{"id":"https://openalex.org/W4388115904","doi":"https://doi.org/10.1109/isi58743.2023.10297272","title":"Mapping Exploit Code on Paste Sites to the MITRE ATT&amp;CK Framework: A Multi-label Transformer Approach","display_name":"Mapping Exploit Code on Paste Sites to the MITRE ATT&amp;CK Framework: A Multi-label Transformer Approach","publication_year":2023,"publication_date":"2023-10-02","ids":{"openalex":"https://openalex.org/W4388115904","doi":"https://doi.org/10.1109/isi58743.2023.10297272"},"language":"en","primary_location":{"id":"doi:10.1109/isi58743.2023.10297272","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi58743.2023.10297272","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5075447553","display_name":"Benjamin Ampel","orcid":"https://orcid.org/0000-0003-0603-0270"},"institutions":[{"id":"https://openalex.org/I138006243","display_name":"University of Arizona","ror":"https://ror.org/03m2x1q45","country_code":"US","type":"education","lineage":["https://openalex.org/I138006243"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Benjamin Ampel","raw_affiliation_strings":["University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","Department of Management Information Systems, University of Arizona, Tucson, AZ, United States"],"affiliations":[{"raw_affiliation_string":"University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","institution_ids":["https://openalex.org/I138006243"]},{"raw_affiliation_string":"Department of Management Information Systems, University of Arizona, Tucson, AZ, United States","institution_ids":["https://openalex.org/I138006243"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5010067332","display_name":"Tala Vahedi","orcid":"https://orcid.org/0000-0002-2353-7244"},"institutions":[{"id":"https://openalex.org/I138006243","display_name":"University of Arizona","ror":"https://ror.org/03m2x1q45","country_code":"US","type":"education","lineage":["https://openalex.org/I138006243"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Tala Vahedi","raw_affiliation_strings":["University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","Department of Management Information Systems, University of Arizona, Tucson, AZ, United States"],"affiliations":[{"raw_affiliation_string":"University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","institution_ids":["https://openalex.org/I138006243"]},{"raw_affiliation_string":"Department of Management Information Systems, University of Arizona, Tucson, AZ, United States","institution_ids":["https://openalex.org/I138006243"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038811607","display_name":"Sagar Samtani","orcid":"https://orcid.org/0000-0002-4513-805X"},"institutions":[{"id":"https://openalex.org/I4210119109","display_name":"Indiana University Bloomington","ror":"https://ror.org/02k40bc56","country_code":"US","type":"education","lineage":["https://openalex.org/I4210119109","https://openalex.org/I592451"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Sagar Samtani","raw_affiliation_strings":["Indiana University,Department of Operations &#x0026; Decision Technologies,Bloomington,IU,United States"],"affiliations":[{"raw_affiliation_string":"Indiana University,Department of Operations &#x0026; Decision Technologies,Bloomington,IU,United States","institution_ids":["https://openalex.org/I4210119109"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5017102020","display_name":"Hsinchun Chen","orcid":"https://orcid.org/0000-0003-3251-2433"},"institutions":[{"id":"https://openalex.org/I138006243","display_name":"University of Arizona","ror":"https://ror.org/03m2x1q45","country_code":"US","type":"education","lineage":["https://openalex.org/I138006243"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Hsinchun Chen","raw_affiliation_strings":["University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","Department of Management Information Systems, University of Arizona, Tucson, AZ, United States"],"affiliations":[{"raw_affiliation_string":"University of Arizona,Department of Management Information Systems,Tucson,AZ,United States","institution_ids":["https://openalex.org/I138006243"]},{"raw_affiliation_string":"Department of Management Information Systems, University of Arizona, Tucson, AZ, United