D-miner: A framework for mining, searching, visualizing, and alerting on darknet events

D-miner: A framework for mining, searching, visualizing, and alerting on darknet events
复制标题

D-miner:针对暗网事件进行挖掘、搜索、可视化和警报的框架

DOI:
--
复制
发表时间:
2017
期刊:
IEEE Conference on Communications and Network Security
影响因子:
--
通讯作者:
C. Zou
C. Zou
中科院分区:
--
文献类型:
--
作者:
Heather Lawrence;A. Hughes;Robert Tonic;C. Zou

文献摘要

被引文献

相似文献

暗网资源的数据被挖掘出来,以便为网络运营商提供可能的网络威胁情报。然而,网络运营商通常只有有限的资源来搜索暗网的威胁。以前在这方面的工作没有解决这个用例,而是专注于销售量,供应商特征,并确定零日漏洞的销售。在本文中,我们介绍了D-miner:一个模块化框架,旨在从网站中挖掘数据,专门针对暗网网站,并将数据解析为JSON对象,用于搜索,可视化和警报。这个暗网挖矿的开源解决方案旨在使网络股东更容易监控暗网的潜在威胁。我们展示了D-miner如何针对多个用例进行自定义,以及如何使用它来可视化数据以帮助分析。
Darknet resources are mined for their data in order to provide possible cyber threat intelligence to network operators. Network operators, however, often have limited resources with which to search the darknet for threats. Previous work in this area has failed to address this use case instead focusing on sales volumes, vendor characteristics, and identifying the sale of zero day exploits. In this paper we present D-miner: a modular framework designed to mine data from websites, specializing in darknet sites, and parse the data into JSON objects for searching, visualizations, and alerts. This open source solution to darknet mining is intended to make it easier for network shareholders to monitor the darknet for potential threats. We show how D-miner is customizable for multiple use cases and how it can be used to visualize data to aid analysis.