{"id":"https://openalex.org/W3158906645","doi":"https://doi.org/10.1155/2021/9961342","title":"A Hierarchical Approach for Advanced Persistent Threat Detection with Attention-Based Graph Neural Networks","display_name":"A Hierarchical Approach for Advanced Persistent Threat Detection with Attention-Based Graph Neural Networks","publication_year":2021,"publication_date":"2021-05-04","ids":{"openalex":"https://openalex.org/W3158906645","doi":"https://doi.org/10.1155/2021/9961342","mag":"3158906645"},"language":"en","primary_location":{"id":"doi:10.1155/2021/9961342","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9961342","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9961342.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj"],"open_access":{"is_oa":true,"oa_status":"hybrid","oa_url":"https://downloads.hindawi.com/journals/scn/2021/9961342.pdf","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5007504195","display_name":"Zitong Li","orcid":"https://orcid.org/0000-0001-8469-7295"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Zitong Li","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5101824799","display_name":"Xiang Cheng","orcid":"https://orcid.org/0000-0001-8432-2426"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiang Cheng","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056965823","display_name":"Lixiao Sun","orcid":null},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Lixiao Sun","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China","institution_ids":["https://openalex.org/I9842412"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100705326","display_name":"Ji Zhang","orcid":"https://orcid.org/0000-0001-7167-6970"},"institutions":[{"id":"https://openalex.org/I185523456","display_name":"University of Southern Queensland","ror":"https://ror.org/04sjbnx57","country_code":"AU","type":"education","lineage":["https://openalex.org/I185523456"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Ji Zhang","raw_affiliation_strings":["School of Sciences, University of Southern Queensland, Toowoomba 4350, Australia"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"School of Sciences, University of Southern Queensland, Toowoomba 4350, Australia","institution_ids":["https://openalex.org/I185523456"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100443103","display_name":"Bing Chen","orcid":"https://orcid.org/0000-0002-2863-5441"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Bing Chen","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China"],"raw_orcid":"https://orcid.org/0000-0002-2863-5441","affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 21106, China","institution_ids":["https://openalex.org/I9842412"]}]}],"institutions":[],"countries_distinct_count":2,"institutions_distinct_count":5,"corresponding_author_ids":["https://openalex.org/A5100443103"],"corresponding_institution_ids":["https://openalex.org/I9842412"],"apc_list":{"value":2100,"currency":"USD","value_usd":2100},"apc_paid":{"value":2100,"currency":"USD","value_usd":2100},"fwci":4.1657,"has_fulltext":true,"cited_by_count":51,"citation_normalized_percentile":{"value":0.94103559,"is_in_top_1_percent":false,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":89,"max":100},"biblio":{"volume":"2021","issue":null,"first_page":"1","last_page":"14"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9970999956130981,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10064","display_name":"Complex Network Analysis Techniques","score":0.9918000102043152,"subfield":{"id":"https://openalex.org/subfields/3109","display_name":"Statistical and Nonlinear Physics"},"field":{"id":"https://openalex.org/fields/31","display_name":"Physics and Astronomy"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8751009702682495},{"id":"https://openalex.org/keywords/anomaly-detection","display_name":"Anomaly detection","score":0.6479872465133667},{"id":"https://openalex.org/keywords/leverage","display_name":"Leverage (statistics)","score":0.5806636810302734},{"id":"https://openalex.org/keywords/embedding","display_name":"Embedding","score":0.5439900755882263},{"id":"https://openalex.org/keywords/graph","display_name":"Graph","score":0.4800516366958618},{"id":"https://openalex.org/keywords/graph-embedding","display_name":"Graph embedding","score":0.4710884988307953},{"id":"https://openalex.org/keywords/theoretical-computer-science","display_name":"Theoretical computer science","score":0.4474430978298187},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.4454371929168701},{"id":"https://openalex.org/keywords/machine-learning","display_name":"Machine learning","score":0.44021496176719666},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.4198811650276184}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8751009702682495},{"id":"https://openalex.org/C739882","wikidata":"https://www.wikidata.org/wiki/Q3560506","display_name":"Anomaly detection","level":2,"score":0.6479872465133667},{"id":"https://openalex.org/C153083717","wikidata":"https://www.wikidata.org/wiki/Q6535263","display_name":"Leverage (statistics)","level":2,"score":0.5806636810302734},{"id":"https://openalex.org/C41608201","wikidata":"https://www.wikidata.org/wiki/Q980509","display_name":"Embedding","level":2,"score":0.5439900755882263},{"id":"https://openalex.org/C132525143","wikidata":"https://www.wikidata.org/wiki/Q141488","display_name":"Graph","level":2,"score":0.4800516366958618},{"id":"https://openalex.org/C75564084","wikidata":"https://www.wikidata.org/wiki/Q5597085","display_name":"Graph embedding","level":3,"score":0.4710884988307953},{"id":"https://openalex.org/C80444323","wikidata":"https://www.wikidata.org/wiki/Q2878974","display_name":"Theoretical computer science","level":1,"score":0.4474430978298187},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.4454371929168701},{"id":"https://openalex.org/C119857082","wikidata":"https://www.wikidata.org/wiki/Q2539","display_name":"Machine learning","level":1,"score":0.44021496176719666},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.4198811650276184}],"mesh":[],"locations_count":2,"locations":[{"id":"doi:10.1155/2021/9961342","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9961342","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9961342.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},{"id":"pmh:oai:doaj.org/article:b70e89445a8d43de9f51f7c93734a4d8","is_oa":true,"landing_page_url":"https://doaj.org/article/b70e89445a8d43de9f51f7c93734a4d8","pdf_url":null,"source":{"id":"https://openalex.org/S4306401280","display_name":"DOAJ (DOAJ: Directory of Open Access Journals)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Security and Communication Networks, Vol 2021 (2021)","raw_type":"article"}],"best_oa_location":{"id":"doi:10.1155/2021/9961342","is_oa":true,"landing_page_url":"https://doi.org/10.1155/2021/9961342","pdf_url":"https://downloads.hindawi.com/journals/scn/2021/9961342.pdf","source":{"id":"https://openalex.org/S120683614","display_name":"Security and Communication Networks","issn_l":"1939-0114","issn":["1939-0114","1939-0122"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319869","host_organization_name":"Hindawi Publishing Corporation","host_organization_lineage":["https://openalex.org/P4310319869"],"host_organization_lineage_names":["Hindawi Publishing Corporation"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Security and Communication Networks","raw_type":"journal-article"},"sustainable_development_goals":[],"awards":[{"id":"https://openalex.org/G5047370617","display_name":null,"funder_award_id":"2019YFB2102002","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320321605","display_name":"Government of Jiangsu