A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums

dc.authorid0000-0001-8857-5148
dc.contributor.authorDelen, Dursun
dc.contributor.authorDelen, Dursun
dc.contributor.authorBiswas, Baidyanath
dc.contributor.authorMukhopadhyay, Arunabha
dc.contributor.authorBhattacharjee, Sudip
dc.contributor.authorKumar, Ajay
dc.contributor.authorDelen, Dursun
dc.contributor.otherYönetim Bilimleri Fakültesi, İşletme Bölümü
dc.contributor.otherYönetim Bilimleri Fakültesi, İşletme Bölümü
dc.date.accessioned2021-12-07T12:37:14Z
dc.date.available2021-12-07T12:37:14Z
dc.date.issued2022
dc.departmentİHÜ, Yönetim Bilimleri Fakültesi, İşletme Bölümü
dc.description.abstractOnline hacker communities are meeting spots for aspiring and seasoned cybercriminals where they engage in technical discussions, share exploits and relevant hacking tools to be used in launching cyber-attacks on business organizations. Sometimes, the affected organizations can detect these attacks in advance, with the help of cyberthreat intelligence derived from the explicit and implicit features of hacker communication in these forums. Herein, we proposed a novel text-mining based cyber-risk assessment and mitigation framework, which performs the following critical tasks. (i) Cyber-risk Assessment - to identify hacker expertise (i.e., newbie, beginner, intermediate, and advanced) using explicit and implicit features applying various classification algorithms. Among these features, cybersecurity keywords, sharing of attachments, and sentiments emerged as significant. Further, we found that expert hackers demonstrate leadership in the online forums that eventually serve as communities of practice. Consequently, novice hackers gradually develop their cyber-attack skills through prolonged observations, interactions, and external influences in this social learning process. (ii) Cyber-risk mitigation - computes financial impact for every {hacker expertise, attack-type} combination, and then by ranking them on a {likelihood, impact} decision-matrix to prioritize mitigation strategies in affected organizations. Through these novel recommendations, our framework can guide managers to decide on appropriate cybersecurity controls using an {expected loss, probability, attack-type, hacker expertise} metric against financial losses due to cyber-attacks.
dc.identifier.citationBiswas, B., Mukhopadhyay, A., Bhattacharjee, S., Kumar, A. ve Delen, D. (2022). A text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums. Decision Support Systems, 152. https://doi.org/10.1016/j.dss.2021.113651
dc.identifier.doi10.1016/j.dss.2021.113651
dc.identifier.issn0167-9236
dc.identifier.issn1873-5797
dc.identifier.scopus2-s2.0-85112357041
dc.identifier.scopusqualityQ1
dc.identifier.urihttp://dx.doi.org/10.1016/j.dss.2021.113651
dc.identifier.urihttps://hdl.handle.net/20.500.12154/1667
dc.identifier.volume152
dc.identifier.wosWOS:000721384400001
dc.identifier.wosqualityQ1
dc.indekslendigikaynakScopus
dc.indekslendigikaynakWeb of Science
dc.institutionauthorDelen, Dursun
dc.institutionauthorid0000-0001-8857-5148
dc.language.isoen
dc.publisherElsevier
dc.relation.ihupublicationcategory114
dc.relation.ispartofDecision Support Systems
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı
dc.rightsinfo:eu-repo/semantics/closedAccess
dc.subjectInformation Security
dc.subjectCyber Risks
dc.subjectHacker Forum
dc.subjectMachine Learning
dc.subjectSentiment Analysis
dc.titleA text-mining based cyber-risk assessment and mitigation framework for critical analysis of online hacker forums
dc.typeArticle
dspace.entity.typePublication
relation.isAuthorOfPublicationde384c43-bcde-4ccb-a0b7-39ead0e59bd0
relation.isAuthorOfPublication.latestForDiscoveryde384c43-bcde-4ccb-a0b7-39ead0e59bd0
relation.isOrgUnitOfPublicationc9253b76-6094-4836-ac99-2fcd5392d68f
relation.isOrgUnitOfPublication.latestForDiscoveryc9253b76-6094-4836-ac99-2fcd5392d68f

Dosyalar

Orijinal paket
Listeleniyor 1 - 1 / 1
[ N/A ]
İsim:
Delen-D.pdf
Boyut:
909.15 KB
Biçim:
Adobe Portable Document Format
Açıklama:
Tam Metin / Full Text
Lisans paketi
Listeleniyor 1 - 1 / 1
[ N/A ]
İsim:
license.txt
Boyut:
1.52 KB
Biçim:
Item-specific license agreed upon to submission
Açıklama: