<?xml version="1.0" encoding="UTF-8" standalone="no"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD Journal Publishing DTD v2.3 20070202//EN" "journalpublishing.dtd">
<article xml:lang="EN" xmlns:mml="http://www.w3.org/1998/Math/MathML" xmlns:xlink="http://www.w3.org/1999/xlink" article-type="research-article">
<front>
<journal-meta>
<journal-id journal-id-type="publisher-id">Front. Comput. Sci.</journal-id>
<journal-title>Frontiers in Computer Science</journal-title>
<abbrev-journal-title abbrev-type="pubmed">Front. Comput. Sci.</abbrev-journal-title>
<issn pub-type="epub">2624-9898</issn>
<publisher>
<publisher-name>Frontiers Media S.A.</publisher-name>
</publisher>
</journal-meta>
<article-meta>
<article-id pub-id-type="doi">10.3389/fcomp.2024.1381351</article-id>
<article-categories>
<subj-group subj-group-type="heading">
<subject>Computer Science</subject>
<subj-group>
<subject>Original Research</subject>
</subj-group>
</subj-group>
</article-categories>
<title-group>
<article-title>Psychological profiling of hackers via machine learning toward sustainable cybersecurity</article-title>
</title-group>
<contrib-group>
<contrib contrib-type="author">
<name><surname>Hani</surname> <given-names>Umema</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<role content-type="https://credit.niso.org/contributor-roles/conceptualization/"/>
<role content-type="https://credit.niso.org/contributor-roles/formal-analysis/"/>
<role content-type="https://credit.niso.org/contributor-roles/investigation/"/>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-original-draft/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/>
</contrib>
<contrib contrib-type="author" corresp="yes">
<name><surname>Sohaib</surname> <given-names>Osama</given-names></name>
<xref ref-type="aff" rid="aff2"><sup>2</sup></xref>
<xref ref-type="aff" rid="aff3"><sup>3</sup></xref>
<xref ref-type="corresp" rid="c001"><sup>&#x0002A;</sup></xref>
<uri xlink:href="http://loop.frontiersin.org/people/2594796/overview"/>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/supervision/"/>
<role content-type="https://credit.niso.org/contributor-roles/validation/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/>
</contrib>
<contrib contrib-type="author">
<name><surname>Khan</surname> <given-names>Khalid</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/supervision/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/>
</contrib>
<contrib contrib-type="author">
<name><surname>Aleidi</surname> <given-names>Asma</given-names></name>
<xref ref-type="aff" rid="aff4"><sup>4</sup></xref>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/resources/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/>
</contrib>
<contrib contrib-type="author">
<name><surname>Islam</surname> <given-names>Noman</given-names></name>
<xref ref-type="aff" rid="aff1"><sup>1</sup></xref>
<role content-type="https://credit.niso.org/contributor-roles/methodology/"/>
<role content-type="https://credit.niso.org/contributor-roles/supervision/"/>
<role content-type="https://credit.niso.org/contributor-roles/writing-review-editing/"/>
</contrib>
</contrib-group>
<aff id="aff1"><sup>1</sup><institution>College of Computing and Information Sciences, Karachi Institute of Economics and Technology</institution>, <addr-line>Karachi</addr-line>, <country>Pakistan</country></aff>
<aff id="aff2"><sup>2</sup><institution>School of Business, American University of Ras Al Khaimah</institution>, <addr-line>Ras Al Khaimah</addr-line>, <country>United Arab Emirates</country></aff>
<aff id="aff3"><sup>3</sup><institution>Department of Computer Science, University of Technology Sydney</institution>, <addr-line>Sydney, NSW</addr-line>, <country>Australia</country></aff>
<aff id="aff4"><sup>4</sup><institution>College of Humanities and Social Sciences, Libraries and Information Department, Princess Nourah Bint Abdulrahman University</institution>, <addr-line>Riyadh</addr-line>, <country>Saudi Arabia</country></aff>
<author-notes>
<fn fn-type="edited-by"><p>Edited by: Javed Ali Khan, University of Hertfordshire, United Kingdom</p></fn>
<fn fn-type="edited-by"><p>Reviewed by: Hafsa Shareef Dar, University of Gujrat, Pakistan</p>
<p>Tawfik Al-Hadhrami, Nottingham Trent University, United Kingdom</p></fn>
<corresp id="c001">&#x0002A;Correspondence: Osama Sohaib <email>osama.sohaib&#x00040;uts.edu.au</email></corresp>
</author-notes>
<pub-date pub-type="epub">
<day>08</day>
<month>04</month>
<year>2024</year>
</pub-date>
<pub-date pub-type="collection">
<year>2024</year>
</pub-date>
<volume>6</volume>
<elocation-id>1381351</elocation-id>
<history>
<date date-type="received">
<day>03</day>
<month>02</month>
<year>2024</year>
</date>
<date date-type="accepted">
<day>22</day>
<month>03</month>
<year>2024</year>
</date>
</history>
<permissions>
<copyright-statement>Copyright &#x000A9; 2024 Hani, Sohaib, Khan, Aleidi and Islam.</copyright-statement>
<copyright-year>2024</copyright-year>
<copyright-holder>Hani, Sohaib, Khan, Aleidi and Islam</copyright-holder>
<license xlink:href="http://creativecommons.org/licenses/by/4.0/"><p>This is an open-access article distributed under the terms of the Creative Commons Attribution License (CC BY). The use, distribution or reproduction in other forums is permitted, provided the original author(s) and the copyright owner(s) are credited and that the original publication in this journal is cited, in accordance with accepted academic practice. No use, distribution or reproduction is permitted which does not comply with these terms.</p></license>
</permissions>
<abstract>
<p>This research addresses a challenge of the hacker classification framework based on the &#x0201C;big five personality traits&#x0201D; model (OCEAN) and explores associations between personality traits and hacker types. The method&#x00027;s application prediction performance was evaluated in two groups: Students with hacking experience who intend to pursue information security and ethical hacking and industry professionals who work as White Hat hackers. These professionals were further categorized based on their behavioral tendencies, incorporating Gray Hat traits. The k-means algorithm analyzed intra-cluster dependencies, elucidating variations within different clusters and their correlation with Hat types. The study achieved an 88% accuracy in mapping clusters with Hat types, effectively identifying cyber-criminal behaviors. Ethical considerations regarding privacy and bias in personality profiling methodologies within cybersecurity are discussed, emphasizing the importance of informed consent, transparency, and accountability in data management practices. Furthermore, the research underscores the need for sustainable cybersecurity practices, integrating environmental and societal impacts into security frameworks. This study aims to advance responsible cybersecurity practices by promoting awareness and ethical considerations and prioritizing privacy, equity, and sustainability principles.</p></abstract>
<kwd-group>
<kwd>hacker identification</kwd>
<kwd>personality traits</kwd>
<kwd>K-means clustering</kwd>
<kwd>cyber security</kwd>
<kwd>social engineering</kwd>
</kwd-group>
<counts>
<fig-count count="6"/>
<table-count count="9"/>
<equation-count count="0"/>
<ref-count count="44"/>
<page-count count="15"/>
<word-count count="8924"/>
</counts>
<custom-meta-wrap>
<custom-meta>
<meta-name>section-at-acceptance</meta-name>
<meta-value>Software</meta-value>
</custom-meta>
</custom-meta-wrap>
</article-meta>
</front>
<body>
<sec sec-type="intro" id="s1">
<title>1 Introduction</title>
<p>The rise of the Internet has led to a corresponding surge in cybercrime instances, as computers have become integral to various facets of life, including commerce, entertainment, and government operations (Siddiqi et al., <xref ref-type="bibr" rid="B35">2022</xref>). Additionally, the emergence of novel networking models such as mobile, wireless, cognitive, mesh, Internet of Things (IoT), and cloud technologies has further complicated the landscape of cybersecurity (Islam and Shaikh, <xref ref-type="bibr" rid="B20">2016</xref>; Tandera et al., <xref ref-type="bibr" rid="B41">2017</xref>; Wong et al., <xref ref-type="bibr" rid="B42">2020</xref>). This evolving scenario poses significant challenges in combating cyber threats. Cybercrime utilizes computers as tools and mediums for criminal activities, targeting security objectives such as privacy, confidentiality, availability, and integrity of information. Common cyber crimes encompass phishing, honeypots, social engineering, spoofing, and disseminating viruses or worms.</p>
<p>The discussion on cybercrimes highlights previous research findings indicating that these activities are primarily carried out by individuals with low technical sophistication and are driven by motivations such as fame, financial gain, revenge, and self-satisfaction (John et al., <xref ref-type="bibr" rid="B22">1999</xref>; Gulati et al., <xref ref-type="bibr" rid="B17">2016</xref>; Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>; Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>; Suryapranata et al., <xref ref-type="bibr" rid="B38">2017</xref>). Hacking, a specialized form of cybercrime, involves illegally accessing personal or sensitive data using technology and knowledge, with various countermeasures such as firewalls and intrusion detection systems in place to mitigate such threats (Gulati et al., <xref ref-type="bibr" rid="B17">2016</xref>; Akdag, <xref ref-type="bibr" rid="B3">2020</xref>). Building on this understanding, the concept of &#x0201C;sustainable cybersecurity&#x0201D; is introduced in this study, emphasizing the need for enduring and efficient strategies to adapt to the evolving challenges posed by hackers (Shackelford et al., <xref ref-type="bibr" rid="B34">2016</xref>; Medoh and Telukdarie, <xref ref-type="bibr" rid="B28">2022</xref>). This approach aligns with corporate social responsibility (CSR) practices, with an increasing number of managers recognizing cybersecurity as integral to safeguarding customers and the public, thereby expanding risk management practices to encompass the prevention of social-engineering-linked attacks (Shackelford et al., <xref ref-type="bibr" rid="B34">2016</xref>; Medoh and Telukdarie, <xref ref-type="bibr" rid="B28">2022</xref>).</p>
<p>In this study, the term &#x0201C;sustainable&#x0201D; indicates the formulation of enduring and efficient cybersecurity strategies. Within this framework, sustainability encompasses the creation of practices, methodologies, and tools capable of persisting and adjusting over time to adeptly confront the continuously evolving challenges presented by hackers. The concept of &#x0201C;Sustainable Cybersecurity&#x0201D; suggests implementing robust and resilient defense mechanisms designed not only to react to existing threats but also to foresee and alleviate potential risks. For instance, social engineering, which focuses on exploiting human psychology to both perpetrate and prevent cyberattacks, diverges from relying solely on technical hacking methods. It is associated with attacks such as phishing emails, deepfakes, and spear phishing (Siddiqi et al., <xref ref-type="bibr" rid="B35">2022</xref>). This field also underscores the application of social psychology to reinforce cybersecurity policies within organizations. Tools such as the Cyber Risk Index (CRI) and the Cybercrime Rapid Identification Tool (CRIT) (Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>) can be implemented and utilized to bolster this approach. The gap between &#x0201C;social engineering&#x0201D; linked attacks and their avoidance measures creates an ongoing challenge for security experts. Therefore, security through technology is not the sole solution; it is the much-needed side to sustain the cyber security world. Even the World Economic Forum declares social engineering cyber-attacks as the reason for organizations&#x00027; alarming security situation.</p>
<p>This study is grounded in research utilizing data collected from personality trait rating scales (Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>; Novikova and Alexandra, <xref ref-type="bibr" rid="B30">2019</xref>; Wong et al., <xref ref-type="bibr" rid="B42">2020</xref>), with Matulessy and Humaira (<xref ref-type="bibr" rid="B26">2017</xref>) providing insight into hacker personality profiles based on the Big Five Personality Traits model. The aim is to construct a machine learning model capable of predicting and analyzing the personality profiles of hackers, utilizing the Big Five personality model and validating its reliability. Understanding the psychology or personality of hackers is essential for implementing effective preventive measures (Javaid, <xref ref-type="bibr" rid="B21">2013</xref>; Ali et al., <xref ref-type="bibr" rid="B6">2020</xref>). The research inquiry addresses the dominant personality traits (openness to experience, conscientiousness, extraversion, agreeableness, and neuroticism) abbreviated as OCEAN that are exhibited by various hacker types (White, Black, and Gray Hats) and how these traits can be accurately identified and categorized through a machine learning-based approach. This identification mechanism holds promise for informing targeted cybercrime prevention strategies. <xref ref-type="fig" rid="F1">Figure 1</xref> illustrates the research flow and target, detailing a secure model for predicting personality traits. The authors devised a questionnaire based on the OCEAN model and applied machine learning models to classify hacker types.</p>
