Cross-Network Verification: A Multi-Dimensional Shield Against Identity Theft
A defence scheme against Identity Theft Attack based on multiple social networks
This paper introduces a defense framework against Identity Theft Attacks (ITA) by leveraging multi-dimensional social networks. The authors propose a composite scheme integrating "Challenge" mechanisms, "Login Account as Identifiers," and "Friend Network Similarity" to verify user authenticity across platforms like Facebook, E-mail, and Instant Messengers.
TL;DR
Identity Theft Attacks (ITA)—specifically profile cloning—exploit the trust inherent in social networks. This paper proposes a defense scheme that doesn't force users to hide their data (which ruins the "social" aspect). Instead, it uses your multi-dimensional social footprint (E-mail, IM, and OSNs) to verify that the person sending you a friend request is actually who they claim to be.
Background: The Price of "Being Social"
The paradox of Online Social Networks (OSNs) is simple: to make friends, you must be searchable; to be searchable, you must be public; but being public makes you a target. Attackers harvest names, photos, and friend lists to create "clones."
The authors categorize these into three scenarios:
- The Vacuum: Cloning your identity on a site you haven't joined yet.
- The Stranger: Creating a clone on a site you are on, but targeting friends you haven't connected with there yet.
- The Upgrade: Sophisticatedly claiming a new account because the "old one was hacked."
Methodology: The Three-Pillar Defense
The core insight is that while an attacker can steal your photo, it is much harder to replicate the entropy of your varied social connections across different platforms.
1. The Challenge (Passive & Active)
A simple duplex communication. If "Bob" adds "Alice" on Facebook, Alice can use a pre-existing trusted channel (like E-mail) to ask: "Hey, did you just add me?"
2. Login Account as Identifier (LAI)
The research found that 80% of users reuse the same prefix for their E-mails and OSN handles. By treating the login string as a unique identifier, the system can automatically cross-reference new requests against known contact lists.
3. Friend Network Similarity (FNS)
This is the mathematical heart of the paper. It calculates the overlap between your current friends and the new requester's friends.

The formula for similarity between a known node and a candidate is: Essentially, it measures: Of the friends I know you have on Network A, how many are also in your list on Network B?
Experimental Insights
The authors conducted extensive surveys on user behavior, revealing that:
- High Overlap: 81% of users have similar contact lists between E-mail and Instant Messengers.
- Login Consistency: 71% use the same login across OSNs and IMs (e.g., Windows Live Messenger).

In practical testing, the Friend Network Similarity proved to be a robust discriminator. As shown in the cumulative distribution graphs, a higher similarity score correlates almost perfectly with a "Real Identity."

Critical Analysis & Conclusion
Takeaway
The strength of this work lies in its practicality. It doesn't require complex encryption or a total overhaul of OSN protocols. It leverages existing user habits (account reuse and social overlap) to build a probabilistic verification layer.
Limitations
- The "Famous Person" Problem: Public figures have "one-way" social networks (thousands of followers, few friends), making FNS less effective.
- Attribute Weighting: The current model treats all friends as equal. In reality, a common "Best Friend" or "Family Member" should carry more weight in verification than a common "Co-worker."
Future Outlook
As we move toward a "Metaverse" or unified digital identity, this cross-platform verification logic will likely become an automated backend service, flagging suspicious "cloned" requests before they even reach a user's inbox.
