Frauds severely hurt many kinds of Internet businesses. Group-based fraud detection is a popular methodology to catch fraudsters who unavoidably exhibit synchronized behaviors. We combine both graph-based features (e.g. cluster density) and information-theoretical features (e.g. probability for the similarity) of fraud groups into two intuitive metrics. Based on these metrics, we build an extensible fraud detection framework, BadLink, to support multimodal datasets with different data types and distributions in a scalable way. Experiments on real production workload, as well as extensive comparison with existing solutions demonstrate the state-of-the-art performance of BadLink, even with sophisticated camouflage traffic.
@article{arxiv.1805.10053,
title = {BadLink: Combining Graph and Information-Theoretical Features for Online Fraud Group Detection},
author = {Yikun Ban and Xin Liu and Tianyi Zhang and Ling Huang and Yitao Duan and Xue Liu and Wei Xu},
journal= {arXiv preprint arXiv:1805.10053},
year = {2018}
}
Comments
We found a bug in the experiement section and the numbers are incorrect