{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,19]],"date-time":"2026-02-19T02:21:51Z","timestamp":1771467711998,"version":"3.50.1"},"reference-count":54,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2019,9,30]],"date-time":"2019-09-30T00:00:00Z","timestamp":1569801600000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2019,9,30]],"date-time":"2019-09-30T00:00:00Z","timestamp":1569801600000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"funder":[{"DOI":"10.13039\/100000181","name":"Air Force Office of Scientific Research","doi-asserted-by":"publisher","award":["FA9550-15-1-0159"],"award-info":[{"award-number":["FA9550-15-1-0159"]}],"id":[{"id":"10.13039\/100000181","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/100006751","name":"U.S. Army","doi-asserted-by":"publisher","award":["W911Nf-15-1-0282"],"award-info":[{"award-number":["W911Nf-15-1-0282"]}],"id":[{"id":"10.13039\/100006751","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Soc. Netw. Anal. Min."],"published-print":{"date-parts":[[2019,12]]},"DOI":"10.1007\/s13278-019-0603-9","type":"journal-article","created":{"date-parts":[[2019,10,1]],"date-time":"2019-10-01T01:35:45Z","timestamp":1569893745000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":17,"title":["Mining user interaction patterns in the darkweb to predict enterprise cyber incidents"],"prefix":"10.1007","volume":"9","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4100-1160","authenticated-orcid":false,"given":"Soumajyoti","family":"Sarkar","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mohammad","family":"Almukaynizi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jana","family":"Shakarian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Paulo","family":"Shakarian","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2019,9,30]]},"reference":[{"issue":"3","key":"603_CR1","doi-asserted-by":"publisher","first-page":"626","DOI":"10.1007\/s10618-014-0365-y","volume":"29","author":"L Akoglu","year":"2015","unstructured":"Akoglu L, Tong H, Koutra D (2015) Graph based anomaly detection and description: a survey. Data Min Knowl Discov 29(3):626\u2013688","journal-title":"Data Min Knowl Discov"},{"key":"603_CR2","doi-asserted-by":"crossref","unstructured":"Allodi L (2017) Economic factors of vulnerability trade and exploitation. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM","DOI":"10.1145\/3133956.3133960"},{"issue":"1","key":"603_CR3","doi-asserted-by":"publisher","first-page":"35","DOI":"10.1109\/TETC.2015.2397395","volume":"4","author":"L Allodi","year":"2016","unstructured":"Allodi L, Corradin M, Massacci F (2016) Then and now: on the maturity of the cybercrime markets the lesson that black-hat marketeers learned. IEEE Trans Emerg Top Comput 4(1):35\u201346","journal-title":"IEEE Trans Emerg Top Comput"},{"key":"603_CR4","doi-asserted-by":"crossref","unstructured":"Almukaynizi M et al (2017a) Predicting cyber threats through the dynamics of user connectivity in darkweb and deepweb forums. In: Proceedings of the 2017 ACM international conference of the computational social science society of the Americas. ACM, Santa Fe, USA","DOI":"10.1145\/3145574.3145590"},{"key":"603_CR5","doi-asserted-by":"crossref","unstructured":"Almukaynizi M et al (2017b) Proactive identification of exploits in the wild through vulnerability mentions online. In: 2017 International conference on cyber conflict (CyCon US). IEEE","DOI":"10.1109\/CYCONUS.2017.8167501"},{"key":"603_CR6","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1016\/j.diin.2015.07.006","volume":"14","author":"K Al-Rowaily","year":"2015","unstructured":"Al-Rowaily K, Abulaish M, Haldar NA-H, Al-Rubaian M (2015) BiSAL-A bilingual sentiment analysis lexicon to analyze Dark Web forums for cyber security. Dig Investig 14:53\u201362","journal-title":"Dig Investig"},{"key":"603_CR7","doi-asserted-by":"crossref","unstructured":"Bilge L, Dumitras T (2012) Before we knew it: an empirical study of zero-day attacks in the real world. In: Proceedings of the 2012 ACM conference on computer and communications security. ACM","DOI":"10.1145\/2382196.2382284"},{"key":"603_CR8","doi-asserted-by":"crossref","unstructured":"Bilge L, Han Y, Dell\u2019Amico M (2017) RiskTeller: predicting the risk of cyber incidents. