Skip to content

Author

Kalin Kopanov

2 papers indexed here

We haven’t gathered this author’s papers yet. Follow them and we’ll fetch their work.

Not the right person? Other researchers publish under this name.

Open access Aug 2026

Time-Series and Social-Media Threat Analytics over a Deployed Cyber-Threat Knowledge Graph

Security teams decide which vulnerabilities to patch first, which alerts to trust, and whether social media warns of new threats earlier than the official feeds. We answer these questions by directly measuring EdgeGuard, a deployed cyber-threat knowledge graph that merges eleven public threat feeds into one Neo4j database via MISP (an open threat-sharing platform) and the STIX 2.1 exchange format, recording for every entry which feed reported it and when. These records let the graph be read as a time series. Read this way, it shows that half of the vulnerabilities known to have been exploited were listed as exploited within five days of their publication (352 cases), and that a large ingestion spike in early 2026 came from a single feed rather than a real attack wave. Benchmarked against 10,000 threat-related social-media posts, the graph already held 96% of the actionable vulnerabilities the posts discussed and reported them at least as quickly, while most posts carried no actionable signal and social media led only in early warning of active exploitation. A crowd-sourced community layer additionally supplies the only intelligence tagged by industry sector. The deployed graph is thus a clean, timely, and comprehensive base, and live social ingestion a small, targeted enhancement.

Kalin Kopanov, K. Dineva, Ivaylo Keremidarski et al. · 0 citations
Open access Jul 2026

Profile-Free Behavioral Characterization of Bot-like Activity in a Political Reply Ecosystem on X: A Case Study

Coordinated and bot-like activity on social media is usually studied with supervised detectors that need rich account data such as profiles, timelines, and follower networks, which is increasingly hard to obtain. We ask what can be established about a single account’s reply ecosystem from its publicly visible posts and replies alone, with no profiles, timelines, or follower data. In a case study of the reply ecosystem of an official political party account (23,953 replies by 1985 accounts, December 2025 to January 2026), we compute profile-free behavioral features covering text duplication, character-level entropy, timing regularity, reply latency, and post coverage, complemented by a co-commenting network analysis, and group active accounts with unsupervised density-based clustering. The clustering, combined with two transparent labeling rules, separates three behavioral tiers: templated amplifiers defined by text reuse, persistent responders with human-like text but extreme volume and coverage, and an organic remainder. The two non-organic tiers comprise 5.4% of accounts, yet produce 53.5% of all comments, a composition that is stable under resampling and threshold sensitivity analysis, with a failure mode that is only conservative, since over-strict settings leave a tier unassigned rather than reshaping it. The platform’s own spam flags, never used as input, rise steadily from organic accounts to templated amplifiers, consistent with the behavioral grouping.

Kalin Kopanov, Tatiana V. Atanasova · 0 citations