{"id":"https://openalex.org/W4400976357","doi":"https://doi.org/10.1145/3664476.3664494","title":"Prov2vec: Learning Provenance Graph Representation for Anomaly Detection in Computer Systems","display_name":"Prov2vec: Learning Provenance Graph Representation for Anomaly Detection in Computer Systems","publication_year":2024,"publication_date":"2024-07-25","ids":{"openalex":"https://openalex.org/W4400976357","doi":"https://doi.org/10.1145/3664476.3664494"},"language":"en","primary_location":{"id":"doi:10.1145/3664476.3664494","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664476.3664494","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5021769364","display_name":"Bibek Bhattarai","orcid":"https://orcid.org/0000-0002-9959-7622"},"institutions":[{"id":"https://openalex.org/I193531525","display_name":"George Washington University","ror":"https://ror.org/00y4zzh67","country_code":"US","type":"education","lineage":["https://openalex.org/I193531525"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Bibek Bhattarai","raw_affiliation_strings":["George Washington University, USA"],"affiliations":[{"raw_affiliation_string":"George Washington University, USA","institution_ids":["https://openalex.org/I193531525"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5002254350","display_name":"H. Howie Huang","orcid":"https://orcid.org/0000-0001-8588-7680"},"institutions":[{"id":"https://openalex.org/I193531525","display_name":"George Washington University","ror":"https://ror.org/00y4zzh67","country_code":"US","type":"education","lineage":["https://openalex.org/I193531525"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"H. Howie Huang","raw_affiliation_strings":["George Washington University, Washington DC, USA, USA"],"affiliations":[{"raw_affiliation_string":"George Washington University, Washington DC, USA, USA","institution_ids":["https://openalex.org/I193531525"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5021769364"],"corresponding_institution_ids":["https://openalex.org/I193531525"],"apc_list":null,"apc_paid":null,"fwci":2.5994,"has_fulltext":false,"cited_by_count":7,"citation_normalized_percentile":{"value":0.90255199,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":90,"max":99},"biblio":{"volume":null,"issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12127","display_name":"Software System Performance and Reliability","score":0.9994000196456909,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9954000115394592,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10260","display_name":"Software Engineering Research","score":0.9904000163078308,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7146412134170532},{"id":"https://openalex.org/keywords/provenance","display_name":"Provenance","score":0.5506885051727295},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.5416635870933533},{"id":"https://openalex.org/keywords/representation","display_name":"Representation (politics)","score":0.5227308869361877},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.4483437240123749},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4302109479904175},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.3533763289451599}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7146412134170532},{"id":"https://openalex.org/C2780049196","wikidata":"https://www.wikidata.org/wiki/Q23582628","display_name":"Provenance","level":2,"score":0.5506885051727295},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.5416635870933533},{"id":"https://openalex.org/C2776359362","wikidata":"https://www.wikidata.org/wiki/Q2145286","display_name":"Representation (politics)","level":3,"score":0.5227308869361877},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.4483437240123749},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4302109479904175},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.3533763289451599},{"id":"https://openalex.org/C94625758","wikidata":"https://www.wikidata.org/wiki/Q7163","display_name":"Politics","level":2,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C5900021","wikidata":"https://www.wikidata.org/wiki/Q163082","display_name":"Petrology","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C127313418","wikidata":"https://www.wikidata.org/wiki/Q1069","display_name":"Geology","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3664476.3664494","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3664476.3664494","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 19th International