{"id":"https://openalex.org/W4387298166","doi":"https://doi.org/10.1145/3607199.3607208","title":"Looking Beyond IoCs: Automatically Extracting Attack Patterns from External CTI","display_name":"Looking Beyond IoCs: Automatically Extracting Attack Patterns from External CTI","publication_year":2023,"publication_date":"2023-10-03","ids":{"openalex":"https://openalex.org/W4387298166","doi":"https://doi.org/10.1145/3607199.3607208"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3607199.3607208","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2211.01753","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5045927406","display_name":"Tanvirul Alam","orcid":"https://orcid.org/0000-0003-4284-2743"},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Md Tanvirul Alam","raw_affiliation_strings":["Rochester Institute of Technology, USA"],"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology, USA","institution_ids":["https://openalex.org/I155173764"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5014560362","display_name":"Dipkamal Bhusal","orcid":"https://orcid.org/0000-0003-1214-1954"},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Dipkamal Bhusal","raw_affiliation_strings":["Rochester Institute of Technology, USA"],"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology, USA","institution_ids":["https://openalex.org/I155173764"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101438262","display_name":"Youngja Park","orcid":"https://orcid.org/0000-0002-4579-9261"},"institutions":[],"countries":["US"],"is_corresponding":false,"raw_author_name":"Youngja Park","raw_affiliation_strings":["IBM Research, USA"],"affiliations":[{"raw_affiliation_string":"IBM Research, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5001140269","display_name":"Nidhi Rastogi","orcid":"https://orcid.org/0000-0002-2002-3213"},"institutions":[{"id":"https://openalex.org/I155173764","display_name":"Rochester Institute of Technology","ror":"https://ror.org/00v4yb702","country_code":"US","type":"education","lineage":["https://openalex.org/I155173764"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Nidhi Rastogi","raw_affiliation_strings":["Rochester Institute of Technology, United States of America"],"affiliations":[{"raw_affiliation_string":"Rochester Institute of Technology, United States of America","institution_ids":["https://openalex.org/I155173764"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":1,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":7.177,"has_fulltext":false,"cited_by_count":16,"citation_normalized_percentile":{"value":0.999946,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":97,"max":98},"biblio":{"volume":null,"issue":null,"first_page":"92","last_page":"108"},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Intrusion Detection and Defense Mechanisms","score":0.9992,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Intrusion Detection and Defense Mechanisms","score":0.9992,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Characterization and Detection of Android Malware","score":0.9987,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Detection and Prevention of Phishing Attacks","score":0.998,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/intrusion-detection","display_name":"Intrusion Detection","score":0.542004},{"id":"https://openalex.org/keywords/security-analysis","display_name":"Security Analysis","score":0.536344},{"id":"https://openalex.org/keywords/attack-patterns","display_name":"Attack patterns","score":0.53275776},{"id":"https://openalex.org/keywords/detection","display_name":"Detection","score":0.528727},{"id":"https://openalex.org/keywords/botnet-detection","display_name":"Botnet Detection","score":0.526978},{"id":"https://openalex.org/keywords/android-malware","display_name":"Android malware","score":0.49507752},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.44870558},{"id":"https://openalex.org/keywords/cyber-attack","display_name":"Cyber-attack","score":0.4196375}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.76884484},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.7130579},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.57846516},{"id":"https://openalex.org/C2780741293","wikidata":"https://www.wikidata.org/wiki/Q4818019","display_name":"Attack patterns","level":3,"score":0.53275776},{"id":"https://openalex.org/C2989133298","wikidata":"https://www.wikidata.org/wiki/Q94","display_name":"Android