TenFor: A Tensor-Based Tool to Extract Interesting Events from Security Forums

11/14/2020
by   Risul Islam, et al.
0

How can we get a security forum to "tell" us its activities and events of interest? We take a unique angle: we want to identify these activities without any a priori knowledge, which is a key difference compared to most of the previous problem formulations. Despite some recent efforts, mining security forums to extract useful information has received relatively little attention, while most of them are usually searching for specific information. We propose TenFor, an unsupervised tensor-based approach, to systematically identify important events in a three-dimensional space: (a) user, (b) thread, and (c) time. Our method consists of three high-level steps: (a) a tensor-based clustering across the three dimensions, (b) an extensive cluster profiling that uses both content and behavioral features, and (c) a deeper investigation, where we identify key users and threads within the events of interest. In addition, we implement our approach as a powerful and easy-to-use platform for practitioners. In our evaluation, we find that 83 meaningful events and we find more meaningful clusters compared to previous approaches. Our approach and our platform constitute an important step towards detecting activities of interest from a forum in an unsupervised learning fashion in practice.

READ FULL TEXT
research
11/14/2020

RecTen: A Recursive Hierarchical Low Rank Tensor Factorization Method to Discover Hierarchical Patterns in Multi-modal Data

How can we expand the tensor decomposition to reveal a hierarchical stru...
research
07/30/2020

Unsupervised Event Detection, Clustering, and Use Case Exposition in Micro-PMU Measurements

Distribution-level phasor measurement units, a.k.a, micro-PMUs, report a...
research
04/08/2019

Unsupervised learning of action classes with continuous temporal embedding

The task of temporally detecting and segmenting actions in untrimmed vid...
research
07/29/2021

Zooming Into the Darknet: Characterizing Internet Background Radiation and its Structural Changes

Network telescopes or "Darknets" provide a unique window into Internet-w...
research
03/11/2015

Automatic Unsupervised Tensor Mining with Quality Assessment

A popular tool for unsupervised modelling and mining multi-aspect data i...
research
02/28/2018

A Bayesian Model for Activities Recommendation and Event Structure Optimization Using Visitors Tracking

In events that are composed by many activities, there is a problem that ...
research
05/03/2021

Learning Good State and Action Representations via Tensor Decomposition

The transition kernel of a continuous-state-action Markov decision proce...

Please sign up or login with your details

Forgot password? Click here to reset