SafeHorizon | Innovations in Detecting and Disrupting Crime-as-a-Service Operations

Summary
SafeHorizon offers computer law enforcement agencies (LEAs), emergency response teams (CERTs), and computer security incident response teams (CSIRTs) a toolbox with underdevelopment and improved open-source solutions that will be simple to plug-and-play, maintain, and adapt. SaferHorizon aims to disrupt CaaS by harnessing intelligence collected from internet-facing services (the clear, deep, and dark web), public dumps and leaks (from ransomware groups and hacking forums and channels), as well as datasets from LEAs and security providers, and using machine learning (ML) to identify correlations and extract actionable evidence that can be used in court. Beyond crawling for information, SafeHorizon will actively search for possible leaks of information on illegal services, forums, and software that would allow LEAs to track down users, developers, and operators. SafeHorizon will deliver i) a toolkit that is broken down into individual and interoperable easy-to-use tools (in the form of Docker containers), ii) a monitoring platform that integrates the output of these tools, iii) a correlation engine to find the connections among diverse and big datasets, and iv) datasets and notebooks that will be shared with all EU LEAs and vetted organisations and companies to enable the easy uptake and processing of data to deliver tangible results. Moreover, SafeHorizon aims to give cybercriminals a taste of their own medicine by, e.g., spreading disinformation on hacking, carding, forums and channels to dismantle their rings of trust.
Unfold all
/
Fold all
More information & hyperlinks
Web resources: https://cordis.europa.eu/project/id/101168562
Start date: 01-09-2024
End date: 31-08-2027
Total budget - Public funding: 3 998 925,00 Euro - 3 998 925,00 Euro
Cordis data

Original description

SafeHorizon offers computer law enforcement agencies (LEAs), emergency response teams (CERTs), and computer security incident response teams (CSIRTs) a toolbox with underdevelopment and improved open-source solutions that will be simple to plug-and-play, maintain, and adapt. SaferHorizon aims to disrupt CaaS by harnessing intelligence collected from internet-facing services (the clear, deep, and dark web), public dumps and leaks (from ransomware groups and hacking forums and channels), as well as datasets from LEAs and security providers, and using machine learning (ML) to identify correlations and extract actionable evidence that can be used in court. Beyond crawling for information, SafeHorizon will actively search for possible leaks of information on illegal services, forums, and software that would allow LEAs to track down users, developers, and operators. SafeHorizon will deliver i) a toolkit that is broken down into individual and interoperable easy-to-use tools (in the form of Docker containers), ii) a monitoring platform that integrates the output of these tools, iii) a correlation engine to find the connections among diverse and big datasets, and iv) datasets and notebooks that will be shared with all EU LEAs and vetted organisations and companies to enable the easy uptake and processing of data to deliver tangible results. Moreover, SafeHorizon aims to give cybercriminals a taste of their own medicine by, e.g., spreading disinformation on hacking, carding, forums and channels to dismantle their rings of trust.

Status

SIGNED

Call topic

HORIZON-CL3-2023-FCT-01-05

Update Date

15-11-2024
Images
No images available.
Geographical location(s)
Structured mapping
Unfold all
/
Fold all
Horizon Europe
HORIZON.2 Global Challenges and European Industrial Competitiveness
HORIZON.2.3 Civil Security for Society
HORIZON.2.3.2 Protection and Security
HORIZON-CL3-2023-FCT-01
HORIZON-CL3-2023-FCT-01-05