In [1]:
import pandas as pd
import numpy as np
import re
import json
import matplotlib.pyplot as plt
import glob, os, csv

from pprint import pprint
from langdetect import detect

import gensim
from gensim.utils import simple_preprocess
from gensim import corpora, models
from gensim.models import CoherenceModel

from bs4 import BeautifulSoup

import ast
from collections import Counter
from operator import add

from nltk.stem import WordNetLemmatizer
from nltk.stem import PorterStemmer

from sklearn.model_selection import train_test_split
import math
from sklearn.naive_bayes import MultinomialNB
from sklearn.feature_extraction import DictVectorizer
from sklearn import preprocessing
from sklearn.metrics import accuracy_score
from sklearn.naive_bayes import GaussianNB
from sklearn.feature_extraction.text import TfidfVectorizer
from sklearn.feature_extraction.text import CountVectorizer
from sklearn.feature_extraction.text import TfidfTransformer

from sklearn.linear_model import LogisticRegression
from sklearn.ensemble import RandomForestClassifier
from sklearn.svm import LinearSVC
from sklearn.svm import SVC
from sklearn.neighbors import KNeighborsClassifier
from sklearn.model_selection import cross_val_score
from sklearn.model_selection import GridSearchCV
from sklearn.ensemble import VotingClassifier, StackingClassifier, AdaBoostClassifier
import seaborn as sns
from sklearn.metrics import classification_report
from xgboost import XGBClassifier
from sklearn.metrics import confusion_matrix

import nltk
nltk.download('stopwords')
nltk.download('wordnet')
nltk.download('punkt')
nltk.download('averaged_perceptron_tagger')
nltk.download('words')
from nltk.stem import WordNetLemmatizer
from nltk.stem import PorterStemmer
from nltk.corpus import stopwords
from nltk.corpus import words
from nltk.corpus import wordnet
stop_words = stopwords.words('english')
stop_words.extend(['from', 'subject', 're', 'edu', 'use', 'http', 'javascript'])

pd.options.mode.chained_assignment = None

[nltk_data] Downloading package stopwords to /home/justin/nltk_data...
[nltk_data]   Package stopwords is already up-to-date!
[nltk_data] Downloading package wordnet to /home/justin/nltk_data...
[nltk_data]   Package wordnet is already up-to-date!
[nltk_data] Downloading package punkt to /home/justin/nltk_data...
[nltk_data]   Package punkt is already up-to-date!
[nltk_data] Downloading package averaged_perceptron_tagger to
[nltk_data]     /home/justin/nltk_data...
[nltk_data]   Package averaged_perceptron_tagger is already up-to-
[nltk_data]       date!
[nltk_data] Downloading package words to /home/justin/nltk_data...
[nltk_data]   Package words is already up-to-date!


In [2]:
# Preprocessing

In [3]:
def language_detect(ls):
    text = ' '.join(ls)
    if text == '':
        result = 'na'
    else:
        result = detect(text)
    return result

In [4]:
stemmer = PorterStemmer()
def lemmatize_stemming(text):
    return stemmer.stem(WordNetLemmatizer().lemmatize(text))

def preprocess(sentences):
    result = []
    
    for sent in sentences:
        lemmas = []
        # tokenize
        tokens = gensim.utils.simple_preprocess(sent)
        for token in tokens:
            lemma = lemmatize_stemming(token)
            # remove stopwords
            if lemma not in stop_words:
                lemmas.append(lemma)
#         # POS tagging
#         nltk_tagged = nltk.pos_tag(lemmas)
#         for word, tag in nltk_tagged:
#             # only keep nouns
#             if tag.startswith('N'):
#                 result.append(word)
        # Without POS tagging
        result += lemmas
    return result

In [5]:
# Preprocess texts in the list
def preprocess_texts(ls):
    parsed_ls = []
    if len(ls) > 0:
        for i in range(len(ls)):
            txt = str(ls[i])
            # Only include non-empty sentences with length > 1
            if len(txt) > 1 and txt != ' ':
                txt = remove_sp_char(txt)
                txt = remove_links(txt)
                txt = remove_email(txt)
                txt = remove_single_char(txt)
                txt = remove_multi_spaces(txt)
                txt = txt.strip()
                if len(txt) > 1:
                    txt = remove_noneng(txt)
                    if txt != '':
                        parsed_ls.append(txt)
        return parsed_ls
    else:
        return []

In [6]:
def remove_multi_spaces(text):
    return re.sub(' +', ' ', text)

In [7]:
def remove_single_char(text):
    return re.sub('(^| ).( |$)', '', text)

