{"id":"https://openalex.org/W3212868562","doi":"https://doi.org/10.1109/tifs.2022.3208815","title":"THREATRACE: Detecting and Tracing Host-Based Threats in Node Level Through Provenance Graph Learning","display_name":"THREATRACE: Detecting and Tracing Host-Based Threats in Node Level Through Provenance Graph Learning","publication_year":2022,"publication_date":"2022-01-01","ids":{"openalex":"https://openalex.org/W3212868562","doi":"https://doi.org/10.1109/tifs.2022.3208815","mag":"3212868562"},"language":"en","primary_location":{"id":"doi:10.1109/tifs.2022.3208815","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3208815","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},"type":"article","indexed_in":["arxiv","crossref"],"open_access":{"is_oa":true,"oa_status":"green","oa_url":"https://arxiv.org/pdf/2111.04333","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5100463046","display_name":"Su Wang","orcid":"https://orcid.org/0000-0001-7094-8890"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Su Wang","raw_affiliation_strings":["Department of Computer Science and Technology, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100343127","display_name":"Zhiliang Wang","orcid":"https://orcid.org/0000-0001-6587-820X"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhiliang Wang","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5061274720","display_name":"Tao Zhou","orcid":"https://orcid.org/0000-0002-2592-1688"},"institutions":[{"id":"https://openalex.org/I45928872","display_name":"Alibaba Group (China)","ror":"https://ror.org/00k642b80","country_code":"CN","type":"company","lineage":["https://openalex.org/I45928872"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Tao Zhou","raw_affiliation_strings":["Alibaba Group, Hangzhou, China"],"affiliations":[{"raw_affiliation_string":"Alibaba Group, Hangzhou, China","institution_ids":["https://openalex.org/I45928872"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100762412","display_name":"Hongbin Sun","orcid":"https://orcid.org/0000-0002-5465-9818"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Hongbin Sun","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100446843","display_name":"Xia Yin","orcid":"https://orcid.org/0000-0001-9784-8742"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xia Yin","raw_affiliation_strings":["Department of Computer Science and Technology, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Department of Computer Science and Technology, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5016545058","display_name":"Dongqi Han","orcid":"https://orcid.org/0000-0002-0807-5934"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Dongqi Han","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100399382","display_name":"Han Zhang","orcid":"https://orcid.org/0000-0003-4429-9959"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Han Zhang","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5047888843","display_name":"Xingang Shi","orcid":"https://orcid.org/0000-0001-6487-9526"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xingang Shi","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5023416195","display_name":"Jiahai Yang","orcid":"https://orcid.org/0000-0001-6109-6737"},"institutions":[{"id":"https://openalex.org/I99065089","display_name":"Tsinghua University","ror":"https://ror.org/03cve4549","country_code":"CN","type":"education","lineage":["https://openalex.org/I99065089"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiahai Yang","raw_affiliation_strings":["Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China"],"affiliations":[{"raw_affiliation_string":"Institute for Network Sciences and Cyberspace, BNRist, Tsinghua University, Beijing, China","institution_ids":["https://openalex.org/I99065089"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":9,"corresponding_author_ids":["https://openalex.org/A5100463046"],"corresponding_institution_ids":["https://openalex.org/I99065089"],"apc_list":null,"apc_paid":null,"fwci":21.6905,"has_fulltext":false,"cited_by_count":167,"citation_normalized_percentile":{"value":0.99715291,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":"17","issue":null,"first_page":"3972","last_page":"3987"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9994999766349792,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9890000224113464,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8151668310165405},{"id":"https://openalex.org/keywords/host","display_name":"Host (biology)","score":0.6092685461044312},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.5765708088874817},{"id":"https://openalex.org/keywords/malware","display_name":"Malware","score":0.5617480278015137},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.5229940414428711},{"id":"https://openalex.org/keywords/scalability","display_name":"Scalability","score":0.43223750591278076},{"id":"https://openalex.org/keywords/tracing","display_name":"Tracing","score":0.41990137100219727},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3734396994113922},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.36269715428352356},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.317252516746521},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.21032008528709412},{"id":"https://openalex.org/keywords/programming-language","display_name":"Programming language","score":0.15775397419929504},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.13691246509552002}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8151668310165405},{"id":"https://openalex.org/C126831891","wikidata":"https://www.wikidata.org/wiki/Q221673","display_name":"Host (biology)","level":2,"score":0.6092685461044312},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.5765708088874817},{"id":"https://openalex.org/C541664917","wikidata":"https://www.wikidata.org/wiki/Q14001","display_name":"Malware","level":2,"score":0.5617480278015137},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.5229940414428711},{"id":"https://openalex.org/C48044578","wikidata":"https://www.wikidata.org/wiki/Q727490","display_name":"Scalability","level":2,"score":0.43223750591278076},{"id":"https://openalex.org/C138673069","wikidata":"https://www.wikidata.org/wiki/Q322229","display_name":"Tracing","level":2,"score":0.41990137100219727},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3734396994113922},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.36269715428352356},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.317252516746521},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.21032008528709412},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.15775397419929504},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.13691246509552002},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C18903297","wikidata":"https://www.wikidata.org/wiki/Q7150","display_name":"Ecology","level":1,"score":0.0}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1109/tifs.2022.3208815","is_oa":false,"landing_page_url":"https://doi.org/10.1109/tifs.2022.3208815","pdf_url":null,"source":{"id":"https://openalex.org/S61310614","display_name":"IEEE Transactions on Information Forensics and Security","issn_l":"1556-6013","issn":["1556-6013","1556-6021"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319808","host_organization_name":"Institute of Electrical and Electronics Engineers","host_organization_lineage":["https://openalex.org/P4310319808"],"host_organization_lineage_names":["Institute of Electrical and Electronics Engineers"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"IEEE Transactions on Information Forensics and Security","raw_type":"journal-article"},{"id":"pmh:oai:arXiv.org:2111.04333","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2111.04333","pdf_url":"https://arxiv.org/pdf/2111.04333","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"}],"best_oa_location":{"id":"pmh:oai:arXiv.org:2111.04333","is_oa":true,"landing_page_url":"http://arxiv.org/abs/2111.04333","pdf_url":"https://arxiv.org/pdf/2111.04333","source":{"id":"https://openalex.org/S4306400194","display_name":"arXiv (Cornell University)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I205783295","host_organization_name":"Cornell University","host_organization_lineage":["https://openalex.org/I205783295"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":null,"raw_type":"text"},"sustainable_development_goals":[{"score":0.699999988079071,"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16"}],"awards":[{"id":"https://openalex.org/G2771372968","display_name":null,"funder_award_id":"2018YFB1800200","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G571043820","display_name":null,"funder_award_id":"62002009","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":58,"referenced_works":["https://openalex.org/W1985987493","https://openalex.org/W2008704879","https://openalex.org/W2106649514","https://openalex.org/W2123504579","https://openalex.org/W2284900416","https://openalex.org/W2513712568","https://openalex.org/W2747669027","https://openalex.org/W2751114427","https://openalex.org/W2767094836","https://openalex.org/W2790557990","https://openalex