版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领
文档简介
1、TOP SECRET/COMINT/REL TO USA, FVEYGiven a handful of courier selectors, can we find othersthat “behave similarly” by analyzingmetadata?Its worth noting that:we are looking for different people using phones in similar wayswithout using any call chaining techniques from known selectorsby scanning thro
2、ugh all selectors seen in Pakistan that have not left Af/Pak (55M)TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYThis presentation describes our search for AQSL couriers using behavioral profilingBehavioral Feature ExtractionCross Validation Experiment on AQSL CouriersPreliminar
3、y SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYCounting unique UCELLIDs shows that couriers travel more often than typical Pakistani selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYBy examining multiple features at once, we can see s
4、ome indicative behaviors of our courier selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYNow, well describe a cross validation experiment on the AQSL selectors that we were providedCross Validation Experiment on AQSL CouriersTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/CO
5、MINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validation Experiment7 MSISDN/IMSI pairsHold each pair out and score them when training the centroid on the restAssume that random draws of Pakistani selectors are nontarge
6、tsHow well do we do?TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validat ExperimentInitial experiments showed EER in 10-20% rangeHere, performance much worse again these
7、nontargets:Seen in PakistanNot seen outside Af/PakNot FVEY selectoTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYStatistical algorithms are able to find the couriers at very low false alarm rates, if were allowed to miss half of themRandom Forest Classifierbetter7 MSISDN/IMSI pa
8、irsHold each pair out and then try to find them af learning how to disting remaining couriers fro other Pakistanis(using 100k random selectors here)Assume that random draws of Pakistani selectors are nontarge0.18% False Alarm Ra 50% Miss RateTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO
9、 USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest:0.18% false alarm rate at 50% miss rate7x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k T
10、est Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneRandomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory SelectorsTOP
11、 SECRET/COMINT/REL TO USA, FVEYTo get more training data we scraped selectors from S2I11 Anchory reports containing keyword “courier”Anchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mobile numbers and kept selectors with “interesting” travel patterns seen in Sma
12、rtTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYAdding selectors from Anchory reports to the training data reduced the false alarm rates even furtherAnchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mob numbers and kept selectors with
13、 “interesting” travel patterns seen in SmartTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest trained on Known Couriers + Anchory Selectors:0.008% false alarm rate at 50% miss r
14、ate46x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k Test Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneR
15、andomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory Selectors0.008%1/14216TOP SECRET/COMINT/REL TO USA, FVEYNow, well investigate some findings after running these classifiers on +55M Pakistani selectors via
16、 MapReducePreliminary SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYPreliminary results indicate that were on the right track, but much remainsCross Validation Experiment:Random Forest classifier operating at 0.18% false alarm rate at 50% missEnhancing training data with Anchory selectors reduced that to 0.008%Mean Reciprocal Rank is 1/10Prelim
温馨提示
- 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
- 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
- 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
- 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
- 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
- 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
- 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。
最新文档
- 2026年轻医美融合项目评估报告
- 2025年丽水市人民法院法官入额笔试题及答案
- 黄环评课件教学课件
- 燃气用户服务改进方案
- 施工现场塔吊管理方案
- 数智化时代大学生就业能力的提升
- 2026届北京市石景山区高三数学第一学期期末考试试题含解析
- 2026年北京广播电视台校园招聘备考题库及参考答案详解
- 2026年巴中市南江县公安局公开招聘警务辅助人员64人备考题库含答案详解
- 2026年中山投资控股集团下属中山温泉酒店康养集团有限公司招聘12人备考题库带答案详解
- 非职业一氧化碳中毒课件
- 保定市道路野生地被植物资源的调查与分析:物种多样性与生态功能的探究
- smt车间安全操作规程
- JJF 2254-2025戥秤校准规范
- 强制医疗活动方案
- DB42T 850-2012 湖北省公路工程复杂桥梁质量鉴定规范
- 月经不调的中医护理常规
- 2024-2025学年江苏省南通市如东县、通州区、启东市、崇川区高一上学期期末数学试题(解析版)
- 瑞幸ai面试题库大全及答案
- 现代密码学(第4版)-习题参考答案
- 缝纫车间主管年终总结
评论
0/150
提交评论