Prototype and Analytics for Discovery and Exploitation of Threat Networks on Social Media

No ratings

Presented at EISIC 2019 by

Identifying and profiling threat actors are high priority tasks for a number of governmental organizations. Thesethreat actors may operate actively, using the Internet to promote propaganda, recruit new members, or exert commandand control over their networks. Alternatively, threat actors may operate passively, demonstrating operationalsecurity awareness online while using their Internet presence to gather information they need to pose an offlinephysical threat. This paper presents a flexible new prototype system that allows analysts to automatically detect,monitor and characterize threat actors and their networks using publicly available information. The proposedprototype system fills a need in the intelligence community for a capability to automate manual construction andanalysis of online threat networks. Leveraging graph sampling approaches, we perform targeted data collection ofextremist social media accounts and their networks. We design and incorporate new algorithms for role classificationand radicalization detection using insights from social science literature of extremism. Additionally, we develop andimplement analytics to facilitate monitoring the dynamic social networks over time. The prototype also incorporatesseveral novel machine learning algorithms for threat actor discovery and characterization, such as classification ofuser posts into discourse categories, user post summaries and gender prediction.