Last updated

The TOC search (Terrorist and Organized Criminal Search) is a dynamic database which offers comprehensive information on global terrorist networks and helps researchers, analysts, students and others to prevent terrorism. It is the result of a common project realized by the Faculty of Security Studies and Faculty of Mathematics, University of Belgrade, which had started the program in December 2007. The scope of TOCSearch is to provide in-depth research and analysis on terrorist incidents, terrorist groups, organizations, their members, leaders and also links and relations between the individuals and groups. The purpose of the database is to integrate data from a variety of sources, including foreign and domestic news, professional security journals, reports and databases, and academic works.



The starting point in the TOCSearch project was the data presented on the map Al-Qaeda Network: Principals, Supporters, Selected Cells and Significant Activities (1992–2004). The map was prepared by J. L. Boesen, Raytheon Genesis Facility Institute Reston (2004), using data derived from open sources. The data presented in the map were classified and stored in order to create backbone of the database.


The data in the database are classified in seven entities: individuals, groups, organizations, supporters, actions, links and GMC reports. The database contains simple and advanced search features.

The simple search enables the researcher to explore the chosen entity by given keyword or part of an entity name. The advanced search feature is implemented for individuals, groups, organizations, supporters and actions. It is performed by using different properties: alias, belongs to organization, belongs to group, leader, religion, in relation with, type or actors of the attack, etc. All search results are presented together with the basic information on the found subjects, enabling in-depth search to be performed as well.

An important feature of TOCSearch is the fact that links between the mentioned terrorist-related categories are stored and classified in the database. The results of both simple and advanced searches provide information whether there is a link (active or inactive) from a particular item. The in-depth search feature gives more information on the found link. This is a unique feature of TOCSearch which no other terrorist database has had up to the point of its creation.

Incoming reports are sorted and stored by date in GMC section of the TOC search database. The George Marshall Center provided TOCSearch with their GMC reports archive and they send daily PTSS and other GMC reports. In this way, a constant refreshment of the base with up-to-date information has been provided. The TOCSearch simple search feature through GMC reports is implemented, which enables the exploration of GMC section by using keywords.

At each moment of using TOCSearch, one can immediately start a new search or switch to advanced search tool. While exploring the database, a researcher usually performs multiple searches. In order to help the user, a tool was implemented called the "select tool". This tool enables the user to pull individual important results obtained from different searches into one place. In this way, all the data that are essential in the research are available during the further exploration. The data in the “selection” tool are easily added or removed. By using option “Feedback” the user may send a message to an administrator on different topics (site bugs, erroneous data, comments, suggestions, etc.)

Preparation of reports

One of the key advantages of TOCSearch is the fact that its basic data source is verified information from the reports prepared and provided by George C Marshall European Center for Security Studies. The reports are produced by a special newsletter service supporting the counter-terrorism course at The George C. Marshall European Center for Security Studies, and it is created for educational purposes only. [1] The newsletter is produced from the open-source media reports by GMC postgraduate students and verified by senior experts and counter-terrorism officers. This is the main reason why PTSS has been chosen as the main data source for TOCSearch. Besides PTSS Reports, GMC also publishes several other reports based on different open source data, such as: Department of Homeland Security Report (DHS), Terrorism Open Source Intelligence Report (TOSIR), Insurgency Literature Review (ILR) and Terrorism Literature Report (TLR).

Availability of data

The information in TOCSearch's database is constantly updated from GMC reports and other publicly available, open-source materials. These include electronic news archives, existing data sets, secondary source materials such as books and journals, and legal documents. The development team performs constant verification of the data by comparing it with other sources and by internal checking of the data and related records.

It is also important to provide the protection of data stored in the database. In this scope, two levels of data access are implemented. The first level is named “blue key” and it is available for students and researchers in academic institutions and research centers. The “blue key” enables the access to all open-source data stored in the base. The second level of data access, named “red key” is reserved for legal authorities, state institutions, and state government. The “red key” opens the part of the database with confidential data. The owner of the “red key” also has access to the open source data, as the “blue key” owner. Only state institutions and agencies which have a contract with TOCSearch have an access to the red key data and are red key members.

