{"id":"https://openalex.org/W3113176930","doi":"https://doi.org/10.1155/2020/8842539","title":"GroupTracer: Automatic Attacker TTP Profile Extraction and Group Cluster in Internet of Things","display_name":"GroupTracer: Automatic Attacker TTP Profile Extraction and Group Cluster in Internet of Things","publication_year":2020,"publication_date":"2020-12-04","ids":{"openalex":"https://openalex.org/W3113176930","doi":"https://doi.org/10.1155/2020/8842539","mag":"3113176930"},"language":"en","primary_location":{"id":"doi:10.1155/2020/8842539","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2020/8842539","pdf_url":"https://downloads.hindawi.com/journals/scn/2020/8842539.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://downloads.hindawi.com/journals/scn/2020/8842539.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5102863764","display_name":"Yixin Wu","orcid":"https://orcid.org/0000-0002-3000-9423"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Yixin Wu","raw_affiliation_strings":["College of Cybersecurity, Sichuan University, Chengdu 610065, China"],"affiliations":[{"raw_affiliation_string":"College of Cybersecurity, Sichuan University, Chengdu 610065, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5075394107","display_name":"Cheng Huang","orcid":"https://orcid.org/0000-0002-5871-946X"},"institutions":[{"id":"https://openalex.org/I24185976","display_name":"Sichuan University","ror":"https://ror.org/011ashp19","country_code":"CN","type":"education","lineage":["https://openalex.org/I24185976"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Cheng Huang","raw_affiliation_strings":["College of Cybersecurity, Sichuan University, Chengdu 610065, China"],"affiliations":[{"raw_affiliation_string":"College of Cybersecurity, Sichuan University, Chengdu 610065, China","institution_ids":["https://openalex.org/I24185976"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100399149","display_name":"Xing Zhang","orcid":"https://orcid.org/0000-0003-0152-3439"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Xing Zhang","raw_affiliation_strings":["NSFOCUS, Beijing 100089, China"],"affiliations":[{"raw_affiliation_string":"NSFOCUS, Beijing 100089, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5064691262","display_name":"Hongyi Zhou","orcid":"https://orcid.org/0000-0002-1434-0431"},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Hongyi Zhou","raw_affiliation_strings":["NSFOCUS, Beijing 100089, China"],"affiliations":[{"raw_affiliation_string":"NSFOCUS, Beijing 100089, China","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5075394107"],"corresponding_institution_ids":["https://openalex.org/I24185976"],"apc_list":{"value":2100,"currency":"USD","value_usd":2100},"apc_paid":{"value":2100,"currency":"USD","value_usd":2100},"fwci":1.1325,"has_fulltext":true,"cited_by_count":14,"citation_normalized_percentile":{"value":0.80988065,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":94,"max":98},"biblio":{"volume":"2020","issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":1.0,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9988999962806702,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8627703189849854},{"id":"https://openalex.org/keywords/honeypot","display_name":"Honeypot","score":0.7665241360664368},{"id":"https://openalex.org/keywords/hacker","display_name":"Hacker","score":0.6973907947540283},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.6910481452941895},{"id":"https://openalex.org/keywords/the-internet","display_name":"The Internet","score":0.6576382517814636},{"id":"https://openalex.org/keywords/cluster-analysis","display_name":"Cluster analysis","score":0.5936858654022217},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.5005245208740234},{"id":"https://openalex.org/keywords/botnet","display_name":"Botnet","score":0.4678198993206024},{"id":"https://openalex.org/keywords/cluster","display_name":"Cluster (spacecraft)","score":0.4387952983379364},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.23670831322669983},{"id":"https://openalex.org/keywords/world-wide-web","display_name":"World Wide Web","score":0.22650864720344543},{"id":"https://openalex.org/keywords/computer-network","display_name":"Computer network","score":0.20476582646369934}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8627703189849854},{"id":"https://openalex.org/C191267431","wikidata":"https://www.wikidata.org/wiki/Q911932","display_name":"Honeypot","level":2,"score":0.7665241360664368},{"id":"https://openalex.org/C86844869","wikidata":"https://www.wikidata.org/wiki/Q2798820","display_name":"Hacker","level":2,"score":0.6973907947540283},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.6910481452941895},{"id":"https://openalex.org/C110875604","wikidata":"https://www.wikidata.org/wiki/Q75","display_name":"The