{"id":"https://openalex.org/W2887106696","doi":"https://doi.org/10.1145/3230833.3233282","title":"Hunting Observable Objects for Indication of Compromise","display_name":"Hunting Observable Objects for Indication of Compromise","publication_year":2018,"publication_date":"2018-08-13","ids":{"openalex":"https://openalex.org/W2887106696","doi":"https://doi.org/10.1145/3230833.3233282","mag":"2887106696"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3230833.3233282","pdf_url":null,"source":{"id":"https://openalex.org/S4363608926","display_name":"Proceedings of the 17th International Conference on Availability, Reliability and Security","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5010425124","display_name":"Arnold Sykosch","orcid":null},"institutions":[{"id":"https://openalex.org/I135140700","display_name":"University of Bonn","ror":"https://ror.org/041nas322","country_code":"DE","type":"education","lineage":["https://openalex.org/I135140700"]},{"id":"https://openalex.org/I4210166245","display_name":"Fraunhofer Institute for Communication, Information Processing and Ergonomics","ror":"https://ror.org/05nn0gw40","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210166245","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Arnold Sykosch","raw_affiliation_strings":["University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany"],"affiliations":[{"raw_affiliation_string":"University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany","institution_ids":["https://openalex.org/I135140700","https://openalex.org/I4210166245"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5078523628","display_name":"Marc Ohm","orcid":"https://orcid.org/0000-0002-2913-5270"},"institutions":[{"id":"https://openalex.org/I135140700","display_name":"University of Bonn","ror":"https://ror.org/041nas322","country_code":"DE","type":"education","lineage":["https://openalex.org/I135140700"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Marc Ohm","raw_affiliation_strings":["University of Bonn, Computer Science IV, Bonn, NRW, Germany"],"affiliations":[{"raw_affiliation_string":"University of Bonn, Computer Science IV, Bonn, NRW, Germany","institution_ids":["https://openalex.org/I135140700"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5103100716","display_name":"Michael Meier","orcid":"https://orcid.org/0000-0002-8443-7618"},"institutions":[{"id":"https://openalex.org/I135140700","display_name":"University of Bonn","ror":"https://ror.org/041nas322","country_code":"DE","type":"education","lineage":["https://openalex.org/I135140700"]},{"id":"https://openalex.org/I4210166245","display_name":"Fraunhofer Institute for Communication, Information Processing and Ergonomics","ror":"https://ror.org/05nn0gw40","country_code":"DE","type":"facility","lineage":["https://openalex.org/I4210166245","https://openalex.org/I4923324"]}],"countries":["DE"],"is_corresponding":false,"raw_author_name":"Michael Meier","raw_affiliation_strings":["University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany"],"affiliations":[{"raw_affiliation_string":"University of Bonn, Computer Science IV, Bonn, NRW, Germany Fraunhofer FKIE, Cyber Security, Bonn, NRW, Germany","institution_ids":["https://openalex.org/I135140700","https://openalex.org/I4210166245"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":0.138,"has_fulltext":true,"fulltext_origin":"ngrams","cited_by_count":1,"citation_normalized_percentile":{"value":0.189737,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":62,"max":70},"biblio":{"volume":"286","issue":null,"first_page":"1","last_page":"8"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9959,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/compromise","display_name":"Compromise","score":0.9577962},{"id":"https://openalex.org/keywords/threat-model","display_name":"Threat model","score":0.43532428}],"concepts":[{"id":"https://openalex.org/C46355384","wikidata":"https://www.wikidata.org/wiki/Q726686","display_name":"Compromise","level":2,"score":0.9577962},{"id":"https://openalex.org/C2780310539","wikidata":"https://www.wikidata.org/wiki/Q12547192","display_name":"Imperfect","level":2,"score":0.8254242},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.70252705},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.6400573},{"id":"https://openalex.org/C158251709","wikidata":"https://www.wikidata.org/wiki/Q354025","display_name":"Intrusion","level":2,"score":0.5841243},{"id":"https://openalex.org/C2779530757","wikidata":"https://www.wikidata.org/wiki/Q1207505","display_name":"Quality (philosophy)","level":2,"score":0.566487},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.54183406},{"id":"https://openalex.org/C140547941","wikidata":"https://www.wikidata.org/wiki/Q7797194","display_name":"Threat model","level":2,"score":0.43532428},{"id":"https://openalex.org/C112930515","wikidata":"https://www.wikidata.org/wiki/Q4389547","display_name":"Risk analysis (engineering)","level":1,"score":0.35122588},{"id":"https://openalex.org/C144133560","wikidata":"https://www.wikidata.org/wiki/Q4830453","display_name":"Business","level":0,"score":0.1466856},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.089940846},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.07655114},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C17409809","wikidata":"https://www.wikidata.org/wiki/Q161764","display_name":"Geochemistry","level":1,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3230833.3233282","pdf_url":null,"source":{"id":"https://openalex.org/S4363608926","display_name":"Proceedings of the 17th International Conference on Availability, Reliability and Security","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.56,"id":"https://metadata.un.org/sdg/15","display_name":"Life on land"}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":17,"referenced_works":["https://openalex.org/W1485364724","https://openalex.org/W1581009051","https://openalex.org/W1978394996","https://openalex.org/W1998789948","https://openalex.org/W2014316112","https://openalex.org/W2024200844","https://openalex.org/W2033811087","https://openalex.org/W2071030167","https://openalex.org/W2111038628","https://openalex.org/W2137786570","https://openalex.org/W2144211451","https://openalex.org/W2533908554","https://openalex.org/W2538865281","https://openalex.org/W2837911466","https://openalex.org/W3186276894","https://openalex.org/W4213009331","https://openalex.org/W4230966618"],"related_works":["https://openalex.org/W4240977217","https://openalex.org/W4214750239","https://openalex.org/W3036524962","https://openalex.org/W2801622120","https://openalex.org/W2515148583","https://openalex.org/W2508088450","https://openalex.org/W2389434635","https://openalex.org/W2279908259","https://openalex.org/W2164141394","https://openalex.org/W2133389611"],"abstract_inverted_index":{"Shared":[0],"Threat":[1],"Intelligence":[2],"is":[3,43,73,83],"often":[4],"imperfect.":[5],"Especially":[6],"so":[7],"called":[8],"Indicator":[9],"of":[10,36],"Compromise":[11],"might":[12,18],"not":[13,32],"be":[14,20],"well":[15],"constructed.":[16],"This":[17],"either":[19],"the":[21,24,41,53],"case":[22],"if":[23],"threat":[25,42],"only":[26,44],"appeared":[27],"recently":[28],"and":[29,82],"recordings":[30],"do":[31],"allow":[33],"for":[34],"construction":[35],"high":[37],"quality":[38,64,81],"Indicators":[39],"or":[40],"observed":[45],"by":[46],"sharing":[47],"partners":[48],"lesser":[49],"capable":[50],"to":[51,75,85],"model":[52],"threat.":[54],"However,":[55],"intrusion":[56,88],"detection":[57],"based":[58],"on":[59],"imperfect":[60],"intelligence":[61],"yields":[62],"low":[63],"results.":[65],"Within":[66],"this":[67],"paper":[68],"we":[69],"illustrate":[70],"how":[71],"one":[72],"able":[74,84],"overcome":[76],"these":[77],"shortcomings":[78],"in":[79],"data":[80],"achieve":[86],"solid":[87],"detection.":[89]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2887106696","counts_by_year":[{"year":2019,"cited_by_count":1}],"updated_date":"2024-12-14T04:15:27.166920","created_date":"2018-08-22"}