<fig id="F1" position="float">
<label>Figure 1</label>
<caption><p>Research flow and target.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0001.tif"/>
</fig>
<p>Different sections in this article are as follows. The section covers relevant literature, Section 3 covers the research method, Section 4 covers experimentation and results of the secure model, Section 5 covers discussions on results and threats to validity, and Section 6 concludes the study and highlights potential future work.</p></sec>
<sec id="s2">
<title>2 Literature review</title>
<p>In today&#x00027;s technologically advancing world, cybercrimes are on the rise. This section discusses targeted studies published previously to investigate contemporary cybercriminal acts.</p>
<p>In the realm of cybersecurity research, many studies have leveraged machine learning methodologies to delve into the intricacies of cybercrime data analysis. Concurrently, Geluvaraj et al. (<xref ref-type="bibr" rid="B15">2019</xref>) have tackled prevalent cybersecurity challenges, proposing innovative machine-learning solutions for their mitigation. Drawing from diverse machine learning techniques, Zheng et al. (<xref ref-type="bibr" rid="B44">2003</xref>) have unraveled concealed patterns within crime data, underscoring the indispensability of data-driven approaches in cybercrime investigations. Meanwhile, Islam et al. (<xref ref-type="bibr" rid="B19">2021</xref>) have explored the transformative potential of artificial intelligence and deep learning in bolstering cybersecurity frameworks. Adewumi and Akinyelu (<xref ref-type="bibr" rid="B2">2017</xref>) have harnessed machine learning algorithms to discern distinctive authorship patterns and shed light on attributing illicit messages in cyberspace. Pastrana et al. (<xref ref-type="bibr" rid="B32">2018</xref>) proposed a comprehensive approach to counter the spread of fake news online, leveraging machine learning technologies. This effort aligns with the rise of blockchain technology, which has become a cornerstone in fortifying applications across mobile and cloud networks, exemplified by the study by Mohammed et al. (<xref ref-type="bibr" rid="B29">2023</xref>) and Tamboli et al. (<xref ref-type="bibr" rid="B39">2023</xref>). Furthermore, pioneering approaches, such as the Low-Latency and High-Throughput Multipath routing technique, as elucidated by Ramachandran et al. (<xref ref-type="bibr" rid="B33">2022</xref>), have been devised to counter novel threats such as black hole attacks. Meanwhile, Imran et al. (<xref ref-type="bibr" rid="B18">2019</xref>) have employed machine learning and nature-inspired algorithms to scrutinize credit card data, fortifying fraud prevention measures. Against this backdrop, integrating artificial intelligence, machine learning, and IoT technologies has heralded a new era in cybercrime analysis and cybersecurity enhancement, a paradigm eloquently underscored by Sood and Enbody (<xref ref-type="bibr" rid="B36">2013</xref>) and epitomized in the broader research landscape.</p>
<p>Bridging the gap between psychology and information security, investigations by Del Pozo et al. (<xref ref-type="bibr" rid="B13">2018</xref>) and Chayal and Patel (<xref ref-type="bibr" rid="B10">2021</xref>) have illuminated the psychological underpinnings crucial to fortifying cyber defenses. Suryapranata et al. (<xref ref-type="bibr" rid="B38">2017</xref>) studied the activities of a user forum to identify the variables that can be used to predict the likelihood of a user being involved in cybercrime. An intervention can benefit in avoiding a crime. The study reports users in an underground forum as providers, advertisers, and buyers (Fox and Holt, <xref ref-type="bibr" rid="B14">2021</xref>). Alashti et al. (<xref ref-type="bibr" rid="B4">2022</xref>) employed logistic regression and latent class analysis to identify risk factors associated with juvenile hacking. Odemis et al. (<xref ref-type="bibr" rid="B31">2022</xref>) observed the behaviors of Iranian hackers via interviews. It was found that young hackers enjoyed the pleasure of cybercrime. Back et al. (<xref ref-type="bibr" rid="B7">2019</xref>) addresses whether we can analyze the psychology and behavior of a hacker by investigating their computer logs. A honeypot system was created for this purpose. Suryapranata et al. (<xref ref-type="bibr" rid="B38">2017</xref>) built profiles of cybercriminals by analyzing court records and media documents for incidents in South Korea. It was found that there is a difference in motivation between young and adult hackers.</p>
<p>The hidden Markov Model has been used in various studies to identify the personality traits of cybercriminals over social media networks (Xie and Wei, <xref ref-type="bibr" rid="B43">2022</xref>). The method comprises a training and identification phase. The average likelihood of the observation sequence is performed in the identification phase. The text information posted by users over social media, blogs, and language characteristics can be analyzed using neural networks, logistic regression, and support vector machines for personality analysis (Golbeck et al., <xref ref-type="bibr" rid="B16">2011</xref>; Adali and Golbeck, <xref ref-type="bibr" rid="B1">2012</xref>; Lima and De Castro, <xref ref-type="bibr" rid="B24">2014</xref>).</p>
<p>Novikova and Alexandra (<xref ref-type="bibr" rid="B30">2019</xref>) discuss the Five Factor Model in detail. The Five Factor Model suggests that all people, regardless of their age, gender, or culture, share some essential traits, but every person differs in their degree of manifestation. John et al. (<xref ref-type="bibr" rid="B22">1999</xref>) discuss the result of an eight-item Cybercrime Rapid Identification Tool (CRIT). It evaluates the psychometric properties of the proposed scale on samples of secondary school and university students. A study on Personality Prediction Systems from Facebook Users attempts to build a system to predict a person&#x00027;s personality based on user information (Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>). The research mentioned in the above studies discusses cybercrimes in general. This includes the essential five personality traits all humans are divided into, the tool for identifying Cybercrimes, and especially the personality profiles of the hackers.</p>
<p>In the realm of hacker classification, researchers often employ a framework akin to the concept of White, Black, and Gray Hats (Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>). White Hat Hackers, the first category, embody ethical hacking practices. Despite engaging in illegal activities, they channel their skills toward constructive and positive ends, often for the betterment of security systems. Contrastingly, Black Hat Hackers, the second category, operate with nefarious intent, breaching security measures for personal gain. Their activities typically involve theft, exploitation, and the illicit sale of data driven by self-interest. Gray Hat Hackers constitute the third category, occupying a space between the ethical and the malicious. While they may identify and exploit vulnerabilities, their actions are not motivated by financial gain. However, their endeavors still fall within the realm of illegality, as they typically lack consent from the system&#x00027;s owner. Gray Hats often have associations with Black Hat hackers, blurring the lines between ethical and unethical practices. In another perspective Javaid (<xref ref-type="bibr" rid="B21">2013</xref>) offered, Gray Hats are portrayed as reformed Black Hats. These individuals, often independent security experts, consultants, or corporate researchers, transition from illicit activities to a more legitimate stance. Notable figures such as Kevin Mitnick exemplify this transformation.</p>
<p>In summary, the delineation between White, Black, and Gray Hats provides a nuanced understanding of hacker motivations and behaviors, shedding light on the spectrum between ethical and malicious hacking practices. Each of the three types of hackers utilizes their skills for different purposes. The previous research defines that each possesses other personality profiles regarding Big Five Personality Traits (OCEAN Model). The research study conducted by Matulessy and Humaira (<xref ref-type="bibr" rid="B26">2017</xref>) described the personality profiles of the hackers concerning the Big Five Personality Traits model using 30 hacker subjects and utilized descriptive qualitative research.</p>
<p>The research claims that hackers are positioned in the middle of the personality trait of extraversion regardless of the categories of hackers. White Hats have more dominant personality traits of agreeableness, and Black Hats have more dominant personality traits of openness to experience. In contrast, Gray Hats have more dominant personality traits in terms of neuroticism (see <xref ref-type="table" rid="T1">Table 1</xref>). <xref ref-type="table" rid="T2">Table 2</xref> presents the summary of the previous research.</p>
<table-wrap position="float" id="T1">
<label>Table 1</label>
<caption><p>OCEAN traits claimed in earlier research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>).</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th/>
<th valign="top" align="left"><bold>Extroversion</bold></th>
<th valign="top" align="left"><bold>Neurotic</bold></th>
<th valign="top" align="left"><bold>Agreeable</bold></th>
<th valign="top" align="left"><bold>Conscientious</bold></th>
<th valign="top" align="left"><bold>Openness</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">White hat</td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>High</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
</tr> <tr>
<td valign="top" align="left">Interview-beginner</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
</tr> <tr>
<td valign="top" align="left">Interview-elite</td>
<td valign="top" align="left">H</td>
<td/>
<td/>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
</tr> <tr>
<td valign="top" align="left">Gray hat</td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>High</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
</tr> <tr>
<td valign="top" align="left">interview-beginner</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td/>
<td valign="top" align="left">H</td>
<td valign="top" align="left">L</td>
</tr> <tr>
<td valign="top" align="left">Interview-elite</td>
<td valign="top" align="left">A</td>
<td/>
<td/>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
</tr> <tr>
<td valign="top" align="left">Black Hat</td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>Average</bold></td>
<td valign="top" align="left"><bold>High</bold></td>
</tr> <tr>
<td valign="top" align="left">Interview-Beginner</td>
<td valign="top" align="left">A</td>
<td/>
<td/>
<td/>
<td valign="top" align="left">H</td>
</tr> <tr>
<td valign="top" align="left">Interview-elite</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">H</td>
<td valign="top" align="left">A</td>
</tr></tbody>
</table>
</table-wrap>
<table-wrap position="float" id="T2">
<label>Table 2</label>
<caption><p>Summary of previous research and hacker profiling gap analysis.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th valign="top" align="left"><bold>References</bold></th>
<th valign="top" align="left"><bold>Main theme of the study</bold></th>
<th valign="top" align="left" colspan="2"><bold>Hacker profiling research using personality traits</bold></th>
</tr>
</thead>
<tbody>
<tr style="background-color:#919498;color:#ffffff">
<td/>
<td valign="top" align="left"><bold>Technology used</bold></td>
<td valign="top" align="left"><bold>Status (Yes/No)</bold></td>
<td valign="top" align="left"><bold>Statistical justification (Yes/No)</bold></td>
</tr> <tr>
<td valign="top" align="left">Mohammed et al. (<xref ref-type="bibr" rid="B29">2023</xref>)</td>
<td valign="top" align="left">Implementation of secure applications using blockchain technology.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Tamboli et al. (<xref ref-type="bibr" rid="B39">2023</xref>)</td>
<td valign="top" align="left">Utilization of blockchain technology for secure applications over mobile and cloud networks.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Ramachandran et al. (<xref ref-type="bibr" rid="B33">2022</xref>)</td>
<td valign="top" align="left">Identification and handling of black hole attacks using Low-Latency and High-Throughput Multipath routing techniques.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Alashti et al. (<xref ref-type="bibr" rid="B4">2022</xref>)</td>
<td valign="top" align="left">Identification of risk factors associated with juvenile hacking using logistic regression and latent class analysis.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Chayal and Patel (<xref ref-type="bibr" rid="B10">2021</xref>)</td>
<td valign="top" align="left">Examination of psychology for information security to predict different cyber attacks.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Islam et al. (<xref ref-type="bibr" rid="B19">2021</xref>)</td>
<td valign="top" align="left">Exploration of the role of artificial intelligence and deep learning in cybersecurity.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Geluvaraj et al. (<xref ref-type="bibr" rid="B15">2019</xref>)</td>
<td valign="top" align="left">Discussion of various cybersecurity issues and the use of machine learning to address them.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Imran et al. (<xref ref-type="bibr" rid="B18">2019</xref>)</td>
<td valign="top" align="left">Application of machine learning and nature-inspired algorithms to analyze credit card data for fraud prevention.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Pastrana et al. (<xref ref-type="bibr" rid="B32">2018</xref>)</td>
<td valign="top" align="left">Identification of fake news spreading over the Internet using machine learning algorithms.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Sood and Enbody (<xref ref-type="bibr" rid="B36">2013</xref>)</td>
<td valign="top" align="left">Utilization of AI, machine learning, and IoT for cybersecurity; Deep understanding of cybersecurity.</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Odemis et al. (<xref ref-type="bibr" rid="B31">2022</xref>)</td>
<td valign="top" align="left">Observation of behaviors of Iranian hackers via interviews; Analysis of young hackers&#x00027; enjoyment of cybercrime.</td>
<td valign="top" align="left">No personality traits used</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Back et al. (<xref ref-type="bibr" rid="B7">2019</xref>)</td>
<td valign="top" align="left">Analysis of hacker psychology and behavior through computer logs using a honeypot system.</td>
<td valign="top" align="left">No personality traits</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Buch et al. (<xref ref-type="bibr" rid="B9">2017</xref>)</td>
<td valign="top" align="left">Investigation of personality prediction systems using social media data; Categorization of hackers into White Hat, Black Hat, and Gray Hat.</td>
<td valign="top" align="left">No personality traits used</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Suryapranata et al. (<xref ref-type="bibr" rid="B38">2017</xref>)</td>
<td valign="top" align="left">Study of user forum activities to predict involvement in cybercrime; Profiling of cybercriminals using court records and media documents.</td>
<td valign="top" align="left">No personality traits used</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Xie and Wei (<xref ref-type="bibr" rid="B43">2022</xref>)</td>
<td valign="top" align="left">Utilization of Hidden Markov Models to identify cybercriminal personality traits. It does not explicitly mention <bold>hacker profiling</bold>, but it does contribute to enhancing security within OSNs by improving the ability to identify fraudulent behavior</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Novikova and Alexandra (<xref ref-type="bibr" rid="B30">2019</xref>)</td>
<td valign="top" align="left">Discussion of the Five Factor Model and its application in personality analysis. It contributes valuable insights to the broader field of personality theory and cross-cultural psychology.</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Larose and Chantal (<xref ref-type="bibr" rid="B23">2014</xref>)</td>
<td valign="top" align="left">Examination of the impact of personality type and matching messaging on password strength.</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Adali and Golbeck (<xref ref-type="bibr" rid="B1">2012</xref>)</td>
<td valign="top" align="left">Analysis of text data from social media, blogs, and language characteristics for personality analysis using neural networks, logistic regression, etc.</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Zheng et al. (<xref ref-type="bibr" rid="B44">2003</xref>)</td>
<td valign="top" align="left">Exploration of techniques (classification, association rules mining, clustering) to identify hidden patterns in crime data.</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">John et al. (<xref ref-type="bibr" rid="B22">1999</xref>)</td>
<td valign="top" align="left">Evaluation of Cybercrime Rapid Identification Tool (CRIT) on <italic>second</italic>ary school and university students.</td>
<td valign="top" align="left">No hackers identification</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Del Pozo et al. (<xref ref-type="bibr" rid="B13">2018</xref>)</td>
<td valign="top" align="left">Study of psychology for information security; Application of machine learning in cybersecurity. It highlights the critical role of understanding human psychology in fortifying information security against social engineering attacks</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Golbeck et al. (<xref ref-type="bibr" rid="B16">2011</xref>)</td>
<td valign="top" align="left">Analysis of text data from social media, blogs, and language characteristics for personality analysis using neural networks, logistic regression, etc. It highlights the implications of personality insights for social media design and broader domains</td>
<td valign="top" align="left">No</td>
<td valign="top" align="left">N/A</td>
</tr> <tr>
<td valign="top" align="left">Matulessy and Humaira (<xref ref-type="bibr" rid="B26">2017</xref>)</td>
<td valign="top" align="left">Description of hacker personality profiles using the Big <italic>Five</italic> Personality Traits model; Utilization of descriptive qualitative research.</td>
<td valign="top" align="left">Yes</td>
<td valign="top" align="left">No Statistical Analysis</td>
</tr></tbody>
</table>
</table-wrap>
<p>Previous researchers have primarily focused on broad aspects of cybercrime identification and personality prediction. While some studies have explored personality prediction systems utilizing social media platforms (Buch et al., <xref ref-type="bibr" rid="B9">2017</xref>), others have theorized based on research findings obtained from personality trait rating scales, interviews, surveys, and questionnaires (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>; Novikova and Alexandra, <xref ref-type="bibr" rid="B30">2019</xref>). However, the scope of investigation in these studies remains somewhat limited, predominantly addressing general trends rather than delving into nuanced aspects of cybercriminal behavior and personality profiling.</p>
<p>This research implements a machine learning-based model that predicts and analyzes the personality profiles of hackers using the Big Five personality model, and it also validates the model on real-life datasets. This study mainly targets White and Gray hackers who either use hacking as their profession or have career motivation to adopt it professionally. For detailed classification, refer to the study by Martineau et al. (<xref ref-type="bibr" rid="B25">2023</xref>) and Chng et al. (<xref ref-type="bibr" rid="B11">2022</xref>) w.r.t hacker type, their possible motivations, and personality type.</p></sec>
<sec id="s3">
<title>3 Research methodology</title>
<p><xref ref-type="fig" rid="F2">Figure 2</xref> shows the research method adopted in this study (McAlaney et al., <xref ref-type="bibr" rid="B27">2020</xref>; Bakas et al., <xref ref-type="bibr" rid="B8">2021</xref>). This study uses a machine learning-based approach to validate the classification of different hacker types (White, Black, and Gray Hats) based on their dominant personality traits (openness to experience, conscientiousness, extraversion, agreeableness, and neuroticism).</p>
<fig id="F2" position="float">
<label>Figure 2</label>
<caption><p>Research method.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0002.tif"/>
</fig>
<p>The K-means algorithm was chosen for its simplicity, ease of implementation, and speed. It is widely used for clustering tasks, including in high-volume datasets such as those associated with criminal data, as described by Aldhyani and Alkahtani (<xref ref-type="bibr" rid="B5">2022</xref>). K-means can generate clusters based on similarities in the data, aiming to group data points close to each other while being far from points in other clusters. This study applied K-means to cluster individuals based on their responses to personality trait questions. By clustering individuals with similar personality trait profiles together, the algorithm aids in identifying distinct groups or &#x0201C;clusters&#x0201D; that may correspond to different types of hackers based on their dominant personality traits. The study also seeks to develop an effective hacker identification mechanism that can accurately categorize these traits and contribute to developing targeted cybercrime prevention strategies related to social policies.</p>
<p>The Big Five Inventory is a 44-item inventory that measures an individual on the Big Five Factors (dimensions or traits) of personality. Each of the five factors is then further divided into personality characteristics. The inventory shares some questions for generic OCEAN personality traits. These are given in the dataset of Kaggle (Akdag, <xref ref-type="bibr" rid="B3">2020</xref>). A reduced set of questions was used from the Five Personality questionnaire comprising 40 questions (Akdag, <xref ref-type="bibr" rid="B3">2020</xref>). The users were asked to indicate their favorable responses to the questionnaire items by selecting an appropriate score. After collecting the questions&#x00027; responses, a machine learning code runs and predicts results against all five personality traits. Based on the results, different hacker types are identified.</p>
<sec>
<title>3.1 Research questionnaire</title>
<p>There are several instruments to measure the Big Five Trait Factors, such as the Big Five Inventory (BFI), the NEO Personality Inventory-Revised (NEO-PI-R), and the International Personality Item Tool (IPIP). This study used the dataset constructed from the IPIP for our research. This dataset was collected (2016&#x02013;2018) through an interactive online personality test and comprises 10,12,050 records (Akdag, <xref ref-type="bibr" rid="B3">2020</xref>). The training dataset trains the clustering model for OCEAN trait prediction.</p>
<p>Following the points concluded in the research mentioned in <xref ref-type="table" rid="T1">Table 1</xref>, 21 questions were selected. Redundant reverse questions were not included to reduce user frustration. In the questionnaire development process, the reverse questions are normally designed to verify the authenticity of answers recorded by random users.</p>
<p>Su&#x000E1;rez &#x000C1;lvarez et al. (<xref ref-type="bibr" rid="B37">2018</xref>) demonstrated the conventional way of handling reverse coding. Here, the reduction was made for all reverse-scored questions included in the 40 questions. These were negatively phrased to ensure the user knew his point of view. Including such questions requires reserve scoring. The negative consequences of using the reverse scoring include a) the flawed measurement precision of the instrument, b) the variance of the combined form is reduced, c) examinees&#x00027; scores differ significantly from those obtained in tests where all of the items are of a similar form, and d) verbal skills influence examinees&#x00027; responses (Su&#x000E1;rez &#x000C1;lvarez et al., <xref ref-type="bibr" rid="B37">2018</xref>). Minor changes in wording can also have a significant effect on responses. One should, therefore, be careful when looking at alternative wordings. Negative words such as &#x0201C;not&#x0201D; should be avoided in questions as respondents easily miss them. In addition, using &#x0201C;not&#x0201D; in a scale such as &#x0201C;Satisfied,&#x0201D; &#x0201C;Neither,&#x0201D; and &#x0201C;Not satisfied&#x0201D; does not provide a true opposite as defined by the Australian Statistic Bureau (Corallo et al., <xref ref-type="bibr" rid="B12">2022</xref>). The questions were then rephrased from native English speakers&#x00027; style into a more understandable one for non-native speakers. See <xref ref-type="table" rid="T3">Table 3</xref> for a detailed set of questions used in this study.</p>
<table-wrap position="float" id="T3">
<label>Table 3</label>
<caption><p>Research questions with no reverse questions.</p></caption>
<table frame="box" rules="all">
<tbody>
<tr>
<td valign="top" align="left">&#x025A0; EXT1: I am the life of the party. I am interactive and never mind being the center of attention.<break/>&#x025A0; EXT2: I talk a lot, even around strangers.<break/>&#x025A0; EXT5: I start a conversation.<break/>&#x025A0; EST1: I get stressed out easily.<break/>&#x025A0; EST3: I often worry about things.<break/>&#x025A0; EST7: I change my mood a lot.<break/>&#x025A0; EST9: I get irritated and annoyed easily.<break/>&#x025A0; AGR2: I care about people as humans and their lives and what they do and say.<break/>&#x025A0; AGR4: I can understand what someone is feeling<break/>&#x025A0; AGR6: I have a soft heart.<break/>&#x025A0; AGR8: I take time out for others and give high priority to others in need.</td>
<td valign="top" align="left">&#x025A0; CSN1: I am always prepared.<break/>&#x025A0; CSN2: I am careless and unsystematic about the things in my ownership.<break/>&#x025A0; CSN3: I pay attention to details in my work as I am demanding.<break/>&#x025A0; CSN5: I get my work done right away.<break/>&#x025A0; CSN7: I like doing things in an organized manner.<break/>&#x025A0; CSN9: I follow a schedule.<break/>&#x025A0; OPN1: I have a rich vocabulary and communicate more engagingly.<break/>&#x025A0; OPN3: I have a vivid (intense) imagination.<break/>&#x025A0; OPN7: I am quick to understand things.<break/>&#x025A0; OPN10: I am full of ideas.</td>
</tr>
</tbody>
</table>
</table-wrap>
</sec>
<sec>
<title>3.2 Questionnaire reliability</title>
<p>The questionnaire&#x00027;s accuracy and precision, i.e., its internal validity (consistency) or reliability, have been checked using Cronbach&#x00027;s alpha score. Its value was reported as 0.874 in previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) on 40 questions. In this research&#x00027;s reduced set of 21 questions, its value is 0.82, which shows acceptable reliability, i.e., &#x0003E;0.7. It always gives the same results when applied to the same group at different times or circumstances (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>).</p></sec>
</sec>
<sec id="s4">
<title>4 Experimentation of results of secure model</title>
<sec>
<title>4.1 Algorithms used and experimentation</title>
<p>The research experimentation is based on two algorithms:</p>
<list list-type="order">
<list-item><p>The machine learning-based OCEAN traits identification dataset is from Kaggle, developed by Akdag (<xref ref-type="bibr" rid="B3">2020</xref>).</p></list-item>
<list-item><p>Identification of specific OCEAN traits-related combinations found in criminals and hackers.</p></list-item>
</list>
<p>The experiment starts with creating an optimal number of clusters on the training dataset downloaded from Kaggle (Akdag, <xref ref-type="bibr" rid="B3">2020</xref>). The k-means algorithm generates clusters (groups of similar data) because of its ease of implementation, simplicity, and speed, which is very appealing in practice. This has been described in detail by Aldhyani and Alkahtani (<xref ref-type="bibr" rid="B5">2022</xref>), who targeted the classification of criminal data. According to the study, K-means is suitable for high-volume crime datasets and can help to extract useful information.</p>
<p>K-means applied in this research is a complete, partitioned clustering technique that attempts to find user-specified clusters (K) represented by their centroids. The distance between any two points in different groups is larger than the distance between any two points within a group. Well-separated clusters do not need to be spherical but can have any shape (Tan et al., <xref ref-type="bibr" rid="B40">2016</xref>).</p>
<p><xref ref-type="fig" rid="F3">Figure 3</xref> shows methods Python uses to calculate an optimum cluster value. The KElbowVisualizer or elbow method selects the optimal number of clusters by fitting the model with a range of values for K, which shows that the calculated value of K is 6. The Silhouette coefficient method is used to know the truth about the dataset by computing the density of clusters. This produces a score between 1 and &#x02212;1, where 1 is a highly dense cluster and &#x02212;1 is a completely incorrect cluster. Here, the value is approximately 0.06, which shows that the number of clusters in this research is dense and thus correct.</p>
<fig id="F3" position="float">
<label>Figure 3</label>
<caption><p>Optimal cluster number. <bold>(A)</bold> KElbowVisualizar; <bold>(B)</bold> Silhouette coefficient.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0003.tif"/>
</fig>
<p>After clustering the training dataset on 6 clusters (0&#x02013;5), the score of the five personality traits is calculated individually based on the responses to the questions. Then, the system is trained to predict the cluster for each dataset and calculate each trait&#x00027;s score respectively (see <xref ref-type="fig" rid="F4">Figure 4</xref>). <xref ref-type="fig" rid="F4">Figure 4</xref> shows how many datasets were assigned to identify each cluster; even the worst count shows 6,200 records.</p>
<fig id="F4" position="float">
<label>Figure 4</label>
<caption><p>Cluster&#x00027;s centers picked by K-means Python estimator. <bold>(A)</bold> Training data distribution across calculated clusters. <bold>(B)</bold> Train data points spread across calculated clusters.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0004.tif"/>
</fig>
</sec>
<sec>
<title>4.2 Scoring values to identify hackers</title>
<p>The same technique is applied to the responses taken from the test datasets, which were collected on 21 questions and converted into responses. According to the user&#x00027;s responses, the system calculates the score of each personality trait. It determines the cluster where the user belongs to three types of hackers who have one most dominant personality trait among all. In previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>), as shown in <xref ref-type="table" rid="T1">Table 1</xref>, for OCEAN traits, the generalized most dominant traits are agreeableness for the White hacker, openness to experience for the Black hacker, and neuroticism for the Gray Hackers. If any of these traits have the maximum score among all four traits, there is a strong possibility that the person can be a hacker or have any illegal intentions.</p>
</sec>
<sec>
<title>4.3 Organizational preventive measures</title>
<p>If the user is found to be suspicious, the system temporarily holds that user on a &#x0201C;watch list&#x0201D; before granting further access to the site or organizational sensitive resources. The organization can add its name to the social policy list to use resources under organizational or web access monitoring software. As mentioned earlier, proper social security and communication policies should be designed based on identified &#x0201C;social psychology&#x0201D; and Crime Risk Index, as suggested by Siddiqi et al. (<xref ref-type="bibr" rid="B35">2022</xref>), or Cybercrime Rapid Identification Tool (CRIT), as suggested by Buch et al. (<xref ref-type="bibr" rid="B9">2017</xref>), must be maintained to differentiate na&#x000EF;ve users from the one who can harm other colleagues or employer organization.</p></sec>
</sec>
<sec id="s5">
<title>5 Validation of secure model</title>
<p>Rather than blindly implementing clusters on previous research claims (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>), its proper validation is performed on (a) average scores as well as on (b) clusters using a prediction performance accuracy measurement of machine learning (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>). In validating the secure model, several techniques are applied to ensure the reliability and accuracy of the model&#x00027;s predictions. These include comparing average scores of the test dataset with established category claims for hacker types, validating clustering outcomes through cluster predictions on the test dataset, analyzing correlations between personality traits using Spearman&#x00027;s rho, quantitatively measuring model performance, examining demographic information, and mapping clusters to hacker types based on observed traits. Collectively, these validation techniques ensure the effectiveness and robustness of the model in identifying hacker types based on personality traits.</p>
<sec>
<title>5.1 Data collection for test set</title>
<p>Test data were collected reliably for a major research project to gather personality traits data across various professional domains in computer science. These data were used to develop a career counseling system for final-year students in higher education institutions. It included responses from final-year students and professionals in domains such as information security, such as hackers, auditors, trainers, and security administrators. The response rate was highly encouraging. Out of 300 records, around 32 were related to hackers, with 30 ultimately included after data cleaning. This aligns with validation criteria from previous psychology research. Despite the lack of progressive research in hacker personality detection, the study aimed to contribute positively to career counseling. The data collection process was based on high trust, as participants and the research team belonged to the same information security professionals community. Data collected from final-year students were deemed reliable due to their field of interest and relevant academic projects noted during their tenure.</p>
</sec>
<sec>
<title>5.2 Demographics on test data</title>
<p>Demographics and frequency scores of the collected dataset for Gray and White hackers are given in <xref ref-type="table" rid="T4">Table 4</xref>. The total respondents for this study were 30 professionals and final-year students who intend to adopt hacking as their profession. The majority of them were male respondents, whereas only two were female respondents. <xref ref-type="table" rid="T5">Table 5</xref> shows all possible details of the collected test dataset.</p>
<table-wrap position="float" id="T4">
<label>Table 4</label>
<caption><p>Hacker type, motivations, and common strategies.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th valign="top" align="left"><bold>Hacker type</bold></th>
<th valign="top" align="left"><bold>Motivations</bold></th>
<th valign="top" align="left"><bold>Common strategies</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">White hat hackers</td>
<td valign="top" align="left">- Enhance cybersecurity. - Identify and fix vulnerabilities.</td>
<td valign="top" align="left">- Conduct ethical hacking. - Collaborate with organizations to strengthen defenses.</td>
</tr> <tr>
<td valign="top" align="left">Black hat hackers</td>
<td valign="top" align="left">- Financial gain. - Data theft. - Disruption.</td>
<td valign="top" align="left">- Exploit vulnerabilities maliciously. - Engage in cybercriminal activities.</td>
</tr> <tr>
<td valign="top" align="left">Gray hat hackers</td>
<td valign="top" align="left">- Curiosity. - Seeking recognition. - Responsible disclosure.</td>
<td valign="top" align="left">- Discover vulnerabilities without authorization. - Disclose responsibly.</td>
</tr> <tr>
<td valign="top" align="left">Script kiddies</td>
<td valign="top" align="left">- Mischief. - Curiosity.</td>
<td valign="top" align="left">- Use pre-written scripts or tools without deep understanding.</td>
</tr></tbody>
</table>
</table-wrap>
<table-wrap position="float" id="T5">
<label>Table 5</label>
<caption><p>Number of test datasets and their demographics.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th valign="top" align="left"><bold>Respondents</bold></th>
<th/>
<th valign="top" align="center"><bold>Number of professional/elite</bold></th>
<th valign="top" align="center"><bold>Number of final year student</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">Test data</td>
<td/>
<td valign="top" align="center"><bold>13</bold></td>
<td valign="top" align="center"><bold>17</bold></td>
</tr> <tr>
<td valign="top" align="left">Age in years</td>
<td/>
<td valign="top" align="center">21&#x02013;25</td>
<td valign="top" align="center">18&#x02013;50</td>
</tr> <tr>
<td valign="top" align="left">Sex</td>
<td valign="top" align="center">Male</td>
<td valign="top" align="center">13</td>
<td valign="top" align="center">15</td>
</tr>
 <tr>
<td/>
<td valign="top" align="center">Female</td>
<td valign="top" align="center">0</td>
<td valign="top" align="center">2</td>
</tr> <tr>
<td valign="top" align="left">City type</td>
<td valign="top" align="center">Urban</td>
<td valign="top" align="center">13</td>
<td valign="top" align="center">15</td>
</tr>
 <tr>
<td/>
<td valign="top" align="center">Rural</td>
<td valign="top" align="center">0</td>
<td valign="top" align="center">2</td>
</tr> <tr>
<td valign="top" align="left">Income range</td>
<td/>
<td valign="top" align="center">0&#x02013;above 200,000 PKR/Month</td>
<td valign="top" align="center">0&#x02013;25,000 PKR/Month</td>
</tr> <tr>
<td valign="top" align="left">Financial satisfaction</td>
<td valign="top" align="center">Yes</td>
<td valign="top" align="center">6</td>
<td valign="top" align="center">15</td>
</tr>
 <tr>
<td/>
<td valign="top" align="center">No</td>
<td valign="top" align="center">7</td>
<td valign="top" align="center">2 (fresh in job)</td>
</tr> <tr>
<td valign="top" align="left">Experience in years</td>
<td/>
<td valign="top" align="center">0&#x02013;1</td>
<td valign="top" align="center">0&#x02013;28</td>
</tr></tbody>
</table>
</table-wrap>
</sec>
<sec>
<title>5.3 Cluster trends on test dataset with hat type mapping for validation</title>
<p>First, the test dataset was given as an input in the clustering algorithm generated, as discussed in Section 4, and clusters were predicted on all datasets. The cluster distribution will be discussed in detail in later sections.</p>
<p>To better understand the cluster trends and establish their mapping with Hat types, there was a need to consider the correlation between the traits on test data. Correlation is a statistical measure that measures the extent to which two variables are in a linear relationship without calculating cause and effect. This means they constantly change; when one changes, the other also changes. It is measured on a scale of &#x02212;1/0/&#x0002B;1, which means an indirect, no, or a direct relationship. For the stated reason, Spearman&#x00027;s correlation was applied to the test dataset (see <xref ref-type="table" rid="T6">Table 6</xref>), showing a few other significant but moderate level inter-dependencies between traits in the correlation coefficient range &#x0002B;/&#x02013; 0.4.</p>