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security. ACM","DOI":"10.1145\/3133956.3134022"},{"issue":"3","key":"603_CR9","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola V, Banerjee A, Kumar V (2009) Anomaly detection: a survey. ACM Comput Surv (CSUR) 41(3):15","journal-title":"ACM Comput Surv (CSUR)"},{"key":"603_CR10","doi-asserted-by":"crossref","unstructured":"Chen H (2008) Sentiment and affect analysis of dark web forums: measuring radicalization on the internet. In: IEEE international conference on intelligence and security informatics, ISI 2008. IEEE","DOI":"10.1109\/ISI.2008.4565038"},{"key":"603_CR11","doi-asserted-by":"crossref","unstructured":"Chierichetti F, Lattanzi S, Panconesi A (2010) Rumour spreading and graph conductance. In: Proceedings of the twenty-first annual ACM-SIAM symposium on discrete algorithms. Society for Industrial and Applied Mathematics","DOI":"10.1137\/1.9781611973075.135"},{"key":"603_CR12","doi-asserted-by":"crossref","unstructured":"Colbaugh R, Glass K (2011) Proactive defense for evolving cyber threats. In: 2011 IEEE international conference on intelligence and security informatics (ISI). IEEE","DOI":"10.1109\/ISI.2011.5984062"},{"key":"603_CR13","unstructured":"Danezis G, Mittal P (2009) SybilInfer: detecting sybil nodes using social networks. In: NDSS, pp 1\u201315"},{"key":"603_CR14","doi-asserted-by":"crossref","unstructured":"Edkrantz M, Truv\u00e9 S, Said A (2015) Predicting vulnerability exploits in the wild. In: 2015 IEEE 2nd international conference on cyber security and cloud computing (CSCloud). IEEE","DOI":"10.1109\/CSCloud.2015.56"},{"issue":"7","key":"603_CR15","doi-asserted-by":"publisher","first-page":"96","DOI":"10.1145\/2818717","volume":"59","author":"E Ferrara","year":"2016","unstructured":"Ferrara E, Varol O, Davis C, Menczer F, Flammini A (2016) The rise of social bots. Commun ACM 59(7):96\u2013104","journal-title":"Commun ACM"},{"key":"603_CR16","unstructured":"Goyal P et al (2018) Discovering signals from web sources to predict cyber attacks. arXiv preprint arXiv:1806.03342"},{"key":"603_CR17","doi-asserted-by":"crossref","unstructured":"Grier C, Ballard L, Caballero J, Chachra N, Dietrich CJ, Levchenko K, Mavrommatis P et al (2012) Manufacturing compromise: the emergence of exploit-as-a-service. In: Proceedings of the 2012 ACM conference on computer and communications security. ACM, pp 821\u2013832","DOI":"10.1145\/2382196.2382283"},{"key":"603_CR18","doi-asserted-by":"crossref","unstructured":"Haslebacher A, Onaolapo J, Stringhini G (2017) All your cards are belong to us: understanding online carding forums. In: 2017 APWG symposium on electronic crime research (eCrime). IEEE","DOI":"10.1109\/ECRIME.2017.7945053"},{"key":"603_CR19","doi-asserted-by":"publisher","first-page":"33","DOI":"10.1007\/978-1-4419-6967-5_3","volume-title":"Economics of information security and privacy","author":"C Herley","year":"2010","unstructured":"Herley C, Flor\u00eancio D (2010) Nobody sells gold for the price of silver: dishonesty, uncertainty and the underground economy. In: Moore T, Pym D, Ioannidis C (eds) Economics of information security and privacy. Springer, Boston, pp 33\u201353"},{"issue":"2","key":"603_CR20","doi-asserted-by":"publisher","first-page":"85","DOI":"10.1023\/B:AIRE.0000045502.10941.a9","volume":"22","author":"V