{"id":"https://openalex.org/W4408354083","doi":"https://doi.org/10.1109/icassp49660.2025.10888022","title":"APTSniffer: Detecting APT Attack Traffic Using Retrieval-Augmented Large Language Models","display_name":"APTSniffer: Detecting APT Attack Traffic Using Retrieval-Augmented Large Language Models","publication_year":2025,"publication_date":"2025-03-12","ids":{"openalex":"https://openalex.org/W4408354083","doi":"https://doi.org/10.1109/icassp49660.2025.10888022"},"language":"en","primary_location":{"id":"doi:10.1109/icassp49660.2025.10888022","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10888022","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101790956","display_name":"Hongbo Xu","orcid":"https://orcid.org/0000-0001-7594-3140"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Hongbo Xu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5091685769","display_name":"Chengxiang Si","orcid":"https://orcid.org/0000-0003-2646-6100"},"institutions":[{"id":"https://openalex.org/I4210087772","display_name":"National Computer Network Emergency Response Technical Team/Coordination Center of Chinar","ror":"https://ror.org/00247dh76","country_code":"CN","type":"nonprofit","lineage":["https://openalex.org/I4210087772"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chengxiang Si","raw_affiliation_strings":["National Computer Network Emergency Response Technical Team/Coordination Center of China,Beijing,China"],"affiliations":[{"raw_affiliation_string":"National Computer Network Emergency Response Technical Team/Coordination Center of China,Beijing,China","institution_ids":["https://openalex.org/I4210087772"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5116594471","display_name":"Zhouzhou","orcid":null},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhouzhou","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100455038","display_name":"Chenxu Wang","orcid":"https://orcid.org/0000-0002-1174-8933"},"institutions":[{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]},{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Chenxu Wang","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5043944711","display_name":"Peishuai Sun","orcid":"https://orcid.org/0000-0003-1135-8297"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Peishuai Sun","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100713362","display_name":"Qingyun Liu","orcid":"https://orcid.org/0000-0003-4815-3463"},"institutions":[{"id":"https://openalex.org/I4210156404","display_name":"Institute of Information Engineering","ror":"https://ror.org/04r53se39","country_code":"CN","type":"facility","lineage":["https://openalex.org/I19820366","https://openalex.org/I4210156404"]},{"id":"https://openalex.org/I19820366","display_name":"Chinese Academy of Sciences","ror":"https://ror.org/034t30j35","country_code":"CN","type":"funder","lineage":["https://openalex.org/I19820366"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Qingyun Liu","raw_affiliation_strings":["Institute of Information Engineering, Chinese Academy of Sciences,Beijing"],"affiliations":[{"raw_affiliation_string":"Institute of Information Engineering, Chinese Academy of Sciences,Beijing","institution_ids":["https://openalex.org/I4210156404","https://openalex.org/I19820366"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5101790956"],"corresponding_institution_ids":["https://openalex.org/I19820366","https://openalex.org/I4210156404"],"apc_list":null,"apc_paid":null,"fwci":11.4397,"has_fulltext":false,"cited_by_count":4,"citation_normalized_percentile":{"value":0.97844408,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":96,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"5"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.995199978351593,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12262","display_name":"Hate Speech and Cyberbullying Detection","score":0.995199978351593,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12380","display_name":"Authorship Attribution and Profiling","score":0.980400025844574,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9399999976158142,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.814717710018158},{"id":"https://openalex.org/keywords/natural-language-processing","display_name":"Natural language processing","score":0.40887224674224854},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.400623619556427},{"id":"https://openalex.org/keywords/information-retrieval","display_name":"Information retrieval","score":0.35591351985931396}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.814717710018158},{"id":"https://openalex.org/C204321447","wikidata":"https://www.wikidata.org/wiki/Q30642","display_name":"Natural language processing","level":1,"score":0.40887224674224854},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.400623619556427},{"id":"https://openalex.org/C23123220","wikidata":"https://www.wikidata.org/wiki/Q816826","display_name":"Information retrieval","level":1,"score":0.35591351985931396}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/icassp49660.2025.10888022","is_oa":false,"landing_page_url":"https://doi.org/10.1109/icassp49660.2025.10888022","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ICASSP 2025 - 2025 IEEE International Conference on Acoustics, Speech and Signal Processing (ICASSP)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":24,"referenced_works":["https://openalex.org/W2019821286","https://openalex.org/W2962703433","https://openalex.org/W2963197901","https://openalex.org/W3005127313","https://openalex.org/W3033696346","https://openalex.org/W3087100893","https://openalex.org/W3128341305","https://openalex.org/W3133235094","https://openalex.org/W3191862235","https://openalex.org/W3205483739","https://openalex.org/W4205088899","https://openalex.org/W4224315052","https://openalex.org/W4283068901","https://openalex.org/W4283382503","https://openalex.org/W4290714064","https://openalex.org/W4312239358","https://openalex.org/W4323321528","https://openalex.org/W4324007233","https://openalex.org/W4375928927","https://openalex.org/W4401043375","https://openalex.org/W6840012785","https://openalex.org/W6845816046","https://openalex.org/W6861295083","https://openalex.org/W6862500282"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2390279801","https://openalex.org/W4391913857","https://openalex.org/W2358668433","https://openalex.org/W4396701345","https://openalex.org/W2376932109","https://openalex.org/W2001405890","https://openalex.org/W3204019825"],"abstract_inverted_index":{"Advanced":[0],"Persistent":[1],"Threats":[2],"(APT)":[3],"differ":[4],"from":[5],"traditional":[6],"attacks":[7],"by":[8,90,101],"using":[9],"more":[10],"complex":[11],"and":[12,24,37,75,83],"covert":[13],"strategies":[14],"for":[15,131],"long-term":[16],"assaults,":[17],"posing":[18],"a":[19,50,61],"severe":[20],"threat":[21],"to":[22,28,109],"organizational":[23],"national":[25],"security.":[26],"Due":[27],"problems":[29],"like":[30],"the":[31,56,80,102],"shortage":[32],"of":[33,86],"APT":[34,46,64,125,132],"traffic":[35,39,47,52,65,93,133],"data":[36,94],"encrypted":[38,63],"obfuscation,":[40],"existing":[41],"methods":[42],"cannot":[43],"accurately":[44],"identify":[45],"with":[48],"just":[49],"few":[51],"samples.":[53],"To":[54],"overcome":[55],"above":[57,121],"limitation,":[58],"we":[59],"propose":[60],"novel":[62],"detection":[66,134],"model,":[67],"APTSniffer,":[68],"which":[69],"combines":[70],"large":[71,87],"language":[72,88,97],"models":[73,89],"(LLM)":[74],"retrieval-augmented":[76],"technology.":[77],"APTSniffer":[78,113],"utilizes":[79],"few-shot":[81],"inference":[82,98],"generalization":[84],"abilities":[85],"converting":[91],"raw":[92],"into":[95],"natural":[96],"examples":[99],"understandable":[100],"LLM.":[103],"Experimental":[104],"results":[105],"show":[106],"that,":[107],"compared":[108],"other":[110],"baseline":[111],"models,":[112],"exhibits":[114],"SOTA":[115],"performance.":[116],"It":[117],"achieves":[118],"F1":[119],"scores":[120],"97%":[122],"on":[123],"three":[124],"datasets,":[126],"making":[127],"it":[128],"practically":[129],"applicable":[130],"tasks.":[135]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":3}],"updated_date":"2025-12-28T23:10:05.387466","created_date":"2025-10-10T00:00:00"}
