IP Library Granted Patent US 12,355,804
Granted Patent B2
US 12,355,804 · App. 18/150,577 · Granted Jul 8, 2025

Systems and methods for social network analysis on dark web forums to predict enterprise cyber incidents

Inventors: Soumajyoti Sarkar (Tempe, AZ); Mohammed Almukaynizi (Chandler, AZ); Jana Shakarian (Chandler, AZ); Paulo Shakarian (Chanlder, AZ)
Assignee: Arizona Board of Regents on Behalf of Arizona State University
H04L63/1433G06N5/02G06N20/00H04L63/1416H04L63/1425
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,355,804
App. No.
18/150,577
Granted
Jul 8, 2025
Kind
B2
Abstract

Systems and methods for predicting enterprise cyber incidents using social network analysis on the darkweb hacker forums are disclosed.

Claims (16)

1. A system for threat prediction based on social network features, comprising:

a processor in communication with a memory, the memory including instructions, which, when executed, cause the processor to:

access a set of features associated with a predetermined user that has participated in one or more forums in the dark web during a time span, the set of features derived from one or more networks formed from thread replies in the one or more forums; and

generate, given a time point t when it is desired to predict an attack of a predetermined event type, a prediction of an attack associated with the predetermined user for the time point t, wherein the processor computes a time series of the set of features across the one or more forums and applies the time series of the set of features as input to one or more predictive models to predict an attack at the time point t.

2. The system of claim 1 , wherein the set of features are updated by the processor by creation of networks on a streaming daily basis such that the networks define nodes as users including the predetermined user, and edges as interactions that are part of a current day for which the set of features are being computed to represent the dynamic nature of forum participants and active participation by the predetermined user.

3. The system of claim 1 , wherein the set of features includes graph-based features pertaining to dynamics of replies from users with credible knowledge to regular posts and features associated with forum metadata used as baselines for the graph-based features.

4. The system of claim 1 , wherein the set of features includes a time series feature from threads in a given forum that maps each time point to a real number.

5. The system of claim 1 , wherein the set of features is computed using a historical network that spans over time and a network induced by user interactions between users and the predetermined user.

6. The system of claim 1 , wherein at least one of the set of features includes a feature formed for every one of the one or more forums separately.

7. The system of claim 1 , wherein the one or more predictive models includes anomaly-based classification.

8. The system of claim 1 , wherein the memory includes further instructions, which, when executed, cause the processor to:

update the set of features associated with the predetermined user to reflect a change in activity by the predetermined user.

9. The system of claim 1 , wherein the set of features represent interactions between the predetermined user and one or more other users.

10. The system of claim 1 , wherein the predetermined user is a known expert that has actively participated in one or more communications within the time span.

11. The system of claim 1 , wherein the set of features are computed using a reply network framework that includes a plurality of networks induced on specific forums.

12. The system of claim 1 , wherein the one or more networks includes temporal networks formed by taking two or more temporal graphs as input and merging them to form an auxiliary graph.

