As adversarial hacker exploits proliferate the media, researchers call for more studies examining their culture, behaviours, and defence mechanisms. This study aims to understand the nature of hackers through their knowledge-sharing behaviours in a coopetitive environment. This understanding may expose emerging threats and cybercriminal activities, which are beneficial to building information security defences. Also, extracting knowledge from darknet sources can help organisations anticipate, defend, and respond to cyber-attacks. Hence, we incorporate hacker forum data and perform a detailed analysis informed by foundational social capital theory. We explore hacker knowledge-sharing patterns with respect to the malicious knowledge shared. Further, we use nonlinear approaches to understand the dynamic relationships in an environment that is both cooperative and competitive. The findings seek to clarify how forms of social capital and coopetitive factors function differently to facilitate or impede knowledge sharing in a darknet context. Specifically, the findings indicate that the sharing of malicious knowledge is non-linear, and that knowledge control (i.e., reduced knowledge sharing) occurs with malicious knowledge as it relates to status and structural positioning.
Collaborative robots are becoming increasingly present in everyday life, with applications ranging food and parcel delivery, security, and more. They can offer great value propositions for organizations and consumers. However, most people lack knowledge of how to interact with robots, and many robots themselves necessitate formal training which can be inaccessible to many and thus not societally scalable. Further, there is a lack of existing work investigating interfaces designs that can support non-dyadic interactions consisting of two or more individuals interacting with a robot sequentially and simultaneously; such interactions will be common in real-world usage. This research explores the efficacy of natural language interfaces for human-robot interaction through a human experiment and post-experiment survey. Results show that the natural language interface can afford teams enhanced capabilities to share robot control and avoid errors relative to other interfaces, while also increasing user perceptions towards overall interaction.
Many organizations are exploring methods to incorporate visual content analyses within their social media and brand tracking decision-making. However, current machine vision services and tools are typically constrained to performing only object recognition and provide limited practical insights to brand managers. For more advanced managerial decision-making, it is necessary to understand the social context and user intentions behind visual content. In this research, we design a framework grounded in Observational Learning Theory to propose a computational system that can infer the social context of social media images by utilizing user comments as crowd-generated labels. The system is then operationalized and tested through a state-of-the-art multimodal learning approach. We contextualize the experiment within the shoe apparel industry to evaluate the proposed framework and demonstrate its usage in different circumstances of real practice. To the best of the authors’ knowledge, this is the first research that seeks to understand an image’s social relevance by not only looking within the image itself, but by also incorporating data beyond the image. This study features both theoretical and managerial implications that benefit business intelligence designs and social media analytics. Results demonstrate the possibility of extracting crowd intelligence from user comments to augment machine learning classifiers’ performance in detecting the social context of images. The model enables practitioners to detect image threads with specific intentions. Organizations can collect product feedback and brand perceptions concerning themselves and their competitors from large volumes of data, and across vast lengths of time.
Social media platforms are facing increasing numbers of cyber-adversaries seeking to manipulate online discourse by using social bots to help automate and scale their attacks. Likewise, some social media users have developed capabilities to identify social bot activity at varying degrees of confidence. We exploit this user intelligence to augment traditional bot detection systems. Furthermore, not all crowd-generated labels are of equal value or credibility. Some individuals are quite adept at identifying social bot activity, whereas others may become merely suspicious but remain uncertain. We design a system inspired by speech act theory to evaluate which crowd-generated labels are most credible for augmenting bot detection system efficacy.
Cyber-threat intelligence (CTI) has matured into its own industry within recent years. CTI efforts frequently involve scrutinizing data within Darknet communities to understand emerging threats. Many hackers within the Darknet share knowledge and other information through a variety of formats, including video. At the same time, many hackers are also making use of the “surface” Internet and traditional video-sharing platforms to disseminate hacking knowledge. Gleaning intelligence from the Darknet can be a very laborious and costly task, raising the question of how meaningful and valuable are the hacker patterns that can be observed on the surface Internet. Extant research contains no studies that compare and contrast hacking videos uploaded to the Darknet versus those uploaded to traditional Internet communities. In this research-in-progress, a testbed of hacking videos is constructed by sourcing videos from a popular video-sharing website, as well as several Darknet forums. The testbed is scrutinized to understand differences in how the populations of users watching such videos respond to them, and whether there are any unique engagement patterns that emerge within the Darknet and surface Internet populations. The results of this work serve to justify further investigations into the hacker knowledge gap between the Darknet and the traditional Internet.
To increase situational awareness, major cybersecurity platforms offer Cyber Threat Intelligence (CTI) about emerging cyber threats, key threat actors, and their modus operandi. However, this intelligence is often reactive, as it analyzes event log files after attacks have already occurred, lacking more active scrutiny of potential threats brewing in cyberspace before an attack has occurred. One intelligence source receiving significant attention is the Dark Web, where significant quantities of malicious hacking tools and other cyber assets are hosted. We present the AZSecure Hacker Assets Portal (HAP). The Dark Web-based HAP collects, analyzes, and reports on the major Dark Web data sources to offer unique perspective of hackers, their cybercriminal assets, and their intentions and motivations, ultimately contributing CTI insights to improve situational awareness. HAP currently supports 200+ users internationally from academic institutions such as UT San Antonio and National Taiwan University, law enforcement entities such as Calgary and Ontario Provincial Police, and industry organizations including General Electric and PayPal.