<table-wrap position="float" id="T6">
<label>Table 6</label>
<caption><p>Spearman&#x00027;s rho correlation checking to make multiple trait-based Hat-type selections.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th/>
<th/>
<th valign="top" align="left"><bold>Extroversion</bold></th>
<th valign="top" align="left"><bold>Neurotic</bold></th>
<th valign="top" align="left"><bold>Agreeable</bold></th>
<th valign="top" align="left"><bold>Conscientious</bold></th>
<th valign="top" align="left"><bold>Open</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" rowspan="2">Extroversion</td>
<td valign="top" align="left">Correlation coefficient</td>
<td valign="top" align="left">1.000</td>
<td valign="top" align="left">&#x02212;0.117</td>
<td valign="top" align="left">0.422<sup>&#x0002A;</sup></td>
<td valign="top" align="left">&#x02212;0.100</td>
<td valign="top" align="left">&#x02212;0.170</td>
</tr>
 <tr>
<td valign="top" align="left">Sig. (two-tailed)</td>
<td/>
<td valign="top" align="left">0.553</td>
<td valign="top" align="left">0.025</td>
<td valign="top" align="left">0.614</td>
<td valign="top" align="left">0.387</td>
</tr> <tr>
<td valign="top" align="left" rowspan="2">Neurotic</td>
<td valign="top" align="left">Correlation coefficient</td>
<td valign="top" align="left">&#x02212;0.117</td>
<td valign="top" align="left">1.000</td>
<td valign="top" align="left">&#x02212;0.035</td>
<td valign="top" align="left">&#x02212;0.284</td>
<td valign="top" align="left">&#x02212;0.311</td>
</tr>
 <tr>
<td valign="top" align="left">Sig. (two-tailed)</td>
<td valign="top" align="left">0.553</td>
<td/>
<td valign="top" align="left">0.861</td>
<td valign="top" align="left">0.143</td>
<td valign="top" align="left">0.107</td>
</tr> <tr>
<td valign="top" align="left" rowspan="2">Agreeable</td>
<td valign="top" align="left">Correlation coefficient</td>
<td valign="top" align="left">0.422<sup>&#x0002A;</sup></td>
<td valign="top" align="left">&#x02212;0.035</td>
<td valign="top" align="left">1.000</td>
<td valign="top" align="left">&#x02212;0.077</td>
<td valign="top" align="left">0.224</td>
</tr>
 <tr>
<td valign="top" align="left">Sig. (two-tailed)</td>
<td valign="top" align="left">0.025</td>
<td valign="top" align="left">0.861</td>
<td/>
<td valign="top" align="left">0.697</td>
<td valign="top" align="left">0.253</td>
</tr> <tr>
<td valign="top" align="left" rowspan="2">Conscientious</td>
<td valign="top" align="left">Correlation coefficient</td>
<td valign="top" align="left">&#x02212;0.100</td>
<td valign="top" align="left">&#x02212;0.284</td>
<td valign="top" align="left">&#x02212;0.077</td>
<td valign="top" align="left">1.000</td>
<td valign="top" align="left">0.410<sup>&#x0002A;</sup></td>
</tr>
 <tr>
<td valign="top" align="left">Sig. (two-tailed)</td>
<td valign="top" align="left">0.614</td>
<td valign="top" align="left">0.143</td>
<td valign="top" align="left">0.697</td>
<td/>
<td valign="top" align="left">0.030</td>
</tr> <tr>
<td valign="top" align="left" rowspan="2">Open</td>
<td valign="top" align="left">Correlation coefficient</td>
<td valign="top" align="left">&#x02212;0.170</td>
<td valign="top" align="left">&#x02212;0.311</td>
<td valign="top" align="left">0.224</td>
<td valign="top" align="left">0.410<sup>&#x0002A;</sup></td>
<td valign="top" align="left">1.000</td>
</tr>
 <tr>
<td valign="top" align="left">Sig. (two-tailed)</td>
<td valign="top" align="left">0.387</td>
<td valign="top" align="left">0.107</td>
<td valign="top" align="left">0.253</td>
<td valign="top" align="left">0.030</td>
<td/>
</tr></tbody>
</table>
<table-wrap-foot>
<p><sup>&#x0002A;</sup>Correlation is significant at the 0.05 level (two-tailed).</p>
</table-wrap-foot>
</table-wrap>
<p>These visible correlations can be generalized as given by Matulessy and Humaira (<xref ref-type="bibr" rid="B26">2017</xref>):</p>
<list list-type="simple">
<list-item><p>a. The openness to experience keeps conscientiousness closer. High openness was claimed to be the major trait of Black Hats.</p></list-item>
<list-item><p>b. Neuroticism depends directly on no other traits. High neuroticism was claimed to be the major trait of Gray Hats.</p></list-item>
<list-item><p>c. Agreeableness keeps extroversion closer. High agreeable was claimed to be the major trait of White Hats.</p></list-item>
</list>
<p><xref ref-type="fig" rid="F5">Figure 5</xref> graphically shows all 6 clusters with average score values and reflects apparent behavior across each cluster on both training and test datasets. It is visible from the two graphs that the K-means clustering algorithm does not just check the average score values while designating the cluster numbers but also reflects intra-cluster trends within specific clusters. Following are the conclusions to map the cluster numbers with the Hat types purely over hacker&#x00027;s data:</p>
<list list-type="order">
<list-item><p>The first cluster, &#x0201C;Cluster-0,&#x0201D; shows the same trend among both datasets. Still, the training dataset has shown less sense of taking creative challenges by the White Hats because their job demands carefully defined method&#x00027;s adaptation. In this combination, the highest level starts with an extra high level of neuroticism, then comes a high level of agreeableness, conscientiousness, openness, and the last somewhat above-average level of extroversion.</p>
<list list-type="bullet">
<list-item><p>Conclusion: &#x0201C;Cluster-0&#x0201D; represents Gray Hats with the highest neuroticism; therefore, it does not depend on other traits.</p></list-item>
</list></list-item>
<list-item><p>The second cluster, which is &#x0201C;Cluster-1,&#x0201D; is closer to the first cluster but has high neuroticism and agreeableness.</p>
<list list-type="bullet">
<list-item><p>Conclusion: &#x0201C;Cluster-0&#x0201D; represents a switching behavior of White Hats with a Gray Hat tendency. White has the highest level of agreeableness but also has a high level of neuroticism; therefore, it does not depend on any other traits.</p></list-item>
</list></list-item>
<list-item><p>The third cluster, &#x0201C;Cluster-2,&#x0201D; is closer to the fourth cluster but has an average level of neuroticism.</p>
<list list-type="bullet">
<list-item><p>Conclusion: &#x0201C;Cluster-2&#x0201D; represents White Hats with average neurotic tendencies and with high agreeableness and average values of extroversion.</p></list-item>
</list></list-item>
<list-item><p>The fifth cluster, &#x0201C;Cluster-4,&#x0201D; shows the same trend captured on the training and test datasets. The highest trait is agreeableness, followed by openness, an average level of conscientiousness, and an average value of extroversion.</p>
<list list-type="bullet">
<list-item><p>Conclusion: &#x0201C;Cluster-4&#x0201D; represents White Hats with low neuroticism, high agreeableness, and average values of extroversion.</p></list-item>
</list></list-item>
</list>
<fig id="F5" position="float">
<label>Figure 5</label>
<caption><p>Average score value against each cluster for OCEAN traits prediction on training data.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0005.tif"/>
</fig>
<p>See <xref ref-type="table" rid="T7">Table 7</xref> for clusters to Hat-type mapping with quantitative values of average scores across each trait for all clusters predicted on the test dataset.</p>
<table-wrap position="float" id="T7">
<label>Table 7</label>
<caption><p>Cluster to Hat-types mapping.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th valign="top" align="left"><bold>Cluster</bold></th>
<th valign="top" align="center"><bold>Extroversion</bold></th>
<th valign="top" align="center"><bold>Neurotic</bold></th>
<th valign="top" align="center"><bold>Agreeable</bold></th>
<th valign="top" align="center"><bold>Conscientious</bold></th>
<th valign="top" align="center"><bold>Openness</bold></th>
<th valign="top" align="left"><bold>Comments with hat mapping</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left">0</td>
<td valign="top" align="center">2.33</td>
<td valign="top" align="center">3.50</td>
<td valign="top" align="center">3.00</td>
<td valign="top" align="center">2.83</td>
<td valign="top" align="center">2.50</td>
<td valign="top" align="left">Gray hats</td>
</tr> <tr>
<td valign="top" align="left">1</td>
<td valign="top" align="center">2.33</td>
<td valign="top" align="center">3.25</td>
<td valign="top" align="center">4.00</td>
<td valign="top" align="center">2.17</td>
<td valign="top" align="center">2.75</td>
<td valign="top" align="left">White hat with gray hat tendency</td>
</tr> <tr>
<td valign="top" align="left">2</td>
<td valign="top" align="center">2.08</td>
<td valign="top" align="center">2.05</td>
<td valign="top" align="center">2.73</td>
<td valign="top" align="center">2.47</td>
<td valign="top" align="center">2.50</td>
<td valign="top" align="left">White Hat with an average neurotic tendency (0.20 points difference in magnitude between traits)</td>
</tr> <tr>
<td valign="top" align="left">4</td>
<td valign="top" align="center">2.22</td>
<td valign="top" align="center">1.42</td>
<td valign="top" align="center">3.67</td>
<td valign="top" align="center">2.89</td>
<td valign="top" align="center">3.33</td>
<td valign="top" align="left">White Hat with a low neurotic tendency (0.80 point difference in magnitude between traits)</td>
</tr></tbody>
</table>
</table-wrap>
</sec>
<sec>
<title>5.4 Validation of average scores</title>
<p>A test dataset of 30 records is collected to check the claims of previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) without applying the clustering algorithm. In <xref ref-type="table" rid="T7">Table 7</xref>, the test dataset matches the previous research&#x00027;s (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) generalized category claim of White Hats, as shown in <xref ref-type="table" rid="T1">Table 1</xref>.</p>
<p>After the detailed experimentation performed in Section 4, a better interpretation of validation results on test data can be made based on <xref ref-type="table" rid="T7">Table 7</xref> cluster to Hat-type mappings (see <xref ref-type="table" rid="T8">Table 8</xref>).</p>
<list list-type="order">
<list-item><p>The average scores of the test dataset for professionals match the generalized score claim for White Hats in previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) but show an average extroversion value (see <xref ref-type="table" rid="T6">Table 6</xref>); therefore, after the following cluster-level validation, it could be placed under Cluster-4.</p></list-item>
<list-item><p>The average scores of the test dataset for student hackers match the generalized score claim for White hackers (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) but show an average neuroticism value (see <xref ref-type="table" rid="T6">Table 6</xref>). Therefore, the student&#x00027;s class belongs to the White Hats but tilts toward Gray Hat traits, and after performing the cluster-level validation, it will be placed under Cluster-2.</p></list-item>
</list>
<table-wrap position="float" id="T8">
<label>Table 8</label>
<caption><p>Validation of average trait scores on test datasets about previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>).</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th/>
<th valign="top" align="left"><bold>Extraversion</bold></th>
<th valign="top" align="left"><bold>Neuroticism</bold></th>
<th valign="top" align="left"><bold>Agreeableness</bold></th>
<th valign="top" align="left"><bold>Conscientious</bold></th>
<th valign="top" align="left"><bold>Openness</bold></th>
<th valign="top" align="left"><bold>Hat type</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left" rowspan="2">Professional&#x00027;s data 13 records</td>
<td valign="top" align="left">1.99</td>
<td valign="top" align="left">1.71</td>
<td valign="top" align="left">2.5</td>
<td valign="top" align="left">2.37</td>
<td valign="top" align="left">2.48</td>
<td valign="top" align="left">White Hats with low Neurotic behavior (later will be generalized to cluster-4)</td>
</tr>
 <tr>
<td valign="top" align="left">Average</td>
<td valign="top" align="left">Low &#x02192; Average</td>
<td valign="top" align="left">High</td>
<td valign="top" align="left">Average &#x02192; High</td>
<td valign="top" align="left">Average &#x02192; High</td>
<td/>
</tr> <tr>
<td valign="top" align="left" rowspan="2">Student&#x00027;s data 17 records</td>
<td valign="top" align="left">2.12</td>
<td valign="top" align="left">2.12</td>
<td valign="top" align="left">3.20</td>
<td valign="top" align="left">2.54</td>
<td valign="top" align="left">2.68</td>
<td valign="top" align="left">White Hats with average Neurotic behavior (later will be generalized to cluster-2)</td>
</tr>
 <tr>
<td valign="top" align="left">Average</td>
<td valign="top" align="left">Average</td>
<td valign="top" align="left">High</td>
<td valign="top" align="left">Average &#x02192; High</td>
<td valign="top" align="left">Average &#x02192; High</td>
<td/>
</tr></tbody>
</table>
</table-wrap>
</sec>
<sec>
<title>5.5 Secure model&#x00027;s clustering model validation</title>
<p>The secure model uses the clusters to predict the criminal&#x00027;s or hacker&#x00027;s personality type.</p>
