{"id":"https://openalex.org/W4399418872","doi":"https://doi.org/10.1145/3651671.3651707","title":"A heterogeneous graph-based approach for cyber threat attribution using threat intelligence","display_name":"A heterogeneous graph-based approach for cyber threat attribution using threat intelligence","publication_year":2024,"publication_date":"2024-02-02","ids":{"openalex":"https://openalex.org/W4399418872","doi":"https://doi.org/10.1145/3651671.3651707"},"language":"en","primary_location":{"id":"doi:10.1145/3651671.3651707","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3651671.3651707","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 16th International Conference on Machine Learning and Computing","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5020357674","display_name":"J. L. Duan","orcid":"https://orcid.org/0009-0002-5789-4693"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Junting Duan","raw_affiliation_strings":["School of Computer Science and Technology, University of Electronic Science and Technology of China, China"],"raw_orcid":"https://orcid.org/0009-0002-5789-4693","affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Electronic Science and Technology of China, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053957678","display_name":"Yujie Luo","orcid":"https://orcid.org/0009-0000-4209-3776"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yujie Luo,","raw_affiliation_strings":["School of Computer Science and Technology, University of Electronic Science and Technology of China, China"],"raw_orcid":"https://orcid.org/0009-0000-4209-3776","affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Electronic Science and Technology of China, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5041621096","display_name":"Zhicheng Zhang","orcid":"https://orcid.org/0009-0007-5970-2129"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zhicheng Zhang","raw_affiliation_strings":["School of Computer Science and Technology, University of Electronic Science and Technology of China, China"],"raw_orcid":"https://orcid.org/0009-0007-5970-2129","affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Electronic Science and Technology of China, China","institution_ids":["https://openalex.org/I150229711"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5050917104","display_name":"Jianjian Peng","orcid":"https://orcid.org/0009-0006-3513-1504"},"institutions":[{"id":"https://openalex.org/I150229711","display_name":"University of Electronic Science and Technology of China","ror":"https://ror.org/04qr3zq92","country_code":"CN","type":"education","lineage":["https://openalex.org/I150229711"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jianjian Peng","raw_affiliation_strings":["School of Computer Science and Technology, University of Electronic Science and Technology of China, China"],"raw_orcid":"https://orcid.org/0009-0006-3513-1504","affiliations":[{"raw_affiliation_string":"School of Computer Science and Technology, University of Electronic Science and Technology of China, China","institution_ids":["https://openalex.org/I150229711"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5020357674"],"corresponding_institution_ids":["https://openalex.org/I150229711"],"apc_list":null,"apc_paid":null,"fwci":4.0368,"has_fulltext":false,"cited_by_count":12,"citation_normalized_percentile":{"value":0.94267741,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"87","last_page":"93"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9955999851226807,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7131977677345276},{"id":"https://openalex.org/keywords/attribution","display_name":"Attribution","score":0.6228660345077515},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4987044334411621},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4574313759803772},{"id":"https://openalex.org/keywords/graph-theory","display_name":"Graph theory","score":0.4149875342845917},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.2751603424549103},{"id":"https://openalex.org/keywords/psychology","display_name":"Psychology","score":0.11103498935699463},{"id":"https://openalex.org/keywords/mathematics","display_name":"Mathematics","score":0.07336363196372986},{"id":"https://openalex.org/keywords/social-psychology","display_name":"Social