SlideShare a Scribd company logo
1 of 13
Security                                          eBooks




  Gold Farmers, Gold
    Frauding, and
    Account Sales


    Steven Davis               Fighting serious
                               fraud in Online
                                   Games

                                         steve@free2secure.com
Games, iGaming, and Gambling                   +1.650.278.7416
Security                                        eBooks


     This is
     about
   Business,
   not Justice

                        Your goal is to maximize
                        revenue, not ensure that
                     people play the way you want
                     or do what you think is “Right”
                                       steve@free2secure.com
Games, iGaming, and Gambling                 +1.650.278.7416
Security                                         eBooks


    You’ve heard of
    Cheaters, Gold
 Farmers, and Pirates?




  •Don’t wait until after launch to consider them
  •Implement and test economic systems EARLY and
  rigorously

                                        steve@free2secure.com
Games, iGaming, and Gambling                  +1.650.278.7416
Security                                      eBooks

             Gold Farmers are not Cheaters

   • They are playing the game
     properly with a different
     Win criteria than you
   • Lots of YOUR players have
     different definitions of
     Winning and Fun
       –   Play with their friends
       –   Not be bored
       –   Be super-powerful
       –   Not have time


                                     steve@free2secure.com
Games, iGaming, and Gambling               +1.650.278.7416
Security                                                                             eBooks

           Stock Market, not Auction House
                                                              item     item     item    item
                                                              item     item     item    item
                                                              item     item     item    item
           Buy Orders                                         item     item     item    item
                                Sell Orders                   item     item     item    item
                                                              item     item     item    item
                                                              item     item     item    item
                                                              item     item     item    item

   •   For each item, implement a queue of buy and sell orders. Matching orders get
       executed
   •   Anonymize and decouple buyers from sellers to prevent covert buying using your
       auction house
   •   Create real market turmoil (potentially) making it potentially riskier to gold farm
   •   Allows efficient intervention by game operator

                                                                       steve@free2secure.com
Games, iGaming, and Gambling                                                 +1.650.278.7416
Security                                            eBooks

        Mini-games and real economy games
   • Mini-games make AI
     challenge for bots and
     enliven time-based
     activities
       – Can be developed or
         acquired at low cost

                                • Detailed economic
                                  system models
                                   – Richer game play gives
                                     ordinary players to
                                     participate in system
                                   – Therefore, players
                                     compete with farmers

                                           steve@free2secure.com
Games, iGaming, and Gambling                     +1.650.278.7416
Security                                                     eBooks

                                  Power-leveling and
                                    Account Sales

                               • Inherently difficult if not
                                 impossible to stop
                               • Best to manage
                                  – Educate players to reset
                                    passwords and password
                                    recovery information
                                  – Orderly account recovery in case
                                    of theft
                               • Make it easy to exchange
                                 characters between accounts
                               • Support escrow transactions

                                                    steve@free2secure.com
Games, iGaming, and Gambling                              +1.650.278.7416
Security                                       eBooks

             Ban Banning

 • Online identity is already
   weak
 • Minimal action…. Let
   troublemakers think they are
   OK
     – Heck, as long as they aren’t
       bugging anyone else, keep
       them around
 • Redirect, Minimize, Isolate


                                      steve@free2secure.com
Games, iGaming, and Gambling                +1.650.278.7416
Security                                                          eBooks

  Deep Logging   •   Log and store game events down to the
                     individual action level
                 •   Provide tools for analysis and replay by staff as
                     well as players
                     – Can be used for live replay and broadcasting more
                       efficiently than screen captures
                 •   Use signatures if sent to third party player
                     – Use integrity function on server to stop replay or
                       spoofing
                 •   Deep Logging combined with Deterministic
                     Game Engines makes game verification MUCH
                     easier
                 •   Should include (either for individual entry or
                     derivable):
                     IP, PlayerID, PlatformID, Session, Action, Action
                     Parameters, Platform Time, Server Time,
                     Signature

                                                       steve@free2secure.com
Games, iGaming, and Gambling                                 +1.650.278.7416
Security                                       eBooks


 Profile                       •   Store periodic
                                   snapshots of player
                                   profile and
Snapshots                          information
                                    – At least for
                                      several sessions
                                      and over a period
                                      of time
                               •   Make it easy to
                                   restore/rollback a
                                   player profile
                                    – Don’t investigate
                                      problems, fix
                                      them – faster,
                                      cheaper, happier
                                      player
                               •   … can even
                                   monetize…


                                    steve@free2secure.com
Games, iGaming, and Gambling              +1.650.278.7416
Security                                              eBooks


   • Use “Free to Play” for
     security
                                                     e:
                                                  ur
       – Insurance for Account

                                                ec ing ity
         Protection
       – “Safe Backup” Images
                                            2S tiz ur
       – Account Locking on Vacation      ee ne ec
       – SMS Verification for           Fr o t S
         Transactions                      M un
       – “Extra” Customer Service for      c co
         security incidents               A
       – … even “Protect Your Kids”
         services

                                             steve@free2secure.com
Games, iGaming, and Gambling                       +1.650.278.7416
Security                                                             eBooks




   What next?
   • Don’t give up!