With the ubiquity of mobile devices and an increasing trend in extending real-world activities into the virtual, goal-directed platforms have experienced rising popularity as they provide individuals with enhanced capabilities for goal pursuit. Prior literature has demonstrated the important role of the diversity in goal pursuit approaches to individuals’ goal pursuit activities. However, a few studies have investigated the technology-mediated goal pursuits especially how mobile channel, as an additional means of web-based goal pursuit means, will affect users’ goal pursuit. In this research, we start with the theoretical perspective of affordance and goal pursuit theory, and then perform a series of empirical analyses to examine the impacts of multi-channel adoption on goal pursuit activity and persistence. Our results indicate that mobile adoption improves overall goal pursuit effort by 140.1%. A positive impact on goal pursuit persistence is also observed. Users spend 0.656 days learning content after they adopted mobile channel. Most notably, users with varying levels of goal specificity and goal pursuit competency benefit differently from the adoption of the mobile channel. Particularly, users with high-level goal specificity are observed to spent 0.234 more days and 56.5% more effort in their goal pursuit compared to uses with a less specific goal. Robustness checks and replication of data analyses further validate our findings under various scenarios.
The evolution of electronic media is a mixed blessing. Due to the easy access, low cost, and faster reach of the information, people search out and devour news from online social networks. In contrast, the increasing acceptance of social media reporting leads to the spread of fake news. This is a minacious problem that causes disputes and endangers the societal stability and harmony. Fake news spread has gained attention from researchers due to its vicious nature. proliferation of misinformation in all media, from the internet to cable news, paid advertising and local news outlets, has made it essential for people to identify the misinformation and sort through the facts. Researchers are trying to analyze the credibility of information and curtail false information on such platforms. Credibility is the believability of the piece of information at hand. Analyzing the credibility of fake news is challenging due to the intent of its creation and the polychromatic nature of the news. In this work, we propose a model for detecting fake news. Our method investigates the content of the news at the early stage i.e., when the news is published but is yet to be disseminated through social media. Our work interprets the content with automatic feature extraction and the relevance of the text pieces. In summary, we introduce stance as one of the features along with the content of the article and employ the pre-trained contextualized word embeddings BERT to obtain the state-of-art results for fake news detection. The experiment conducted on the real-world dataset indicates that our model outperforms the previous work and enables fake news detection with an accuracy of 95.32%.
Cyber-threat intelligence (CTI) has matured and grown into its own industry within recent years. Many CTI efforts involve scrutinizing text-based conversations in DarkNet forums and markets. However, hackers commonly share knowledge and other information through video formats that have been largely ignored. Further, cybercriminals are increasingly making use of mainstream social media to transmit hacking knowledge and assets, but this has gone unexplored in literature. In this research-in-progress, a video classifier to detect cybercriminal content in mainstream social media is designed and implemented. A collection of hacking and non-hacking videos was retrieved from a popular social media website to serve as a testbed. Feature sets included video metadata as well as features engineered from the videos themselves, including object detection and aesthetic qualities. This study demonstrates a methodological proof-of-concept that can enable future research that further investigates cyber-adversarial video contents, which have remained largely unexplored to this day. This study also contributes to literature regarding cyber-adversarial contents in mainstream social media.
Society’s growing dependence on computers and information technologies has been matched by an escalation of the frequency and sophistication of cyber attacks committed by criminals operating from the Darknet. As a result, security researchers have taken an interest in scrutinizing the Darknet and other underground web communities to develop a better understanding of cybercriminals and emerging threats. However, many scholars lack the capability or expertise to operationalize Darknet research and are thus unable to contribute to this increasingly impactful body of literature. This article introduces a framework for guiding such research, called Darknet Identification, Collection, Evaluation, with Ethics (DICE-E). The DICE-E framework provides a focused reference point and detailed guidelines for scholars wishing to become active in the Darknet research stream. Four steps to conducting Darknet forum research are outlined: (1) identification of Darknet data sources, (2) data collection strategies, (3) evaluation of Darknet data, and (4) ethical concerns related to Darknet research. To illustrate how DICE-E can be utilized, an example empirical study is reported. This exemplar illustrates how DICE-E can guide scholars through key decision points when attempting to incorporate the Darknet within their research.
Online cybercriminal communities exist in various geopolitical regions, including America, China, Russia, and more. Some multilingual forums exist where cybercriminals of differing geopolitical origin interact and exchange hacking knowledge and cybercriminal assets. Researchers can study such forums to better understand the global cybercriminal supply chain and cybercrime trends. However, little work has focused on identifying members of different language groups and geopolitical origin within such forums. One challenge is the necessity of a technique that scales across multiple languages. We are motivated to explore computational techniques that support automated and scalable categorization of cybercriminal forum participants into varying language groups. In particular, we make use of Paragraph Vectors, a state-of-the-art neural network language model to generate fixed-length vector representations (i.e., document embeddings) of messages posted by forum participants. Results indicate Paragraph Vectors outperforms traditional n-gram frequency approaches for generating document embeddings that are useful for clustering cybercriminals into language groups.