In [8]:
# Remove special characters in the text
def remove_sp_char(text):
    return re.sub('[^0-9a-zA-Z]+', ' ', text)

In [9]:
# Remove URL links in the text
def remove_links(text):
    text = re.sub('(?:https?://)?(?:www)?(\S*?\.onion)\b', '', text)
    text = re.sub('(http|ftp|https)://([\w_-]+(?:(?:\.[\w_-]+)+))([\w.,@?^=%&:/~+#-]*[\w@?^=%&/~+#-])?', '', text)
    return text

In [10]:
# Remove email addressed in the text
def remove_email(text):
    return re.sub('\S*@\S*\s?', '', text)

In [11]:
# Replace non-english sentences with ''
def remove_noneng(text):
    try:
        lang = detect(text)
        if lang != 'en':
            return ''
        else:
            return text
    except:
        return ''

In [12]:
def get_domain(url):
    url = str(url)
    result = re.findall('^(?:https?\:\/\/)?[\w\-\.]+\.onion', url)
    if len(result) < 1:
        return 'NA'
    else:
        return result[0]

In [13]:
## Categories ##
# 1: Market: Drug, gun, 
# 2: Counterfeit: counterfeit credit cards, money, ID
# 3: Services: Hosting service, forum, email, pastebin, file-sharing
# 4: Security: Security-related information, tutorials or services, leaked data
# 5: Porn: Hosting pornographic material
# 6: Cryptocurrency
# 7: NoAccess: Login, Down, Empty
# 8: Other: Cannot be classified in any other category (e.g. personal blog)

In [14]:
# Dictionary of conversion of categories
conversion_dict = {
    'Art': 'Other',
    'Casino': 'Services',
    'Counterfeit Credit-Cards': 'Counterfeit',
    'Counterfeit Money': 'Counterfeit',
    'Counterfeit Personal-Identification': 'Counterfeit',
    'Cryptocurrency': 'Cryptocurrency',
    'Cryptolocker': 'Security',
    'Down': 'NoAccess',
    'Drugs': 'Market',
    'Empty': 'NoAccess',
    'Forum': 'Services',
    'Hacking': 'Security',
    'Hosting': 'Services',
    'Leaked-Data': 'Services',
    'Library': 'Other',
    'Locked': 'NoAccess',
    'Marketplace': 'Market',
#     'Onion Directory/Wiki': ['directory', 'dir', 'wiki'],
    'Personal': 'Other',
    'Politics': 'Other',
    'Porno': 'Porn',
    'Religion': 'Other',
    'Services': 'Services',
    'Social-Network': 'Services',
    'Violence': 'Market',
    'Other': 'Other'
}

In [15]:
# Read input data
df_combined = pd.read_csv('../data/dataset-combined-jan-feb.csv')
df_combined['body_text'] = df_combined['body_text'].apply(ast.literal_eval)

df_combined

Unnamed: 0,domain_url,title,body_text
0,22oxht5ep3hvyboc.onion,Onion Dir - Adult,[Baby Bitch CP is an unique new portal. We are...
1,22pp2nrnjcmtlzja.onion,PayPal Plaza | The Tor Marketplace For Buying ...,"[$47.02, Order Now ($11.05), $75.09, What You ..."
2,2464b3fu462tx2en.onion,CHILD PORN CENTER,"[6, CHILD PORN CENTER, http://x5y2b4xjf46idxzp..."
3,24adsavjl3u6tylr.onion,"CP Video HD 2021, PTHC, Loli, child porn, pret...","[70 Gb, Video HD 4K, 400 Gb, CC, © Copyright 2..."
4,2ajtkan56n6aiyl6.onion,Hard Porn Forum,"[Category, 36, Email, value 01, 268, 78, video..."
...,...,...,...
12551,rkvwooasau2goqeamkqbade4yv2hnt6dc4ol5kgnaaoihd...,Moneys spider - financial pyramid,"[Create account, Email address, No wallet? get..."
12552,e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsy...,BenTasker.co.uk - The Home of Ben Tasker - www...,"[Home / Uncategorised, Latest Posts, This site..."
12553,4vzhn5j644aa523g.onion,Canny,"[4vzhn5j644aa523g.onion, Buy the access to the..."
12554,cashgodr53umth4z.onion,Cash God - Real Cash Sellers,"[No Risk for You, Our Method, Contact us, 2020..."