Assignments (3)
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE FROM CYBER RECONNAISSANCE, INC. TO READ SECURIN, INC. PREVIOUSLY RECORDED ON REEL 66652 FRAME 531. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNORS' INTEREST. Recorded Jun 16, 2025
From: SHAKARIAN, JANA
To: SECURIN, INC.
Reel/Frame 071656/0082 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: SARKAR, SOUMAJYOTI; ALMUKAYNIZI, MOHAMMED; SHAKARIAN, PAULO
To: ARIZONA BOARD OF REGENTS ON BEHALF OF ARIZONA STATE UNIVERSITY
Reel/Frame 066652/0453 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 5, 2024
From: SHAKARIAN, JANA
To: CYBER RECONNAISSANCE, INC.
Reel/Frame 066652/0531 →
Continuity (3)
Continuation 16653899 · Oct 15, 2019
Provisional Application 62745731 · Oct 15, 2018
Related Publication 20230388333A1 · Nov 30, 2023
References Cited (77)
US 10176438B2 · Shakarian et al. · 2019 [imported from a related ]
US 10313385B2 · Shakarian et al. · 2019 [imported from a related ]
US 10437945B2 · Shakarian et al. · 2019 [imported from a related ]
US 20170171231A1 · Reybok, Jr. · 2017 [cited by examiner]
US 20180225372A1 · Lecue et al. · 2018 [imported from a related ]
US 20190095530A1 · Booker et al. · 2019 [imported from a related ]
US 20190132352A1 · Zhang et al. · 2019 [imported from a related ]
US 20190266283A1 · Shukla et al. · 2019 [imported from a related ]
US 20190347327A1 · Patil et al. · 2019 [imported from a related ]
US 20190349393A1 · Nunes · 2019 [cited by examiner]
US 20200036743A1 · Almukaynizi · 2020 [cited by examiner]
US 20200169483A1 · Kursun · 2020 [imported from a related ]
US 20200356675A1 · Shakarian · 2020 [cited by examiner]
US 20200364349A1 · Nunes · 2020 [cited by examiner]
US 20200410028A1 · Shaabani et al. · 2020 [imported from a related ]
US 20210019762A1 · Bosnjakovic et al. · 2021 [imported from a related ]
US 20210073855A1 · Francia · 2021 [cited by examiner]
US 20210158176A1 · Wan et al. · 2021 [imported from a related ]
US 20210367966A1 · Yanay et al. · 2021 [imported from a related ]
US 20210382944A1 · Li et al. · 2021 [imported from a related ]
US 20220327108A1 · Manolache · 2022 [cited by examiner]
US 20230336586A1 · Sopan · 2023 [cited by examiner]
US 20240340296A1 · Brunner · 2024 [cited by examiner]
CN 107749835A · 2018 [cited by examiner]
CN 113271321A · 2021 [cited by examiner]
GB 2583892A · 2020 [imported from a related ]
WO WO2019089389A1 · 2019 [cited by examiner]
WO WO2020089532A1 · 2020 [cited by examiner]
Nagaraja, et al., Anonymity in the wild: Mixes on unstructured networks, International Workshop on PrivacyBerlin, Heidelberg, 2007. [imported from a related ]
Nagaraja, et al., BotGrep: Finding P2P Bots with Structured Graph Analysis, USENIX Security Symposium, vol. 10, pp. 95-110, 2010. [imported from a related ]
Nunes, et al., Darknet and deepnet mining for proactive cybersecurity threat intelligence, arXiv preprint arXiv:1607.08583, 2016. [imported from a related ]
Okutan, et al., Forecasting cyber at-tacks with imbalanced data sets and different time granularities, arXiv preprint arXiv:1803.09560, 2018. [imported from a related ]
Phillips, et al., Extracting social structure from darkweb forums. 97-102, 2015. [imported from a related ]
Randall, Rapidly mixing Markov chains with applications in computer science and physics, Computing in Science and Engineering 8.2: 30-41, 2006. [imported from a related ]
Liu, et al., Predicting cyber security incidents using feature-based characterization of network-level malicious activities, Proceedings of the 2015 ACM International Workshop on International Workshop on Security and P… [imported from a related ]
Meier, The group lasso for logistic regression, Journal of the Royal Statistical Society: Series B (Statistical Methodology) 70.1: 53-71, 2008. [imported from a related ]
Lakhina, et al., Diagnosing network-wide traffic anomalies, ACM SIGCOMM Computer Communication Review, vol. 34, No. 4, pp. 219-230. ACM, 2004. [imported from a related ]
L'huillier, et al., Topic-based social network analysis for virtual communities of interests in the dark web, ACM SIGKDD Explorations Newsletter 12, No. 2: 66-73, 2011. [imported from a related ]
Liu, et al., Cloudy with a Chance of Breach: Forecasting Cyber Security Incidents, USENIX Security Symposium, pp. 1009-1024, Aug. 2015. [imported from a related ]
Shakarian, et al., Exploring malicious hacker forums, Cyber Deception. Springer, Cham, 2016. 259-282. [imported from a related ]
Shlens, A tutorial on principal component analysis, arXiv preprint arXiv:1404.1100 2014. [imported from a related ]
Sood, et al., Cybercrime: Dissecting the state of underground enterprise, IEEE internet computing 17.1 (2013): 60-68. [imported from a related ]
Soule, et al., Combining filtering and statistical methods for anomaly detection, Proceedings of the 5th ACM SIGCOMM conference on Internet Measurement. USENIX Association, 2005. [imported from a related ]
Tang, et al., Temporal distance metrics for social network analysis, Proceedings of the 2nd ACM workshop on Online social networks, pp. 31-36. ACM, 2009. [imported from a related ]
Thonnard, et al. Are you at risk? Profiling organizations and individuals subject to targeted attacks, International Conference on Financial Cryptography and Data Security. Springer, Berlin, Heidelberg, 2015. [imported from a related ]
Tibshirani, et al., An ordered lasso and sparse time-lagged regression, Technometrics 58, No. 4 (2016); 415-423. [imported from a related ]