Internet","level":2,"score":0.6576382517814636},{"id":"https://openalex.org/C73555534","wikidata":"https://www.wikidata.org/wiki/Q622825","display_name":"Cluster analysis","level":2,"score":0.5936858654022217},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.5005245208740234},{"id":"https://openalex.org/C22735295","wikidata":"https://www.wikidata.org/wiki/Q317671","display_name":"Botnet","level":3,"score":0.4678198993206024},{"id":"https://openalex.org/C164866538","wikidata":"https://www.wikidata.org/wiki/Q367351","display_name":"Cluster (spacecraft)","level":2,"score":0.4387952983379364},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.23670831322669983},{"id":"https://openalex.org/C136764020","wikidata":"https://www.wikidata.org/wiki/Q466","display_name":"World Wide Web","level":1,"score":0.22650864720344543},{"id":"https://openalex.org/C31258907","wikidata":"https://www.wikidata.org/wiki/Q1301371","display_name":"Computer network","level":1,"score":0.20476582646369934}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1155/2020/8842539","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2020/8842539","pdf_url":"https://downloads.hindawi.com/journals/scn/2020/8842539.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:2eff8be5fa884c5aa2bd5349c1b8ca5b","is_oa":true,"landing_page_url":"https://doaj.org/article/2eff8be5fa884c5aa2bd5349c1b8ca5b","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Security and Communication Networks, Vol 2020 (2020)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1155/2020/8842539","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2020/8842539","pdf_url":"https://downloads.hindawi.com/journals/scn/2020/8842539.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"sustainable_development_goals":[{"display_name":"Industry, innovation and infrastructure","score":0.6299999952316284,"id":"https://metadata.un.org/sdg/9"}],"awards":[{"id":"https://openalex.org/G1121271761","display_name":null,"funder_award_id":"Program","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G1243841829","display_name":null,"funder_award_id":"2018YFB0804503","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2087396116","display_name":null,"funder_award_id":"China","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2206035631","display_name":null,"funder_award_id":"6190226","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G2938939561","display_name":null,"funder_award_id":"2016YFE0206700","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G3317480652","display_name":null,"funder_award_id":"Science","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G4009927024","display_name":null,"funder_award_id":"61902265","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G4016639641","display_name":null,"funder_award_id":"61902265","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5848258319","display_name":null,"funder_award_id":"0 and","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G5994120800","display_name":null,"funder_award_id":"Natural","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G7108774048","display_name":null,"funder_award_id":"2018YFB0804503","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G7974928415","display_name":null,"funder_award_id":"61902265)","funder_id":"https://openalex.org/F4320321001","funder_display_name":"National Natural Science Foundation of China"},{"id":"https://openalex.org/G8114646031","display_name":null,"funder_award_id":"2016Y","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"},{"id":"https://openalex.org/G8288812276","display_name":null,"funder_award_id":"2016YFE0206700","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320321001","display_name":"National Natural Science Foundation of