用机器学习识别暗网巴西葡语恶意帖子,提升网络安全预警能力
Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning
- 构建三套原始数据集,采用多重标注法融合威胁指标与人工分析
- 最佳模型(LightGBM+TF-IDF)检测准确率高,可有效识别恶意内容
- 首次聚焦巴西葡语暗网文本,适合网络安全与数字取证研究者
随着网络攻击日益频繁且复杂,网络安全已无法仅依赖传统防御手段,主动识别威胁成为关键。网络威胁情报(CTI)通过提供基于证据的威胁知识发挥重要作用。本文利用文本挖掘与机器学习技术,分析来自巴西葡语暗网论坛的数据,旨在识别恶意帖子。研究贡献包括创建三个原创数据集、提出结合威胁指标(IoCs)、上下文关键词与人工分析的多阶段标注流程,以及对多种文本表示和分类器的全面评估。据我们所知,这是首个专注于巴西葡语暗网内容的研究。最优模型(LightGBM与TF-IDF结合)表现出高检测准确率;通过主题建模验证未标注数据输出,进一步证实了模型在真实场景中的稳健性。
原文摘要 · Abstract (English)
Given the constant growth and increasing sophistication of cyberattacks, cybersecurity can no longer rely solely on traditional defense techniques and tools. Proactive detection of cyber threats has become essential to help security teams identify potential risks and implement effective mitigation measures. Cyber Threat Intelligence (CTI) plays a key role by providing security analysts with evidence-based knowledge about cyber threats. CTI information can be extracted using various techniques and data sources; however, machine learning has proven promising. As for data sources, social networks and online discussion forums are commonly explored. In this study, we apply text mining techniques and machine learning to data collected from Dark Web forums in Brazilian Portuguese to identify malicious posts. Our contributions include the creation of three original datasets, a novel multi-stage labeling process combining indicators of compromise (IoCs), contextual keywords, and manual analysis, and a comprehensive evaluation of text representations and classifiers. To our knowledge, this is the first study to focus specifically on Brazilian Portuguese content in this domain. The best-performing model, using LightGBM and TF-IDF, was able to detect relevant posts with high accuracy. We also applied topic modeling to validate the model's outputs on unlabeled data, confirming its robustness in real-world scenarios.
Thank you to arXiv for use of its open access interoperability. PaperDance 不是 arXiv 官方产品;中文卡片由大模型生成,请以原文为准。