Hodge","year":"2004","unstructured":"Hodge V, Austin J (2004) A survey of outlier detection methodologies. Artif Intell Rev 22(2):85\u2013126","journal-title":"Artif Intell Rev"},{"key":"603_CR21","first-page":"617","volume-title":"Advances in neural information processing systems","author":"L Huang","year":"2007","unstructured":"Huang L, Nguyen X, Garofalakis M, Jordan MI, Joseph A, Taft N (2007) In-network PCA and anomaly detection. In: Mozer MC, Jordan MI, Petsche T (eds) Advances in neural information processing systems. MIT Press, Cambridge, pp 617\u2013624"},{"key":"603_CR22","doi-asserted-by":"crossref","unstructured":"Khandpur RP et al (2017) Crowdsourcing cybersecurity: cyber attack detection using social media. In: Proceedings of the 2017 ACM on conference on information and knowledge management. ACM","DOI":"10.1145\/3132847.3132866"},{"key":"603_CR23","doi-asserted-by":"crossref","unstructured":"Kotenko I, Stepashkin M (2005) Analyzing vulnerabilities and measuring security level at design and exploitation stages of computer network life cycle. In: International workshop on mathematical methods, models, and architectures for computer network security. Springer, Berlin","DOI":"10.1007\/11560326_24"},{"key":"603_CR24","doi-asserted-by":"crossref","unstructured":"Lakhina A, Crovella M, Diot C (2004) Diagnosing network-wide traffic anomalies. In: ACM SIGCOMM computer communication review, vol 34, no 4, pp 219\u2013230. ACM","DOI":"10.1145\/1030194.1015492"},{"issue":"2","key":"603_CR25","doi-asserted-by":"publisher","first-page":"66","DOI":"10.1145\/1964897.1964917","volume":"12","author":"G L\u2019huillier","year":"2011","unstructured":"L\u2019huillier G, Alvarez H, R\u00edos SA, Aguilera F (2011) Topic-based social network analysis for virtual communities of interests in the dark web. ACM SIGKDD Explor Newsl 12(2):66\u201373","journal-title":"ACM SIGKDD Explor Newsl"},{"key":"603_CR26","doi-asserted-by":"crossref","unstructured":"Liu Y et al (2015) Predicting cyber security incidents using feature-based characterization of network-level malicious activities. In: Proceedings of the 2015 ACM international workshop on international workshop on security and privacy analytics. ACM","DOI":"10.1145\/2713579.2713582"},{"key":"603_CR27","unstructured":"Liu Y, Sarabi A, Zhang J, Naghizadeh P, Karir M, Bailey M, Liu M (2015) Cloudy with a chance of breach: forecasting cyber security incidents. In: USENIX security symposium, pp 1009\u20131024"},{"issue":"1","key":"603_CR28","doi-asserted-by":"publisher","first-page":"53","DOI":"10.1111\/j.1467-9868.2007.00627.x","volume":"70","author":"L Meier","year":"2008","unstructured":"Meier L, Van De Geer S, B\u00fchlmann P (2008) The group lasso for logistic regression. J R Stat Soc Ser B (Stat Methodol) 70(1):53\u201371","journal-title":"J R Stat Soc Ser B (Stat Methodol)"},{"key":"603_CR29","unstructured":"Miller C (2007) The legitimate vulnerability market: inside the secretive world of 0-day exploit sales. In: Sixth workshop on the economics of information security"},{"key":"603_CR30","doi-asserted-by":"crossref","unstructured":"Nagaraja S (2007) Anonymity in the wild: mixes on unstructured networks. In: International workshop on privacy enhancing technologies. Springer, Berlin, pp 254\u2013271","DOI":"10.1007\/978-3-540-75551-7_16"},{"key":"603_CR31","unstructured":"Nagaraja S, Mittal P, Hong C-Y, Caesar M, Borisov N (2010) BotGrep: finding P2P bots with structured graph analysis. In: USENIX security symposium, vol 10, pp 95\u2013110"},{"key":"603_CR32","unstructured":"Okutan A, Yang SJ, McConky K (2018) Forecasting cyber attacks with imbalanced data sets and different time granularities. arXiv preprint