   • More security presentations at:
     http://free2secure.com/

   • Check out my book “Protecting Games”
       – Additional information at http://playnoevil.com/


   • You can “win” the security game
                                                            steve@free2secure.com
Games, iGaming, and Gambling                                      +1.650.278.7416
Security                                                                  eBooks

      About Me
  •   Steven Davis
       – 25+ Years of Security Expertise
       – I have worked on everything from
         online games and satellite TV to
         Nuclear Command and Control and
         military communications
           • http://www.linkedin.com/in/playnoevil
       – Author, “Protecting Games”

  •   Why Free2Secure?
       – Security is too expensive and isn’t working. There has to be a better way.
         I’m exploring these issues for IT security, ebooks, games, and whatever
         else strikes my fancy at http://free2secure.com/
       – Join me there, ask questions, challenge assumptions, let’s make things
         better

                                                               steve@free2secure.com
Games, iGaming, and Gambling                                         +1.650.278.7416

More Related Content

Recently uploaded

JustNaik Solution Deck (stage bus sector)
JustNaik Solution Deck (stage bus sector)JustNaik Solution Deck (stage bus sector)
JustNaik Solution Deck (stage bus sector)
Max Lee
 

Recently uploaded (20)

JustNaik Solution Deck (stage bus sector)
JustNaik Solution Deck (stage bus sector)JustNaik Solution Deck (stage bus sector)
JustNaik Solution Deck (stage bus sector)
 
Top Mobile App Development Companies 2024
Top Mobile App Development Companies 2024Top Mobile App Development Companies 2024
Top Mobile App Development Companies 2024
 
COMPUTER AND ITS COMPONENTS PPT.by naitik sharma Class 9th A mittal internati...
COMPUTER AND ITS COMPONENTS PPT.by naitik sharma Class 9th A mittal internati...COMPUTER AND ITS COMPONENTS PPT.by naitik sharma Class 9th A mittal internati...
COMPUTER AND ITS COMPONENTS PPT.by naitik sharma Class 9th A mittal internati...
 
Facemoji Keyboard released its 2023 State of Emoji report, outlining the most...
Facemoji Keyboard released its 2023 State of Emoji report, outlining the most...Facemoji Keyboard released its 2023 State of Emoji report, outlining the most...
Facemoji Keyboard released its 2023 State of Emoji report, outlining the most...
 
The Impact of PLM Software on Fashion Production
The Impact of PLM Software on Fashion ProductionThe Impact of PLM Software on Fashion Production
The Impact of PLM Software on Fashion Production
 
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
Tree in the Forest - Managing Details in BDD Scenarios (live2test 2024)
 
OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024OpenChain @ LF Japan Executive Briefing - May 2024
OpenChain @ LF Japan Executive Briefing - May 2024
 
10 Essential Software Testing Tools You Need to Know About.pdf
10 Essential Software Testing Tools You Need to Know About.pdf10 Essential Software Testing Tools You Need to Know About.pdf
10 Essential Software Testing Tools You Need to Know About.pdf
 
Secure Software Ecosystem Teqnation 2024
Secure Software Ecosystem Teqnation 2024Secure Software Ecosystem Teqnation 2024
Secure Software Ecosystem Teqnation 2024
 
Microsoft 365 Copilot; An AI tool changing the world of work _PDF.pdf
Microsoft 365 Copilot; An AI tool changing the world of work _PDF.pdfMicrosoft 365 Copilot; An AI tool changing the world of work _PDF.pdf
Microsoft 365 Copilot; An AI tool changing the world of work _PDF.pdf
 
StrimziCon 2024 - Transition to Apache Kafka on Kubernetes with Strimzi.pdf
StrimziCon 2024 - Transition to Apache Kafka on Kubernetes with Strimzi.pdfStrimziCon 2024 - Transition to Apache Kafka on Kubernetes with Strimzi.pdf
StrimziCon 2024 - Transition to Apache Kafka on Kubernetes with Strimzi.pdf
 
Optimizing Operations by Aligning Resources with Strategic Objectives Using O...
Optimizing Operations by Aligning Resources with Strategic Objectives Using O...Optimizing Operations by Aligning Resources with Strategic Objectives Using O...
Optimizing Operations by Aligning Resources with Strategic Objectives Using O...
 
