{"id":"https://openalex.org/W4206583610","doi":"https://doi.org/10.1109/milcom52596.2021.9653049","title":"Network Data Curation Toolkit: Cybersecurity Data Collection, Aided-Labeling, and Rule Generation","display_name":"Network Data Curation Toolkit: Cybersecurity Data Collection, Aided-Labeling, and Rule Generation","publication_year":2021,"publication_date":"2021-11-29","ids":{"openalex":"https://openalex.org/W4206583610","doi":"https://doi.org/10.1109/milcom52596.2021.9653049"},"language":"en","primary_location":{"id":"doi:10.1109/milcom52596.2021.9653049","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom52596.2021.9653049","pdf_url":null,"source":{"id":"https://openalex.org/S4363608138","display_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5029731437","display_name":"Jaime C. Acosta","orcid":"https://orcid.org/0000-0003-2555-9989"},"institutions":[{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]},{"id":"https://openalex.org/I2802705668","display_name":"United States Army Combat Capabilities Development Command","ror":"https://ror.org/02rdkx920","country_code":"US","type":"other","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Jaime C. Acosta","raw_affiliation_strings":["DEVCOM Army Research Laboratory"],"affiliations":[{"raw_affiliation_string":"DEVCOM Army Research Laboratory","institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2802705668"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5015239196","display_name":"Stephanie Medina","orcid":"https://orcid.org/0000-0003-1614-5469"},"institutions":[{"id":"https://openalex.org/I164936912","display_name":"The University of Texas at El Paso","ror":"https://ror.org/04d5vba33","country_code":"US","type":"education","lineage":["https://openalex.org/I164936912"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Stephanie Medina","raw_affiliation_strings":["Department of Computer Science, University of Texas at El Paso"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Texas at El Paso","institution_ids":["https://openalex.org/I164936912"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5038223145","display_name":"Jason Ellis","orcid":null},"institutions":[{"id":"https://openalex.org/I2802705668","display_name":"United States Army Combat Capabilities Development Command","ror":"https://ror.org/02rdkx920","country_code":"US","type":"other","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]},{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Jason Ellis","raw_affiliation_strings":["DEVCOM Army Research Laboratory"],"affiliations":[{"raw_affiliation_string":"DEVCOM Army Research Laboratory","institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2802705668"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5049761359","display_name":"Luisana Clarke","orcid":null},"institutions":[{"id":"https://openalex.org/I164936912","display_name":"The University of Texas at El Paso","ror":"https://ror.org/04d5vba33","country_code":"US","type":"education","lineage":["https://openalex.org/I164936912"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Luisana Clarke","raw_affiliation_strings":["Department of Computer Science, University of Texas at El Paso"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Texas at El Paso","institution_ids":["https://openalex.org/I164936912"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5113213885","display_name":"Veronica M. Rivas","orcid":null},"institutions":[{"id":"https://openalex.org/I164936912","display_name":"The University of Texas at El Paso","ror":"https://ror.org/04d5vba33","country_code":"US","type":"education","lineage":["https://openalex.org/I164936912"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Veronica Rivas","raw_affiliation_strings":["Department of Computer Science, University of Texas at El Paso"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science, University of Texas at El Paso","institution_ids":["https://openalex.org/I164936912"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5087854761","display_name":"Allison Newcomb","orcid":null},"institutions":[{"id":"https://openalex.org/I166416128","display_name":"DEVCOM Army Research Laboratory","ror":"https://ror.org/011hc8f90","country_code":"US","type":"government","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I166416128","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]},{"id":"https://openalex.org/I2802705668","display_name":"United States Army Combat Capabilities Development Command","ror":"https://ror.org/02rdkx920","country_code":"US","type":"other","lineage":["https://openalex.org/I1304082316","https://openalex.org/I1330347796","https://openalex.org/I2802705668","https://openalex.org/I4210154437"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Allison Newcomb","raw_affiliation_strings":["DEVCOM Army Research Laboratory"],"affiliations":[{"raw_affiliation_string":"DEVCOM Army Research Laboratory","institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2802705668"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":6,"corresponding_author_ids":["https://openalex.org/A5029731437"],"corresponding_institution_ids":["https://openalex.org/I166416128","https://openalex.org/I2802705668"],"apc_list":null,"apc_paid":null,"fwci":0.616,"has_fulltext":false,"cited_by_count":2,"citation_normalized_percentile":{"value":0.58049266,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"849","last_page":"854"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11598","display_name":"Internet Traffic Analysis and Secure E-voting","score":0.9990000128746033,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9987000226974487,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8196603059768677},{"id":"https://openalex.org/keywords/deep-packet-inspection","display_name":"Deep packet inspection","score":0.5273849964141846},{"id":"https://openalex.org/keywords/workflow","display_name":"Workflow","score":0.5235499739646912},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.46092861890792847},{"id":"https://openalex.org/keywords/modular-design","display_name":"Modular