arXiv:1803.09560"},{"key":"603_CR33","volume-title":"Security in computing","author":"CP Pfleeger","year":"2002","unstructured":"Pfleeger CP, Pfleeger SL (2002) Security in computing. Prentice Hall Professional Technical Reference, Upper Saddle River"},{"key":"603_CR34","unstructured":"Phillips E et al (2015) Extracting social structure from darkweb forums. In: IARIA fifth international conference on social media technologies, communication, and informatics (SOTICS), Barcelona, Spain 2015, pp 97\u2013102"},{"issue":"2","key":"603_CR35","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/MCSE.2006.30","volume":"8","author":"D Randall","year":"2006","unstructured":"Randall D (2006) Rapidly mixing Markov chains with applications in computer science and physics. Comput Sci Eng 8(2):30\u201341","journal-title":"Comput Sci Eng"},{"key":"603_CR36","unstructured":"Rek\u0161\u0146a T (2017) Complex network analysis of darknet black market forum structure. MS thesis"},{"key":"603_CR37","doi-asserted-by":"crossref","unstructured":"Ribeiro MT, Singh S, Guestrin C (2016) Why should I trust you? Explaining the predictions of any classifier. In: Proceedings of the 22nd ACM SIGKDD international conference on knowledge discovery and data mining. ACM, pp 1135\u20131144","DOI":"10.1145\/2939672.2939778"},{"key":"603_CR38","unstructured":"Sabottke C, Suciu O, Dumitras T (2015) Vulnerability disclosure in the age of social media: exploiting twitter for predicting real-world exploits. In: USENIX security symposium"},{"key":"603_CR39","doi-asserted-by":"crossref","unstructured":"Samtani S, Chinn R, Chen H (2015) Exploring hacker assets in underground forums. In: 2015 IEEE international conference on intelligence and security informatics (ISI). IEEE","DOI":"10.1109\/ISI.2015.7165935"},{"key":"603_CR40","doi-asserted-by":"crossref","unstructured":"Sapienza A, Ernala SK, Bessi A, Lerman K, Ferrara E (2018) DISCOVER: mining online chatter for emerging cyber threats. In: Companion of the the web conference 2018 on the web conference 2018. International world wide web conferences steering committee, pp 983\u2013990","DOI":"10.1145\/3184558.3191528"},{"key":"603_CR41","unstructured":"Sarkar S et al (2018) Predicting enterprise cyber incidents using social network analysis on the darkweb hacker forums. arXiv preprint arXiv:1811.06537"},{"key":"603_CR42","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1007\/978-3-319-32699-3_11","volume-title":"Cyber deception","author":"J Shakarian","year":"2016","unstructured":"Shakarian J, Gunn AT, Shakarian P (2016) Exploring malicious hacker forums. In: Jajodia S, Subrahmanian V, Swarup V, Wang C (eds) Cyber deception. Springer, Cham, pp 259\u2013282"},{"key":"603_CR43","unstructured":"Shlens J (2014) A tutorial on principal component analysis. arXiv preprint arXiv:1404.1100"},{"issue":"1","key":"603_CR44","doi-asserted-by":"publisher","first-page":"60","DOI":"10.1109\/MIC.2012.61","volume":"17","author":"AK Sood","year":"2013","unstructured":"Sood AK, Bansal R, Enbody RJ (2013) Cybercrime: dissecting the state of underground enterprise. IEEE Internet Comput 17(1):60\u201368","journal-title":"IEEE Internet Comput"},{"key":"603_CR45","doi-asserted-by":"crossref","unstructured":"Soule A, Salamatian K, Taft N (2005) Combining filtering and statistical methods for anomaly detection. In: Proceedings of the 5th ACM SIGCOMM conference on internet measurement. USENIX Association","DOI":"10.1145\/1330107.1330147"},{"key":"603_CR46","doi-asserted-by":"crossref","unstructured":"Tang J, Musolesi M, Mascolo C, Latora V (2009) Temporal distance metrics for social network analysis. In: Proceedings of the 2nd ACM workshop on Online social networks. ACM, pp 31\u201336","DOI":"10.1145\/1592665.1592674"},{"key":"603_CR47","doi-asserted-by":"crossref","unstructured":"Thonnard