Logo des Repositoriums
  • English
  • Deutsch
Anmelden
Keine TU-ID? Klicken Sie hier für mehr Informationen.
  1. Startseite
  2. Publikationen
  3. Publikationen der Technischen Universität Darmstadt
  4. Zweitveröffentlichungen
  5. Navigating the Shadows: Manual and Semi-Automated Evaluation of the Dark Web for Cyber Threat Intelligence
 
  • Details
2024
Zweitveröffentlichung
Artikel
Verlagsversion

Navigating the Shadows: Manual and Semi-Automated Evaluation of the Dark Web for Cyber Threat Intelligence

File(s)
Download
Hauptpublikation
Navigating_the_Shadows_Manual_and_Semi-Automated_Evaluation_of_the_Dark_Web_for_Cyber_Threat_Intelligence.pdf
CC BY-NC-ND 4.0 International
Format: Adobe PDF
Size: 2.45 MB
TUDa URI
tuda/14456
URN
urn:nbn:de:tuda-tuprints-314754
DOI
10.26083/tuprints-00031475
Autor:innen
Kühn, Philipp ORCID 0000-0002-1739-876X
Wittorf, Kyra
Reuter, Christian ORCID 0000-0003-1920-038X
Kurzbeschreibung (Abstract)

In today’s world, cyber-attacks are becoming more frequent and thus proactive protection against them is becoming more important. Cyber Threat Intelligence (CTI) is a possible solution, as it collects threat information in various information sources and derives stakeholder intelligence to protect one’s infrastructure. The current focus of CTI in research is the clear web, but the dark web may contain further information. To further advance protection, this work analyzes the dark web as Open Source Intelligence (OSINT) data source to complement current CTI information. The underlying assumption is that hackers use the dark web to exchange, develop, and share information and assets. This work aims to understand the structure of the dark web and identify the amount of its openly available CTI related information. We conducted a comprehensive literature review for dark web research and CTI. To follow this up we manually investigated and analyzed 65 dark web forum (DWF), 7 single-vendor shops, and 72 dark web marketplace (DWM). We documented the content and relevance of DWFs and DWMs for CTI, as well as challenges during the extraction and provide mitigations. During our investigation we identified IT security relevant information in both DWFs and DWMs, ranging from malware toolboxes to hacking-as-a-service. One of the most present challenges during our manual analysis were necessary interactions to access information and anti-crawling measures, i.e., CAPTCHAs. This analysis showed 88% of marketplaces and 53% of forums contained relevant data. Our complementary semi-automated analysis of 1 186 906 onion addresses indicates, that the necessary interaction makes it difficult to see the dark web as an open, but rather treat it as specialized information source, when clear web information does not suffice.

Freie Schlagworte

Dark Web

Computer crime

Cyber threat intellig...

Manuals

Ethics

Data mining

Visualization

Computer security

Sprache
Englisch
Fachbereich/-gebiet
20 Fachbereich Informatik > Wissenschaft und Technik für Frieden und Sicherheit (PEASEC)
DDC
000 Allgemeines, Informatik, Informationswissenschaft > 004 Informatik
Institution
Universitäts- und Landesbibliothek Darmstadt
Ort
Darmstadt
Titel der Zeitschrift / Schriftenreihe
IEEE Access
Startseite
118903
Endseite
118922
Jahrgang der Zeitschrift
12
ISSN
2169-3536
Verlag
IEEE
Ort der Erstveröffentlichung
New York, NY
Publikationsjahr der Erstveröffentlichung
2024
Verlags-DOI
10.1109/ACCESS.2024.3448247
PPN
54013564X
Zusätzliche Infomationen
Funding information: This work was supported in part by German Federal Ministry of Education and Research (BMBF) in the Project CYWARN under Grant 13N15407; and in part by German Federal Ministry of Education and Research and the Hessian Ministry of Higher Education, Research, Science and the Arts in their Joint Support of the ATHENE National Research Center for Applied Cybersecurity

  • TUprints Leitlinien
  • Cookie-Einstellungen
  • Impressum
  • Datenschutzbestimmungen
  • Webseitenanalyse
Diese Webseite wird von der Universitäts- und Landesbibliothek Darmstadt (ULB) betrieben.