{"id":"https://openalex.org/W2973625556","doi":"https://doi.org/10.3390/s19184045","title":"Cyber Situation Comprehension for IoT Systems based on APT Alerts and Logs Correlation","display_name":"Cyber Situation Comprehension for IoT Systems based on APT Alerts and Logs Correlation","publication_year":2019,"publication_date":"2019-09-19","ids":{"openalex":"https://openalex.org/W2973625556","doi":"https://doi.org/10.3390/s19184045","mag":"2973625556","pmid":"https://pubmed.ncbi.nlm.nih.gov/31546845"},"language":"en","primary_location":{"id":"doi:10.3390/s19184045","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s19184045","pdf_url":"https://www.mdpi.com/1424-8220/19/18/4045/pdf?version=1568949086","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},"type":"article","indexed_in":["crossref","doaj","pubmed"],"open_access":{"is_oa":true,"oa_status":"gold","oa_url":"https://www.mdpi.com/1424-8220/19/18/4045/pdf?version=1568949086","any_repository_has_fulltext":true},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101824799","display_name":"Xiang Cheng","orcid":"https://orcid.org/0000-0001-8432-2426"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Xiang Cheng","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","institution_ids":["https://openalex.org/I9842412"]},{"raw_affiliation_string":"The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China","institution_ids":[]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5100744176","display_name":"Jiale Zhang","orcid":"https://orcid.org/0000-0002-2143-5666"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":false,"raw_author_name":"Jiale Zhang","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","institution_ids":["https://openalex.org/I9842412"]},{"raw_affiliation_string":"The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5100443103","display_name":"Bing Chen","orcid":"https://orcid.org/0000-0002-2863-5441"},"institutions":[{"id":"https://openalex.org/I9842412","display_name":"Nanjing University of Aeronautics and Astronautics","ror":"https://ror.org/01scyh794","country_code":"CN","type":"education","lineage":["https://openalex.org/I9842412"]}],"countries":["CN"],"is_corresponding":true,"raw_author_name":"Bing Chen","raw_affiliation_strings":["College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China"],"affiliations":[{"raw_affiliation_string":"College of Computer Science and Technology, Nanjing University of Aeronautics and Astronautics, Nanjing 211106, China","institution_ids":["https://openalex.org/I9842412"]},{"raw_affiliation_string":"The Collaborative Innovation Center of Novel Software Technology and Industrialization, Nanjing 210023, China","institution_ids":[]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5100443103"],"corresponding_institution_ids":["https://openalex.org/I9842412"],"apc_list":{"value":2400,"currency":"CHF","value_usd":2598},"apc_paid":{"value":2400,"currency":"CHF","value_usd":2598},"fwci":1.6718,"has_fulltext":false,"cited_by_count":21,"citation_normalized_percentile":{"value":0.85890221,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":91,"max":99},"biblio":{"volume":"19","issue":"18","first_page":"4045","last_page":"4045"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9991999864578247,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9962999820709229,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9950000047683716,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7860820293426514},{"id":"https://openalex.org/keywords/comprehension","display_name":"Comprehension","score":0.5168452858924866},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.49562108516693115},{"id":"https://openalex.org/keywords/cyber-attack","display_name":"Cyber-attack","score":0.4790707528591156},{"id":"https://openalex.org/keywords/correlation","display_name":"Correlation","score":0.4431701898574829},{"id":"https://openalex.org/keywords/internet-of-things","display_name":"Internet of