<p>In this section, the clustering outcomes are validated to visualize the cluster&#x00027;s outcome spread when run over the test dataset (see <xref ref-type="fig" rid="F6">Figure 6</xref>). Validation was performed by making cluster predictions over the test dataset using a 6-clusters-based model trained on 21 factors-based train datasets. As shown in <xref ref-type="table" rid="T9">Table 9</xref>, the overall prediction performance accuracy is 100% of the time. This can be seen when using the correlation information in <xref ref-type="table" rid="T6">Table 6</xref> to better understand the varying trait-wise mapping for hackers in the test dataset.</p>
<list list-type="order">
<list-item><p>The professional dataset has shown 100% accuracy as they are all White Hats since Cluster-2 and Cluster-4 represent White Hats.</p></list-item>
<list-item><p>The student&#x00027;s dataset predicts 88% of White Hats and 11.7% of Gray Hats or White Hats with Gray Hat tendency. Both Cluster-0 and Cluster-1 show Gray Hat tendencies.</p></list-item>
</list>
<fig id="F6" position="float">
<label>Figure 6</label>
<caption><p>Test data points spread across the predicted clusters.</p></caption>
<graphic mimetype="image" mime-subtype="tiff" xlink:href="fcomp-06-1381351-g0006.tif"/>
</fig>
<table-wrap position="float" id="T9">
<label>Table 9</label>
<caption><p>Distribution of test dataset on 5 and 6 cluster-based hacker identification models.</p></caption>
<table frame="box" rules="all">
<thead>
<tr style="background-color:#919498;color:#ffffff">
<th valign="top" align="left"><bold>5 Cluster</bold></th>
<th valign="top" align="center"><bold>Total data</bold></th>
<th valign="top" align="left"><bold>Number of test sets for professionals</bold></th>
<th valign="top" align="left"><bold>Number of test sets for students</bold></th>
<th valign="top" align="left"><bold>Hat types</bold></th>
</tr>
</thead>
<tbody>
<tr>
<td valign="top" align="left"><bold>4</bold></td>
<td valign="top" align="center">6</td>
<td valign="top" align="left">3</td>
<td valign="top" align="left">3</td>
<td valign="top" align="left">White Hats with low Neurotic behavior</td>
</tr> <tr>
<td valign="top" align="left"><bold>1</bold></td>
<td valign="top" align="center">3</td>
<td valign="top" align="left">1</td>
<td valign="top" align="left">2</td>
<td valign="top" align="left">White Hat with Gray Hat tendency</td>
</tr> <tr>
<td valign="top" align="left"><bold>0</bold></td>
<td valign="top" align="center">3</td>
<td valign="top" align="left">1</td>
<td valign="top" align="left">2</td>
<td valign="top" align="left">Gray Hats</td>
</tr> <tr>
<td valign="top" align="left"><bold>2</bold></td>
<td valign="top" align="center">18</td>
<td valign="top" align="left">8</td>
<td valign="top" align="left">10</td>
<td valign="top" align="left">White Hats with average Neurotic behavior</td>
</tr> <tr>
<td valign="top" align="left">Performance accuracy on a 6 cluster model</td>
<td valign="top" align="center">100%</td>
<td valign="top" align="left">100%</td>
<td valign="top" align="left">88% White Hats; 11.7% Gray Hats</td>
<td/>
</tr></tbody>
</table>
</table-wrap>
</sec>
</sec>
<sec sec-type="discussion" id="s6">
<title>6 Discussion</title>
<p>This research uses machine learning to validate the proposed approach on approximately 30 real-life datasets. The application prediction performance was evaluated on (a) the final-year students who have some experience in hacking and intend to choose information security and ethical hacking as their profession and (b) professionals from the industry who are working as White Hackers. The study aimed to understand cluster trends and their association with different Hat types, requiring consideration of trait correlations in the test data. Spearman&#x00027;s correlation analysis was conducted, revealing moderate inter-dependencies between traits. These correlations were generalized, associating certain traits with specific Hat types.</p>
<p>The clustering analysis highlighted distinct trends across datasets, with clusters exhibiting varying trait compositions. The validation of these clusters using a 6-cluster model showed a high prediction accuracy of 100%, with professionals predominantly classified as White Hats and students displaying a mix of White Hat and Gray Hat tendencies. It has successfully mapped the different clusters with the different Hat types in the test dataset (see <xref ref-type="table" rid="T9">Table 9</xref>) with 88% accuracy. This can predict 11.7% of our false understanding of test data to consider two correctly predicted students as we conceived Gray Hats as White Hats. Previous research (Matulessy and Humaira, <xref ref-type="bibr" rid="B26">2017</xref>) being conducted under the psychology domain only discusses results at generalized higher levels, covers no scientific experimentation, and has no detail of cluster assignments; therefore, it was neither possible to correctly understand individual tests nor the implementation done for cyber-criminal identification as hackers.</p>
<sec>
<title>6.1 Implications</title>
<p>Incorporating personality profiling methodologies within the realm of cybersecurity elicits profound ethical inquiries necessitating meticulous examination. Chief among these concerns is the pivotal issue of privacy, wherein the acquisition and scrutiny of individuals&#x00027; personality traits may encroach upon their privacy entitlements, and absent explicit consent and robust protective measures, with a palpable risk of unauthorized access to sensitive personal data, potentially precipitating privacy breaches and data misuse. Additionally, the deployment of personality profiling algorithms introduces the specter of bias, engendering the prospect of unjust treatment or discriminatory practices targeting specific individuals or demographic groups.</p>
<p>Securing informed consent stands as a crucial element in navigating these ethical challenges. Organizations are responsible for ensuring that individuals are comprehensively informed about the intentions and potential consequences of gathering and scrutinizing their personality data for cybersecurity aims. This empowers individuals to make informed decisions regarding their participation, allowing them to grant consent or abstain. Transparency and accountability take center stage in this process, compelling organizations to openly disclose their data management procedures and to shoulder accountability for any ethical implications arising from the application of personality profiling.</p>
<p>Moreover, the cultivation of sustainable cybersecurity practices assumes critical importance in ensuring that security measures are deployed to minimize adverse environmental and societal impacts. This necessitates concerted efforts to curtail the environmental footprint associated with cybersecurity operations, promote social responsibility, and fortify resilience against cyber threats over the long term. Organizations can bolster security postures by integrating sustainability imperatives into cybersecurity frameworks while advancing equitable and environmentally conscious digital ecosystems.</p>
<p>The implications of our research underscore the imperative of comprehending hacker behavior, advocating for ethical considerations in cybersecurity practices, and promoting sustainable security paradigms. Through the dissemination of awareness on these issues, our endeavor is to facilitate informed decision-making and foster responsible cybersecurity practices that accord primacy to principles of privacy, equity, and sustainability.</p>
</sec>
<sec>
<title>6.2 Conclusion and future work</title>
<p>Following the research, it can be concluded that at a higher level, the hackers possess personality traits of agreeableness, neuroticism, and openness to experience. K-means algorithm of machine learning can be used to detect the personality traits of hackers. This research is an in-depth study to establish a quantitative and statistically significant mapping between predicted clusters and their respective Hat types using machine learning and correlation techniques. The mapping established in this research justifies the test dataset prediction performance accuracy of &#x0007E;94%. Cross-validation was not utilized due to the ample size of the training set. Additionally, the training and test sets were distinct. For future work, it is suggested that if reliable access to hackers becomes available, the training set could primarily consist of hacker data, which would then be validated using cross-validation techniques.</p>
<p>The model must also validate the test dataset for Black Hat types from reliable resources. Further work can be done to make this approach more advanced by replacing the questionnaire with some other graphical or pictorial techniques to judge the personalities of employees before the contract signup stage or at the time of the signup process on office systems.</p>
<p>Despite the strength of our approach and findings, it is important to recognize some limitations. One key issue is the size and diversity of our sample. Our study&#x00027;s sample might not be big or varied enough to apply our findings to all hackers. Most of our participants were final-year students and cybersecurity professionals, so our conclusions might not fully represent all hacker personality traits. In addition, since our sample was mostly male, we might not have captured the full range of hacker demographics. Additionally, relying on self-reported data and personality tests could introduce biases. Participants might try to give answers they think are socially desirable, affecting the accuracy of our data.</p>
<p>Finally, our study focused on specific personality traits linked to hackers, but there could be other factors at play in cybersecurity behavior. Future research should aim to overcome these limitations by using more diverse samples, which would help make our findings more reliable and widely applicable.</p></sec>
</sec>
<sec sec-type="data-availability" id="s7">
<title>Data availability statement</title>
<p>The raw data supporting the conclusions of this article will be made available by the authors, without undue reservation.</p></sec>
<sec sec-type="ethics-statement" id="s8">
<title>Ethics statement</title>
<p>Ethical review and approval was not required for the study on human participants in accordance with the local legislation and institutional requirements. Written informed consent from the [patients/ participants OR patients/participants legal guardian/next of kin] was not required to participate in this study in accordance with the national legislation and the institutional requirements.</p></sec>
<sec sec-type="author-contributions" id="s9">
<title>Author contributions</title>
<p>UH: Conceptualization, Formal analysis, Investigation, Methodology, Writing &#x02013; original draft, Writing &#x02013; review and editing. OS: Methodology, Supervision, Validation, Writing &#x02013; review and editing. KK: Methodology, Supervision, Writing &#x02013; review and editing. AA: Methodology, Resources, Writing &#x02013; review and editing. NI: Methodology, Supervision, Writing &#x02013; review and editing.</p></sec>
</body>
<back>
<sec sec-type="funding-information" id="s10">
<title>Funding</title>
<p>The author(s) declare that no financial support was received for the research, authorship, and/or publication of this article.</p>
</sec>
<sec sec-type="COI-statement" id="conf1">
<title>Conflict of interest</title>
<p>The authors declare that the research was conducted in the absence of any commercial or financial relationships that could be construed as a potential conflict of interest.</p>
</sec>
<sec sec-type="disclaimer" id="s11">
<title>Publisher&#x00027;s note</title>
<p>All claims expressed in this article are solely those of the authors and do not necessarily represent those of their affiliated organizations, or those of the publisher, the editors and the reviewers. Any product that may be evaluated in this article, or claim that may be made by its manufacturer, is not guaranteed or endorsed by the publisher.</p>
</sec>
<ref-list>
<title>References</title>
<ref id="B1">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Adali</surname> <given-names>S.</given-names></name> <name><surname>Golbeck</surname> <given-names>J.</given-names></name></person-group> (<year>2012</year>). <article-title>&#x0201C;Predicting personality with social behavior,&#x0201D;</article-title> in <source>2012 IEEE/ACM International Conference on Advances in Social Networks Analysis and Mining</source> (<publisher-loc>Istanbul</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>302</fpage>&#x02013;<lpage>309</lpage>.</citation>
</ref>
<ref id="B2">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Adewumi</surname> <given-names>A. O.</given-names></name> <name><surname>Akinyelu</surname> <given-names>A. A.</given-names></name></person-group> (<year>2017</year>). <article-title>A survey of machine-learning and nature-inspired based credit card fraud detection techniques</article-title>. <source>Int. J. Syst. Assurance Eng. Manage.</source><volume>8</volume>, <fpage>937</fpage>&#x02013;<lpage>953</lpage>. <pub-id pub-id-type="doi">10.1007/s13198-016-0551-y</pub-id></citation>
</ref>
<ref id="B3">
