{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,5,25]],"date-time":"2025-05-25T04:03:25Z","timestamp":1748145805944,"version":"3.41.0"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783031893629","type":"print"},{"value":"9783031893636","type":"electronic"}],"license":[{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,1]],"date-time":"2025-01-01T00:00:00Z","timestamp":1735689600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025]]},"DOI":"10.1007\/978-3-031-89363-6_14","type":"book-chapter","created":{"date-parts":[[2025,5,24]],"date-time":"2025-05-24T07:44:30Z","timestamp":1748072670000},"page":"249-266","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Sky-Eye: Detect Multi-stage Cyber Attacks at\u00a0the\u00a0Bigger Picture"],"prefix":"10.1007","author":[{"given":"Pengcheng","family":"Bi","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zhuohang","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiaochun","family":"Yun","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Tianning","family":"Zang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,5,25]]},"reference":[{"key":"14_CR1","unstructured":"Alahmadi, B.A., Axon, L., Martinovic, I.: 99% false positives: a qualitative study of SOC analysts\u2019 perspectives on security alarms. In: Proceedings of the 31st USENIX Security Symposium, Boston, MA, 10\u201312 August 2022, pp. 2783\u20132800. USENIX Assoc; Meta; Google; NSF; Baidu; Chainlink; IBM; Intel Secur; Red Canary; Mercari; Paloalto; Technol Innovat Inst (2022)"},{"key":"14_CR2","unstructured":"Barre, M., Gehani, A., Yegneswaran, V.: Mining data provenance to detect advanced persistent threats. In: 11th International Workshop on Theory and Practice of Provenance (TaPP 2019) (2019)"},{"key":"14_CR3","doi-asserted-by":"publisher","unstructured":"Berrada, G., et al.: A baseline for unsupervised advanced persistent threat detection in system-level provenance. Future Gener. Comput. Syst. Int. J. ESci. 108, 401\u2013413 (2020). https:\/\/doi.org\/10.1016\/j.future.2020.02.015","DOI":"10.1016\/j.future.2020.02.015"},{"key":"14_CR4","unstructured":"Chen, T., et al.: APT-KGL: an intelligent apt detection system based on threat knowledge and heterogeneous provenance graph learning. IEEE Trans. Dependable Secur. Comput. (2022)"},{"key":"14_CR5","doi-asserted-by":"publisher","unstructured":"Coulter, R., Zhang, J., Pan, L., Xiang, Y.: Domain adaptation for windows advanced persistent threat detection. Comput. Secur. 112 (2022). https:\/\/doi.org\/10.1016\/j.cose.2021.102496","DOI":"10.1016\/j.cose.2021.102496"},{"key":"14_CR6","unstructured":"Dong, F., et al.: DISTDET: a cost-effective distributed cyber threat detection system. In: Proceedings of the 32nd USENIX Security Symposium, Anaheim, CA, 09\u201311 August 2023, pp. 6575\u20136592. USENIX; Meta; Futurewei Technologies; Google; NSF; TikTok; Amazon; Ant Res; IBM; Technol Innovat Res; Cisco; Paloalto; ACM Queue; Elect Frontier Fdn (2023)"},{"key":"14_CR7","doi-asserted-by":"publisher","unstructured":"Du, M., Li, F., Zheng, G., Srikumar, V.: DeepLog: anomaly detection and diagnosis from system logs through deep learning. In: CCS 2017: Proceedings of the 2017 24th ACM SIGSAC Conference on Computer and Communications Security, Dallas, TX, 30 Oct\u201303 Nov 2017, pp. 1285\u20131298. ACM SIGSAC; Assoc Comp Machinery; AT &T Business; Baidu; NSF; CISCO; Internet Finance Authenticat Alliance; Samsung; Univ Texas Dallas; Google; IBM Res; Paloalto Networks; Visa Res; Army Res Off; Nasher Sculpture Ctr (2017). https:\/\/doi.org\/10.1145\/3133956.3134015","DOI":"10.1145\/3133956.3134015"},{"key":"14_CR8","doi-asserted-by":"crossref","unstructured":"Eke, H.N., Petrovski, A., Ahriz, H.: The use of machine learning algorithms for detecting advanced persistent threats. In: Proceedings of the 12th International Conference on Security of Information and Networks, pp.\u00a01\u20138 (2019)","DOI":"10.1145\/3357613.3357618"},{"key":"14_CR9","doi-asserted-by":"publisher","unstructured":"Han, X., Pasquier, T., Bates, A., Mickens, J., Seltzer, M.: Unicorn: runtime provenance-based detector for advanced persistent threats. In: 27th Annual Network and Distributed System Security Symposium (NDSS 2020), San Diego, CA, 23\u201326 February 2020 (2020). https:\/\/doi.org\/10.14722\/ndss.2020.24046","DOI":"10.14722\/ndss.2020.24046"},{"key":"14_CR10","unstructured":"Hossain, M.N., et al.: SLEUTH: real-time attack scenario reconstruction from COTS audit data. In: Proceedings of the 26th USENIX Security Symposium (USENIX Security 2017), Vancouver, Canada, 16\u201318 August 