{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,30]],"date-time":"2026-04-30T16:36:35Z","timestamp":1777566995872,"version":"3.51.4"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031541285","type":"print"},{"value":"9783031541292","type":"electronic"}],"license":[{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,1,1]],"date-time":"2024-01-01T00:00:00Z","timestamp":1704067200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024]]},"DOI":"10.1007\/978-3-031-54129-2_5","type":"book-chapter","created":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:03:15Z","timestamp":1710194595000},"page":"76-91","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":7,"title":["Labeling NIDS Rules with\u00a0MITRE ATT &amp;CK Techniques Using ChatGPT"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5310-2324","authenticated-orcid":false,"given":"Nir","family":"Daniel","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Florian Klaus","family":"Kaiser","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Anton","family":"Dzega","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0918-0146","authenticated-orcid":false,"given":"Aviad","family":"Elyashar","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7229-3899","authenticated-orcid":false,"given":"Rami","family":"Puzis","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2024,3,12]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Arafune, M., et al.: Design and development of automated threat hunting in industrial control systems. In: 2022 IEEE International Conference on Pervasive Computing and Communications Workshops and other Affiliated Events (PerCom Workshops), pp. 618\u2013623. IEEE (2022)","DOI":"10.1109\/PerComWorkshops53856.2022.9767375"},{"issue":"1","key":"5_CR2","doi-asserted-by":"publisher","first-page":"18","DOI":"10.3390\/data8010018","volume":"8","author":"SS Bagui","year":"2023","unstructured":"Bagui, S.S., et al.: Introducing UWF-ZeekData22: a comprehensive network traffic dataset based on the MITRE ATT &CK framework. Data 8(1), 18 (2023)","journal-title":"Data"},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Chakrabarti, S., Chakraborty, M., Mukhopadhyay, I.: Study of snort-based IDS. In: Proceedings of the International Conference and Workshop on Emerging Trends in Technology, pp. 43\u201347 (2010)","DOI":"10.1145\/1741906.1741914"},{"issue":"2","key":"5_CR4","first-page":"36","volume":"3","author":"D Chismon","year":"2015","unstructured":"Chismon, D., Ruks, M.: Threat intelligence: collecting, analysing, evaluating. MWR InfoSecurity Ltd. 3(2), 36\u201342 (2015)","journal-title":"MWR InfoSecurity Ltd."},{"key":"5_CR5","volume-title":"Ttp-based Hunting","author":"R Daszczyszak","year":"2019","unstructured":"Daszczyszak, R., Ellis, D., Luke, S., Whitley, S.: Ttp-based Hunting. Tech. rep, MITRE CORP MCLEAN VA (2019)"},{"key":"5_CR6","doi-asserted-by":"crossref","unstructured":"Elitzur, A., Puzis, R., Zilberman, P.: Attack hypothesis generation. In: 2019 European Intelligence and Security Informatics Conference (EISIC), pp. 40\u201347. IEEE (2019)","DOI":"10.1109\/EISIC49498.2019.9108886"},{"key":"5_CR7","unstructured":"Gjerstad, J.L.: Generating labelled network datasets of APT with the MITRE CALDERA framework, Master\u2019s thesis (2022)"},{"key":"5_CR8","unstructured":"Haddad, A., Aaraj, N., Nakov, P., Mare, S.F.: Automated mapping of CVE vulnerability records to MITRE CWE weaknesses. arXiv preprint arXiv:2304.11130 (2023)"},{"key":"5_CR9","doi-asserted-by":"crossref","unstructured":"Husari, G., Al-Shaer, E., Ahmed, M., Chu, B., Niu, X.: Ttpdrill: automatic and accurate extraction of threat actions from unstructured text of CTI sources. In: Proceedings of the 33rd Annual Computer Security Applications Conference, pp. 103\u2013115 (2017)","DOI":"10.1145\/3134600.3134646"},{"key":"5_CR10","doi-asserted-by":"publisher","first-page":"4793","DOI":"10.1109\/TDSC.2022.3233703","volume":"20","author":"FK Kaiser","year":"2023","unstructured":"Kaiser, F.K., et al.: Attack hypotheses generation based on threat intelligence knowledge graph. IEEE Trans. Dependable Secure Comput. 20, 4793\u20134809 (2023)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"5_CR11","doi-asserted-by":"crossref","unstructured":"Khamphakdee, N., Benjamas, N., Saiyod, S.: Improving intrusion detection system based on Snort rules for network probe attack detection. In: 2014 2nd International Conference on Information and Communication Technology (ICoICT), pp. 69\u201374. IEEE (2014)","DOI":"10.1109\/ICoICT.2014.6914042"},{"key":"5_CR12","unstructured":"Legoy, V., Caselli, M., Seifert, C., Peter, A.: Automated retrieval of ATT &CK tactics and techniques for cyber threat reports. arXiv preprint arXiv:2004.14322 (2020)"},{"key":"5_CR13","doi-asserted-by":"publisher","unstructured":"Li, Z., Zeng, J., Chen, Y., Liang, Z.: Attackg: Constructing technique knowledge graph from cyber threat intelligence reports. In: Atluri, V., Di Pietro, R., Jensen, C.D., Meng, W. (eds.) Computer Security \u2013 ESORICS 2022. ESORICS 2022. Lecture Notes in Computer Science, vol. 13554, pp. 589\u2013609. Springer, Cham (2022). https:\/\/doi.org\/10.1007\/978-3-031-17140-6_29","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"5_CR14","doi-asserted-by":"crossref","unstructured":"Liao, X., Yuan, K., Wang, X., Li, Z., Xing, L., Beyah, R.: Acing the IOC game: toward