Conference on Availability, Reliability and Security","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"score":0.46000000834465027,"display_name":"Reduced inequalities","id":"https://metadata.un.org/sdg/10"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":42,"referenced_works":["https://openalex.org/W1985987493","https://openalex.org/W1999092742","https://openalex.org/W2009232481","https://openalex.org/W2039444222","https://openalex.org/W2053076698","https://openalex.org/W2104812688","https://openalex.org/W2147286743","https://openalex.org/W2208211896","https://openalex.org/W2284900416","https://openalex.org/W2510664603","https://openalex.org/W2532844970","https://openalex.org/W2536393303","https://openalex.org/W2560674852","https://openalex.org/W2747669027","https://openalex.org/W2767094836","https://openalex.org/W2772632044","https://openalex.org/W2790316935","https://openalex.org/W2790557990","https://openalex.org/W2792207129","https://openalex.org/W2807975761","https://openalex.org/W2885157095","https://openalex.org/W2890262614","https://openalex.org/W2947745012","https://openalex.org/W2962703433","https://openalex.org/W2978956219","https://openalex.org/W2986944522","https://openalex.org/W2988337058","https://openalex.org/W2994598354","https://openalex.org/W2997591727","https://openalex.org/W2998647325","https://openalex.org/W3008508243","https://openalex.org/W3015650867","https://openalex.org/W3099203541","https://openalex.org/W3104667978","https://openalex.org/W4225697716","https://openalex.org/W4226139354","https://openalex.org/W4245671428","https://openalex.org/W4281383000","https://openalex.org/W4288057803","https://openalex.org/W4311703141","https://openalex.org/W4387298384","https://openalex.org/W6888517835"],"related_works":["https://openalex.org/W2354627941","https://openalex.org/W2347483153","https://openalex.org/W2353379336","https://openalex.org/W2379683085","https://openalex.org/W2363868702","https://openalex.org/W2374448931","https://openalex.org/W2376723740","https://openalex.org/W2370535391","https://openalex.org/W2370679613","https://openalex.org/W2380057024"],"abstract_inverted_index":{"Modern":[0],"cyber":[1],"attackers":[2],"use":[3,21],"advanced":[4],"zero-day":[5],"exploits,":[6],"highly":[7],"targeted":[8],"spear":[9],"phishing,":[10],"and":[11,19,97,127],"other":[12,130],"social":[13],"engineering":[14],"techniques":[15,23],"to":[16,24,70,85,111,132,148,152,177],"gain":[17],"access,":[18],"also":[20],"evasion":[22],"maintain":[25],"a":[26,60,106,171],"prolonged":[27],"presence":[28],"within":[29],"the":[30,37,50,63,76,90,98,113,117,134,137,154,166],"victim":[31],"network":[32],"while":[33,180],"working":[34],"gradually":[35],"towards":[36],"objective.":[38],"To":[39],"minimize":[40],"damage,":[41],"detecting":[42],"these":[43],"Advanced":[44],"Persistent":[45],"Threats":[46],"as":[47,52],"early":[48],"in":[49,143],"campaign":[51],"possible":[53],"is":[54,121],"crucial.":[55],"This":[56],"paper":[57],"proposes,":[58],"Prov2vec,":[59],"system":[61,82,102,118],"for":[62],"continuous":[64],"monitoring":[65],"of":[66,93,116,129,157],"enterprise":[67,95],"host\u2019s":[68],"behavior":[69,156],"detect":[71,133],"attackers\u2019":[72],"activities.":[73],"It":[74,104],"leverages":[75],"data":[77],"provenance":[78,108,167],"graph":[79,109,168],"built":[80],"using":[81],"event":[83],"logs":[84],"get":[86],"complete":[87],"visibility":[88],"into":[89],"execution":[91],"state":[92],"an":[94,158],"host":[96],"causal":[99],"relationship":[100],"between":[101],"entities.":[103],"proposes":[105],"novel":[107],"kernel":[110,169],"obtain":[112],"canonical":[114],"representation":[115,175],"behavior,":[119],"which":[120],"compared":[122,176],"against":[123],"its":[124],"historical":[125],"behaviors":[126],"that":[128,165],"hosts":[131],"deviation":[135],"from":[136],"norm.":[138],"These":[139],"representations":[140],"are":[141],"used":[142],"several":[144],"machine":[145],"learning":[146],"models":[147],"evaluate":[149],"their":[150],"ability":[151],"capture":[153],"underlying":[155],"endpoint":[159],"host.":[160],"We":[161],"have":[162],"empirically":[163],"demonstrated":[164],"produces":[170],"much":[172],"more":[173],"compact":[174],"existing":[178],"methods":[179],"improving":[181],"prediction":[182],"ability.":[183]},"counts_by_year":[{"year":2026,"cited_by_count":1},{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":1}],"updated_date":"2026-03-03T08:47:05.690250","created_date":"2025-10-10T00:00:00"}