psychology","score":0.06825867295265198}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7131977677345276},{"id":"https://openalex.org/C143299363","wikidata":"https://www.wikidata.org/wiki/Q900584","display_name":"Attribution","level":2,"score":0.6228660345077515},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4987044334411621},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4574313759803772},{"id":"https://openalex.org/C88230418","wikidata":"https://www.wikidata.org/wiki/Q131476","display_name":"Graph theory","level":2,"score":0.4149875342845917},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.2751603424549103},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.11103498935699463},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.07336363196372986},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.06825867295265198},{"id":"https://openalex.org/C114614502","wikidata":"https://www.wikidata.org/wiki/Q76592","display_name":"Combinatorics","level":1,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3651671.3651707","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3651671.3651707","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2024 16th International Conference on Machine Learning and Computing","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":19,"referenced_works":["https://openalex.org/W77083600","https://openalex.org/W2011493390","https://openalex.org/W2604314403","https://openalex.org/W2758108284","https://openalex.org/W2783245716","https://openalex.org/W2911286998","https://openalex.org/W2914662937","https://openalex.org/W3004507689","https://openalex.org/W3008445684","https://openalex.org/W3012871709","https://openalex.org/W3017733550","https://openalex.org/W3103513278","https://openalex.org/W3138686850","https://openalex.org/W3196325333","https://openalex.org/W4205142619","https://openalex.org/W4286375281","https://openalex.org/W4294771230","https://openalex.org/W4312941299","https://openalex.org/W6603173816"],"related_works":["https://openalex.org/W4391375266","https://openalex.org/W2748952813","https://openalex.org/W2035546108","https://openalex.org/W2376361520","https://openalex.org/W2133328864","https://openalex.org/W2093949997","https://openalex.org/W2570200690","https://openalex.org/W2389726244","https://openalex.org/W3030478661","https://openalex.org/W2323536476"],"abstract_inverted_index":{"Cyber":[0],"Threat":[1],"attribution":[2,30,95,117,142,177],"is":[3,16,143],"the":[4,11,47,62,74,77,147,150,172],"process":[5,15],"of":[6,34,67,76,82,139,174],"associating":[7],"a":[8,31,91,109,119,128,158],"cyberattack":[9],"with":[10,180],"threat":[12,29,51,94,105,116,153,163],"groups.":[13,154],"This":[14],"essential":[17],"for":[18,64],"enhancing":[19],"defense":[20,39],"strategies":[21],"and":[22,80,126,152],"enabling":[23],"rapid":[24],"response":[25],"to":[26,45,107,136],"threats,":[27],"making":[28],"critical":[32],"component":[33],"an":[35,55],"effective":[36],"network":[37],"security":[38],"system.":[40],"Current":[41],"methods":[42,135],"often":[43],"struggle":[44],"leverage":[46],"intricate":[48],"relationships":[49],"among":[50],"behaviors":[52],"or":[53],"lack":[54],"attacker\u2019s":[56],"feature":[57,138],"extraction":[58],"mechanism":[59],"resulting":[60],"in":[61,73],"need":[63],"manual":[65],"analysis":[66],"vast":[68],"data,":[69],"thereby":[70],"presenting":[71],"challenges":[72],"face":[75],"escalating":[78],"number":[79],"complexity":[81],"attacks.":[83],"To":[84],"tackle":[85],"these":[86],"challenges,":[87],"we":[88,114,170],"propose":[89,127],"HG-CTA,":[90],"novel":[92],"cyber":[93,104],"method":[96,178],"based":[97,131],"on":[98,123,157],"heterogeneous":[99,110,124,132],"graph.":[100],"We":[101],"first":[102],"utilize":[103],"intelligence(CTI)":[106],"construct":[108],"knowledge":[111],"base.":[112],"Then":[113],"formalize":[115],"as":[118],"link":[120],"prediction":[121],"task":[122],"graph":[125,133],"metapath":[129],"context":[130],"embedding":[134],"extract":[137],"attackers.":[140],"Finally,":[141],"achieved":[144],"by":[145,166],"inferring":[146],"relationship":[148],"between":[149],"attackers":[151],"Through":[155],"experiment":[156],"data":[159],"set":[160],"constructed":[161],"from":[162],"intelligence":[164],"provided":[165],"Alienvault,":[167],"Miter":[168],"ATT&CK,":[169],"demonstrate":[171],"effectiveness":[173],"our":[175],"proposed":[176],"compared":[179],"baseline":[181],"models.":[182]},"counts_by_year":[{"year":2025,"cited_by_count":11},{"year":2024,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
