A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums

被引:29
作者
Biswas, Baidyanath [1 ]
Mukhopadhyay, Arunabha [2 ]
Bhattacharjee, Sudip [3 ]
Kumar, Ajay [4 ]
Delen, Dursun [5 ,6 ]
机构
[1] Int Management Inst IMI, Kolkata, India
[2] Indian Inst Management, Lucknow, Uttar Pradesh, India
[3] Univ Connecticut, Sch Business, Dept Operat & Informat Management, Storrs, CT 06269 USA
[4] EMLYON Business Sch, Ecully, France
[5] Oklahoma State Univ, Spears Sch Business, Ctr Hlth Syst Innovat, Stillwater, OK 74078 USA
[6] Ibn Haldun Univ, Sch Business, Istanbul, Turkey
关键词
Information security; Cyber risks; Hacker forum; Machine learning; Sentiment analysis; SOCIAL MEDIA; KNOWLEDGE; BEHAVIOR; COMMUNITIES; EXCHANGE; IMPROVE; MODELS;
D O I
10.1016/j.dss.2021.113651
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
Online hacker communities are meeting spots for aspiring and seasoned cybercriminals where they engage in technical discussions, share exploits and relevant hacking tools to be used in launching cyber-attacks on business organizations. Sometimes, the affected organizations can detect these attacks in advance, with the help of cyberthreat intelligence derived from the explicit and implicit features of hacker communication in these forums. Herein, we proposed a novel text-mining based cyber-risk assessment and mitigation framework, which performs the following critical tasks. (i) Cyber-risk Assessment - to identify hacker expertise (i.e., newbie, beginner, intermediate, and advanced) using explicit and implicit features applying various classification algorithms. Among these features, cybersecurity keywords, sharing of attachments, and sentiments emerged as significant. Further, we found that expert hackers demonstrate leadership in the online forums that eventually serve as communities of practice. Consequently, novice hackers gradually develop their cyber-attack skills through prolonged observations, interactions, and external influences in this social learning process. (ii) Cyber-risk mitigation - computes financial impact for every {hacker expertise, attack-type} combination, and then by ranking them on a {likelihood, impact} decision-matrix to prioritize mitigation strategies in affected organizations. Through these novel recommendations, our framework can guide managers to decide on appropriate cybersecurity controls using an {expected loss, probability, attack-type, hacker expertise} metric against financial losses due to cyber-attacks.
引用
收藏
页数:13
相关论文
共 53 条
  • [31] Introduction to Information Retrieval
    Larson, Ray R.
    [J]. JOURNAL OF THE AMERICAN SOCIETY FOR INFORMATION SCIENCE AND TECHNOLOGY, 2010, 61 (04): : 852 - 853
  • [32] Lave J., 1991, Situated Learning: Legitimate Peripheral Participation, P1
  • [33] What motivates health information exchange in social media? The roles of the social cognitive theory and perceived interactivity
    Lin, Hsien-Cheng
    Chang, Chun-Ming
    [J]. INFORMATION & MANAGEMENT, 2018, 55 (06) : 771 - 780
  • [34] Mining Key-Hackers on Darkweb Forums
    Marin, Ericsson
    Shakarian, Jana
    Shakarian, Paulo
    [J]. 2018 1ST INTERNATIONAL CONFERENCE ON DATA INTELLIGENCE AND SECURITY (ICDIS 2018), 2018, : 73 - 80
  • [35] Matei Sorin Adam, 2017, 2017 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining (ASONAM), P72, DOI 10.1145/3110025.3110040
  • [36] McMillan R, 2013, THREAT INTELLIGENCE
  • [37] Harnessing Artificial Intelligence to Improve the Quality of Answers in Online Question-answering Health Forums
    Mousavi, Reza
    Raghu, T. S.
    Frey, Keith
    [J]. JOURNAL OF MANAGEMENT INFORMATION SYSTEMS, 2020, 37 (04) : 1073 - 1098
  • [38] Cyber Risk Assessment and Mitigation (CRAM) Framework Using Logit and Probit Models for Cyber Insurance
    Mukhopadhyay, Arunabha
    Chatterjee, Samir
    Bagchi, Kallol K.
    Kirs, Peteer J.
    Shukla, Girja K.
    [J]. INFORMATION SYSTEMS FRONTIERS, 2019, 21 (05) : 997 - 1018
  • [39] Cyber-risk decision models: To insure IT or not?
    Mukhopadhyay, Arunabha
    Chatterjee, Samir
    Saha, Debashis
    Mahanti, Ambuj
    Sadhukhan, Samir K.
    [J]. DECISION SUPPORT SYSTEMS, 2013, 56 : 11 - 26
  • [40] Disentangling the effects of efficacy-facilitating informational support on health resilience in online health communities based on phrase-level text analysis
    Park, Insu
    Sarnikar, Surendra
    Cho, Jeewon
    [J]. INFORMATION & MANAGEMENT, 2020, 57 (08)