{"about":{"site":"https://codewithpapers.app","non_affiliation":"Code with Papers and Syntology are not affiliated with, endorsed by, or sponsored by Papers with Code, Meta, or the pwc-archive mirror.","licence":"CC BY-SA 4.0","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","attribution":"https://codewithpapers.app/attribution","modified":"archive material modified by Syntology; see the attribution page"},"url":"/paper/cyberthreat-detection-from-twitter-using-deep","title":"Cyberthreat Detection from Twitter using Deep Neural Networks","arxiv_id":"1904.01127","date":"2019-04-01","proceeding":null,"authors":["Nuno Dionísio","Fernando Alves","Pedro M. Ferreira","Alysson Bessani"],"abstract":"To be prepared against cyberattacks, most organizations resort to security\ninformation and event management systems to monitor their infrastructures.\nThese systems depend on the timeliness and relevance of the latest updates,\npatches and threats provided by cyberthreat intelligence feeds. Open source\nintelligence platforms, namely social media networks such as Twitter, are\ncapable of aggregating a vast amount of cybersecurity-related sources. To\nprocess such information streams, we require scalable and efficient tools\ncapable of identifying and summarizing relevant information for specified\nassets. This paper presents the processing pipeline of a novel tool that uses\ndeep neural networks to process cybersecurity information received from\nTwitter. A convolutional neural network identifies tweets containing\nsecurity-related information relevant to assets in an IT infrastructure. Then,\na bidirectional long short-term memory network extracts named entities from\nthese tweets to form a security alert or to fill an indicator of compromise.\nThe proposed pipeline achieves an average 94% true positive rate and 91% true\nnegative rate for the classification task and an average F1-score of 92% for\nthe named entity recognition task, across three case study infrastructures.","url_abs":"http://arxiv.org/abs/1904.01127v1","url_pdf":"http://arxiv.org/pdf/1904.01127v1.pdf","source":{"archive":"pwc-archive (Hugging Face), CC BY-SA 4.0","snapshot":"2025-07-28","licence_url":"https://creativecommons.org/licenses/by-sa/4.0/legalcode","row_kind":"abstracts"},"code_links":[{"paper_slug":"cyberthreat-detection-from-twitter-using-deep","repo_url":"https://github.com/ndionysus/twitter-cyberthreat-detection","is_official":1,"mentioned_in_paper":1,"mentioned_in_github":0,"framework":"pytorch","reach":null}],"tasks":[{"task_slug":"management","task_name":"Management"},{"task_slug":"named-entity-recognition-1","task_name":"Named Entity Recognition"},{"task_slug":"named-entity-recognition-ner","task_name":"Named Entity Recognition (NER)"},{"task_slug":"named-entity-recognition","task_name":"named-entity-recognition"}],"methods":[{"method_slug":"memory-network","method_name":"Memory Network"}],"datasets_introduced":[{"slug":"twitter-cyberthreat-detection-dataset","name":"Twitter Cyberthreat Detection Dataset","full_name":""}],"methods_introduced":[],"results":[],"syntology":{"atlas_url":null,"mcp":null,"developers":"https://syntology.ai/developers"},"arxiv_metadata":null,"syntology_extracted_results":null}