
Security News
Axios Supply Chain Attack Reaches OpenAI macOS Signing Pipeline, Forces Certificate Rotation
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.
Netanos (Named Entity-based Text ANonymization for Open Science) is a natural language processing software that anonymizes texts by identifying and replacing named entities. The key feature of NETANOS is that the anonymization preserves critical context that allows for secondary linguistic analyses on anonymized texts.
NETANOS requires Stanford's Named Entity Recognizer (Finkel, Grenager, & Manning, 2005). You can download the Java distribution here. Once you have it downloaded, the Stanford NER needs to be executed before NETANOS can be used. This can be done as follows (with Stanford NER running on port 8080):
netanos/libs/stanford-ner/ and run the following command (in Terminal) after unzipping the downloaded Stanford NER file:$ java -mx1000m -cp "./stanford-ner.jar:lib/*" edu.stanford.nlp.ie.NERServer -loadClassifier classifiers/english.muc.7class.distsim.crf.ser.gz -port 8080 -outputFormat inlineXML
./netanos to run your anonymization script with node run.jscrtl + cFurthermore, NETANOS relies on the following node.js-dependencies:
You can use npm install or compile NETANOS from source. For both installation types, make sure you've got the Node.js dependencies installed:
npm install ner
npm install promise
NETANOS can easily be installed via npm.
$ npm install netanos
The integration is illustrated below. The anonymization function takes the input string and a callback function as arguments and returns the anonymized string via the callback.
var netanos = require("netanos"); //note that this is different from the filepath in the from-source installation
var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
netanos.ner(input, function(output) {
console.log(output);
});
/*
"Barry and Rick spent more than 997 hours on writing the software. They started in January 14 2016 in Odessa."
*/
Alternatively, the NETANOS source-code can be integrated manually with the Netanos.js file as user endpoint.
run.js to set the input of your string.var netanos = require("./Netanos.js");
var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
netanos.ner(input, function(output) {
console.log(output);
});
/*
"Barry and Rick spent more than 997 hours on writing the software. They started in January 14 2016 in Odessa."
*/
run.js script:node run.js
npm testOnce the Java server is running, you can test the functionality of NETANOS with npm test. To do this, make sure you've got the JavaScript test framework mocha.js installed (use npm install mocha).
The tests will run for all four core methods of NETANOS.
NETANOS offers the following functionality:
netanos.anon): each identified entity is replaced with an indexed generic replacement of the entity type (e.g. Peter -> [PERSON_1], Chicago -> [LOCATION_1]).var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
netanos.anon(input, function(output) {
console.log(output);
});
/*
"[PERSON_1] and [PERSON_2] spent more than [DATE/TIME_1] on writing the software. They started in [DATE/TIME_2] in [LOCATION_1]."
*/
netanos.ner): each identified entity will be replaced with a different entity of the same type (e.g. Peter -> Alfred, Chicago -> London).var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
netanos.ner(input, function(output) {
console.log(output);
});
/*
“Barry and Rick spent more than 997 hours on writing the software. They started in January 14 2016 in Odessa.”
*/
netanos.noncontext): this approach is not based on named entities and replaces every word starting with a capital letter and every numeric value with "XXX".var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
/*
Note that the non-context preserving replacement is not asynchronous as it does not rely on the named entitiy recognition.
*/
var anonymized = netanos.noncontext(input);
console.log(anonymized);
/*
“XXX and XXX spent more than XXX hours on writing the software. XXX started in XXX XXX in XXX.”
*/
netanos.combined): the non-context preserving replacement and the named entity-based replacement are combined such that each word starting with a capital letter, each numeric value and all identified named entities are replaced with "XXX".var input = "Max and Ben spent more than 1000 hours on writing the software. They started in August 2016 in Amsterdam.";
netanos.combined(input, function(output) {
console.log(output);
});
/*
“XXX and XXX spent more than XXX XXX on writing the software. XXX started in XXX XXX in XXX.”
*/
MIT © Bennett Kleinberg & Maximilian Mozes
FAQs
NETANOS: Named entity-based Text Anonymization for Open Science
We found that netanos demonstrated a not healthy version release cadence and project activity because the last version was released a year ago. It has 2 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Security News
OpenAI rotated macOS signing certificates after a malicious Axios package reached its CI pipeline in a broader software supply chain attack.

Security News
Open source is under attack because of how much value it creates. It has been the foundation of every major software innovation for the last three decades. This is not the time to walk away from it.

Security News
Socket CEO Feross Aboukhadijeh breaks down how North Korea hijacked Axios and what it means for the future of software supply chain security.