<citation citation-type="web"><person-group person-group-type="author"><name><surname>Akdag</surname> <given-names>M.</given-names></name></person-group> (<year>2020</year>). <source>Open Psychometrics, Big Five Personality Test, International Personality Item Pool IPIP-BFFM</source>. Available online at: <ext-link ext-link-type="uri" xlink:href="https://www.kaggle.com/akdagmelih/five-personality-clusters-k-means">https://www.kaggle.com/akdagmelih/five-personality-clusters-k-means</ext-link> (accessed November 27, 2023).</citation>
</ref>
<ref id="B4">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Alashti</surname> <given-names>Z. F.</given-names></name> <name><surname>Bojnordi</surname> <given-names>A. J. J.</given-names></name> <name><surname>Sani</surname> <given-names>S. M. S.</given-names></name></person-group> (<year>2022</year>). <article-title>Toward a carnivalesque analysis of hacking: a qualitative study of Iranian hackers</article-title>. <source>Asian J. Soc. Sci</source>. <volume>50</volume>, <fpage>147</fpage>&#x02013;<lpage>155</lpage>. <pub-id pub-id-type="doi">10.1016/j.ajss.2022.01.001</pub-id></citation>
</ref>
<ref id="B5">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Aldhyani</surname> <given-names>T. H.</given-names></name> <name><surname>Alkahtani</surname> <given-names>H.</given-names></name></person-group> (<year>2022</year>). <article-title>Attacks to autonomous vehicles: a deep learning algorithm for cybersecurity</article-title>. <source>Sensors</source> <volume>22</volume>, <fpage>360</fpage>. <pub-id pub-id-type="doi">10.3390/s22010360</pub-id><pub-id pub-id-type="pmid">35009899</pub-id></citation></ref>
<ref id="B6">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ali</surname> <given-names>A.</given-names></name> <name><surname>Wasim</surname> <given-names>A.</given-names></name> <name><surname>Husam</surname> <given-names>A.</given-names></name> <name><surname>Manasa</surname> <given-names>K. N.</given-names></name></person-group> (<year>2020</year>). <article-title>Crime analysis and prediction using K-means clustering technique</article-title>. <source>EPRA Int. J. Econ. Business Rev.</source> <volume>3</volume>, <fpage>2925</fpage>&#x02013;<lpage>2929</lpage>. <pub-id pub-id-type="doi">10.36713/epra2016</pub-id></citation>
</ref>
<ref id="B7">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Back</surname> <given-names>S.</given-names></name> <name><surname>LaPrade</surname> <given-names>J.</given-names></name> <name><surname>Shehadeh</surname> <given-names>L.</given-names></name> <name><surname>Kim</surname> <given-names>M.</given-names></name></person-group> (<year>2019</year>). <article-title>&#x0201C;Youth hackers and adult hackers in South Korea: An application of cybercriminal profiling,&#x0201D;</article-title> in <source>2019 IEEE European Symposium on Security and Privacy Workshops (EuroS&#x00026;PW)</source> (<publisher-loc>Stockholm</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>410</fpage>&#x02013;<lpage>413</lpage>.</citation>
</ref>
<ref id="B8">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Bakas</surname> <given-names>A.</given-names></name> <name><surname>Wagner</surname> <given-names>A.</given-names></name> <name><surname>Johnston</surname> <given-names>S.</given-names></name> <name><surname>Kennison</surname> <given-names>S.</given-names></name> <name><surname>Chan-Tin</surname> <given-names>E.</given-names></name></person-group> (<year>2021</year>). <article-title>Impact of personality types and matching messaging on password strength</article-title>. <source>EAI Endors. Trans. Secur. Safety</source>. 8, e1-e1. <pub-id pub-id-type="doi">10.4108/eai.1-6-2021.170012</pub-id></citation>
</ref>
<ref id="B9">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Buch</surname> <given-names>R.</given-names></name> <name><surname>Dhatri</surname> <given-names>G.</given-names></name> <name><surname>Pooja</surname> <given-names>K.</given-names></name> <name><surname>Nirali</surname> <given-names>B.</given-names></name></person-group> (<year>2017</year>). <article-title>World of cyber security and cybercrime</article-title>. <source>RTPL</source> <volume>4</volume>, <fpage>18</fpage>&#x02013;<lpage>23</lpage>.</citation>
</ref>
<ref id="B10">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Chayal</surname> <given-names>N. M.</given-names></name> <name><surname>Patel</surname> <given-names>N. P.</given-names></name></person-group> (<year>2021</year>). <article-title>Review of machine learning and data mining methods to predict different cyberattacks</article-title>. <source>Data Sci. Intellig. Applicat.</source> 43&#x02013;51. <pub-id pub-id-type="doi">10.1007/978-981-15-4474-3_5</pub-id></citation>
</ref>
<ref id="B11">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Chng</surname> <given-names>S.</given-names></name> <name><surname>Lu</surname> <given-names>H. Y.</given-names></name> <name><surname>Kumar</surname> <given-names>A.</given-names></name> <name><surname>Yau</surname> <given-names>D.</given-names></name></person-group> (<year>2022</year>). <article-title>Hacker types, motivations and strategies: A comprehensive framework</article-title>. <source>Comp. Human Behav. Rep.</source> <volume>5</volume>, <fpage>100167</fpage>. <pub-id pub-id-type="doi">10.1016/j.chbr.2022.100167</pub-id></citation>
</ref>
<ref id="B12">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Corallo</surname> <given-names>A.</given-names></name> <name><surname>Lazoi</surname> <given-names>M.</given-names></name> <name><surname>Lezzi</surname> <given-names>M.</given-names></name> <name><surname>Luperto</surname> <given-names>A.</given-names></name></person-group> (<year>2022</year>). <article-title>Cybersecurity awareness in the context of the Industrial Internet of Things: a systematic literature review</article-title>. <source>Comp. Indust.</source> <volume>137</volume>, <fpage>103614</fpage>. <pub-id pub-id-type="doi">10.1016/j.compind.2022.103614</pub-id></citation>
</ref>
<ref id="B13">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Del Pozo</surname> <given-names>I.</given-names></name> <name><surname>Iturralde</surname> <given-names>M.</given-names></name> <name><surname>Restrepo</surname> <given-names>F.</given-names></name></person-group> (<year>2018</year>). <article-title>&#x0201C;Social engineering: Application of psychology to information security,&#x0201D;</article-title> in <source>2018 6th International Conference on Future Internet of Things and Cloud Workshops (FiCloudW)</source> (<publisher-loc>Barcelona</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>108</fpage>&#x02013;<lpage>114</lpage>.</citation>
</ref>
<ref id="B14">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Fox</surname> <given-names>B.</given-names></name> <name><surname>Holt</surname> <given-names>T. J.</given-names></name></person-group> (<year>2021</year>). <article-title>Use of a multitheoretic model to understand and classify juvenile computer hacking behavior</article-title>. <source>Crim. Justice Behav.</source> <volume>48</volume>, <fpage>943</fpage>&#x02013;<lpage>963</lpage>. <pub-id pub-id-type="doi">10.1177/0093854820969754</pub-id></citation>
</ref>
<ref id="B15">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Geluvaraj</surname> <given-names>B.</given-names></name> <name><surname>Satwik</surname> <given-names>P. M.</given-names></name> <name><surname>Ashok Kumar</surname> <given-names>T. A.</given-names></name></person-group> (<year>2019</year>). <article-title>&#x0201C;The future of cybersecurity: Major role of artificial intelligence, machine learning, and deep learning in cyberspace,&#x0201D;</article-title> in <source>International Conference on Computer Networks and Communication Technologies</source> (<publisher-loc>Cham</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>739</fpage>&#x02013;<lpage>747</lpage>.</citation>
</ref>
<ref id="B16">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Golbeck</surname> <given-names>J.</given-names></name> <name><surname>Robles</surname> <given-names>C.</given-names></name> <name><surname>Edmondson</surname> <given-names>M.</given-names></name> <name><surname>Turner</surname> <given-names>K.</given-names></name></person-group> (<year>2011</year>). <article-title>&#x0201C;Predicting personality from twitter,&#x0201D;</article-title> in <source>2011 IEEE Third International Conference on Privacy, Security, Risk and Trust and 2011 IEEE Third International Conference on Social Computing</source> (<publisher-loc>Boston</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>149</fpage>&#x02013;<lpage>156</lpage>.</citation>
</ref>
<ref id="B17">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Gulati</surname> <given-names>J.</given-names></name> <name><surname>Priya</surname> <given-names>B.</given-names></name> <name><surname>Bharti</surname> <given-names>S.</given-names></name> <name><surname>Anu</surname> <given-names>S. L.</given-names></name></person-group> (<year>2016</year>). <article-title>A study of the relationship between performance, temperament, and personality of a software programmer</article-title>. <source>ACM SIGSOFT Softw. Eng. Notes</source> <volume>41</volume>, <fpage>1</fpage>&#x02013;<lpage>5</lpage>. <pub-id pub-id-type="doi">10.1145/2853073.2853089</pub-id></citation>
</ref>
<ref id="B18">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Imran</surname> <given-names>M.</given-names></name> <name><surname>Faisal</surname> <given-names>M.</given-names></name> <name><surname>Islam</surname> <given-names>N.</given-names></name></person-group> (<year>2019</year>). <article-title>&#x0201C;Problems and vulnerabilities of ethical hacking in Pakistan,&#x0201D;</article-title> in <source>2019 Second International Conference on Latest Trends in Electrical Engineering and Computing Technologies (INTELLECT)</source> (<publisher-loc>Karachi</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>1</fpage>&#x02013;<lpage>6</lpage>.</citation>
</ref>
<ref id="B19">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Islam</surname> <given-names>N.</given-names></name> <name><surname>Shaikh</surname> <given-names>A.</given-names></name> <name><surname>Qaiser</surname> <given-names>A.</given-names></name> <name><surname>Asiri</surname> <given-names>Y.</given-names></name> <name><surname>Almakdi</surname> <given-names>S.</given-names></name> <name><surname>Sulaiman</surname> <given-names>A.</given-names></name> <etal/></person-group>. (<year>2021</year>). <article-title>Ternion: an autonomous model for fake news detection</article-title>. <source>Appl. Sci.</source> <volume>11</volume>, <fpage>9292</fpage>. <pub-id pub-id-type="doi">10.3390/app11199292</pub-id></citation>
</ref>
<ref id="B20">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Islam</surname> <given-names>N.</given-names></name> <name><surname>Shaikh</surname> <given-names>Z. A.</given-names></name></person-group> (<year>2016</year>). <article-title>&#x0201C;A study of research trends and issues in wireless ad hoc networks,&#x0201D;</article-title> in <source>Mobile Computing and Wireless Networks: Concepts, Methodologies, Tools, and Applications</source>, ed I. Management Association (IGI Global), <fpage>1819</fpage>&#x02013;<lpage>1859</lpage>. <pub-id pub-id-type="doi">10.4018/978-1-4666-8751-6.ch081</pub-id></citation>
</ref>
<ref id="B21">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Javaid</surname> <given-names>M. A.</given-names></name></person-group> (<year>2013</year>). <article-title>Psychology of hackers</article-title>. <source>SSRN Electr. J</source>. 15, 26. <pub-id pub-id-type="doi">10.2139/ssrn.2342620</pub-id></citation>
</ref>
<ref id="B22">
<citation citation-type="web"><person-group person-group-type="author"><name><surname>John</surname> <given-names>P.</given-names></name> <name><surname>Oliver</surname> <given-names>Sanjay, S.</given-names></name></person-group> (<year>1999</year>). <source>The Big-Five Trait Taxonomy: History, Measurement, and Theoretical Perspectives</source>. Berkeley: University of California. Available online at: <ext-link ext-link-type="uri" xlink:href="https://personality-project.org/revelle/syllabi/classreadings/john.pdf">https://personality-project.org/revelle/syllabi/classreadings/john.pdf</ext-link> (accessed March 10, 2024).</citation>
</ref>
<ref id="B23">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Larose</surname> <given-names>D. T.</given-names></name> <name><surname>Chantal</surname> <given-names>D. L.</given-names></name></person-group> (<year>2014</year>). <article-title>&#x0201C;Discovering knowledge in data: an introduction to data mining,&#x0201D;</article-title> in <source>IEEE Computer Society, 2nd ed</source>. <publisher-loc>Hoboken</publisher-loc>: <publisher-name>John Wiley and Sons</publisher-name>.</citation>
</ref>
<ref id="B24">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Lima</surname> <given-names>A. C. E.</given-names></name> <name><surname>De Castro</surname> <given-names>L. N.</given-names></name></person-group> (<year>2014</year>). <article-title>A multi-label, semi-supervised classification approach applied to personality prediction in social media</article-title>. <source>Neural Netw.</source> <volume>58</volume>, <fpage>122</fpage>&#x02013;<lpage>130</lpage>. <pub-id pub-id-type="doi">10.1016/j.neunet.2014.05.020</pub-id><pub-id pub-id-type="pmid">24969690</pub-id></citation></ref>