To further cybersecurity, there is interest in studying online cybercriminal communities to learn more about emerging cyber threats. Literature documents the existence of many online Internet Relay Chat (IRC) cybercriminal communities where cybercriminals congregate and share hacking tools, malware, and more. However, many cybercriminal community participants appear unskilled and have fleeting interests, making it difficult to detect potential long-term or key participants. This is a challenge for researchers and practitioners to quickly identify cybercriminals that may provide credible threat intelligence. Thus, we propose a computational approach to analyze cybercriminals IRC communities in order to identify potential long-term and key participants. We use the extended Cox model to scrutinize cybercriminal IRC participation for better understanding of behaviors exhibited by cybercriminals of importance. Results indicate that key cybercriminals may be quickly identifiable by assessing the scale of their interaction and networks with other participants.
Cybersecurity is a problem of growing relevance that impacts all facets of society. As a result, many researchers have become interested in studying cybercriminals and online hacker communities in order to develop more effective cyber defenses. In particular, analysis of hacker community contents may reveal existing and emerging threats that pose great risk to individuals, businesses, and government. Thus, we are interested in developing an automated methodology for identifying tangible and verifiable evidence of potential threats within hacker forums, IRC channels, and carding shops. To identify threats, we couple machine learning methodology with information retrieval techniques. Our approach allows us to distill potential threats from the entirety of collected hacker contents. We present several examples of identified threats found through our analysis techniques. Results suggest that hacker communities can be analyzed to aid in cyber threat detection, thus providing promising direction for future work.
Emotion plays an important role in shaping public policy and business decisions. The growth of social media has allowed people to express their emotion publicly in an unprecedented manner. Textual content and user linkages fostered by social media networks can be used to examine emotion types, intensity, and contagion. However, research into how emotion evolves and entrains in social media that influence security issues is scarce. In this research, we developed an approach to analyzing emotion expressed in political social media. We compared two methods of emotion analysis to identify influential users and to trace their contagion effects on public emotion, and report preliminary findings of analyzing the emotion of 105,304 users who posted 189,012 tweets on the U.S. immigration and border security issues in November 2014. The results provide strong implication for understanding social actions and for collecting social intelligence for security informatics. This research should contribute to helping decision makers and security personnel to use public emotion effectively to develop appropriate strategies.
The need for more research scrutinizing online hacker communities is a common suggestion in recent years. However, researchers and practitioners face many challenges when attempting to do so. In particular, they may encounter hacking-specific terms, concepts, tools, and other items that are unfamiliar and may be challenging to understand. For these reasons, we are motivated to develop an automated method for developing understanding of hacker language. We utilize the latest advancements in recurrent neural network language models (RNNLMs) to develop an unsupervised machine learning technique for learning hacker language. The selected RNNLM produces state-of-the-art word embeddings that are useful for understanding the relations between different hacker terms and concepts. We evaluate our work by testing the RNNLMs ability to learn relevant relations between known hacker terms. Results suggest that the latest work in RNNLMs can aid in modeling hacker language, providing promising direction for future research.
Methods and tools to conduct authorship analysis of web contents is of growing interest to researchers and practitioners in various security-focused disciplines, including cybersecurity, counter-terrorism, and other fields in which authorship of text may at times be uncertain or obfuscated. Here we demonstrate an automated approach for authorship analysis of web contents. Analysis is conducted through the use of machine learning methodologies, an expansive stylometric feature set, and a series of visualizations intended to help facilitate authorship analysis at the author, message, and feature levels. To operationalize this, we utilize a testbed containing 506,554 forum messages in English and Arabic, source from 14,901 authors that participated in an online web forum. A prototype portal system providing authorship comparisons and visualizations was then designed and constructed in order to support feasibility analysis and real world value of the automated authorship analysis approach. A preliminary user evaluation was performed to assess the efficacy of visualizations, with evaluation results demonstrating task performance accuracy and efficiency was improved through use of the portal.
As the Internet becomes ubiquitous, it has advanced to more closely represent aspects of the real world. Due to this trend, researchers in various disciplines have become interested in studying relationships between real-world phenomena and their virtual representations. One such area of emerging research seeks to study relationships between real-world and virtual activism of social movement organization (SMOs). In particular, SMOs holding extreme social perspectives are often studied due to their tendency to have robust virtual presences to circumvent real-world social barriers preventing information dissemination. However, many previous studies have been limited in scope because they utilize manual data-collection and analysis methods. They also often have failed to consider the real-world aspects of groups that partake in virtual activism. We utilize automated data-collection and analysis methods to identify significant relationships between aspects of SMO virtual communities and their respective real-world locations and ideological perspectives. Our results also demonstrate that the interconnectedness of SMO virtual communities is affected specifically by aspects of the real world. These observations provide insight into the behaviors of SMOs within virtual environments, suggesting that the virtual communities of SMOs are strongly affected by aspects of the real world.
Wingyan Chung合作论文数Institute for Simulation and Training,University of Central Florida5