Things","score":0.4364430606365204},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.29027366638183594}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7860820293426514},{"id":"https://openalex.org/C511192102","wikidata":"https://www.wikidata.org/wiki/Q5156948","display_name":"Comprehension","level":2,"score":0.5168452858924866},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.49562108516693115},{"id":"https://openalex.org/C201307755","wikidata":"https://www.wikidata.org/wiki/Q4071928","display_name":"Cyber-attack","level":2,"score":0.4790707528591156},{"id":"https://openalex.org/C117220453","wikidata":"https://www.wikidata.org/wiki/Q5172842","display_name":"Correlation","level":2,"score":0.4431701898574829},{"id":"https://openalex.org/C81860439","wikidata":"https://www.wikidata.org/wiki/Q251212","display_name":"Internet of Things","level":2,"score":0.4364430606365204},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.29027366638183594},{"id":"https://openalex.org/C2524010","wikidata":"https://www.wikidata.org/wiki/Q8087","display_name":"Geometry","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0}],"mesh":[],"locations_count":5,"locations":[{"id":"doi:10.3390/s19184045","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s19184045","pdf_url":"https://www.mdpi.com/1424-8220/19/18/4045/pdf?version=1568949086","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},{"id":"pmid:31546845","is_oa":false,"landing_page_url":"https://pubmed.ncbi.nlm.nih.gov/31546845","pdf_url":null,"source":{"id":"https://openalex.org/S4306525036","display_name":"PubMed","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors (Basel, Switzerland)","raw_type":null},{"id":"pmh:oai:doaj.org/article:9ad8e52dbc7f4fca8f180d1401541fa2","is_oa":true,"landing_page_url":"https://doaj.org/article/9ad8e52dbc7f4fca8f180d1401541fa2","pdf_url":null,"source":{"id":"https://openalex.org/S112646816","display_name":"SHILAP Revista de lepidopterolog\u00eda","issn_l":"0300-5267","issn":["0300-5267","2340-4078"],"is_oa":true,"is_in_doaj":true,"is_core":false,"host_organization":null,"host_organization_name":null,"host_organization_lineage":[],"host_organization_lineage_names":[],"type":"journal"},"license":"cc-by-sa","license_id":"https://openalex.org/licenses/cc-by-sa","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors, Vol 19, Iss 18, p 4045 (2019)","raw_type":"article"},{"id":"pmh:oai:mdpi.com:/1424-8220/19/18/4045/","is_oa":true,"landing_page_url":"http://dx.doi.org/10.3390/s19184045","pdf_url":null,"source":{"id":"https://openalex.org/S4306400947","display_name":"MDPI (MDPI AG)","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I4210097602","host_organization_name":"Multidisciplinary Digital Publishing Institute (Switzerland)","host_organization_lineage":["https://openalex.org/I4210097602"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors","raw_type":"Text"},{"id":"pmh:oai:pubmedcentral.nih.gov:6767330","is_oa":true,"landing_page_url":"https://www.ncbi.nlm.nih.gov/pmc/articles/6767330","pdf_url":null,"source":{"id":"https://openalex.org/S2764455111","display_name":"PubMed Central","issn_l":null,"issn":null,"is_oa":true,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I1299303238","host_organization_name":"National Institutes of Health","host_organization_lineage":["https://openalex.org/I1299303238"],"host_organization_lineage_names":[],"type":"repository"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Sensors (Basel)","raw_type":"Text"}],"best_oa_location":{"id":"doi:10.3390/s19184045","is_oa":true,"landing_page_url":"https://doi.org/10.3390/s19184045","pdf_url":"https://www.mdpi.com/1424-8220/19/18/4045/pdf?version=1568949086","source":{"id":"https://openalex.org/S101949793","display_name":"Sensors","issn_l":"1424-8220","issn":["1424-8220"],"is_oa":true,"is_in_doaj":true,"is_core":true,"host_organization":"https://openalex.org/P4310310987","host_organization_name":"Multidisciplinary Digital Publishing Institute","host_organization_lineage":["https://openalex.org/P4310310987"],"host_organization_lineage_names":["Multidisciplinary Digital Publishing Institute"],"type":"journal"},"license":"cc-by","license_id":"https://openalex.org/licenses/cc-by","version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Sensors","raw_type":"journal-article"},"sustainable_development_goals":[{"score":0.46000000834465027,"id":"https://metadata.un.org/sdg/16","display_name":"Peace, Justice and strong institutions"}],"awards":[{"id":"https://openalex.org/G5137950446","display_name":null,"funder_award_id":"2017YFB0802303","funder_id":"https://openalex.org/F4320335777","funder_display_name":"National Key Research and Development Program of