<ref id="B25">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Martineau</surname> <given-names>M.</given-names></name> <name><surname>Spiridon</surname> <given-names>E.</given-names></name> <name><surname>Aiken</surname> <given-names>M.</given-names></name></person-group> (<year>2023</year>). <article-title>A comprehensive framework for cyber behavioral analysis based on a systematic review of cyber profiling literature</article-title>. <source>Forens. Sci.</source> <volume>3</volume>, <fpage>452</fpage>&#x02013;<lpage>477</lpage> <pub-id pub-id-type="doi">10.3390/forensicsci3030032</pub-id></citation>
</ref>
<ref id="B26">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Matulessy</surname> <given-names>A.</given-names></name> <name><surname>Humaira</surname> <given-names>N. H</given-names></name></person-group>. (<year>2017</year>). <article-title>Hacker personality profiles reviewed in terms of the big five personality traits</article-title>. <source>Psychol. Behav. Sci.</source> <volume>5</volume>, <fpage>137</fpage>&#x02013;<lpage>142</lpage>. <pub-id pub-id-type="doi">10.11648/j.pbs.20160506.12</pub-id></citation>
</ref>
<ref id="B27">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>McAlaney</surname> <given-names>J.</given-names></name> <name><surname>Hambidge</surname> <given-names>S.</given-names></name> <name><surname>Kimpton</surname> <given-names>E.</given-names></name> <name><surname>Thackray</surname> <given-names>H.</given-names></name></person-group> (<year>2020</year>). <article-title>&#x0201C;Knowledge is power: an analysis of discussions on hacking forums,&#x0201D;</article-title> in <source>2020 IEEE European Symposium on Security and Privacy Workshops (EuroS&#x00026;PW)</source> (<publisher-loc>Genoa</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>477</fpage>&#x02013;<lpage>483</lpage>.</citation>
</ref>
<ref id="B28">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Medoh</surname> <given-names>C.</given-names></name> <name><surname>Telukdarie</surname> <given-names>A.</given-names></name></person-group> (<year>2022</year>). <article-title>The future of cybersecurity: a system dynamics approach</article-title>. <source>Procedia Comp. Sci.</source> <volume>200</volume>, <fpage>318</fpage>&#x02013;<lpage>326</lpage>. <pub-id pub-id-type="doi">10.1016/j.procs.2022.01.230</pub-id></citation>
</ref>
<ref id="B29">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Mohammed</surname> <given-names>Z. H.</given-names></name> <name><surname>Chankaew</surname> <given-names>K.</given-names></name> <name><surname>Vallabhuni</surname> <given-names>R. R.</given-names></name> <name><surname>Sonawane</surname> <given-names>V. R.</given-names></name> <name><surname>Ambala</surname> <given-names>S.</given-names></name> <name><surname>Markkandan</surname> <given-names>S.</given-names></name></person-group> (<year>2023</year>). <article-title>Blockchain-enabled bioacoustics signal authentication for cloud-based electronic medical records</article-title>. <source>Measurem. Sens</source>. 26, 100706. <pub-id pub-id-type="doi">10.1016/j.measen.2023.100706</pub-id></citation>
</ref>
<ref id="B30">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Novikova</surname> <given-names>I. A.</given-names></name> <name><surname>Alexandra</surname> <given-names>A. V.</given-names></name></person-group> (<year>2019</year>). <article-title>&#x0201C;The five-factor model: contemporary personality theory,&#x0201D;</article-title> in <source>Cross-Cultural Psychology: Contemporary Themes and Perspectives</source> (<publisher-loc>Hoboken</publisher-loc>: <publisher-name>John Wiley and Sons Press</publisher-name>), <fpage>685</fpage>&#x02013;<lpage>706</lpage>.</citation>
</ref>
<ref id="B31">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Odemis</surname> <given-names>M.</given-names></name> <name><surname>Yucel</surname> <given-names>C.</given-names></name> <name><surname>Koltuksuz</surname> <given-names>A.</given-names></name></person-group> (<year>2022</year>). <article-title>Detecting user behavior in cyber threat intelligence: development of honeypsy system</article-title>. <source>Secur Commun. Netw.</source> <volume>2022</volume>, <fpage>7620125</fpage>. <pub-id pub-id-type="doi">10.1155/2022/7620125</pub-id></citation>
</ref>
<ref id="B32">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Pastrana</surname> <given-names>S.</given-names></name> <name><surname>Hutchings</surname> <given-names>A.</given-names></name> <name><surname>Caines</surname> <given-names>A.</given-names></name> <name><surname>Buttery</surname> <given-names>P.</given-names></name></person-group> (<year>2018</year>). <article-title>&#x0201C;Characterizing eve: Analysing cybercrime actors in a large underground forum,&#x0201D;</article-title> in <source>International Symposium on Research in Attacks, Intrusions, and Defenses (Cham:</source> Springer), <fpage>207</fpage>&#x02013;<lpage>227</lpage>.</citation>
</ref>
<ref id="B33">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Ramachandran</surname> <given-names>D.</given-names></name> <name><surname>Rajeev Ratna</surname> <given-names>V.</given-names></name> <name><surname>PT</surname> <given-names>V. R.</given-names></name> <name><surname>Garip</surname> <given-names>I.</given-names></name></person-group> (<year>2022</year>). A low-latency and high-throughput multipath technique to overcome black hole attack in mobile <italic>ad hoc</italic> network (MTBD). <italic>Secur. Commun. Netw</italic>. 2022, 8067447. <pub-id pub-id-type="doi">10.1155/2022/8067447</pub-id></citation>
</ref>
<ref id="B34">
<citation citation-type="web"><person-group person-group-type="author"><name><surname>Shackelford</surname> <given-names>S. J.</given-names></name> <name><surname>Raymond</surname> <given-names>A.</given-names></name> <name><surname>Fort</surname> <given-names>T. L.</given-names></name> <name><surname>Charoen</surname> <given-names>D. A.</given-names></name></person-group> (<year>2016</year>). <source>Sustainable Cybersecurity: Applying Lessons from the Green Movement to Managing Cyber Attacks</source>. Chicago: University of Illinios Law Review. Available online at: <ext-link ext-link-type="uri" xlink:href="https://illinoislawrev.web.illinois.edu/wp-content/uploads/2016/10/Shackelford.pdf">https://illinoislawrev.web.illinois.edu/wp-content/uploads/2016/10/Shackelford.pdf</ext-link> (accessed March 10, 2024).</citation>
</ref>
<ref id="B35">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Siddiqi</surname> <given-names>M. A.</given-names></name> <name><surname>Pak</surname> <given-names>W.</given-names></name> <name><surname>Siddiqi</surname> <given-names>M. A.</given-names></name></person-group> (<year>2022</year>). <article-title>A study on the psychology of social engineering-based cyberattacks and existing countermeasures</article-title>. <source>Appl. Sci</source>. 12, 6042. <pub-id pub-id-type="doi">10.3390/app12126042</pub-id></citation>
</ref>
<ref id="B36">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Sood</surname> <given-names>A. K.</given-names></name> <name><surname>Enbody</surname> <given-names>R. J.</given-names></name></person-group> (<year>2013</year>). <article-title>Crimeware-as-a-service: a survey of commoditized crimeware in the underground market</article-title>. <source>Int. J. Criti. Infrastruct. Protect.</source> <volume>6</volume>, <fpage>28</fpage>&#x02013;<lpage>38</lpage>. <pub-id pub-id-type="doi">10.1016/j.ijcip.2013.01.002</pub-id></citation>
</ref>
<ref id="B37">
<citation citation-type="web"><person-group person-group-type="author"><name><surname>Su&#x000E1;rez &#x000C1;lvarez</surname> <given-names>J.</given-names></name> <name><surname>Pedrosa</surname> <given-names>I.</given-names></name> <name><surname>Lozano</surname> <given-names>L. M.</given-names></name> <name><surname>Garc&#x000ED;a Cueto</surname> <given-names>E.</given-names></name> <name><surname>Cuesta Izquierdo</surname> <given-names>M.</given-names></name> <name><surname>Mu&#x000F1;iz Fern&#x000E1;ndez</surname> <given-names>J.</given-names></name></person-group> (<year>2018</year>). <article-title>&#x0201C;Using reversed items in Likert scales: A questionable practice,&#x0201D;</article-title> in <source>Psicothema</source>, 30. Available online at: <ext-link ext-link-type="uri" xlink:href="https://digibuo.uniovi.es/dspace/bitstream/handle/10651/48979/Using%20.pdf?sequence=1">https://digibuo.uniovi.es/dspace/bitstream/handle/10651/48979/Using%20.pdf?sequence=1</ext-link> (accessed March 10, 2024).<pub-id pub-id-type="pmid">29694314</pub-id></citation></ref>
<ref id="B38">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Suryapranata</surname> <given-names>K. P.</given-names></name> <name><surname>Louis</surname> <given-names>P. K.</given-names></name> <name><surname>Gede</surname> <given-names>H.</given-names></name> <name><surname>Yaya</surname> <given-names>H.</given-names></name> <name><surname>Bahtiar</surname> <given-names>S. A.</given-names></name> <etal/></person-group>. (<year>2017</year>). <article-title>&#x0201C;Personality trait prediction based on game character design using a machine learning approach,&#x0201D;</article-title> in <source>Proc. ICITech</source> (<publisher-loc>Salatiga</publisher-loc>: <publisher-name>IEEE</publisher-name>), <fpage>1</fpage>&#x02013;<lpage>5</lpage>.</citation>
</ref>
<ref id="B39">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Tamboli</surname> <given-names>M. S.</given-names></name> <name><surname>Vallabhuni</surname> <given-names>R. R.</given-names></name> <name><surname>Shinde</surname> <given-names>A.</given-names></name> <name><surname>Kataraki</surname> <given-names>K.</given-names></name> <name><surname>Makineedi</surname> <given-names>R. B.</given-names></name></person-group> (<year>2023</year>). <article-title>Block chain based integrated data aggregation and segmentation framework by reputation metrics for mobile adhoc networks</article-title>. <source>Measurem.: Sens.</source> <volume>27</volume>, <fpage>100803</fpage>. <pub-id pub-id-type="doi">10.1016/j.measen.2023.100803</pub-id></citation>
</ref>
<ref id="B40">
<citation citation-type="web"><person-group person-group-type="author"><name><surname>Tan</surname> <given-names>P. N.</given-names></name> <name><surname>Steinbach</surname> <given-names>M.</given-names></name> <name><surname>Kumar</surname> <given-names>V.</given-names></name></person-group> (<year>2016</year>). <source>Introduction to Data Mining</source>. Washington DC: Pearson Education India. Available online at: <ext-link ext-link-type="uri" xlink:href="https://www-users.cse.umn.edu/&#x0007E;kumar001/dmbook/ch7_clustering.pdf">https://www-users.cse.umn.edu/&#x0007E;kumar001/dmbook/ch7_clustering.pdf</ext-link> (accessed March 10, 2024).</citation>
</ref>
<ref id="B41">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Tandera</surname> <given-names>T.</given-names></name> <name><surname>Derwin</surname> <given-names>S.</given-names></name> <name><surname>Rini</surname> <given-names>W.</given-names></name> <name><surname>Yen</surname> <given-names>L. P.</given-names></name></person-group> (<year>2017</year>). <article-title>Personality prediction system from Facebook users</article-title>. <source>Procedia Comp. Sci.</source> <volume>116</volume>, <fpage>604</fpage>&#x02013;<lpage>611</lpage>. <pub-id pub-id-type="doi">10.1016/j.procs.2017.10.016</pub-id></citation>
</ref>
<ref id="B42">
<citation citation-type="journal"><person-group person-group-type="author"><name><surname>Wong</surname> <given-names>S.</given-names></name> <name><surname>Dennis Sai-fu</surname> <given-names>F.</given-names></name></person-group> (<year>2020</year>). <article-title>Development of the cybercrime rapid identification tool for adolescents</article-title>. <source>Int. J. Environ. Res. Public Health</source> <volume>17</volume>, <fpage>4691</fpage>. <pub-id pub-id-type="doi">10.3390/ijerph17134691</pub-id><pub-id pub-id-type="pmid">32629769</pub-id></citation></ref>
<ref id="B43">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Xie</surname> <given-names>B.</given-names></name> <name><surname>Wei</surname> <given-names>N.</given-names></name></person-group> (<year>2022</year>). <article-title>&#x0201C;Personality trait identification based on hidden semi-Markov model in online social networks,&#x0201D;</article-title> in <source>Proceedings of the 2022 7th International Conference on Intelligent Information Technology (ICIIT &#x00027;22)</source> (<publisher-loc>New York, NY</publisher-loc>: <publisher-name>Association for Computing Machinery</publisher-name>), <fpage>52</fpage>&#x02013;<lpage>58</lpage>. <pub-id pub-id-type="doi">10.1145/3524889.3524898</pub-id></citation>
</ref>
<ref id="B44">
<citation citation-type="book"><person-group person-group-type="author"><name><surname>Zheng</surname> <given-names>R.</given-names></name> <name><surname>Qin</surname> <given-names>Y.</given-names></name> <name><surname>Huang</surname> <given-names>Z.</given-names></name> <name><surname>Chen</surname> <given-names>H.</given-names></name></person-group> (<year>2003</year>). <article-title>&#x0201C;Authorship analysis in cybercrime investigation,&#x0201D;</article-title> in <source>International Conference on Intelligence and Security Informatics</source> (<publisher-loc>Berlin</publisher-loc>: <publisher-name>Springer</publisher-name>), <fpage>59</fpage>&#x02013;<lpage>73</lpage>.</citation>
</ref>
</ref-list>
</back>
</article> 