States","institution_ids":["https://openalex.org/I138006243"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5075447553"],"corresponding_institution_ids":["https://openalex.org/I138006243"],"apc_list":null,"apc_paid":null,"fwci":0.4582,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.70442251,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":95},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"6"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9993000030517578,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9983000159263611,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9933000206947327,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/exploit","display_name":"Exploit","score":0.8592655658721924},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7346409559249878},{"id":"https://openalex.org/keywords/pooling","display_name":"Pooling","score":0.66092848777771},{"id":"https://openalex.org/keywords/source-code","display_name":"Source code","score":0.6586754322052002},{"id":"https://openalex.org/keywords/convolutional-neural-network","display_name":"Convolutional neural network","score":0.6028484106063843},{"id":"https://openalex.org/keywords/transformer","display_name":"Transformer","score":0.5786135196685791},{"id":"https://openalex.org/keywords/hamming-code","display_name":"Hamming code","score":0.4828556180000305},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4744333326816559},{"id":"https://openalex.org/keywords/f1-score","display_name":"F1 score","score":0.4180988669395447},{"id":"https://openalex.org/keywords/pattern-recognition","display_name":"Pattern recognition (psychology)","score":0.3704606890678406},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.3669937551021576},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.32222121953964233},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.18537431955337524},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.17164331674575806},{"id":"https://openalex.org/keywords/algorithm","display_name":"Algorithm","score":0.15125247836112976},{"id":"https://openalex.org/keywords/engineering","display_name":"Engineering","score":0.1364833414554596},{"id":"https://openalex.org/keywords/decoding-methods","display_name":"Decoding methods","score":0.12481421232223511},{"id":"https://openalex.org/keywords/block-code","display_name":"Block code","score":0.09185194969177246}],"concepts":[{"id":"https://openalex.org/C165696696","wikidata":"https://www.wikidata.org/wiki/Q11287","display_name":"Exploit","level":2,"score":0.8592655658721924},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7346409559249878},{"id":"https://openalex.org/C70437156","wikidata":"https://www.wikidata.org/wiki/Q7228652","display_name":"Pooling","level":2,"score":0.66092848777771},{"id":"https://openalex.org/C43126263","wikidata":"https://www.wikidata.org/wiki/Q128751","display_name":"Source code","level":2,"score":0.6586754322052002},{"id":"https://openalex.org/C81363708","wikidata":"https://www.wikidata.org/wiki/Q17084460","display_name":"Convolutional neural network","level":2,"score":0.6028484106063843},{"id":"https://openalex.org/C66322947","wikidata":"https://www.wikidata.org/wiki/Q11658","display_name":"Transformer","level":3,"score":0.5786135196685791},{"id":"https://openalex.org/C73150493","wikidata":"https://www.wikidata.org/wiki/Q853922","display_name":"Hamming code","level":4,"score":0.4828556180000305},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4744333326816559},{"id":"https://openalex.org/C148524875","wikidata":"https://www.wikidata.org/wiki/Q6975395","display_name":"F1 score","level":2,"score":0.4180988669395447},{"id":"https://openalex.org/C153180895","wikidata":"https://www.wikidata.org/wiki/Q7148389","display_name":"Pattern recognition (psychology)","level":2,"score":0.3704606890678406},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.3669937551021576},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.32222121953964233},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.18537431955337524},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.17164331674575806},{"id":"https://openalex.org/C11413529","wikidata":"https://www.wikidata.org/wiki/Q8366","display_name":"Algorithm","level":1,"score":0.15125247836112976},{"id":"https://openalex.org/C127413603","wikidata":"https://www.wikidata.org/wiki/Q11023","display_name":"Engineering","level":0,"score":0.1364833414554596},{"id":"https://openalex.org/C57273362","wikidata":"https://www.wikidata.org/wiki/Q576722","display_name":"Decoding methods","level":2,"score":0.12481421232223511},{"id":"https://openalex.org/C157125643","wikidata":"https://www.wikidata.org/wiki/Q884707","display_name":"Block