IP Library Granted Patent US 11,552,976
Granted Patent B2
US 11,552,976 · App. 16/653,899 · Granted Jan 10, 2023

Systems and methods for social network analysis on dark web forums to predict enterprise cyber incidents

Inventors: Soumajyoti Sarkar (Tempe, AZ); Mohammed Almukaynizi (Chandler, AZ); Jana Shakarian (Chandler, AZ); Paulo Shakarian (Chanlder, AZ)
Assignees: Arizona Board of Regents on behalf of Arizona State University; Cyber Reconnaissance, Inc.
H04L63/1433G06N5/02G06N20/00H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,552,976
App. No.
16/653,899
Granted
Jan 10, 2023
Kind
B2
Abstract

Systems and methods for predicting enterprise cyber incidents using social network analysis on the darkweb hacker forums are disclosed.

Claims (28)

1. A method of threat prediction based on social network features computed on a streaming basis, comprising:

generating, by a processor, a plurality of evolving networks including a historical network defining a first temporal graph corresponding to a first set of forum posts aggregated within a predetermined time period, and a daily network defining a second temporal graph corresponding to a second set of forum posts for a current day;

generating, by the processor, an auxiliary graph that incorporates historical information from the plurality of evolving networks by merging the first temporal graph with the second temporal graph; and

computing by the processor a set of features for the current day from the auxiliary graph based on community information about known expert users associated with the first temporal graph.

2. The method of claim 1 , further comprising computing the set of features, by:

inputting a set of predetermined experts and a set of tuples associated with the set of predetermined experts;

outputting a number of non-experts at a certain time that share communities with the set of predetermined experts;

extracting a plurality of communities from the plurality of evolving networks;

defining a community associated with the set of predetermined experts;

computing, for each of the set of experts, all associated communities;

defining a set of individuals who have posted in a timeframe based on the auxiliary network;

defining a set of tuples associated with the timeframe;

iterating through each of the set of individuals who posted during the time frame to assess a measure of common communities.

3. The method of claim 2 , wherein each of the set of individuals are connected using heuristics through one of either a temporal constraint or a spatial constraint.

4. The method of claim 2 , wherein the set of predetermined experts is extracted from the historical network while excluding the daily network.

5. The method of claim 2 , wherein the set of predetermined experts is extracted from the historical network following constraints comprising:

extracting each of the set of predetermined users who have mentioned a common vulnerability and exposure in a post in a time spanned by the historical network;

extracting each of the set of predetermined users who have mentioned a common vulnerability and exposure in a post belonging to a number of top common platform enumerations for a time spanned by the historical network; and

extracting each of the set of predetermined users who have an indegree in the historical network greater than a predetermined threshold.

6. The method of claim 1 , wherein the evolving networks include a reply network corresponding to a thread within a forum.

7. The method of claim 1 , wherein the set of features comprise a measure of graph conductance, a measure of shortest path, a set of expert replies, and the measure of common communities.

8. The method of claim 1 , further comprising employing, by the processor, an unsupervised machine learning model configured to:

aggregate a time series associated with the historical network;

separate a set of daily feature vectors into normal and anomalous components;

compute a squared prediction error from the anomalous components; and

flag points within the set of daily feature vectors as anomalous using a threshold based measure, the threshold based measure denoting a limit for anomaly among a set of values chosen for flagging a point for the set of daily feature vectors.

9. The method of claim 1 , wherein the historical network is constant for all days in a particular month.

10. The method of claim 1 , wherein the daily network is recreated on a daily basis.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 28, 2020
From: SHAKARIAN, JANA
To: CYBER RECONNAISSANCE, INC.
Reel/Frame 051960/0571 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2019
From: SARKAR, SOUMAJYOTI; ALMUKAYNIZI, MOHAMMED; SHAKARIAN, PAULO
To: ARIZONA BOARD OF REGENTS ON BEHALF OF ARIZONA STATE UNIVERSITY
Reel/Frame 050796/0962 →
Continuity (2)
Provisional Application 62745731 · Oct 15, 2018
Related Publication 20220070196A1 · Mar 3, 2022
Cited By (1)
US 12,436,827