{"id":"https://openalex.org/W4292826129","doi":"https://doi.org/10.1007/978-3-031-15777-6_30","title":"TapTree: Process-Tree Based Host Behavior Modeling and\u00a0Threat Detection Framework via\u00a0Sequential Pattern Mining","display_name":"TapTree: Process-Tree Based Host Behavior Modeling and\u00a0Threat Detection Framework via\u00a0Sequential Pattern Mining","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W4292826129","doi":"https://doi.org/10.1007/978-3-031-15777-6_30"},"language":"en","primary_location":{"id":"doi:10.1007/978-3-031-15777-6_30","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-031-15777-6_30","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},"type":"book-chapter","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2312.07575","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056921549","display_name":"Mohammad Mamun","orcid":"https://orcid.org/0000-0002-4045-8687"},"institutions":[{"id":"https://openalex.org/I4210159778","display_name":"National Research Council Canada","ror":"https://ror.org/04mte1k06","country_code":"CA","type":"government","lineage":["https://openalex.org/I4210159778"]},{"id":"https://openalex.org/I4210098097","display_name":"Research and Productivity Council","ror":"https://ror.org/00yeap462","country_code":"CA","type":"government","lineage":["https://openalex.org/I4210098097"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Mohammad Mamun","raw_affiliation_strings":["National Research Council Canada, Fredericton, NB, Canada"],"affiliations":[{"raw_affiliation_string":"National Research Council Canada, Fredericton, NB, Canada","institution_ids":["https://openalex.org/I4210098097","https://openalex.org/I4210159778"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5020247375","display_name":"Scott Buffett","orcid":null},"institutions":[{"id":"https://openalex.org/I4210098097","display_name":"Research and Productivity Council","ror":"https://ror.org/00yeap462","country_code":"CA","type":"government","lineage":["https://openalex.org/I4210098097"]},{"id":"https://openalex.org/I4210159778","display_name":"National Research Council Canada","ror":"https://ror.org/04mte1k06","country_code":"CA","type":"government","lineage":["https://openalex.org/I4210159778"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Scott Buffett","raw_affiliation_strings":["National Research Council Canada, Fredericton, NB, Canada"],"affiliations":[{"raw_affiliation_string":"National Research Council Canada, Fredericton, NB, Canada","institution_ids":["https://openalex.org/I4210098097","https://openalex.org/I4210159778"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5056921549"],"corresponding_institution_ids":["https://openalex.org/I4210098097","https://openalex.org/I4210159778"],"apc_list":{"value":5000,"currency":"EUR","value_usd":5392},"apc_paid":null,"fwci":0.6153,"has_fulltext":true,"cited_by_count":1,"citation_normalized_percentile":{"value":0.69016067,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"546","last_page":"565"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9997000098228455,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.986299991607666,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8039714097976685},{"id":"https://openalex.org/keywords/semantics","display_name":"Semantics (computer science)","score":0.5957874655723572},{"id":"https://openalex.org/keywords/benchmark","display_name":"Benchmark (surveying)","score":0.5438776612281799},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.5245283246040344},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5230816006660461},{"id":"https://openalex.org/keywords/behavioral-pattern","display_name":"Behavioral pattern","score":0.5206136703491211},{"id":"https://openalex.org/keywords/abstraction","display_name":"Abstraction","score":0.5178447365760803},{"id":"https://openalex.org/keywords/pattern-matching","display_name":"Pattern matching","score":0.5174787044525146},{"id":"https://openalex.org/keywords/tree","display_name":"Tree (set theory)","score":0.5174037218093872},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.49364861845970154},{"id":"https://openalex.org/keywords/event","display_name":"Event (particle physics)","score":0.42267870903015137},{"id":"https://openalex.org/keywords/audit","display_name":"Audit","score":0.4194400906562805},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3710976839065552},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.14190244674682617},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.09573808312416077}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8039714097976685},{"id":"https://openalex.org/C184337299","wikidata":"https://www.wikidata.org/wiki/Q1437428","display_name":"Semantics (computer science)","level":2,"score":0.5957874655723572},{"id":"https://openalex.org/C185798385","wikidata":"https://www.wikidata.org/wiki/Q1161707","display_name":"Benchmark (surveying)","level":2,"score":0.5438776612281799},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.5245283246040344},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5230816006660461},{"id":"https://openalex.org/C83804111","wikidata":"https://www.wikidata.org/wiki/Q1063558","display_name":"Behavioral