内容天网项目skynet courier detection via machine learning_第1页
内容天网项目skynet courier detection via machine learning_第2页
内容天网项目skynet courier detection via machine learning_第3页
内容天网项目skynet courier detection via machine learning_第4页
内容天网项目skynet courier detection via machine learning_第5页
已阅读5页,还剩15页未读 继续免费阅读

下载本文档

版权说明:本文档由用户提供并上传,收益归属内容提供方,若内容存在侵权,请进行举报或认领

文档简介

1、TOP SECRET/COMINT/REL TO USA, FVEYGiven a handful of courier selectors, can we find othersthat “behave similarly” by analyzingmetadata?Its worth noting that:we are looking for different people using phones in similar wayswithout using any call chaining techniques from known selectorsby scanning thro

2、ugh all selectors seen in Pakistan that have not left Af/Pak (55M)TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYThis presentation describes our search for AQSL couriers using behavioral profilingBehavioral Feature ExtractionCross Validation Experiment on AQSL CouriersPreliminar

3、y SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYCounting unique UCELLIDs shows that couriers travel more often than typical Pakistani selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYBy examining multiple features at once, we can see s

4、ome indicative behaviors of our courier selectorsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYNow, well describe a cross validation experiment on the AQSL selectors that we were providedCross Validation Experiment on AQSL CouriersTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/CO

5、MINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validation Experiment7 MSISDN/IMSI pairsHold each pair out and score them when training the centroid on the restAssume that random draws of Pakistani selectors are nontarge

6、tsHow well do we do?TOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYOur initial detector uses the centroid of the AQSL couriers to “find other selectors like these”AQSL Cross-Validat ExperimentInitial experiments showed EER in 10-20% rangeHere, performance much worse again these

7、nontargets:Seen in PakistanNot seen outside Af/PakNot FVEY selectoTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYStatistical algorithms are able to find the couriers at very low false alarm rates, if were allowed to miss half of themRandom Forest Classifierbetter7 MSISDN/IMSI pa

8、irsHold each pair out and then try to find them af learning how to disting remaining couriers fro other Pakistanis(using 100k random selectors here)Assume that random draws of Pakistani selectors are nontarge0.18% False Alarm Ra 50% Miss RateTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO

9、 USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest:0.18% false alarm rate at 50% miss rate7x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k T

10、est Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneRandomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory SelectorsTOP

11、 SECRET/COMINT/REL TO USA, FVEYTo get more training data we scraped selectors from S2I11 Anchory reports containing keyword “courier”Anchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mobile numbers and kept selectors with “interesting” travel patterns seen in Sma

12、rtTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYAdding selectors from Anchory reports to the training data reduced the false alarm rates even furtherAnchory SelectorsSearched for reports containing “S2I11” AND “courier”Filtered out non-mob numbers and kept selectors with

13、 “interesting” travel patterns seen in SmartTrackerTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYWeve been experimenting with several error metrics on both small and large test setsRandom Forest trained on Known Couriers + Anchory Selectors:0.008% false alarm rate at 50% miss r

14、ate46x improvement over random performance when evaluating its tasked precision at 100TOP SECRET/COMINT/REL TO USA, FVEYTraining DataClassifierFeatures100k Test Selectors55M Test SelectorsFalse Alarm Rate at 50% Miss RateMean Reciprocal RankTasked Selectors in Top 500Tasked Selectors in Top 100NoneR

15、andomNone50%1/23k (simulated)0.64(active/Pak)0.13(active/Pak)Known CouriersCentroidAll20%1/18kOutgoing43%1/27kRandom Forest0.18%1/9.951+ Anchory Selectors0.008%1/14216TOP SECRET/COMINT/REL TO USA, FVEYNow, well investigate some findings after running these classifiers on +55M Pakistani selectors via

16、 MapReducePreliminary SIGINT FindingsTOP SECRET/COMINT/REL TO USA, FVEYTOP SECRET/COMINT/REL TO USA, FVEYPreliminary results indicate that were on the right track, but much remainsCross Validation Experiment:Random Forest classifier operating at 0.18% false alarm rate at 50% missEnhancing training data with Anchory selectors reduced that to 0.008%Mean Reciprocal Rank is 1/10Prelim

温馨提示

  • 1. 本站所有资源如无特殊说明,都需要本地电脑安装OFFICE2007和PDF阅读器。图纸软件为CAD,CAXA,PROE,UG,SolidWorks等.压缩文件请下载最新的WinRAR软件解压。
  • 2. 本站的文档不包含任何第三方提供的附件图纸等,如果需要附件,请联系上传者。文件的所有权益归上传用户所有。
  • 3. 本站RAR压缩包中若带图纸,网页内容里面会有图纸预览,若没有图纸预览就没有图纸。
  • 4. 未经权益所有人同意不得将文件中的内容挪作商业或盈利用途。
  • 5. 人人文库网仅提供信息存储空间,仅对用户上传内容的表现方式做保护处理,对用户上传分享的文档内容本身不做任何修改或编辑,并不能对任何下载内容负责。
  • 6. 下载文件中如有侵权或不适当内容,请与我们联系,我们立即纠正。
  • 7. 本站不保证下载资源的准确性、安全性和完整性, 同时也不承担用户因使用这些下载资源对自己和他人造成任何形式的伤害或损失。

评论

0/150

提交评论