HyperMan: detecting misbehavior in online forums based on hyperlink posting behavior

HyperMan: detecting misbehavior in online forums based on hyperlink posting behavior
复制标题

DOI:
10.1007/s13278-022-00943-3
复制
发表时间:
2022-08
影响因子:
2.8
通讯作者:
Risul Islam;Ben Treves;Md Omar Faruk Rokon;M. Faloutsos
Risul Islam;Ben Treves;Md Omar Faruk Rokon;M. Faloutsos
中科院分区:
--
文献类型:
--
作者:
Risul Islam;Ben Treves;Md Omar Faruk Rokon;M. Faloutsos

文献摘要

相似文献

我们如何检测和分析在线论坛中由超链接驱动的不当行为?在线论坛包含大量用户生成的内容,其中的帖子和评论经常由超链接补充。这些超链接通常是带有恶意的,我们将其称为“超链接驱动的不当行为”。我们提出了HyperMan,这是一套系统的功能,用于检测和分析在线论坛中由超链接驱动的不当行为。我们以独特的视角关注用户的超链接分享行为,以发现不当行为。HyperMan可以将这些超链接归类为(A)网络钓鱼、(B)垃圾邮件和(B)推广恶意产品。我们的方法包括三个高级阶段:(A)从文本数据中提取超链接,(B)识别行为不当的超链接,(C)对超链接共享的行为模式进行建模,其中我们识别关键超链接并分析超链接共享的协作动态。此外,我们将我们的方法作为一个强大且易于使用的开放平台实施,供从业者使用。我们使用HyperMan来发现来自三个在线安全论坛的不当行为,我们希望用户在这些论坛上有更多的安全意识。与以前的解决方案相比,我们的方法在检索和分类超链接方面效果很好。此外,我们还发现了相当多且经常是系统性的不当行为:(A)我们发现总共有2703个行为不端的超链接,以及(B)我们识别出94个串通的用户群体来推广超链接。我们的工作是朝着挖掘在线论坛和全面检测行为不端用户迈出的重要一步。
How can we detect and analyze hyperlink-driven misbehavior in online forums? Online forums contain enormous amounts of user-generated contents, with threads and comments frequently supplemented by hyperlinks. These hyperlinks are often posted with malicious intention and we refer to this as ‘hyperlink-driven misbehavior.’ We present HyperMan, a systematic suite of capabilities, to detect and analyze hyperlink-driven misbehavior in online forums. We take a unique perspective focusing on hyperlink sharing practices of the users to spot misbehavior. HyperMan can categorize these hyperlinks as (a) phishing, (b) spamming, and (b) promoting malicious products. Our approach consists of three high-level phases: (a) extracting hyperlinks from the textual data, (b) identifying misbehaving hyperlinks, and (c) modeling the behavioral patterns of hyperlink sharing, where we identify key hyperlinks and analyze the collaboration dynamics of hyperlink sharing. In addition, we implement our approach as a powerful and easy-to-use open platform for practitioners. We apply HyperMan to spot misbehavior from three online security forums, where we expect the users to be more security-aware. We show that our approach works very well in terms of retrieving and classifying hyperlinks compared to previous solutions. Furthermore, we find non-trivial and often systematic misbehavior: (a) we find a total of 2703 misbehaving hyperlinks, and (b) we identify 94 colluding groups of users in terms of promoting hyperlinks. Our work is a significant step toward mining online forums and detecting misbehaving users comprehensively.