Predicting Cyber-Events by Leveraging Hacker Sentiment

被引:26
作者
Deb, Ashok [1 ]
Lerman, Kristina [1 ]
Ferrara, Emilio [1 ]
机构
[1] Univ Southern Calif, Informat Sci Inst, Marina Del Rey, CA 90292 USA
关键词
sentiment analysis; cyber-security; dark web;
D O I
10.3390/info9110280
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
Recent high-profile cyber-attacks exemplify why organizations need better cyber-defenses. Cyber-threats are hard to accurately predict because attackers usually try to mask their traces. However, they often discuss exploits and techniques on hacking forums. The community behavior of the hackers may provide insights into the groups' collective malicious activity. We propose a novel approach to predict cyber-events using sentiment analysis. We test our approach using cyber-attack data from two major business organizations. We consider three types of events: malicious software installation, malicious-destination visits, and malicious emails that surmounted the target organizations' defenses. We construct predictive signals by applying sentiment analysis to hacker forum posts to better understand hacker behavior. We analyze over 400 K posts written between January 2016 and January 2018 on over 100 hacking forums both on the surface and dark web. We find that some forums have significantly more predictive power than others. Sentiment-based models that leverage specific forums can complement state-of-the-art time-series models on forecasting cyber-attacks weeks ahead of the events.
引用
收藏
页数:18
相关论文
共 34 条
[1]   BiSAL - A bilingual sentiment analysis lexicon to analyze Dark Web forums for cyber security [J].
Al-Rowaily, Khalid ;
Abulaish, Muhammad ;
Haldar, Nur Al-Hasan ;
Al-Rubaian, Majed .
DIGITAL INVESTIGATION, 2015, 14 :53-62
[2]  
Almukaynizi Mohammed, 2017, P INT C CYBER CONFLI, P82, DOI DOI 10.1109/CYCONUS.2017.8167501
[3]  
[Anonymous], 2015, ARXIV151106858
[4]  
Asur S., 2010, Proceedings 2010 IEEE/ACM International Conference on Web Intelligence-Intelligent Agent Technology (WI-IAT), P492, DOI 10.1109/WI-IAT.2010.63
[5]  
Chen HC, 2008, ISI 2008: 2008 IEEE INTERNATIONAL CONFERENCE ON INTELLIGENCE AND SECURITY INFORMATICS, P104, DOI 10.1109/ISI.2008.4565038
[6]  
Dingledine R., 2004, TECHNICAL REPORT
[7]   Cyber Situation Awareness: Modeling Detection of Cyber Attacks With Instance-Based Learning Theory [J].
Dutt, Varun ;
Ahn, Young-Suk ;
Gonzalez, Cleotilde .
HUMAN FACTORS, 2013, 55 (03) :605-618
[8]   Cyber situational awareness - A systematic review of the literature [J].
Franke, Ulrik ;
Brynielsson, Joel .
COMPUTERS & SECURITY, 2014, 46 :18-31
[9]  
Freud S., 1901, T JAMES STRACHEY, V24, P1953
[10]  
Gandotra E., 2015, INTELLIGENT COMPUTIN, P247