Naer Toolbar Redesign - Usability Research Synthesis
Naer Toolbar Redesign - Usability Research SynthesisNaer Toolbar Redesign - Usability Research Synthesis
Naer Toolbar Redesign - Usability Research Synthesis
 
Malaysia E-Invoice digital signature docpptx
Malaysia E-Invoice digital signature docpptxMalaysia E-Invoice digital signature docpptx
Malaysia E-Invoice digital signature docpptx
 
KLARNA - Language Models and Knowledge Graphs: A Systems Approach
KLARNA -  Language Models and Knowledge Graphs: A Systems ApproachKLARNA -  Language Models and Knowledge Graphs: A Systems Approach
KLARNA - Language Models and Knowledge Graphs: A Systems Approach
 
Workforce Efficiency with Employee Time Tracking Software.pdf
Workforce Efficiency with Employee Time Tracking Software.pdfWorkforce Efficiency with Employee Time Tracking Software.pdf
Workforce Efficiency with Employee Time Tracking Software.pdf
 
Entropy, Software Quality, and Innovation (presented at Princeton Plasma Phys...
Entropy, Software Quality, and Innovation (presented at Princeton Plasma Phys...Entropy, Software Quality, and Innovation (presented at Princeton Plasma Phys...
Entropy, Software Quality, and Innovation (presented at Princeton Plasma Phys...
 
Lessons Learned from Building a Serverless Notifications System.pdf
Lessons Learned from Building a Serverless Notifications System.pdfLessons Learned from Building a Serverless Notifications System.pdf
Lessons Learned from Building a Serverless Notifications System.pdf
 
SQL Injection Introduction and Prevention
SQL Injection Introduction and PreventionSQL Injection Introduction and Prevention
SQL Injection Introduction and Prevention
 
architecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdfarchitecting-ai-in-the-enterprise-apis-and-applications.pdf
architecting-ai-in-the-enterprise-apis-and-applications.pdf
 

Featured

How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
ThinkNow
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
Kurio // The Social Media Age(ncy)
 

Featured (20)

Everything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPTEverything You Need To Know About ChatGPT
Everything You Need To Know About ChatGPT
 
Product Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage EngineeringsProduct Design Trends in 2024 | Teenage Engineerings
Product Design Trends in 2024 | Teenage Engineerings
 
How Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental HealthHow Race, Age and Gender Shape Attitudes Towards Mental Health
How Race, Age and Gender Shape Attitudes Towards Mental Health
 
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdfAI Trends in Creative Operations 2024 by Artwork Flow.pdf
AI Trends in Creative Operations 2024 by Artwork Flow.pdf
 
Skeleton Culture Code
Skeleton Culture CodeSkeleton Culture Code
Skeleton Culture Code
 
PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024PEPSICO Presentation to CAGNY Conference Feb 2024
PEPSICO Presentation to CAGNY Conference Feb 2024
 
Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)Content Methodology: A Best Practices Report (Webinar)
Content Methodology: A Best Practices Report (Webinar)
 
How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024How to Prepare For a Successful Job Search for 2024
How to Prepare For a Successful Job Search for 2024
 
Social Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie InsightsSocial Media Marketing Trends 2024 // The Global Indie Insights
Social Media Marketing Trends 2024 // The Global Indie Insights
 
Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024Trends In Paid Search: Navigating The Digital Landscape In 2024
Trends In Paid Search: Navigating The Digital Landscape In 2024
 
5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary5 Public speaking tips from TED - Visualized summary
5 Public speaking tips from TED - Visualized summary
 
ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd ChatGPT and the Future of Work - Clark Boyd
ChatGPT and the Future of Work - Clark Boyd
 
Getting into the tech field. what next
Getting into the tech field. what next Getting into the tech field. what next
Getting into the tech field. what next
 
Google's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search IntentGoogle's Just Not That Into You: Understanding Core Updates & Search Intent
Google's Just Not That Into You: Understanding Core Updates & Search Intent
 
How to have difficult conversations
How to have difficult conversations How to have difficult conversations
How to have difficult conversations
 
Introduction to Data Science
Introduction to Data ScienceIntroduction to Data Science
Introduction to Data Science
 
Time Management & Productivity - Best Practices
Time Management & Productivity -  Best PracticesTime Management & Productivity -  Best Practices
Time Management & Productivity - Best Practices
 
The six step guide to practical project management
The six step guide to practical project managementThe six step guide to practical project management
The six step guide to practical project management
 
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
Beginners Guide to TikTok for Search - Rachel Pearson - We are Tilt __ Bright...
 
