Twitter Fights Phishing, Malware with Link Scanning Service

執筆者
Brian Prince
Brian Prince
Published: Mar 10, 2010
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

Twitter has announced plans to route all links through a scanner in a bid to boost security and weed out malicious activity.

The move follows a partnership announced in November between URL shortening service Bit.ly and security companies VeriSign, Websense and Sophos.

“By routing all links submitted to Twitter through this new service, we can detect, intercept and prevent the spread of bad links across all of Twitter,” blogged Del Harvey, director of Twitter’s Trust and Safety team. “Even if a bad link is already sent out in an e-mail notification and somebody clicks on it, we’ll be able to keep that user safe.”

“Since these attacks occur primarily on Direct Messages and e-mail notifications about Direct Messages, this is where we have focused our initial efforts,” Harvey added. “For the most part, you will not notice this feature because it works behind the scenes but you may notice links shortened to twt.tl in Direct Messages and e-mail notifications.”

Twitter security has been in the spotlight in the past two years as the number of users – and attacks – soared. In a new report by Barracuda Networks (PDF), researchers analyzed 19 million accounts and found that the Twitter crime rate – the percentage of accounts suspended each month due to suspicious or malicious activity – rose from 1.2 percent in 2006 to 12 percent in October 2009.

Oftentimes the links lead to sites pushing rogue antivirus or other malware. Other times, they lead to phishing sites were the user is prompted to give up their Twitter account information, which can sell for as much as $1,000 in the cyber-underworld.

“What’s significant about the Twitter announcement is that they are announcing that there’s a security problem,” said Paul Judge, chief research officer and vice president at Barracuda Networks, told eWEEK.

Twitter currently uses a mix of algorithms, user reports and systems monitoring to determine if an account has been compromised. Judge, however, said the announcement sounds like Twitter is making a foray into the URL-shortening business, and the microblogging service should focus on leveraging user data effectively to take a more reputation-based approach to security.

For example, in the Barracuda report researchers found that just 27 percent of users have tweeted more than 10 times, and 34 percent have never tweeted since they opened their account. Twenty-six percent of users have at least 10 followers, and 40 percent are following at least 10 people. A drastic deviation from any of these statistics in a short period – such as a formerly dormant account suddenly sending out 40 messages in a day should send up a red flag, Judge said.

Advertisement

“There’s a handful of good people on Twitter that actually use the network, and then there are a lot of malicious accounts and inactive users, and there’s some very basic reputation approaches that can be used to sort out those two types of people,” he said.

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。