Future uses

In the next phase of the project, several analytical features are to be incorporated in the database. Analytical tools will provide statistical information analysis of the global terrorist network. A researcher will be able to analyze terrorism trends over time and to compare different aspects of terrorism between countries, regions and terrorist groups (for example: type of terrorist attacks, level of organization, tactics, communication level, size of a terrorist group, age or race of its members, and many others). The results of statistical analysis will be presented graphically in various charts, showing the dependencies and / or the comparisons of the chosen aspects. The chart type can also be chosen by the user.

An analytically focused system will be used to understand the structure of different terrorist organizations with respect to particular attack types or regions of their activity. By using this system, intelligence analysts will be able to develop hypotheses and then validate them (or not) against the data in the database. In this way, it will be possible to provide certain predictions of international terrorism trends, seasonality, and periodicity of terrorist events.

In the future phase of the project, image search features are also planned. This tool will enable to search the image data base for related photographs of individuals or terrorist attacks by using keywords (individual's name, group / organization name, or the part of the name, specific terrorist incident, date, etc.).

Regarding the practical aspects of the database, the TOCSearch data were primarily collected by academic groups. This means that the development team was under no political or government pressure in terms of how to collect the data or how to classify them. Although TOCSearch is still in its construction phase, it has already been used in the purpose of Security of the Olympic Games in Beijing 2008, and was also used in the purpose of Security of the World Championship in Football 2010.

Related Research Articles

<span class="mw-page-title-main">Database</span> Organized collection of data in computing

In computing, a database is an organized collection of data stored and accessed electronically. Small databases can be stored on a file system, while large databases are hosted on computer clusters or cloud storage. The design of databases spans formal techniques and practical considerations, including data modeling, efficient data representation and storage, query languages, security and privacy of sensitive data, and distributed computing issues, including supporting concurrent access and fault tolerance.

Computer and network surveillance is the monitoring of computer activity and data stored locally on a computer or data being transferred over computer networks such as the Internet. This monitoring is often carried out covertly and may be completed by governments, corporations, criminal organizations, or individuals. It may or may not be legal and may or may not require authorization from a court or other independent government agencies. Computer and network surveillance programs are widespread today and almost all Internet traffic can be monitored.

<span class="mw-page-title-main">Information Awareness Office</span> DARPA division overseeing the "Total Information Awareness" program

The Information Awareness Office (IAO) was established by the United States Defense Advanced Research Projects Agency (DARPA) in January 2002 to bring together several DARPA projects focused on applying surveillance and information technology to track and monitor terrorists and other asymmetric threats to U.S. national security by achieving "Total Information Awareness" (TIA).

<span class="mw-page-title-main">Total Information Awareness</span> US mass detection program

Total Information Awareness (TIA) was a mass detection program by the United States Information Awareness Office. It operated under this title from February to May 2003 before being renamed Terrorism Information Awareness.

Open-source intelligence (OSINT) is the collection and analysis of data gathered from open sources to produce actionable intelligence. OSINT is primarily used in national security, law enforcement, and business intelligence functions and is of value to analysts who use non-sensitive intelligence in answering classified, unclassified, or proprietary intelligence requirements across the previous intelligence disciplines.

Internet research is the practice of using Internet information, especially free information on the World Wide Web, or Internet-based resources in research.

A sequence profiling tool in bioinformatics is a type of software that presents information related to a genetic sequence, gene name, or keyword input. Such tools generally take a query such as a DNA, RNA, or protein sequence or ‘keyword’ and search one or more databases for information related to that sequence. Summaries and aggregate results are provided in standardized format describing the information that would otherwise have required visits to many smaller sites or direct literature searches to compile. Many sequence profiling tools are software portals or gateways that simplify the process of finding information about a query in the large and growing number of bioinformatics databases. The access to these kinds of tools is either web based or locally downloadable executables.

Enterprise content management (ECM) extends the concept of content management by adding a timeline for each content item and, possibly, enforcing processes for its creation, approval and distribution. Systems using ECM generally provide a secure repository for managed items, analog or digital. They also include one methods for importing content to bring manage new items, and several presentation methods to make items available for use. Although ECM content may be protected by digital rights management (DRM), it is not required. ECM is distinguished from general content management by its cognizance of the processes and procedures of the enterprise for which it is created.