code","level":3,"score":0.09185194969177246},{"id":"https://openalex.org/C165801399","wikidata":"https://www.wikidata.org/wiki/Q25428","display_name":"Voltage","level":2,"score":0.0},{"id":"https://openalex.org/C119599485","wikidata":"https://www.wikidata.org/wiki/Q43035","display_name":"Electrical engineering","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isi58743.2023.10297272","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi58743.2023.10297272","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2023 IEEE International Conference on Intelligence and Security Informatics (ISI)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","score":0.8100000023841858,"id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G3807895572","display_name":null,"funder_award_id":"DGE-1921485 (SFS),OAC- 1917117 (CICI),CNS-1850362 (SaTC CRII)","funder_id":"https://openalex.org/F4320306076","funder_display_name":"National Science Foundation"}],"funders":[{"id":"https://openalex.org/F4320306076","display_name":"National Science Foundation","ror":"https://ror.org/021nxhr62"}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":28,"referenced_works":["https://openalex.org/W1832693441","https://openalex.org/W2888726123","https://openalex.org/W2889903231","https://openalex.org/W2890067501","https://openalex.org/W2899423466","https://openalex.org/W2941814890","https://openalex.org/W2948780215","https://openalex.org/W2970047711","https://openalex.org/W2990511376","https://openalex.org/W2995744795","https://openalex.org/W3106373739","https://openalex.org/W3112475728","https://openalex.org/W3113358185","https://openalex.org/W3116216483","https://openalex.org/W3159077217","https://openalex.org/W3160262311","https://openalex.org/W3165871279","https://openalex.org/W3174492648","https://openalex.org/W3215448314","https://openalex.org/W3217791241","https://openalex.org/W4288289156","https://openalex.org/W4385245566","https://openalex.org/W6739901393","https://openalex.org/W6761563299","https://openalex.org/W6765264507","https://openalex.org/W6770600591","https://openalex.org/W6771550025","https://openalex.org/W6795842910"],"related_works":["https://openalex.org/W2953234277","https://openalex.org/W2626256601","https://openalex.org/W147410782","https://openalex.org/W2900413183","https://openalex.org/W4390975304","https://openalex.org/W3022252430","https://openalex.org/W4287804464","https://openalex.org/W3103989898","https://openalex.org/W4287854475","https://openalex.org/W3186737058"],"abstract_inverted_index":{"Cyber-criminals":[0],"often":[1],"use":[2],"information-sharing":[3],"platforms":[4],"such":[5,19],"as":[6,20],"paste":[7,28,55,157],"sites":[8],"(e.g.,":[9],"Pastebin)":[10],"to":[11,60,65,108],"share":[12],"vast":[13],"amounts":[14],"of":[15,26,71,132,141],"malicious":[16,27,154],"text":[17],"content,":[18],"exploit":[21,57],"source":[22,58],"code.":[23],"Careful":[24],"analysis":[25],"site":[29,56],"content":[30],"can":[31],"provide":[32],"Cyber":[33],"Threat":[34],"Intelligence":[35],"(CTI)":[36],"about":[37],"potential":[38],"threats.":[39],"In":[40],"this":[41],"research,":[42],"we":[43],"propose":[44],"a":[45,79,86,89,93,101,142],"Convolutional":[46,75,123],"BiLSTM":[47,76,102,124],"Transformer":[48,77,87,107,125],"multi-label":[49,117],"classification":[50,118],"method":[51],"that":[52,150],"automatically":[53],"maps":[54],"code":[59],"the":[61,106,146],"MITRE":[62],"ATT&CK":[63],"framework":[64],"identify":[66],"adversarial":[67],"techniques":[68],"in":[69,130],"support":[70],"proactive":[72],"CTI.":[73],"The":[74,139],"combines":[78],"convolutional":[80],"neural":[81],"network":[82],"layer":[83],"placed":[84],"before":[85],"block,":[88],"concatenated":[90],"pooling":[91,96],"from":[92],"global":[94,98],"max":[95],"and":[97,100,111,136,148],"average,":[99],"pair-wise":[103],"function":[104],"within":[105],"capture":[109],"word":[110],"sequence":[112],"orders.":[113],"We":[114],"conducted":[115],"an":[116],"experiment":[119],"where":[120],"our":[121],"proposed":[122],"model":[126],"achieved":[127],"state-of-the-art":[128],"results":[129,140],"terms":[131],"accuracy,":[133],"recall,":[134],"F1-score,":[135],"hamming":[137],"loss.":[138],"case":[143],"study":[144],"showed":[145],"tactics":[147],"tools":[149],"are":[151],"used":[152],"by":[153],"actors":[155],"on":[156],"sites.":[158]},"counts_by_year":[{"year":2025,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