O et al (2015) Are you at risk? Profiling organizations and individuals subject to targeted attacks. In: International conference on financial cryptography and data security. Springer, Berlin","DOI":"10.1007\/978-3-662-47854-7_2"},{"issue":"4","key":"603_CR48","doi-asserted-by":"publisher","first-page":"415","DOI":"10.1080\/00401706.2015.1079245","volume":"58","author":"R Tibshirani","year":"2016","unstructured":"Tibshirani R, Suo X (2016) An ordered lasso and sparse time-lagged regression. Technometrics 58(4):415\u2013423","journal-title":"Technometrics"},{"key":"603_CR49","unstructured":"Veeramachaneni K, Arnaldo I, Korrapati V, Bassias C, Li K (2016) AI$${\\hat{2}}$$: training a big data machine to defend. In 2016 IEEE 2nd international conference on big data security on cloud (BigDataSecurity), IEEE international conference on high performance and smart computing (HPSC), and IEEE International conference on intelligent data and security (IDS). IEEE, pp 49\u201354"},{"issue":"10","key":"603_CR50","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1145\/1400181.1400198","volume":"51","author":"J Xu","year":"2008","unstructured":"Xu J, Chen H (2008) The topology of dark networks. Commun ACM 51(10):58\u201365","journal-title":"Commun ACM"},{"key":"603_CR51","doi-asserted-by":"crossref","unstructured":"Xu T, Sun J, Bi J (2015) Longitudinal lasso: jointly learning features and temporal contingency for outcome prediction. In: Proceedings of the 21th ACM SIGKDD international conference on knowledge discovery and data mining. ACM","DOI":"10.1145\/2783258.2783403"},{"key":"603_CR52","doi-asserted-by":"publisher","first-page":"30750","DOI":"10.1038\/srep30750","volume":"6","author":"Z Yang","year":"2016","unstructured":"Yang Z, Algesheimer R, Tessone CJ (2016) A comparative analysis of community detection algorithms on artificial networks. Sci Rep 6:30750","journal-title":"Sci Rep"},{"key":"603_CR53","doi-asserted-by":"crossref","unstructured":"Yip M, Shadbolt N, Webber C (2013) Why forums? An empirical analysis into the facilitating factors of carding forums. In: Proceedings of the 5th annual ACM web science conference. ACM","DOI":"10.1145\/2464464.2464524"},{"key":"603_CR54","doi-asserted-by":"crossref","unstructured":"Zhang D, Liu J, Shen D (2012) Temporally-constrained group sparse learning for longitudinal data analysis. In: International conference on medical image computing and computer-assisted intervention. Springer, Berlin","DOI":"10.1007\/978-3-642-33454-2_33"}],"container-title":["Social Network Analysis and Mining"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13278-019-0603-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/article\/10.1007\/s13278-019-0603-9\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/s13278-019-0603-9.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,1,23]],"date-time":"2021-01-23T20:50:35Z","timestamp":1611435035000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/s13278-019-0603-9"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019,9,30]]},"references-count":54,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2019,12]]}},"alternative-id":["603"],"URL":"https:\/\/doi.org\/10.1007\/s13278-019-0603-9","relation":{},"ISSN":["1869-5450","1869-5469"],"issn-type":[{"value":"1869-5450","type":"print"},{"value":"1869-5469","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019,9,30]]},"assertion":[{"value":"21 December 2018","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"6 August 2019","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"19 September 2019","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"30 September 2019","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}],"article-number":"57"}}