Samtani, et al., Exploring hacker assets in under-ground forums, Intelligence and Security Informatics (ISI), 2015 IEEE International Conference on. IEEE, 2015. [imported from a related ]
Sapienza, et al., Discover: Mining Online Chatter for Emerging Cyber Threats, Companion of the The Web Conference 2018 on The Web Conference 2018, pp. 983-990. International World Wide Web Conferences Steering Committee… [imported from a related ]
Sarkar, et al., Predicting enterprise cyber incidents using social network analysis on the darkweb hacker forums, arXiv preprint arXiv:1811.06537, 2018. [imported from a related ]
Reksna, Complex Network Analysis of Darknet Black Market Forum Structure. MS thesis. 2017. [imported from a related ]
Ribeiro, et al., Why should I trust you ?: Explaining the predictions of any classifier, Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining (pp. 1135-1144). ACM, Aug. 2016. [imported from a related ]
Sabottke, et al., Vulnerability Disclosure in the Age of Social Media: Exploiting Twitter for Predicting Real-World Exploits, USENIX Security Symposium. 2015. [imported from a related ]
Edkrantz, et al., Predicting vulnerability exploits in the wild, Cyber Security and Cloud Computing (CSCloud), 2015 IEEE 2nd International Conference on. IEEE, 2015. [imported from a related ]
Ferrara, et al., The rise of social bots, Communications of the ACM, 59(7), pp. 96-104. [imported from a related ]
Goyal, et al., Discovering Signals from Web Sources to Predict Cyber Attacks, arXiv preprint arXiv:1806.03342, 2018. [imported from a related ]
Chierichetti, et al., Rumour spreading and graph conductance, Proceedings of the twenty-first annual ACM-SIAM symposium on Discrete Algorithms, Society for Industrial and Applied Mathematics, 2010. [imported from a related ]
Colbaugh, et al., Proactive defense for evolving cyber threats, Intelligence and Security Informatics (ISI), 2011 IEEE International Conference on. IEEE, 2011. [imported from a related ]
Danezis, et al., Sybillnfer: Detecting Sybil Nodes using Social Networks, NDSS, pp. 1-15, 2009. [imported from a related ]
Hodge, et al., A survey of outlier detection methodologies, Artificial intelligence review 22.2: 85-126, 2004. [imported from a related ]
Huang, et al., In-network PCA and anomaly detection, Advances in Neural Information Processing Systems, pp. 617-624. 2007. [imported from a related ]
Khandpur, et al., Crowdsourcing cybersecurity: Cyber attack detection using social media, Proceedings of the 2017 ACM on Conference on Information and Knowledge Management. ACM, 2017. [imported from a related ]
Kotenko, et al., Analyzing vulnerabilities and measuring security level at design and exploitation stages of computer network life cycle, International Workshop on Mathematical Methods, Models, and Architectures for Com… [imported from a related ]
Grier, et al., Manufacturing compromise: the emergence of exploit-as-a-service, Proceedings of the 2012 ACM conference on Computer and communications security, pp. 821-832. ACM, 2012. [imported from a related ]
Haslebacher, et al., All your cards are belong to US: Understanding online carding forums, Electronic Crime Research (eCrime), 2017 APWG Symposium on. IEEE, 2017. [imported from a related ]
Herley, et al., Nobody sells gold for the price of silver: Dishonesty, uncertainty and the underground economy, Economics of information security and privacy. Springer, Boston, MA, 2010. 33-53. [imported from a related ]
Almukaynizi, et al., Proactive identification of exploits in the wild through vulnerability mentions online, Cyber Conflict (CyCon US), 2017 Intemational Conference on. IEEE, 2017. [imported from a related ]
Ai-Rowaily, et al., BiSALA bilingual sentiment analysis lexicon to analyze Dark Web forums for cyber security, Digital Investigation 14: 53-62, 2015. [imported from a related ]
Bilge, et al., Before we knew it: an empirical study of zero-day attacks in the real world, Proceedings of the 2012 ACM conference on Computer and communications security. ACM. 2012. [imported from a related ]
Bilge, et al., RiskTeller: Predicting the Risk of Cyber Incidents, Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2017. [imported from a related ]
Chandola, et al., Anomaly detection: A survey, ACM computing surveys (CSUR) 41.3: 15, 2009. [imported from a related ]
Chen, Sentiment and affect analysis of dark web forums: Measuring radicalization on the internet, Intelligence and Security Infomatics, ISI 2008, IEEE International Conference, 2008. [imported from a related ]
Allodi, Economic factors of vulnerability trade and exploitation, Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security. ACM, 2017. [imported from a related ]
Allodi, et al., Then and now: On the maturity of the cybercrime markets the lesson that black-hat marketeers learned, IEEE Transactions on Emerging Topics in Computing 4.1 (2016): 35-46. [imported from a related ]
Almukaynizi, et al., Predicting cyber threats through the dynamics of user connectivity in darkweb and deepweb forums, ACM Computational Social Science. ACM, 2017. [imported from a related ]
Pfleeger, et al., Security in computing. Prentice Hall Professional Technical Reference, 2002. [imported from a related ]
U.S. Appl. No. 16/548,329, filed Aug. 22, 2019, Tavabi et al. [imported from a related ]
Akoglu, et al., Graph based anomaly detection and description: a survey. Data mining and knowledge discovery, 29(3), pp. 626-688. [imported from a related ]