China","ror":"https://ror.org/01h0zpd94"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"pdf":true,"grobid_xml":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3113176930.pdf","grobid_xml":"https://content.openalex.org/works/W3113176930.grobid-xml"},"referenced_works_count":33,"referenced_works":["https://openalex.org/W1538412636","https://openalex.org/W1669806660","https://openalex.org/W1851665508","https://openalex.org/W1977556410","https://openalex.org/W1987971958","https://openalex.org/W1998871699","https://openalex.org/W2022686119","https://openalex.org/W2025899538","https://openalex.org/W2051224630","https://openalex.org/W2085487226","https://openalex.org/W2105803478","https://openalex.org/W2146957318","https://openalex.org/W2207386025","https://openalex.org/W2267635142","https://openalex.org/W2302325356","https://openalex.org/W2307930854","https://openalex.org/W2324662912","https://openalex.org/W2335062971","https://openalex.org/W2425931228","https://openalex.org/W2574448563","https://openalex.org/W2593800047","https://openalex.org/W2611145822","https://openalex.org/W2738501932","https://openalex.org/W2848278845","https://openalex.org/W2964074409","https://openalex.org/W2971604521","https://openalex.org/W2997842691","https://openalex.org/W3123969097","https://openalex.org/W3141614604","https://openalex.org/W4249448758","https://openalex.org/W6637397297","https://openalex.org/W6685380521","https://openalex.org/W6753041022"],"related_works":["https://openalex.org/W2362574935","https://openalex.org/W1926248","https://openalex.org/W3159372857","https://openalex.org/W2363507101","https://openalex.org/W4320401378","https://openalex.org/W1517527854","https://openalex.org/W776729438","https://openalex.org/W2147767253","https://openalex.org/W3118687971","https://openalex.org/W1560502410"],"abstract_inverted_index":{"As":[0,215],"Advanced":[1],"Persistent":[2],"Threat":[3],"(APT)":[4],"becomes":[5],"increasingly":[6],"frequent":[7],"around":[8],"the":[9,24,30,32,44,75,107,118,129,142,169,208,216,230,237,250],"world,":[10],"security":[11],"experts":[12],"are":[13,37,165,220,258],"starting":[14],"to":[15,19,43,54,84,115,168,172,228],"look":[16],"at":[17],"how":[18],"observe,":[20],"predict,":[21],"and":[22,40,93,105,124,137,139,156,190,206,268,284],"mitigate":[23],"damage":[25,90],"from":[26,160],"APT":[27,56],"attacks.":[28,57,111,148],"In":[29],"meantime,":[31],"Internet":[33,66,91,108],"of":[34,65,67,109,131,195],"things":[35,68,110],"devices":[36,69],"also":[38],"risky":[39],"heavily":[41],"exposed":[42],"Internet,":[45],"making":[46],"them":[47],"more":[48],"easily":[49],"used":[50],"by":[51,153],"hacker":[52],"organizations":[53],"launch":[55,85],"An":[58],"excellent":[59,243],"attacker":[60,144],"can":[61,81,127],"take":[62],"down":[63],"millions":[64],"in":[70,245],"a":[71,101,193],"short":[72],"time.":[73],"Once":[74],"IoT":[76,154],"botnet":[77],"is":[78,113],"built,":[79],"attackers":[80,132],"use":[82],"it":[83,150],"complex":[86,147],"attacks":[87,152],"which":[88],"could":[89,276],"infrastructure":[92],"cause":[94],"network":[95],"disconnection.":[96],"This":[97],"paper":[98],"proposes":[99],"GroupTracer,":[100],"framework":[102,171,239],"for":[103,260],"observing":[104],"predicting":[106],"GroupTracer":[112,180],"designed":[114],"automatically":[116,166],"extract":[117],"TTP":[119,175,186],"profiles":[120,176],"(i.e.,":[121],"tactics,":[122,135],"techniques,":[123,136],"procedures)":[125],"that":[126,236],"describe":[128],"behavior":[130],"through":[133,202],"their":[134],"processes":[138],"dig":[140],"out":[141],"potential":[143,199,247],"groups":[145,201,248],"behind":[146],"Firstly,":[149],"captures":[151],"honeypots":[155],"extracts":[157],"relevant":[158],"fields":[159],"logs.":[161],"Then,":[162],"attack":[163,200,256,266,274,281],"behaviors":[164],"mapped":[167],"ATT&amp;CK":[170],"achieve":[173],"automatic":[174],"extraction.":[177],"After":[178],"that,":[179],"presents":[181],"four":[182],"feature":[183],"groups,":[184],"including":[185],"profiles,":[187],"Time,":[188],"IP,":[189],"URL":[191],"features,":[192,197],"total":[194],"18":[196],"mines":[198],"hierarchical":[203],"clustering":[204,209],"algorithm,":[205],"compares":[207],"results":[210,234],"with":[211],"two":[212],"baseline":[213],"algorithms.":[214],"ground":[217],"truth":[218],"labels":[219],"unknown,":[221],"we":[222],"apply":[223],"three":[224],"internal":[225],"validation":[226],"indexes":[227],"evaluate":[229],"cluster":[231,262],"quantity.":[232],"Experimental":[233],"showed":[235],"proposed":[238],"has":[240],"achieved":[241],"an":[242],"performance":[244],"exploiting":[246],"as":[249],"Calinski\u2013Harabasz":[251],"index":[252],"reaches":[253],"3416.93.":[254],"Eventually,":[255],"trees":[257,275],"generated":[259],"each":[261,280],"where":[263],"nodes":[264],"indicate":[265],"commands":[267],"edges":[269],"represent":[270],"command":[271],"sequences.":[272],"These":[273],"help":[277],"better":[278],"understand":[279],"group\u2019s":[282],"actions":[283],"techniques.":[285]},"counts_by_year":[{"year":2025,"cited_by_count":5},{"year":2024,"cited_by_count":2},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":4}],"updated_date":"2026-04-10T15:06:20.359241","created_date":"2025-10-10T00:00:00"}
