All problem statements
SIH26151SoftwareBlockchain & Cybersecurity

Dark web threat actor de-anonymization

National Technical Research Organisation (NTRO)

Ideas submitted
64 / 500
Deadline
30 September 2026
Category
Software
Theme
Blockchain & Cybersecurity

Looks like it needs

Web (React / Node)BlockchainCybersecurity

• Background The dark web has become a preferred operating space for threat actors in the modern age, mainly because it lets them hide their identity behind Tor hidden services, which makes attribution of threat actors operating on darkweb the main challenge for any investigation. Such threat actors carry out a wide range of unlawful activities such as drugs and arms sale, stolen data and hacking services, money laundering, terror financing, etc. The objective of this problem statement is to build a system for the deanonymization of dark web threat actors and link them to suspect real-world entities.

• Description The system shall deanonymize dark web threat actors by continuously gathering their footprints from a range of sources (marketplaces, forums, deep web etc.) and linking them to the identifying information available on those sources. The system envisages three core capabilities. First, finding misconfigurations in Tor hidden services—such as exposed server-status pages, SSL certificates tied to clearnet domains, default service banners, descriptor inconsistencies, etc and matching them with clearnet infrastructure to point to the likely origin servers. Second, mapping threat actors across multiple marketplaces into a single relationship graph of handles, PGP keys, wallets and trust links. Third, using AI-based analysis, including stylometric persona identification and behavioural profiling, to link rebranded or migrated personas to known threat actors. The system shall provide an analytical front end to query the database across a chosen timeline and shall work in an autonomous mode, drawing on available sources of good quality and reliability.

• Expected Solution An end-to-end system shall be developed for the collection, storage, contextualization and querying (through GUI/dashboards) of dark web threat actor intelligence—covering actor profiles, identifiers (handles, PGP keys, wallets etc.), hidden service infrastructure indicators, persona linkages, attribution confidence, category, last scan date and source. The system shall also provide the facility to export the result set in CSV, JSON and report formats.

How contested this one is

as of 28 Sept
64ideas submitted+12 in 2 days

That puts it 159th of the 240 statements that have any ideas at all, out of 240 on the board. It is moving, so the field here is already forming.

See what the whole field is picking →

Counted from the official portal twice a day. The portal itself only shows today.

What a jury will ask about this

  1. 01“Who actually faces this problem today?”

    What works: Naming one real person and what they do instead right now. Reading the statement back is not an answer, they already read it.

  2. 02“This already exists. Why yours?”

    What works: That existing tools are consumer products. Yours is built for the ministry, works offline, in the local language, on official data.

  3. 03“Then why has nobody solved it yet?”

    What works: The real blocker. No connectivity, no incentive, nobody owns the data. You only know this if you read the ministry's own reports.

All 18 questions, with the trap answers →

More in Blockchain & Cybersecurity

See all →