Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning

Fuente: arXiv
Saved in:
Bibliographic Details
Main Authors: Filho, Sebastião Alves de Jesus, Bernardo, Gustavo Di Giovanni, Gabriel, Paulo Henrique Ribeiro, Zarpelão, Bruno Bogaz, Miani, Rodrigo Sanches
Format: Preprint
Published: 2025
Subjects:
Online Access:
Tags: Add Tag
No Tags, Be the first to tag this record!
_version_ 1866915643351105536
author Filho, Sebastião Alves de Jesus
Bernardo, Gustavo Di Giovanni
Gabriel, Paulo Henrique Ribeiro
Zarpelão, Bruno Bogaz
Miani, Rodrigo Sanches
author_facet Filho, Sebastião Alves de Jesus
Bernardo, Gustavo Di Giovanni
Gabriel, Paulo Henrique Ribeiro
Zarpelão, Bruno Bogaz
Miani, Rodrigo Sanches
contents Given the constant growth and increasing sophistication of cyberattacks, cybersecurity can no longer rely solely on traditional defense techniques and tools. Proactive detection of cyber threats has become essential to help security teams identify potential risks and implement effective mitigation measures. Cyber Threat Intelligence (CTI) plays a key role by providing security analysts with evidence-based knowledge about cyber threats. CTI information can be extracted using various techniques and data sources; however, machine learning has proven promising. As for data sources, social networks and online discussion forums are commonly explored. In this study, we apply text mining techniques and machine learning to data collected from Dark Web forums in Brazilian Portuguese to identify malicious posts. Our contributions include the creation of three original datasets, a novel multi-stage labeling process combining indicators of compromise (IoCs), contextual keywords, and manual analysis, and a comprehensive evaluation of text representations and classifiers. To our knowledge, this is the first study to focus specifically on Brazilian Portuguese content in this domain. The best-performing model, using LightGBM and TF-IDF, was able to detect relevant posts with high accuracy. We also applied topic modeling to validate the model's outputs on unlabeled data, confirming its robustness in real-world scenarios.
format Preprint
id arxiv_https___arxiv_org_abs_2511_23183
institution arXiv
publishDate 2025
record_format arxiv
spellingShingle Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning
Filho, Sebastião Alves de Jesus
Bernardo, Gustavo Di Giovanni
Gabriel, Paulo Henrique Ribeiro
Zarpelão, Bruno Bogaz
Miani, Rodrigo Sanches
Cryptography and Security
Artificial Intelligence
Given the constant growth and increasing sophistication of cyberattacks, cybersecurity can no longer rely solely on traditional defense techniques and tools. Proactive detection of cyber threats has become essential to help security teams identify potential risks and implement effective mitigation measures. Cyber Threat Intelligence (CTI) plays a key role by providing security analysts with evidence-based knowledge about cyber threats. CTI information can be extracted using various techniques and data sources; however, machine learning has proven promising. As for data sources, social networks and online discussion forums are commonly explored. In this study, we apply text mining techniques and machine learning to data collected from Dark Web forums in Brazilian Portuguese to identify malicious posts. Our contributions include the creation of three original datasets, a novel multi-stage labeling process combining indicators of compromise (IoCs), contextual keywords, and manual analysis, and a comprehensive evaluation of text representations and classifiers. To our knowledge, this is the first study to focus specifically on Brazilian Portuguese content in this domain. The best-performing model, using LightGBM and TF-IDF, was able to detect relevant posts with high accuracy. We also applied topic modeling to validate the model's outputs on unlabeled data, confirming its robustness in real-world scenarios.
title Identification of Malicious Posts on the Dark Web Using Supervised Machine Learning
topic Cryptography and Security
Artificial Intelligence
url https://arxiv.org/abs/2511.23183