can be useful.
{ Utilize information. The obtained information can be the goal or just the
starting point for a new attack. Data sciences can be useful in analysing and
processing collected information.
5
      </p>
    </sec>
    <sec id="sec-5">
      <title>An Attack Scenario</title>
      <p>The purpose of this section is to brie y describe a possible attack scenario based
on open data, knowledge discovery (and data sciences in general) and social
engineering. Research { according to the law, the University of Cagliari must share
as \open" all information regarding any purchase of equipment. The attacker
downloads the XML le containing a date, a list of all purchased equipments
and legal informations regarding the seller's company. The attacker uses seller's
information as input for a common search engine and easily obtains
information such as: company's web site, telephone number, legal documents. Business
oriented search engines provide even maps and other intelligence. Developing
rapport and trust { the attacker examines the harvested data and devises a
strategy: he will send an email posing as an university employee asking for
collaboration in order to solve a minor administrative problem. The seller will be
told that the problem has been already solved but he is required to read the
attached le and con rm that everything is correct by replying to the email.
An email is considered a good attack vector since its commonly used for o cial
communication with public institutions. The content looks realistic (i.e. is based
on true facts) and is interesting (i.e. is about work). The required action looks
simple and easy (i.e. just read a short le and reply). Exploit trust { the
attacker uses an harvested le as attachment adding a malicious payload. Utilize
information { attacker's goal is to infect victim's computer with a malware (e.g.
ransom-ware, botnet campaigns, etc.).
6</p>
    </sec>
    <sec id="sec-6">
      <title>Conclusions</title>
      <p>Previously described scenario, albeit simple and \new", is not only realistic but
dangerous for several reasons: it is easy to automate, can target a huge number
of victims, can be applied to similar cases (e.g. procedures about contracts
agreement). Following our example, represented in the poster and in these pages, if
we just take into account the University of Cagliari we have the following data:
University of Cagliari entrusted 6566 agreements with private rms during the
year 2015, 5295 during 2014 and 2635 during 2013 with a total of 14496 in the
last three years1.</p>
      <p>There are 93 universities in Italy and the same scenario can be applied to
every public institution since the data must have the same structure (i.e. XML
Schema De nition2).</p>
      <p>The XML structure is known and well documented3 .</p>
      <p>Similar attack scenarios should be considered realistic for all UE
universities and public institutions, not just Italian ones. Governments should carefully
consider the impact of data sharing from a security perspective and take some
actions in order to reduce the dangers associated with malicious use of this data.
It should be noted that OD, SE and KW can also be successfully used to ght
cyber-crime directly (e.g. www.illbuster-project.eu) or to rise awareness (e.g.
www.dogana-project.eu) about dangers associated to attacks similar to the one
described in this paper and not just for nefarious purposes.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgments</title>
      <p>This work has been partially supported by the DOGANA project. DOGANA is
a project funded by the European Union Horizon 2020 framework programme,
under grant agreement number 653618.
1 http://trasparenza.unica.it/bandi-di-gara-e-contratti/
2 http://dati.avcp.it/schema/datasetAppaltiL190.xsd
3 http://goo.gl/WdOBBT</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Lathrop</surname>
            ,
            <given-names>D.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Ruma</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Open</surname>
            <given-names>Government</given-names>
          </string-name>
          : Transparency, Collaboration and Participation in Practice.
          <source>O'Reilly Media. ISBN 978-0-596-80435-0.</source>
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Schauer</surname>
          </string-name>
          , Frederick, Transparency in Three Dimensions, University of Illinois Law Review,
          <year>2011</year>
          (4): pp.
          <volume>1339</volume>
          {
          <fpage>1358</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Mitnick</surname>
            ,
            <given-names>K.</given-names>
          </string-name>
          ;
          <article-title>The Art of Deception</article-title>
          . Wiley,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Cialdini</surname>
          </string-name>
          , R. B.;
          <source>In uence: Science and Practice, Pearson</source>
          ,
          <year>2008</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Auer</surname>
            ,
            <given-names>S. R.</given-names>
          </string-name>
          ; Bizer,
          <string-name>
            <given-names>C.</given-names>
            ;
            <surname>Kobilarov</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G.</given-names>
            ;
            <surname>Lehmann</surname>
          </string-name>
          ,
          <string-name>
            <surname>J.</surname>
          </string-name>
          ; Cyganiak,
          <string-name>
            <given-names>R.</given-names>
            ;
            <surname>Ives</surname>
          </string-name>
          ,
          <string-name>
            <surname>Z. .</surname>
          </string-name>
          <article-title>DBpedia: A Nucleus for a Web of Open Data</article-title>
          . In Springer LNCS,
          <volume>4825</volume>
          . pp.
          <fpage>722</fpage>
          -
          <lpage>735</lpage>
          ,
          <year>2007</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Broadhurst</surname>
            , R.; Grabosky,
            <given-names>P.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Alazab</surname>
            ,
            <given-names>M</given-names>
          </string-name>
          ; Chon,
          <string-name>
            <surname>S.</surname>
          </string-name>
          ;
          <article-title>Organizations and Cyber crime: An Analysis of the Nature of Groups engaged in Cyber Crime</article-title>
          .
          <source>International Journal of Cyber Criminology</source>
          , vol.
          <volume>8</volume>
          (
          <issue>1</issue>
          ), pp.
          <fpage>1</fpage>
          -
          <lpage>20</lpage>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Kharouni</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ;
          <article-title>Africa a new safe-harbor for cybercriminals?</article-title>
          .
          <source>Trend Micro Incorporated Research Paper</source>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Muscanell</surname>
            ,
            <given-names>N. L.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Guadagno</surname>
            ,
            <given-names>R. E.</given-names>
          </string-name>
          ;
          <string-name>
            <surname>Murphy</surname>
            ,
            <given-names>S.</given-names>
          </string-name>
          ;
          <article-title>Weapons of In uence Misused: A Social In uence Analysis of Why People Fall Prey to Internet Scams. Social and Personality Psychology Compass</article-title>
          , vol.
          <volume>8</volume>
          (
          <issue>7</issue>
          ), pp.
          <fpage>388</fpage>
          -
          <lpage>396</lpage>
          , WILEY,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Stoyanov</surname>
          </string-name>
          , R. Russian Financial Cybercrime:
          <article-title>How it works</article-title>
          .
          <source>Kaspersky Lab Cybercrime Underground Report</source>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>