版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、TOP SECRET/COMINT/REL TO USA, FVEYGiven a handful of courier selectors, can we find othersthat “behave similarly” by analyzingmetadata?Its worth noting that:we are looking for different people using phones in similar wayswithout using any call chaining techniques from known selectorsby scanning thro
2、ugh all selectors seen in Pakistan that have not left Af/Pak (55M)TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYThis presentation describes our search for AQSL couriers using behavioral profilingBehavioral Feature ExtractionCross Validation Experiment on AQSL CouriersPreliminar
3、y SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYCounting unique UCELLIDs shows that couriers travel more often than typical Pakistani selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYBy examining multiple features at once, we can see s
4、ome indicative behaviors of our courier selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYNow, well describe a cross validation experiment on the AQSL selectors that we were providedCross Validation Experiment on AQSL CouriersTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/CO
5、MINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validation Experiment7 MSISDN/IMSI pairsHold each pair out and score them when training the centroid on the restAssume that random draws of Pakistani selectors are nontarge
6、tsHow well do we do?TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validat ExperimentInitial experiments showed EER in 10-20% rangeHere, performance much worse again these
7、nontargets:Seen in PakistanNot seen outside Af/PakNot FVEY selectoTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYStatistical algorithms are able to find the couriers at very low false alarm rates, if were allowed to miss half of themRandom Forest Classifierbetter7 MSISDN/IMSI pa
8、irsHold each pair out and then try to find them af learning how to disting remaining couriers fro other Pakistanis(using 100k random selectors here)Assume that random draws of Pakistani selectors are nontarge0.18% False Alarm Ra 50% Miss RateTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO
9、 USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest:0.18% false alarm rate at 50% miss rate7x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k T
10、est Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneRandomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory SelectorsTOP
11、 SECRET/COMINT/REL TO USA, FVEYTo get more training data we scraped selectors from S2I11 Anchory reports containing keyword “courier”Anchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mobile numbers and kept selectors with “interesting” travel patterns seen in Sma
12、rtTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYAdding selectors from Anchory reports to the training data reduced the false alarm rates even furtherAnchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mob numbers and kept selectors with
13、 “interesting” travel patterns seen in SmartTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest trained on Known Couriers + Anchory Selectors:0.008% false alarm rate at 50% miss r
14、ate46x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k Test Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneR
15、andomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory Selectors0.008%1/14216TOP SECRET/COMINT/REL TO USA, FVEYNow, well investigate some findings after running these classifiers on +55M Pakistani selectors via
16、 MapReducePreliminary SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYPreliminary results indicate that were on the right track, but much remainsCross Validation Experiment:Random Forest classifier operating at 0.18% false alarm rate at 50% missEnhancing training data with Anchory selectors reduced that to 0.008%Mean Reciprocal Rank is 1/10Prelim
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 《GBT 9969-2008工业产品使用说明书 总则》专题研究报告:面向未来的产品信息沟通战略与合规实践深度
- 《GB-T 26179-2010光源的光谱辐射度测量》专题研究报告
- 《GBT 21611-2008 危险品 易燃固体自燃试验方法》专题研究报告
- 《GBT 2423.21-2008电工电子产品环境试验 第2部分:试验方法 试验M:低气压》专题研究报告
- 《GBT 22231-2008 颗粒物粒度分布纤维长度和直径分布》专题研究报告-深度与前瞻应用
- 道路安全培训活动方案课件
- 2026年鲁教版九年级语文上册期末综合考核试题及答案
- 2025脓胸:全面解析与治疗指南课件
- 达内网络安全培训教程课件
- 车险培训课件2017
- 非职业一氧化碳中毒课件
- 保定市道路野生地被植物资源的调查与分析:物种多样性与生态功能的探究
- smt车间安全操作规程
- JJF 2254-2025戥秤校准规范
- 强制医疗活动方案
- DB42T 850-2012 湖北省公路工程复杂桥梁质量鉴定规范
- 月经不调的中医护理常规
- 2024-2025学年江苏省南通市如东县、通州区、启东市、崇川区高一上学期期末数学试题(解析版)
- 瑞幸ai面试题库大全及答案
- 现代密码学(第4版)-习题参考答案
- 缝纫车间主管年终总结
评论
0/150
提交评论