.org/W2792581684","https://openalex.org/W2798819286","https://openalex.org/W2803831897","https://openalex.org/W2889379876","https://openalex.org/W2904378456","https://openalex.org/W2908442265","https://openalex.org/W2946234452","https://openalex.org/W2947745012","https://openalex.org/W2947815220","https://openalex.org/W2949208225","https://openalex.org/W2962703433","https://openalex.org/W2962785074","https://openalex.org/W2963053388","https://openalex.org/W2963175158","https://openalex.org/W2963791934","https://openalex.org/W2964858965","https://openalex.org/W2966149470","https://openalex.org/W2970089374","https://openalex.org/W2978956219","https://openalex.org/W2984488829","https://openalex.org/W2986944522","https://openalex.org/W2993658339","https://openalex.org/W2994598354","https://openalex.org/W2997494090","https://openalex.org/W2998038410","https://openalex.org/W2998367408","https://openalex.org/W3006711782","https://openalex.org/W3015650867","https://openalex.org/W3016038045","https://openalex.org/W3092382617","https://openalex.org/W3099203541","https://openalex.org/W3101089035","https://openalex.org/W3104667978","https://openalex.org/W3152911549","https://openalex.org/W3158906645","https://openalex.org/W3176642478","https://openalex.org/W4288057803","https://openalex.org/W4294558607","https://openalex.org/W6675849491","https://openalex.org/W6738964360","https://openalex.org/W6743841043","https://openalex.org/W6766014713","https://openalex.org/W6766715506","https://openalex.org/W6766867396","https://openalex.org/W6779739866","https://openalex.org/W6784004519","https://openalex.org/W6793953445","https://openalex.org/W6797281886"],"related_works":["https://openalex.org/W2097492617","https://openalex.org/W2753240997","https://openalex.org/W1764168690","https://openalex.org/W2537959205","https://openalex.org/W2740895074","https://openalex.org/W2772446090","https://openalex.org/W4284893819","https://openalex.org/W3152891574","https://openalex.org/W4316881845","https://openalex.org/W2975527072"],"abstract_inverted_index":{"Host-based":[0],"threats":[1,32,115],"such":[2],"as":[3],"Program":[4],"Attack,":[5],"Malware":[6],"Implantation,":[7],"and":[8,60,65,96,158],"Advanced":[9],"Persistent":[10],"Threats":[11],"(APT),":[12],"are":[13,86],"commonly":[14],"adopted":[15],"by":[16],"modern":[17],"attackers.":[18],"Recent":[19],"studies":[20],"propose":[21],"leveraging":[22],"the":[23,71,83,90],"rich":[24],"contextual":[25],"information":[26,74],"in":[27,33,49,70,99,140,164],"data":[28],"provenance":[29,37,51,84,142],"to":[30,89,134],"detect":[31],"a":[34,39,50,141,146,154],"host.":[35],"Data":[36],"is":[38,145,150],"directed":[40],"acyclic":[41],"graph":[42,52,131],"constructed":[43],"from":[44],"system":[45,54,68,117],"audit":[46],"data.":[47],"Nodes":[48],"represent":[53,67],"entities":[55,95],"(e.g.,":[56],"<italic":[57,61],"xmlns:mml=\"http://www.w3.org/1998/Math/MathML\"":[58,62],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">processes</i>":[59],"xmlns:xlink=\"http://www.w3.org/1999/xlink\">files</i>":[63],")":[64],"edges":[66],"calls":[69],"direction":[72],"of":[73,82,93,123,152,160],"flow.":[75],"However,":[76],"previous":[77],"studies,":[78],"which":[79,149],"extract":[80],"features":[81],"graph,":[85],"not":[87],"sensitive":[88],"small":[91],"quantity":[92],"threat-related":[94],"thus":[97],"result":[98],"low":[100],"performance":[101],"when":[102],"hunting":[103],"stealthy":[104],"threats.":[105],"We":[106,126,168],"present":[107],"THREATRACE,":[108],"an":[109,129],"anomaly-based":[110],"detector":[111],"that":[112,178],"detects":[113],"host-based":[114,162],"at":[116],"entity":[118],"level":[119],"without":[120],"prior":[121],"knowledge":[122],"attack":[124],"patterns.":[125],"tailor":[127],"GraphSAGE,":[128],"inductive":[130],"neural":[132],"network,":[133],"learn":[135],"every":[136],"benign":[137],"entity\u2019s":[138],"role":[139],"graph.":[143],"THREATRACE":[144,170,179],"real-time":[147],"system,":[148],"scalable":[151],"monitoring":[153],"long-term":[155],"running":[156],"host":[157,183],"capable":[159],"detecting":[161],"intrusion":[163,184],"their":[165],"early":[166],"phase.":[167],"evaluate":[169],"on":[171],"five":[172],"public":[173],"datasets.":[174],"The":[175],"results":[176],"show":[177],"outperforms":[180],"seven":[181],"state-of-the-art":[182],"detection":[185],"systems.":[186]},"counts_by_year":[{"year":2026,"cited_by_count":15},{"year":2025,"cited_by_count":98},{"year":2024,"cited_by_count":39},{"year":2023,"cited_by_count":15}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