<span class="mw-page-title-main">Mozilla Application Suite</span> Discontinued Internet suite

The Mozilla Application Suite is a discontinued cross-platform integrated Internet suite. Its development was initiated by Netscape Communications Corporation, before their acquisition by AOL. It was based on the source code of Netscape Communicator. The development was spearheaded by the Mozilla Organization from 1998 to 2003, and by the Mozilla Foundation from 2003 to 2006.

<span class="mw-page-title-main">National Counterterrorism Center</span> U.S. government organization responsible for national and international counterterrorism efforts

The National Counterterrorism Center (NCTC) is a United States government organization responsible for national and international counterterrorism efforts. It is based in Liberty Crossing, a modern complex near Tysons Corner in McLean, Virginia. NCTC advises the United States on terrorism.

<span class="mw-page-title-main">Transnational organized crime</span> Organized crime across national borders

Transnational organized crime (TOC) is organized crime coordinated across national borders, involving groups or markets of individuals working in more than one country to plan and execute illegal business ventures. In order to achieve their goals, these criminal groups use systematic violence and corruption. Common transnational organized crimes include conveying drugs, conveying arms, trafficking for sex, toxic waste disposal, materials theft and poaching.

The MIPT Terrorism Knowledge Base (TKB) was an online portal containing information on terrorist incidents, leaders, groups, and related court cases. It was active from September 2004 to March 2008 and is now defunct, but the group profiles that were included in the knowledge base are now hosted by the National Consortium for the Study of Terrorism and Responses to Terrorism. The TKB was sponsored by the National Memorial Institute for the Prevention of Terrorism (MIPT), a non-profit organization funded by the United States Department of Homeland Security.

Knowledge management software is a subset of enterprise content management software, which contains a range of software that specializes in the way information is collected, stored and/or accessed. The concept of knowledge management is based on a range of practices used by an individual, a business, or a large corporation to identify, create, represent and redistribute information for a range of purposes. Software that enables an information practice or range of practices at any part of the processes of information management can be deemed to be called information management software. A subset of information management software that emphasizes an approach to build knowledge out of information that is managed or contained is often called knowledge management software.

The counter-terrorism page primarily deals with special police or military organizations that carry out arrest or direct combat with terrorists. This page deals with the other aspects of counter-terrorism:

The Keyword Services Platform (KSP) is a keyword research tool available through Microsoft adCenter, which contains a set of algorithms for providing information about keywords used in search engine queries.

<span class="mw-page-title-main">Metadata</span> Data about data

Metadata is "data that provides information about other data", but not the content of the data, such as the text of a message or the image itself. There are many distinct types of metadata, including:

International Aging Research Portfolio (IARP) is a non-profit, open-access knowledge management system incorporating grants, publications, conferences in natural and social & behavioral sciences. In addition to the advanced search and visual trend analysis tools the system includes a directory of research projects classified into categories related to aging research. The system uses automatic classification algorithms with elements of machine learning to assign research projects to the relevant categories. The directory is curated by many expert category editors and science advisory board members. The chair of the science advisory board is Dr. Charles Cantor.

The National Consortium for the Study of Terrorism and Responses to Terrorism (START) is an emeritus Homeland Security Centers of Excellence at the University of Maryland, College Park that researches the causes and consequences of terrorism in the United States and around the world. It maintains the Global Terrorism Database, which includes over 200,000 terrorist attacks and which it describes as the "most comprehensive unclassified data base on terrorist events in the world."

The Real Time Regional Gateway (RT-RG) is a data processing and data mining system introduced in 2007 by the US National Security Agency (NSA) and deployed during the American military operations in Iraq and Afghanistan. It is able to store, fuse, search and analyze data from numerous sources, from intercepted communications to open source information. It was effective in providing information about Iraqi insurgents who had eluded less comprehensive techniques.

<span class="mw-page-title-main">State Intelligence Agency (Bulgaria)</span>

The State Intelligence Agency (SIA) is a Bulgarian foreign intelligence service, which obtains, processes, analyzes and provides the state leadership with intelligence, assessments, analyses and prognoses, related to the national security, interests and priorities of the Republic of Bulgaria.


  1. PTSS - Program on Terrorism and Security Studies

As of this edit, this article uses content from "Terrorist and Organized Criminal Search Data Base" , which is licensed in a way that permits reuse under the Creative Commons Attribution-ShareAlike 3.0 Unported License, but not under the GFDL. All relevant terms must be followed.