{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:42:37Z","timestamp":1784238157184,"version":"3.55.0"},"publisher-location":"Cham","reference-count":26,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030415785","type":"print"},{"value":"9783030415792","type":"electronic"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-41579-2_11","type":"book-chapter","created":{"date-parts":[[2020,2,17]],"date-time":"2020-02-17T16:09:09Z","timestamp":1581955749000},"page":"181-196","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["CTLMD: Continuous-Temporal Lateral Movement Detection Using Graph Embedding"],"prefix":"10.1007","author":[{"given":"Suya","family":"Zhao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Renzheng","family":"Wei","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lijun","family":"Cai","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Aimin","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dan","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2020,2,18]]},"reference":[{"key":"11_CR1","unstructured":"Morgan, J.P.: Chase Hack Affects 76 Million Households. https:\/\/dealbook.nytimes.com\/2014\/10\/02\/jpmorgan-discovers-further-cyber-security-issues\/. Accessed 30 May 2019"},{"key":"11_CR2","unstructured":"Home Depot Hackers Exposed 53 Million Email Addresses. http:\/\/www.wsj.com\/articles\/home-depot-hackers-used-password-stolen-from-vendor-1415309282. Accessed 1 June 2019"},{"key":"11_CR3","unstructured":"Smokescreen Technologies Pvt. Ltd.: Top 20 Lateral Movement Tactics. https:\/\/www.smokescreen.io\/wp-content\/uploads\/2016\/08\/Top-20-Lateral-Movement-Tactics.pdf. Accessed 3 July 2019"},{"key":"11_CR4","unstructured":"How Do Threat Actors Move Deeper Into Your Network. http:\/\/about-threats.trendmicro.com\/cloud-content\/us\/ent-primers\/pdf\/tlp_lateral_movement.pdf. Accessed 10 July 2019"},{"issue":"3","key":"11_CR5","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1080\/19393555.2011.654318","volume":"21","author":"S Zeadally","year":"2012","unstructured":"Zeadally, S., Yu, B., Jeong, D.H., Liang, L.: Detecting insider threats: solutions and trends. Inf. Secur. J. Glob. Perspect. 21(3), 183\u2013192 (2012)","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"11_CR6","doi-asserted-by":"publisher","unstructured":"Nguyen, G.H., Lee, J.B., Rossi, R.A., Ahmed, N.K., Koh, E., Kim, S.: Continuous-time dynamic network embeddings. In: Companion Proceedings of the Web Conference 2018, Lyon, pp. 969\u2013976. IWWWCSC (2018). https:\/\/doi.org\/10.1145\/3184558.3191526","DOI":"10.1145\/3184558.3191526"},{"key":"11_CR7","doi-asserted-by":"publisher","unstructured":"Gao, M., Chen, L., He, X., Zhou, A.: BiNE: bipartite network embedding. In: Ann, A. (ed.) The 41st International ACM SIGIR Conference on Research & Development in Information Retrieval, New York, pp. 715\u2013724. ACM (2018). https:\/\/doi.org\/10.1145\/3209978.3209987","DOI":"10.1145\/3209978.3209987"},{"key":"11_CR8","unstructured":"Detecting malicious lateral movement across a computer network. http:\/\/www.freepatentsonline.com\/20180367548.pdf. Accessed 14 May 2019"},{"key":"11_CR9","doi-asserted-by":"publisher","unstructured":"Johnson, J.R., Hogan, E.A.: A graph analytic metric for mitigating advanced persistent threat. In: 2013 IEEE International Conference on Intelligence and Security Informatics, Seattle, pp. 129\u2013133. IEEE (2013). https:\/\/doi.org\/10.1109\/ISI.2013.6578801","DOI":"10.1109\/ISI.2013.6578801"},{"issue":"1","key":"11_CR10","doi-asserted-by":"publisher","first-page":"58","DOI":"10.1109\/TDSC.2017.2652469","volume":"16","author":"A Pope","year":"2017","unstructured":"Pope, A., Tauritz, D., Kent, A.: Evolving bipartite authentication graph partitions. IEEE Trans. Dependable Secure Comput. 16(1), 58\u201371 (2017)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"issue":"1","key":"11_CR11","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1016\/j.cose.2014.09.001","volume":"48","author":"D Kent","year":"2015","unstructured":"Kent, D., Liebrock, M., Neil, C.: Analyzing user behavior within an enterprise network. Comput. Secur. 48(1), 150\u2013166 (2015)","journal-title":"Comput. Secur."},{"key":"11_CR12","doi-asserted-by":"publisher","unstructured":"Siadati, H., Memon, N.: Detecting structurally anomalous logins within enterprise networks. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Texas, pp. 1273\u20131284. ACM (2017). https:\/\/doi.org\/10.1145\/3133956.3134003","DOI":"10.1145\/3133956.3134003"},{"issue":"1","key":"11_CR13","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1080\/19361610.2011.529413","volume":"6","author":"W Eberle","year":"2010","unstructured":"Eberle, W., Graves, J., Holder, L.: Insider threat detection using a graph-based approach. J. Appl. Secur. Res. 6(1), 32\u201381 (2010)","journal-title":"J. Appl. Secur. Res."},{"key":"11_CR14","doi-asserted-by":"publisher","unstructured":"Hogan, E., Johnson, J.R., Halappanavar, M.: Graph coarsening for path finding in cybersecurity graphs. In: Proceedings of the Eighth Annual Cyber Security and Information Intelligence Research Workshop, Tennessee, p. 7. ACM (2013). https:\/\/doi.org\/10.1145\/2459976.2459984","DOI":"10.1145\/2459976.2459984"},{"key":"11_CR15","doi-asserted-by":"publisher","unstructured":"Xu, X., Liu, C., Feng, Q., Yin, H., Song, L., Song, D.: Neural network-based graph embedding for cross-platform binary code similarity detection. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, Dallas, pp. 363\u2013376. ACM (2017). https:\/\/doi.org\/10.1145\/3133956.3134018","DOI":"10.1145\/3133956.3134018"},{"key":"11_CR16","doi-asserted-by":"publisher","unstructured":"Ding, S., Fung, B., Charland, P.: Asm2Vec: boosting static representation robustness for binary clone search against code obfuscation and compiler optimization. In: Proceedings of the 2019 IEEE Symposium on Security and Privacy, San Francisco, pp. 38\u201355. IEEE (2019). https:\/\/doi.org\/10.1109\/SP.2019.00003","DOI":"10.1109\/SP.2019.00003"},{"key":"11_CR17","doi-asserted-by":"publisher","unstructured":"Song, W., Yin, H., Liu, C., Song, D.: DeepMem: learning graph neural network models for fast and robust memory forensic analysis. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security, Toronto, pp. 606\u2013618. ACM (2018). https:\/\/doi.org\/10.1145\/3243734.3243813","DOI":"10.1145\/3243734.3243813"},{"key":"11_CR18","doi-asserted-by":"publisher","unstructured":"Chen, M., Yao, Y., Liu, J., Jiang, B., Su, L., Lu, Z.: A novel approach for identifying lateral movement attacks based on network embedding. In: 2018 IEEE International Conference on Parallel & Distributed Processing with Applications, Ubiquitous Computing & Communications, Big Data & Cloud Computing, Social Computing & Networking, Sustainable Computing & Communications (ISPA\/IUCC\/BDCloud\/SocialCom\/SustainCom), Melbourne, pp. 708\u2013715. IEEE (2018). https:\/\/doi.org\/10.1109\/BDCloud.2018.00107","DOI":"10.1109\/BDCloud.2018.00107"},{"key":"11_CR19","doi-asserted-by":"publisher","unstructured":"Bohara, A., Noureddine, M., Fawaz, A., Sanders, W.: An unsupervised multi-detector approach for identifying malicious lateral movement. In: 2017 IEEE 36th Symposium on Reliable Distributed Systems (SRDS), Hong Kong, pp. 224\u2013233. IEEE (2017). https:\/\/doi.org\/10.1109\/SRDS.2017.31","DOI":"10.1109\/SRDS.2017.31"},{"key":"11_CR20","doi-asserted-by":"publisher","unstructured":"Dong, B., et al.: Efficient discovery of abnormal event sequences in enterprise security systems. In: Proceedings of the 2017 ACM on Conference on Information and Knowledge Management, Singapore, pp. 707\u2013715. ACM (2017). https:\/\/doi.org\/10.1145\/3132847.3132854","DOI":"10.1145\/3132847.3132854"},{"key":"11_CR21","volume-title":"Search Engine: Detailed Core Technology","author":"Z Junlin","year":"2012","unstructured":"Junlin, Z.: Search Engine: Detailed Core Technology, 1st edn. Publishing House of Electronics Industry, Beijing (2012)","edition":"1"},{"key":"11_CR22","doi-asserted-by":"publisher","unstructured":"Dunagan, J., Zheng, A.X., Simon, D.R.: Heat-ray: combating identity snowball attacks using machine learning, combinatorial optimization and attack graphs. In: Proceedings of the 22nd ACM Symposium on Operating Systems Principles, , Montana, pp. 305\u2013320. ACM (2009). https:\/\/doi.org\/10.1145\/1629575.1629605","DOI":"10.1145\/1629575.1629605"},{"key":"11_CR23","doi-asserted-by":"publisher","unstructured":"Perozzi, B., Al-Rfou, R., Skiena, S.: DeepWalk: online learning of social representations. In: Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, New York, pp. 701\u2013710. ACM (2014). https:\/\/doi.org\/10.1145\/2623330.2623732","DOI":"10.1145\/2623330.2623732"},{"key":"11_CR24","doi-asserted-by":"publisher","unstructured":"Tang, J., Qu, M., Wang, M., Zhang, M., Yan, J., Mei, Q.: Line: large-scale information network embedding. In: Proceedings of the 24th International Conference on World Wide Web, Florence, pp. 1067\u20131077. ACM (2015). https:\/\/doi.org\/10.1145\/2736277.2741093","DOI":"10.1145\/2736277.2741093"},{"key":"11_CR25","doi-asserted-by":"crossref","unstructured":"Kent, D.: Cyber security data sources for dynamic network research. In: Dynamic Networks and Cyber-Security, pp. 37\u201365 (2016)","DOI":"10.1142\/9781786340757_0002"},{"key":"11_CR26","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"577","DOI":"10.1007\/978-3-319-93034-3_46","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"TS Buda","year":"2018","unstructured":"Buda, T.S., Caglayan, B., Assem, H.: DeepAD: a generic framework based on deep learning for time series anomaly detection. In: Phung, D., Tseng, V.S., Webb, G.I., Ho, B., Ganji, M., Rashidi, L. (eds.) PAKDD 2018. LNCS (LNAI), vol. 10937, pp. 577\u2013588. Springer, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-93034-3_46"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-41579-2_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,26]],"date-time":"2020-11-26T20:12:43Z","timestamp":1606421563000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-41579-2_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030415785","9783030415792"],"references-count":26,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-41579-2_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"18 February 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easy Chair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"199","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"47","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}