automatic discovery and analysis of open-source cyber threat intelligence. In: Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security, pp. 755\u2013766 (2016)","DOI":"10.1145\/2976749.2978315"},{"key":"5_CR15","doi-asserted-by":"crossref","unstructured":"Lin, S.X., Li, Z.J., Chen, T.Y., Wu, D.J.: Attack tactic labeling for cyber threat hunting. In: 2022 24th International Conference on Advanced Communication Technology (ICACT), pp. 34\u201339. IEEE (2022)","DOI":"10.23919\/ICACT53585.2022.9728949"},{"key":"5_CR16","doi-asserted-by":"crossref","unstructured":"Long, C., et al.: Evaluating ChatGPT4 in Canadian otolaryngology-head and neck surgery board examination using the CVSA model. medRxiv pp. 2023\u201305 (2023)","DOI":"10.1101\/2023.05.30.23290758"},{"key":"5_CR17","unstructured":"McPhee, M.: Methods to employ zeek in detecting MITRE ATT &CK techniques, Tech. Rep. (2020)"},{"key":"5_CR18","unstructured":"Mendsaikhan, O., Hasegawa, H., Yamaguchi, Y., Shimada, H.: Automatic mapping of vulnerability information to adversary techniques. In: The Fourteenth International Conference on Emerging Security Information, Systems and Technologies SECUREWARE2020 (2020)"},{"key":"5_CR19","unstructured":"Palacin, V.: Practical Threat Intelligence and Data-driven Threat Hunting. Packt Publishing (2021)"},{"key":"5_CR20","doi-asserted-by":"crossref","unstructured":"Peng, Y., Wang, H.: Design and implementation of network instruction detection system based on snort and NTOP. In: 2012 International Conference on Systems and Informatics (ICSAI2012), pp. 116\u2013120. IEEE (2012)","DOI":"10.1109\/ICSAI.2012.6223247"},{"key":"5_CR21","doi-asserted-by":"crossref","unstructured":"Rani, N., Saha, B., Maurya, V., Shukla, S.K.: TTPHunter: automated extraction of actionable intelligence as TTPs from narrative threat reports. In: Proceedings of the 2023 Australasian Computer Science Week, pp. 126\u2013134 (2023)","DOI":"10.1145\/3579375.3579391"},{"key":"5_CR22","doi-asserted-by":"crossref","unstructured":"Satvat, K., Gjomemo, R., Venkatakrishnan, V.: Extractor: extracting attack behavior from threat reports. In: 2021 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 598\u2013615. IEEE (2021)","DOI":"10.1109\/EuroSP51992.2021.00046"},{"key":"5_CR23","unstructured":"Sentonas, M.: Crowdstrike introduces Charlotte AI, generative AI security analyst - crowdstrike (2023). https:\/\/www.crowdstrike.com\/blog\/crowdstrike-introduces-charlotte-ai-to-deliver-generative-ai-powered-cybersecurity\/"},{"key":"5_CR24","unstructured":"Shackleford, D.: Who\u2019s using cyberthreat intelligence and how. SANS Institute (2015)"},{"key":"5_CR25","unstructured":"Sharma, Y., Birnbach, S., Martinovic, I.: Radar: Effective network-based malware detection based on the MITRE ATT &CK framework. arXiv preprint arXiv:2212.03793 (2022)"},{"key":"5_CR26","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., Thomas, C.B.: MITRE ATT &CK\u00ae: Design and philosophy (2020)"},{"key":"5_CR27","doi-asserted-by":"crossref","unstructured":"Tod-R\u0103ileanu, G., Axinte, S.D.: ChatGPT-information security overview. In: International Conference on Cybersecurity and Cybercrime, vol. 10 (2023)","DOI":"10.19107\/CYBERCON.2023.10"},{"key":"5_CR28","unstructured":"T\u00f6rnberg, P.: Chatgpt-4 outperforms experts and crowd workers in annotating political twitter messages with zero-shot learning. arXiv preprint arXiv:2304.06588 (2023)"},{"key":"5_CR29","unstructured":"Vulnerabilities, C.: Common vulnerabilities and exposures (2005). https:\/\/www.cve.org\/About\/Metrics"},{"issue":"1","key":"5_CR30","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1186\/s42400-021-00106-5","volume":"5","author":"Y You","year":"2022","unstructured":"You, Y., et al.: TIM: threat context-enhanced TTP intelligence mining on unstructured threat data. Cybersecurity 5(1), 3 (2022)","journal-title":"Cybersecurity"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2023 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-54129-2_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,3,11]],"date-time":"2024-03-11T22:04:15Z","timestamp":1710194655000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-54129-2_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024]]},"ISBN":["9783031541285","9783031541292"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-54129-2_5","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024]]},"assertion":[{"value":"12 March 2024","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Hague","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"The Netherlands","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2023","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"25 September 2023","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 September 2023","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"28","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2023","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/esorics2023.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easychair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"478","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"93","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"19% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3-4","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"10","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}