design","score":0.4573686718940735},{"id":"https://openalex.org/keywords/data-curation","display_name":"Data curation","score":0.4533889889717102},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.3770313858985901},{"id":"https://openalex.org/keywords/network-packet","display_name":"Network packet","score":0.3608661890029907},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.29377949237823486},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.2879428267478943},{"id":"https://openalex.org/keywords/operating-system","display_name":"Operating system","score":0.15297788381576538}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8196603059768677},{"id":"https://openalex.org/C204679922","wikidata":"https://www.wikidata.org/wiki/Q734252","display_name":"Deep packet inspection","level":3,"score":0.5273849964141846},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.5235499739646912},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.46092861890792847},{"id":"https://openalex.org/C101468663","wikidata":"https://www.wikidata.org/wiki/Q1620158","display_name":"Modular design","level":2,"score":0.4573686718940735},{"id":"https://openalex.org/C91632574","wikidata":"https://www.wikidata.org/wiki/Q15088675","display_name":"Data curation","level":2,"score":0.4533889889717102},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.3770313858985901},{"id":"https://openalex.org/C158379750","wikidata":"https://www.wikidata.org/wiki/Q214111","display_name":"Network packet","level":2,"score":0.3608661890029907},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.29377949237823486},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.2879428267478943},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.15297788381576538}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/milcom52596.2021.9653049","is_oa":false,"landing_page_url":"https://doi.org/10.1109/milcom52596.2021.9653049","pdf_url":null,"source":{"id":"https://openalex.org/S4363608138","display_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"conference"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"MILCOM 2021 - 2021 IEEE Military Communications Conference (MILCOM)","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.4000000059604645,"id":"https://metadata.un.org/sdg/17","display_name":"Partnerships for the goals"}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":15,"referenced_works":["https://openalex.org/W405461467","https://openalex.org/W1576185228","https://openalex.org/W2089938540","https://openalex.org/W2099218848","https://openalex.org/W2165855437","https://openalex.org/W2184553289","https://openalex.org/W2188584537","https://openalex.org/W2532424365","https://openalex.org/W2772231779","https://openalex.org/W2789828921","https://openalex.org/W2799210984","https://openalex.org/W2888802852","https://openalex.org/W2963748489","https://openalex.org/W3047415238","https://openalex.org/W3119524937"],"related_works":["https://openalex.org/W1981780420","https://openalex.org/W2182707996","https://openalex.org/W2701062589","https://openalex.org/W45233828","https://openalex.org/W2964988449","https://openalex.org/W4308914582","https://openalex.org/W188202134","https://openalex.org/W2397952901","https://openalex.org/W2594425278","https://openalex.org/W2171331105"],"abstract_inverted_index":{"Cybersecurity":[0],"network":[1,119,125,194],"data":[2,48,149,216],"curation":[3,49],"is":[4,157],"the":[5,19,60,75,79,107,115,140,172,206],"collection,":[6],"labeling,":[7,94],"and":[8,29,34,38,59,66,71,84,88,93,98,133,162],"packaging":[9],"of":[10,55,68,81,117,137,174],"datasets":[11],"that":[12,15,86,202],"contain":[13],"artifacts":[14],"are":[16,24,50],"important":[17],"in":[18,52,176],"cybersecurity":[20,27,187],"domain.":[21],"These":[22],"assets":[23],"essential":[25],"for":[26,31,47,146,226],"research":[28,65],"key":[30],"defense":[32],"technologies":[33,85],"systems":[35],"to":[36,40,159,163,214],"detect":[37],"respond":[39],"anomalies":[41],"caused":[42],"by":[43,189],"adversaries.":[44],"However,":[45],"tools":[46,83],"lacking":[51],"all":[53,148],"domains":[54],"cybersecurity,":[56],"including":[57,221],"enterprise":[58],"military.":[61],"Curation":[62,110],"fuels":[63],"empirical":[64],"validation":[67],"protection,":[69],"detection,":[70],"prevention":[72],"techniques.":[73],"Closing":[74],"gap":[76],"will":[77],"require":[78],"development":[80],"research-driven":[82],"facilitate":[87,164],"enforce":[89],"not":[90],"only":[91],"collection":[92],"but":[95],"also":[96],"standardization":[97],"distribution.":[99],"This":[100],"paper":[101],"describes":[102],"a":[103,135,143,151,199,210,218],"novel":[104],"tool,":[105],"called":[106],"Network":[108],"Data":[109],"Toolkit":[111],"(NDCT),":[112],"which":[113,208],"simplifies":[114],"process":[116],"collecting":[118],"traffic,":[120],"keystrokes,":[121],"mouse":[122],"clicks;":[123],"allows":[124],"packet":[126],"labeling;":[127],"automatically":[128],"generates":[129],"intrusion":[130,223],"detection":[131,224],"rules;":[132],"provides":[134,209],"visualization":[136],"results.":[138],"Moreover,":[139],"tool":[141,156],"has":[142],"built-in":[144],"mechanism":[145],"exporting":[147],"into":[150,167],"single":[152],"distributable":[153],"file.":[154],"The":[155],"modular":[158],"allow":[160],"extension":[161],"its":[165],"incorporation":[166],"existing":[168],"workflows.":[169],"We":[170,180,196],"demonstrate":[171],"use":[173],"NDCT":[175,184],"two":[177],"case":[178],"studies.":[179],"first":[181],"show":[182],"how":[183],"can":[185],"augment":[186],"exercises":[188],"having":[190],"participants":[191],"label":[192],"their":[193],"data.":[195],"then":[197],"describe":[198],"separate":[200],"system":[201],"was":[203],"embedded":[204],"with":[205],"NDCT,":[207],"workspace,":[211],"allowing":[212],"users":[213],"curate":[215],"through":[217],"multi-session":[219],"environment,":[220],"generating":[222],"rules":[225],"malware.":[227]},"counts_by_year":[{"year":2024,"cited_by_count":1},{"year":2023,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