Province","ror":"https://ror.org/004svx814"},{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W3158906645.pdf","grobid_xml":"https://content.openalex.org/works/W3158906645.grobid-xml"},"referenced_works_count":38,"referenced_works":["https://openalex.org/W168132470","https://openalex.org/W1444906800","https://openalex.org/W1549725782","https://openalex.org/W1981158329","https://openalex.org/W2089554624","https://openalex.org/W2154851992","https://openalex.org/W2284900416","https://openalex.org/W2295705535","https://openalex.org/W2519887557","https://openalex.org/W2766503369","https://openalex.org/W2767083275","https://openalex.org/W2790557990","https://openalex.org/W2807975761","https://openalex.org/W2891432086","https://openalex.org/W2895460099","https://openalex.org/W2910711617","https://openalex.org/W2944250323","https://openalex.org/W2962703433","https://openalex.org/W2964015378","https://openalex.org/W2966841471","https://openalex.org/W2978956219","https://openalex.org/W2988337058","https://openalex.org/W2997780732","https://openalex.org/W3002573977","https://openalex.org/W3033087971","https://openalex.org/W3101089035","https://openalex.org/W3105780912","https://openalex.org/W3126165507","https://openalex.org/W3158266296","https://openalex.org/W4285723986","https://openalex.org/W4297571622","https://openalex.org/W6707620307","https://openalex.org/W6752919903","https://openalex.org/W6770444538","https://openalex.org/W6785463497","https://openalex.org/W6929373306","https://openalex.org/W6929443371","https://openalex.org/W6948116018"],"related_works":["https://openalex.org/W3036264823","https://openalex.org/W3206528106","https://openalex.org/W2123605750","https://openalex.org/W2912814903","https://openalex.org/W2088740331","https://openalex.org/W2950907416","https://openalex.org/W3038102983","https://openalex.org/W2082479932","https://openalex.org/W2932872266","https://openalex.org/W4281484020"],"abstract_inverted_index":{"Advanced":[0],"Persistent":[1],"Threats":[2],"(APTs)":[3],"are":[4,90],"the":[5,77,99,102,145,160,164,171,175],"most":[6],"sophisticated":[7],"attacks":[8],"for":[9,37,110,123,132],"modern":[10],"information":[11],"systems.":[12],"Currently,":[13],"more":[14,16],"and":[15,34,89,127,147],"researchers":[17],"begin":[18],"to":[19,30,53,84,92,157],"focus":[20],"on":[21,49,63],"graph-based":[22],"anomaly":[23],"detection":[24,112,161,166],"methods":[25],"that":[26,170],"leverage":[27],"graph":[28,65,125,135],"data":[29],"model":[31,162],"normal":[32],"behaviors":[33,139],"detect":[35],"outliers":[36],"defending":[38],"against":[39],"APTs.":[40],"However,":[41],"previous":[42],"studies":[43],"of":[44,101],"provenance":[45,124],"graphs":[46,61,95],"mainly":[47],"concentrate":[48],"system":[50,146],"calls,":[51],"leading":[52],"difficulties":[54],"in":[55,163,178],"modeling":[56],"network":[57,148],"behaviors.":[58],"Coarse-grained":[59],"correlation":[60],"depend":[62],"handcrafted":[64],"construction":[66],"rules":[67],"and,":[68],"thus,":[69,137],"cannot":[70],"adequately":[71],"explore":[72],"log":[73],"node":[74],"attributes.":[75],"Besides,":[76],"traditional":[78],"Graph":[79],"Neural":[80],"Networks":[81],"(GNNs)":[82],"fail":[83],"consider":[85],"meaningful":[86],"edge":[87,129],"features":[88],"difficult":[91],"perform":[93],"heterogeneous":[94],"embedding.":[96],"To":[97],"overcome":[98],"limitations":[100],"existing":[103],"approaches,":[104],"we":[105],"present":[106],"a":[107,119],"hierarchical":[108,165],"approach":[109],"APT":[111,138,179],"with":[113],"novel":[114,151],"attention-based":[115],"GNNs.":[116],"We":[117],"propose":[118],"metapath":[120],"aggregated":[121],"GNN":[122,131],"embedding":[126],"an":[128],"enhanced":[130],"host":[133],"interactive":[134],"embedding;":[136],"can":[140],"be":[141],"captured":[142],"at":[143],"both":[144],"levels.":[149],"A":[150],"enhancement":[152],"mechanism":[153],"is":[154],"also":[155],"introduced":[156],"dynamically":[158],"update":[159],"framework.":[167],"Evaluations":[168],"show":[169],"proposed":[172],"method":[173],"outperforms":[174],"state-of-the-art":[176],"baselines":[177],"detection.":[180]},"counts_by_year":[{"year":2026,"cited_by_count":4},{"year":2025,"cited_by_count":21},{"year":2024,"cited_by_count":10},{"year":2023,"cited_by_count":8},{"year":2022,"cited_by_count":7},{"year":2021,"cited_by_count":1}],"updated_date":"2026-05-21T06:26:12.895304","created_date":"2025-10-10T00:00:00"}
