Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning
Fuente:
arXiv
Saved in:
| Main Authors: | , , , , |
|---|---|
| Format: | Preprint |
| Published: |
2025
|
| Subjects: | |
| Online Access: | |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866915643351105536 |
|---|---|
| author | Filho, Sebastião Alves de Jesus Bernardo, Gustavo Di Giovanni Gabriel, Paulo Henrique Ribeiro Zarpelão, Bruno Bogaz Miani, Rodrigo Sanches |
| author_facet | Filho, Sebastião Alves de Jesus Bernardo, Gustavo Di Giovanni Gabriel, Paulo Henrique Ribeiro Zarpelão, Bruno Bogaz Miani, Rodrigo Sanches |
| contents | Given the constant growth and increasing sophistication of cyberattacks, cybersecurity can no longer rely solely on traditional defense techniques and tools. Proactive detection of cyber threats has become essential to help security teams identify potential risks and implement effective mitigation measures. Cyber Threat Intelligence (CTI) plays a key role by providing security analysts with evidence-based knowledge about cyber threats. CTI information can be extracted using various techniques and data sources; however, machine learning has proven promising. As for data sources, social networks and online discussion forums are commonly explored. In this study, we apply text mining techniques and machine learning to data collected from Dark Web forums in Brazilian Portuguese to identify malicious posts. Our contributions include the creation of three original datasets, a novel multi-stage labeling process combining indicators of compromise (IoCs), contextual keywords, and manual analysis, and a comprehensive evaluation of text representations and classifiers. To our knowledge, this is the first study to focus specifically on Brazilian Portuguese content in this domain. The best-performing model, using LightGBM and TF-IDF, was able to detect relevant posts with high accuracy. We also applied topic modeling to validate the model's outputs on unlabeled data, confirming its robustness in real-world scenarios. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2511_23183 |
| institution | arXiv |
| publishDate | 2025 |
| record_format | arxiv |
| spellingShingle | Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning Filho, Sebastião Alves de Jesus Bernardo, Gustavo Di Giovanni Gabriel, Paulo Henrique Ribeiro Zarpelão, Bruno Bogaz Miani, Rodrigo Sanches Cryptography and Security Artificial Intelligence Given the constant growth and increasing sophistication of cyberattacks, cybersecurity can no longer rely solely on traditional defense techniques and tools. Proactive detection of cyber threats has become essential to help security teams identify potential risks and implement effective mitigation measures. Cyber Threat Intelligence (CTI) plays a key role by providing security analysts with evidence-based knowledge about cyber threats. CTI information can be extracted using various techniques and data sources; however, machine learning has proven promising. As for data sources, social networks and online discussion forums are commonly explored. In this study, we apply text mining techniques and machine learning to data collected from Dark Web forums in Brazilian Portuguese to identify malicious posts. Our contributions include the creation of three original datasets, a novel multi-stage labeling process combining indicators of compromise (IoCs), contextual keywords, and manual analysis, and a comprehensive evaluation of text representations and classifiers. To our knowledge, this is the first study to focus specifically on Brazilian Portuguese content in this domain. The best-performing model, using LightGBM and TF-IDF, was able to detect relevant posts with high accuracy. We also applied topic modeling to validate the model's outputs on unlabeled data, confirming its robustness in real-world scenarios. |
| title | Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning |
| topic | Cryptography and Security Artificial Intelligence |
| url | https://arxiv.org/abs/2511.23183 |