In [16]:
# Remove special chars, URL links, email addresses,non-english sentences and empty sentences
df_combined['body_text'] = df_combined['body_text'].apply(preprocess_texts)
# Only keep unique processed texts
df_combined['body_text'] = df_combined['body_text'].apply(lambda x: list(set(x)))
# Generate tokens based on texts
df_combined['body_token'] = df_combined['body_text'].map(preprocess)
df_combined

Unnamed: 0,domain_url,title,body_text,body_token
0,22oxht5ep3hvyboc.onion,Onion Dir - Adult,[Rape Amateur Anal Arab Asian ASMR Ass BBW Zoo...,"[rape, amateur, anal, arab, asian, asmr, bbw, ..."
1,22pp2nrnjcmtlzja.onion,PayPal Plaza | The Tor Marketplace For Buying ...,[PayPal Plaza The Tor Marketplace For Buying S...,"[paypal, plaza, tor, marketplac, buy, sell, pa..."
2,2464b3fu462tx2en.onion,CHILD PORN CENTER,"[Chika Club child porn, http 7oodcg4dnetxxegx ...","[chika, club, child, porn, oodcg, dnetxxegx, o..."
3,24adsavjl3u6tylr.onion,"CP Video HD 2021, PTHC, Loli, child porn, pret...",[Attention the form of payment requires Javasc...,"[attent, form, payment, requir, pleas, enabl, ..."
4,2ajtkan56n6aiyl6.onion,Hard Porn Forum,[torture man who does not listen and cries wit...,"[tortur, man, doe, listen, cri, chimpanze, enj..."
...,...,...,...,...
12551,rkvwooasau2goqeamkqbade4yv2hnt6dc4ol5kgnaaoihd...,Moneys spider - financial pyramid,"[No wallet get it here https www coinbase com,...","[wallet, get, www, coinbas, com, lucki, invit,..."
12552,e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsy...,BenTasker.co.uk - The Home of Ben Tasker - www...,[vepretty broad range of skills all built up t...,"[vepretti, broad, rang, skill, built, experi, ..."
12553,4vzhn5j644aa523g.onion,Canny,"[Biggest collection with daily updates, Buy th...","[biggest, collect, daili, updat, buy, access, ..."
12554,cashgodr53umth4z.onion,Cash God - Real Cash Sellers,"[Cash God Real Cash Sellers, We Need Your Help...","[cash, god, real, cash, seller, need, help, co..."


In [19]:
# Detect language
df_combined['language'] = df_combined['body_token'].apply(language_detect)
# Only keep English sites
df_combined = df_combined[df_combined['language'] == 'en']
df_combined = df_combined[['domain_url', 'title', 'body_text', 'body_token', 'language']]
df_combined

Unnamed: 0,domain_url,title,body_text,body_token,language
0,22oxht5ep3hvyboc.onion,Onion Dir - Adult,[Rape Amateur Anal Arab Asian ASMR Ass BBW Zoo...,"[rape, amateur, anal, arab, asian, asmr, bbw, ...",en
1,22pp2nrnjcmtlzja.onion,PayPal Plaza | The Tor Marketplace For Buying ...,[PayPal Plaza The Tor Marketplace For Buying S...,"[paypal, plaza, tor, marketplac, buy, sell, pa...",en
2,2464b3fu462tx2en.onion,CHILD PORN CENTER,"[Chika Club child porn, http 7oodcg4dnetxxegx ...","[chika, club, child, porn, oodcg, dnetxxegx, o...",en
3,24adsavjl3u6tylr.onion,"CP Video HD 2021, PTHC, Loli, child porn, pret...",[Attention the form of payment requires Javasc...,"[attent, form, payment, requir, pleas, enabl, ...",en
4,2ajtkan56n6aiyl6.onion,Hard Porn Forum,[torture man who does not listen and cries wit...,"[tortur, man, doe, listen, cri, chimpanze, enj...",en
...,...,...,...,...,...
12551,rkvwooasau2goqeamkqbade4yv2hnt6dc4ol5kgnaaoihd...,Moneys spider - financial pyramid,"[No wallet get it here https www coinbase com,...","[wallet, get, www, coinbas, com, lucki, invit,...",en
12552,e26whn2524322mkxb3cbyk27ev2ihhq2biz35hty7gzgsy...,BenTasker.co.uk - The Home of Ben Tasker - www...,[vepretty broad range of skills all built up t...,"[vepretti, broad, rang, skill, built, experi, ...",en
12553,4vzhn5j644aa523g.onion,Canny,"[Biggest collection with daily updates, Buy th...","[biggest, collect, daili, updat, buy, access, ...",en
12554,cashgodr53umth4z.onion,Cash God - Real Cash Sellers,"[Cash God Real Cash Sellers, We Need Your Help...","[cash, god, real, cash, seller, need, help, co...",en


In [18]:
df_combined.to_csv('../data/model_testing_dataset_domain.csv', index=False)