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
Unlocking the Power of ChatGPT and AI in Testing - A Real-World Look, present...
 

Fight Serious Fraud in Your Online Game

  • 1. Security eBooks Gold Farmers, Gold Frauding, and Account Sales Steven Davis Fighting serious fraud in Online Games steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 2. Security eBooks This is about Business, not Justice Your goal is to maximize revenue, not ensure that people play the way you want or do what you think is “Right” steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 3. Security eBooks You’ve heard of Cheaters, Gold Farmers, and Pirates? •Don’t wait until after launch to consider them •Implement and test economic systems EARLY and rigorously steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 4. Security eBooks Gold Farmers are not Cheaters • They are playing the game properly with a different Win criteria than you • Lots of YOUR players have different definitions of Winning and Fun – Play with their friends – Not be bored – Be super-powerful – Not have time steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 5. Security eBooks Stock Market, not Auction House item item item item item item item item item item item item Buy Orders item item item item Sell Orders item item item item item item item item item item item item item item item item • For each item, implement a queue of buy and sell orders. Matching orders get executed • Anonymize and decouple buyers from sellers to prevent covert buying using your auction house • Create real market turmoil (potentially) making it potentially riskier to gold farm • Allows efficient intervention by game operator steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 6. Security eBooks Mini-games and real economy games • Mini-games make AI challenge for bots and enliven time-based activities – Can be developed or acquired at low cost • Detailed economic system models – Richer game play gives ordinary players to participate in system – Therefore, players compete with farmers steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 7. Security eBooks Power-leveling and Account Sales • Inherently difficult if not impossible to stop • Best to manage – Educate players to reset passwords and password recovery information – Orderly account recovery in case of theft • Make it easy to exchange characters between accounts • Support escrow transactions steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 8. Security eBooks Ban Banning • Online identity is already weak • Minimal action…. Let troublemakers think they are OK – Heck, as long as they aren’t bugging anyone else, keep them around • Redirect, Minimize, Isolate steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 9. Security eBooks Deep Logging • Log and store game events down to the individual action level • Provide tools for analysis and replay by staff as well as players – Can be used for live replay and broadcasting more efficiently than screen captures • Use signatures if sent to third party player – Use integrity function on server to stop replay or spoofing • Deep Logging combined with Deterministic Game Engines makes game verification MUCH easier • Should include (either for individual entry or derivable): IP, PlayerID, PlatformID, Session, Action, Action Parameters, Platform Time, Server Time, Signature steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 10. Security eBooks Profile • Store periodic snapshots of player profile and Snapshots information – At least for several sessions and over a period of time • Make it easy to restore/rollback a player profile – Don’t investigate problems, fix them – faster, cheaper, happier player • … can even monetize… steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 11. Security eBooks • Use “Free to Play” for security e: ur – Insurance for Account ec ing ity Protection – “Safe Backup” Images 2S tiz ur – Account Locking on Vacation ee ne ec – SMS Verification for Fr o t S Transactions M un – “Extra” Customer Service for c co security incidents A – … even “Protect Your Kids” services steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 12. Security eBooks What next? • Don’t give up! • More security presentations at: http://free2secure.com/ • Check out my book “Protecting Games” – Additional information at http://playnoevil.com/ • You can “win” the security game steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416
  • 13. Security eBooks About Me • Steven Davis – 25+ Years of Security Expertise – I have worked on everything from online games and satellite TV to Nuclear Command and Control and military communications • http://www.linkedin.com/in/playnoevil – Author, “Protecting Games” • Why Free2Secure? – Security is too expensive and isn’t working. There has to be a better way. I’m exploring these issues for IT security, ebooks, games, and whatever else strikes my fancy at http://free2secure.com/ – Join me there, ask questions, challenge assumptions, let’s make things better steve@free2secure.com Games, iGaming, and Gambling +1.650.278.7416

Editor's Notes

  1. http://diablo3guideonline.files.wordpress.com/2012/04/diablo1.jpg http://www.voig.com/l.c.bin/F/12565662/Tabula_Rasa_Review.jpg
  2. http://rlv.zcache.com/daddys_gold_farmer_tshirt-p235231639907489770zv2sj_400.jpg
  3. http://organizations.weber.edu/sascm/supply_chain.bmp