malware","level":3,"score":0.49507752},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.44870558},{"id":"https://openalex.org/C201307755","wikidata":"https://www.wikidata.org/wiki/Q4071928","display_name":"Cyber-attack","level":2,"score":0.4196375},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.33936757},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.18571141},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/3607199.3607208","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2211.01753","pdf_url":"https://arxiv.org/pdf/2211.01753","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false}],"best_oa_location":{"is_oa":true,"landing_page_url":"https://arxiv.org/abs/2211.01753","pdf_url":"https://arxiv.org/pdf/2211.01753","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":["Cornell University"],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","display_name":"Peace, justice, and strong institutions","score":0.44}],"grants":[],"datasets":[],"versions":[],"referenced_works_count":31,"referenced_works":["https://openalex.org/W1529533208","https://openalex.org/W1963826206","https://openalex.org/W1986203139","https://openalex.org/W2538865281","https://openalex.org/W2560828726","https://openalex.org/W2759136286","https://openalex.org/W2771963642","https://openalex.org/W2890262614","https://openalex.org/W2970641574","https://openalex.org/W2980659949","https://openalex.org/W2984452801","https://openalex.org/W2997634552","https://openalex.org/W3000539293","https://openalex.org/W3003265726","https://openalex.org/W3008445684","https://openalex.org/W3011594683","https://openalex.org/W3014343990","https://openalex.org/W3023882301","https://openalex.org/W3035390927","https://openalex.org/W3099203541","https://openalex.org/W3103296573","https://openalex.org/W3111854523","https://openalex.org/W3113026249","https://openalex.org/W3171540545","https://openalex.org/W3186276894","https://openalex.org/W3198980504","https://openalex.org/W3211888892","https://openalex.org/W3214285526","https://openalex.org/W3214329506","https://openalex.org/W4200000055","https://openalex.org/W4328028831"],"related_works":["https://openalex.org/W4383468964","https://openalex.org/W4312234627","https://openalex.org/W4249118297","https://openalex.org/W3200508744","https://openalex.org/W3195312353","https://openalex.org/W3025122950","https://openalex.org/W2895504842","https://openalex.org/W2560361988","https://openalex.org/W2507113366","https://openalex.org/W2311926078"],"abstract_inverted_index":{"Public":[0],"and":[1,16,34,95,98,125],"commercial":[2],"organizations":[3],"extensively":[4],"share":[5],"cyberthreat":[6,161],"intelligence":[7,59,162],"(CTI)":[8],"to":[9,12,54,102,115,123,130,140,158],"prepare":[10,131],"systems":[11],"defend":[13],"against":[14,45],"existing":[15,124],"emerging":[17,126],"cyberattacks.":[18],"However,":[19],"traditional":[20],"CTI":[21,77],"has":[22],"primarily":[23],"focused":[24],"on":[25],"tracking":[26],"known":[27],"threat":[28,58],"indicators":[29],"such":[30],"as":[31],"IP":[32],"addresses":[33],"domain":[35],"names,":[36],"which":[37],"may":[38],"not":[39],"provide":[40,151],"long-term":[41],"value":[42],"in":[43,93,146],"defending":[44],"evolving":[46],"attacks.":[47],"To":[48],"address":[49],"this":[50],"challenge,":[51],"we":[52,150],"propose":[53],"use":[55,138],"more":[56],"robust":[57],"signals":[60],"called":[61],"attack":[62,74,84,92,120],"patterns.":[63],"LADDER":[64,108,145],"is":[65],"a":[66,152],"knowledge":[67],"extraction":[68],"framework":[69,82],"that":[70],"can":[71,109],"extract":[72],"text-based":[73],"patterns":[75,85],"from":[76],"reports":[78],"at":[79],"scale.":[80],"The":[81],"characterizes":[83],"by":[86,112],"capturing":[87],"the":[88,103,117,142],"phases":[89],"of":[90,119,144],"an":[91],"Android":[94],"enterprise":[96],"networks":[97],"systematically":[99],"maps":[100],"them":[101,129],"MITRE":[104],"ATT&CK":[105],"pattern":[106],"framework.":[107],"be":[110],"used":[111],"security":[113],"analysts":[114],"determine":[116],"presence":[118],"vectors":[121],"related":[122],"threats,":[127],"enabling":[128],"defenses":[132],"proactively.":[133],"We":[134],"also":[135],"present":[136],"several":[137],"cases":[139],"demonstrate":[141],"application":[143],"real-world":[147],"scenarios.":[148],"Finally,":[149],"new,":[153],"open-access":[154],"benchmark":[155],"malware":[156],"dataset":[157],"train":[159],"future":[160],"models.":[163]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W4387298166","counts_by_year":[{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":5}],"updated_date":"2024-12-04T08:48:17.959942","created_date":"2023-10-04"}