Characterizing Activity on the Deep and Dark Web
Abstract
The deep and darkweb (d2web) refers to limited access web sites that require registration, authentication, or more complex encryption protocols to access them. These web sites serve as hubs for a variety of illicit activities: to trade drugs, stolen user credentials, hacking tools, and to coordinate attacks and manipulation campaigns. Despite its importance to cyber crime, the d2web has not been systematically investigated. In this paper, we study a large corpus of messages posted to 80 d2web forums over a period of more than a year. We identify topics of discussion using LDA and use a non-parametric HMM to model the evolution of topics across forums. Then, we examine the dynamic patterns of discussion and identify forums with similar patterns. We show that our approach surfaces hidden similarities across different forums and can help identify anomalous events in this rich, heterogeneous data.
Más información
| Título según WOS: | ID WOS:000474353100034 Not found in local WOS DB |
| Título de la Revista: | COMPANION OF THE WORLD WIDE WEB CONFERENCE (WWW 2019 ) |
| Editorial: | ASSOC COMPUTING MACHINERY |
| Fecha de publicación: | 2019 |
| Página de inicio: | 206 |
| Página final: | 213 |
| DOI: |
10.1145/3308560.3316502 |
| Notas: | ISI |