China"}],"funders":[{"id":"https://openalex.org/F4320335777","display_name":"National Key Research and Development Program of China","ror":null}],"has_content":{"grobid_xml":true,"pdf":true},"content_urls":{"pdf":"https://content.openalex.org/works/W2973625556.pdf","grobid_xml":"https://content.openalex.org/works/W2973625556.grobid-xml"},"referenced_works_count":22,"referenced_works":["https://openalex.org/W27721215","https://openalex.org/W207930717","https://openalex.org/W1602380388","https://openalex.org/W1972062587","https://openalex.org/W1991318433","https://openalex.org/W2004360894","https://openalex.org/W2061571685","https://openalex.org/W2075185877","https://openalex.org/W2102941975","https://openalex.org/W2140947476","https://openalex.org/W2152183345","https://openalex.org/W2161830378","https://openalex.org/W2260239758","https://openalex.org/W2336089435","https://openalex.org/W2582259743","https://openalex.org/W2794596638","https://openalex.org/W2895698828","https://openalex.org/W6601099728","https://openalex.org/W6608575244","https://openalex.org/W6669179502","https://openalex.org/W6683581553","https://openalex.org/W6732702117"],"related_works":["https://openalex.org/W4245926026","https://openalex.org/W4311097251","https://openalex.org/W2586548817","https://openalex.org/W2625093826","https://openalex.org/W4200598720","https://openalex.org/W2921026492","https://openalex.org/W4247463117","https://openalex.org/W4361251261","https://openalex.org/W3031181660","https://openalex.org/W4238100021"],"abstract_inverted_index":{"With":[0],"the":[1,4,24,48,73,104,114,129,169,177,184,189,198],"emergence":[2],"of":[3,12,20,26,42,69,171],"Advanced":[5],"Persistent":[6],"Threat":[7],"(APT)":[8],"attacks,":[9],"many":[10],"Internet":[11],"Things":[13],"(IoT)":[14],"systems":[15],"have":[16],"faced":[17],"large":[18],"numbers":[19],"potential":[21],"threats":[22],"with":[23,139],"characteristics":[25],"concealment,":[27],"permeability,":[28],"and":[29,34,39,60,66,106,135,156,208,223],"pertinence.":[30],"However,":[31],"existing":[32],"methods":[33],"technologies":[35],"cannot":[36],"provide":[37],"comprehensive":[38],"prompt":[40],"recognition":[41],"latent":[43],"APT":[44,58,110,133,146,153,158,185],"attack":[45,111,154,186],"activities":[46,112],"in":[47,113,188,214],"IoT":[49,74,115,190],"systems.":[50,116,191],"To":[51],"address":[52],"this":[53],"problem,":[54],"we":[55,95,118,142],"propose":[56,144],"an":[57,77,145,157],"Alerts":[59],"Logs":[61],"Correlation":[62,205,211],"Method,":[63],"named":[64],"APTALCM":[65,71,174],"a":[67,98,120],"framework":[68],"deploying":[70],"on":[72,128],"system,":[75],"where":[76],"edge":[78],"computing":[79],"architecture":[80],"was":[81],"used":[82],"to":[83,108,151,163],"achieve":[84,218],"cyber":[85,99,121,178],"situation":[86,100,122,179],"comprehension":[87,180],"without":[88],"too":[89],"much":[90],"data":[91],"transmission":[92],"cost.":[93],"Specifically,":[94],"firstly":[96],"present":[97],"ontology":[101],"for":[102,132],"modeling":[103],"concepts":[105],"properties":[107],"formalize":[109],"Then,":[117],"introduce":[119],"instance":[123,140,166],"similarity":[124],"measurement":[125],"method":[126,150,162],"based":[127],"SimRank":[130],"mechanism":[131],"alerts":[134],"logs":[136],"Correlation.":[137],"Combining":[138],"similarity,":[141],"further":[143],"alert":[147],"instances":[148,160],"correlation":[149,161],"reconstruct":[152],"scenarios":[155],"log":[159,165],"detect":[164],"communities.":[167],"Through":[168],"coalescence":[170],"these":[172],"methods,":[173],"can":[175,217],"accomplish":[176],"effectively":[181],"by":[182],"recognizing":[183],"intentions":[187],"The":[192],"exhaustive":[193],"experimental":[194],"results":[195],"demonstrate":[196],"that":[197],"two":[199],"kernel":[200],"modules,":[201],"i.e.,":[202],"Alert":[203],"Instance":[204,210],"Module":[206,212],"(AICM)":[207],"Log":[209],"(LICM)":[213],"our":[215],"APTALCM,":[216],"both":[219],"high":[220],"true-positive":[221],"rate":[222],"low":[224],"false-positive":[225],"rate.":[226]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2024,"cited_by_count":8},{"year":2023,"cited_by_count":3},{"year":2022,"cited_by_count":3},{"year":2021,"cited_by_count":4},{"year":2020,"cited_by_count":2}],"updated_date":"2026-04-21T08:09:41.155169","created_date":"2025-10-10T00:00:00"}
