africa-cross-border-cybercrime-network
收藏资源简介:
本数据集名为跨境网络犯罪网络情报(非洲),是非洲网络威胁情报系列的一部分。它是一个合成数据集,旨在模拟在非洲运营、以非洲为跳板或针对非洲目标的跨国网络犯罪网络。数据集捕捉了犯罪者如何利用非洲跨境执法协调薄弱、边界管控宽松、引渡条约有限以及区域自由流动协议(如ECOWAS、SADC、EAC)来建立有韧性的跨国犯罪企业,同时反映了国际网络犯罪集团将非洲司法管辖区作为运营基地、洗钱渠道和招募地的现象。数据内容详细刻画了非洲特有的犯罪模式,包括西非的雅虎男孩网络和浪漫诈骗咖啡馆;东非的肯尼亚-索马里移动洗钱走廊和针对海湾国家侨民的埃塞俄比亚IT诈骗团伙;南部非洲的南非集团招募津巴布韦/莫桑比克附属成员和跨境SIM交换团伙;北非的埃及/摩洛哥网络钓鱼即服务平台和针对欧洲的突尼斯勒索软件附属机构;以及整个非洲大陆存在的协调有限、跨境情报共享薄弱、移动货币作为主要洗钱渠道、利用侨民社区和难民等独特动态。数据集包含20种预定义的网络犯罪类型(如浪漫诈骗集团、商业电邮入侵团伙、勒索软件附属网络、加密货币洗钱链、网络钓鱼即服务等)和13种洗钱方法(如加密货币混淆、跨境移动货币代理、哈瓦拉非正式转账、空壳公司发票、房地产购买等)。数据规模为10,000行,样本平衡(50%为犯罪网络,50%为合法网络),所有记录均为合成数据(is_synthetic=1)但基于现实世界的研究数据。数据以表格形式呈现,包含58个特征列,涵盖网络基本信息(如记录ID、基础国家、运营国家数量、网络类型、角色)、技术操作特征(如使用VPN/Tor、加密货币钱包、僵尸网络基础设施、云服务滥用)、财务指标(如估计收入、受害者数量、洗钱成功率)、腐败与内部人员参与情况(如腐败官员、银行内部人员、边境官员腐败)、执法与结果指标(如是否被检测、逮捕数量、起诉是否成功、网络是否被瓦解),以及最终的二元分类标签(1表示犯罪网络,0表示合法网络)。此外,README还列出了从原始特征中提取的一系列衍生特征,用于计算技术复杂度得分、跨境范围、网络成熟度、腐败深度、财务规模等复合指标。该数据集适用于表格分类任务,特别是用于识别和分类跨国网络犯罪网络,可用于网络安全研究、威胁情报分析、执法机构培训以及制定针对非洲跨境网络犯罪的政策和应对策略。
The dataset is named Cross-Border Cybercrime Network Intelligence (Africa) and is part of the Africa Cyber Threat Intelligence series. It is a synthetic dataset designed to simulate transnational cybercrime networks operating in Africa, using Africa as a springboard, or targeting African entities. The dataset captures how criminals exploit weak cross-border law enforcement coordination, lax border controls, limited extradition treaties, and regional free movement agreements (e.g., ECOWAS, SADC, EAC) in Africa to build resilient transnational criminal enterprises. It also reflects the phenomenon of international cybercrime groups using African jurisdictions as operational bases, money laundering channels, and recruitment grounds. The data content details Africa-specific crime patterns, including: West Africa (ECOWAS) Yahoo Boys networks and romance scam cafes; East Africas Kenya-Somalia mobile money laundering corridor and Ethiopian IT scam groups targeting Gulf diaspora; Southern Africas South African groups recruiting Zimbabwean/Mozambican affiliates and cross-border SIM swapping gangs; North Africas Egypt/Morocco phishing-as-a-service platforms and Tunisian ransomware affiliates targeting Europe; and continent-wide dynamics such as limited coordination, weak cross-border intelligence sharing, mobile money as a primary laundering channel, and exploitation of diaspora communities and refugees. The dataset includes 20 predefined cybercrime types (e.g., romance scam groups, business email compromise gangs, ransomware affiliate networks, cryptocurrency laundering chains, phishing-as-a-service) and 13 money laundering methods (e.g., cryptocurrency obfuscation, cross-border mobile money agents, Hawala informal transfers, shell company invoicing, real estate purchases). The data scale is 10,000 rows, with balanced samples (50% criminal networks, 50% legitimate networks). All records are synthetic (is_synthetic=1) but based on real-world research data. The data is presented in tabular format with 58 feature columns, covering network basic information (e.g., record ID, base country, number of operating countries, network type, roles), technical operational features (e.g., use of VPN/Tor, cryptocurrency wallets, botnet infrastructure, cloud service abuse), financial metrics (e.g., estimated revenue, victim count, money laundering success rate), corruption and insider involvement (e.g., corrupt officials, bank insiders, border official corruption), law enforcement and outcome indicators (e.g., detected, arrest count, prosecution success, network dismantled), and a final binary classification label (1 for criminal networks, 0 for legitimate networks). Additionally, the README lists a series of derived features extracted from original features for calculating composite indicators such as technical complexity score, cross-border scope, network maturity, corruption depth, and financial scale. This dataset is suitable for tabular classification tasks, particularly for identifying and classifying transnational cybercrime networks, and can be used for cybersecurity research, threat intelligence analysis, law enforcement training, and developing policies and countermeasures against cross-border cybercrime in Africa.