pattern","level":2,"score":0.5206136703491211},{"id":"https://openalex.org/C124304363","wikidata":"https://www.wikidata.org/wiki/Q673661","display_name":"Abstraction","level":2,"score":0.5178447365760803},{"id":"https://openalex.org/C68859911","wikidata":"https://www.wikidata.org/wiki/Q1503724","display_name":"Pattern matching","level":2,"score":0.5174787044525146},{"id":"https://openalex.org/C113174947","wikidata":"https://www.wikidata.org/wiki/Q2859736","display_name":"Tree (set theory)","level":2,"score":0.5174037218093872},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.49364861845970154},{"id":"https://openalex.org/C2779662365","wikidata":"https://www.wikidata.org/wiki/Q5416694","display_name":"Event (particle physics)","level":2,"score":0.42267870903015137},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.4194400906562805},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3710976839065552},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.14190244674682617},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.09573808312416077},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C13280743","wikidata":"https://www.wikidata.org/wiki/Q131089","display_name":"Geodesy","level":1,"score":0.0},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.0},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0},{"id":"https://openalex.org/C205649164","wikidata":"https://www.wikidata.org/wiki/Q1071","display_name":"Geography","level":0,"score":0.0}],"mesh":[],"locations_count":3,"locations":[{"id":"doi:10.1007/978-3-031-15777-6_30","is_oa":false,"landing_page_url":"https://doi.org/10.1007/978-3-031-15777-6_30","pdf_url":null,"source":{"id":"https://openalex.org/S106296714","display_name":"Lecture notes in computer science","issn_l":"0302-9743","issn":["0302-9743","1611-3349"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319900","host_organization_name":"Springer Science+Business Media","host_organization_lineage":["https://openalex.org/P4310319900","https://openalex.org/P4310319965"],"host_organization_lineage_names":["Springer Science+Business Media","Springer Nature"],"type":"book series"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Lecture Notes in Computer Science","raw_type":"book-chapter"},{"id":"pmh:oai:cisti-icist.nrc-cnrc.ca:cistinparc:96464603-3451-434c-9358-7197364ac54e","is_oa":false,"landing_page_url":"https://nrc-publications.canada.ca/eng/view/object/?id=96464603-3451-434c-9358-7197364ac54e","pdf_url":null,"source":{"id":"https://openalex.org/S7407055245","display_name":"NPARC","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"acceptedVersion","is_accepted":true,"is_published":false,"raw_source_name":null,"raw_type":"article"},{"id":"pmh:oai:arXiv.org:2312.07575","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2312.07575","pdf_url":"https://arxiv.org/pdf/2312.07575","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2312.07575","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2312.07575","pdf_url":"https://arxiv.org/pdf/2312.07575","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/13","score":0.4699999988079071,"display_name":"Climate action"}],"awards":[],"funders":[{"id":"https://openalex.org/F4320311065","display_name":"University of Windsor","ror":"https://ror.org/01gw3d370"}],"has_content":{"pdf":true,"grobid_xml":false},"content_urls":{"pdf":"https://content.openalex.org/works/W4292826129.pdf"},"referenced_works_count":30,"referenced_works":["https://openalex.org/W1985716338","https://openalex.org/W1997102766","https://openalex.org/W2084959893","https://openalex.org/W2095898397","https://openalex.org/W2096347345","https://openalex.org/W2158454296","https://openalex.org/W2302058010","https://openalex.org/W2585367509","https://openalex.org/W2614763420","https://openalex.org/W2751114427","https://openalex.org/W2767094836","https://openalex.org/W2790557990","https://openalex.org/W2891432086","https://openalex.org/W2910675037","https://openalex.org/W2963523189","https://openalex.org/W2963611658","https://openalex.org/W2963843206","https://openalex.org/W2969491951","https://openalex.org/W2986944522","https://openalex.org/W2995786003","https://openalex.org/W2998038410","https://openalex.org/W3006711782","https://openalex.org/W3105780912","https://openalex.org/W3123076006","https://openalex.org/W3137205257","https://openalex.org/W3158266296","https://openalex.org/W3158906645","https://openalex.org/W3165750692","https://openalex.org/W3196544260","https://openalex.org/W3196640496"],"related_works":["https://openalex.org/W2045155990","https://openalex.org/W4313163053","https://openalex.org/W3045811229","https://openalex.org/W4300973204","https://openalex.org/W1483408780","https://openalex.org/W4284884309","https://openalex.org/W2908749798","https://openalex.org/W2105980483","https://openalex.org/W4243842598","https://openalex.org/W1514435881"],"abstract_inverted_index":null,"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2026-03-20T23:20:44.827607","created_date":"2025-10-10T00:00:00"}