2017, pp. 487\u2013504. USENIX; Facebook; NSF; Baidu; Cisco; Google; Netflix; IBM Res; Visa Res; Yubico (2017)"},{"key":"14_CR11","unstructured":"Keromytis, A.D.: Transparent computing engagement 3 data release, January 2020. https:\/\/github.com\/darpa-i2o\/Transparent-Computing"},{"key":"14_CR12","unstructured":"Le, Q., Mikolov, T.: Distributed representations of sentences and documents. In: International Conference on Machine Learning, pp. 1188\u20131196. PMLR (2014)"},{"key":"14_CR13","doi-asserted-by":"publisher","unstructured":"LeCun, Y., Bengio, Y., Hinton, G.: Deep learning. Nature 521(7553), 436\u2013444 (2015). https:\/\/doi.org\/10.1038\/nature14539","DOI":"10.1038\/nature14539"},{"key":"14_CR14","doi-asserted-by":"publisher","unstructured":"Li, Z., Cheng, X., Sun, L., Zhang, J., Chen, B.: A hierarchical approach for advanced persistent threat detection with attention-based graph neural networks. Secur. Commun. Netw. 2021 (2021). https:\/\/doi.org\/10.1155\/2021\/9961342","DOI":"10.1155\/2021\/9961342"},{"key":"14_CR15","doi-asserted-by":"publisher","unstructured":"Liu, F., Wen, Y., Zhang, D., Jiang, X., Xing, X., Meng, D.: Log2vec: a heterogeneous graph embedding based approach for detecting cyber threats within enterprise. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security (CCS 2019), London, England, 11\u201315 November 2019, pp. 1777\u20131794. Assoc Comp Machinery; ACM SIGSAC (2019). https:\/\/doi.org\/10.1145\/3319535.3363224","DOI":"10.1145\/3319535.3363224"},{"key":"14_CR16","doi-asserted-by":"publisher","unstructured":"Liu, Y., et al.: Towards a timely causality analysis for enterprise security. In: 25th Annual Network and Distributed System Security Symposium (NDSS 2018), San Diego, CA, 18\u201321 February 2018 (2018). https:\/\/doi.org\/10.14722\/ndss.2018.23254","DOI":"10.14722\/ndss.2018.23254"},{"key":"14_CR17","unstructured":"Mandiant: Cyber attack lifecycle, November 2022. https:\/\/www.iacpcybercenter.org\/resource-center\/what-is-cyber-crime\/cyber-attack-lifecycle\/"},{"key":"14_CR18","unstructured":"Martin, L.: Cyber kill chain, October 2017. https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html"},{"key":"14_CR19","doi-asserted-by":"publisher","unstructured":"Milajerdi, S.M., Gjomemo, R., Eshete, B., Sekar, R., Venkatakrishnan, V.N.: Holmes: real-time APT detection through correlation of suspicious information flows. In: 2019 40th IEEE Symposium on Security and Privacy (SP 2019), San Francisco, CA, 19\u201323 May 2019, pp. 1137\u20131152. IEEE Comp Soc; CS Financial (2019). https:\/\/doi.org\/10.1109\/SP.2019.00026","DOI":"10.1109\/SP.2019.00026"},{"key":"14_CR20","unstructured":"MITRE: Cyber kill chain, October 2022. https:\/\/attack.mitre.org\/"},{"key":"14_CR21","doi-asserted-by":"publisher","unstructured":"Shen, Y., Mariconti, E., Vervier, P.A., Stringhini, G.: Tiresias: predicting security events through deep learning. In: Proceedings of the 2018 ACM SIGSAC Conference on Computer and Communications Security (CCS 2018), Toronto, Canada, 15\u201319 October 2018, pp. 592\u2013605. Assoc Comp Machinery; ACM SIGSAC; NSF; ANT Financial; Baidu; Cisco; Samsung Res; BlackBerry; Facebook; IBM Res; Ledger; SAP; Visa Res (2018). https:\/\/doi.org\/10.1145\/3243734.3243811","DOI":"10.1145\/3243734.3243811"},{"key":"14_CR22","unstructured":"Sun, F.Y., Hoffmann, J., Verma, V., Tang, J.: InfoGraph: unsupervised and semi-supervised graph-level representation learning via mutual information maximization. arXiv preprint arXiv:1908.01000 (2019)"},{"key":"14_CR23","unstructured":"Tao, Z.: Use model to deconstruct threats: detect intrusion by statistical learning, March 2019. https:\/\/data.hackinn.com\/ppt\/RSA2019\/Use%20Model%20to%20Deconstruct %20Threats%EF%BC%9ADetect%20Intrusion%20by%20Statistical %20Learning.pdf"},{"key":"14_CR24","doi-asserted-by":"publisher","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","volume":"17","author":"S Wang","year":"2022","unstructured":"Wang, S., et al.: THREATRACE: detecting and tracing host-based threats in node level through provenance graph learning. IEEE Trans. Inf. Forensics Secur. 17, 3972\u20133987 (2022). https:\/\/doi.org\/10.1109\/TIFS.2022.3208815","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"issue":"2","key":"14_CR25","doi-asserted-by":"publisher","first-page":"1624","DOI":"10.1109\/TDSC.2022.3160879","volume":"20","author":"Y Wu","year":"2023","unstructured":"Wu, Y., et al.: Paradise: real-time, generalized, and distributed provenance-based intrusion detection. IEEE Trans. Dependable Secur. Comput. 20(2), 1624\u20131640 (2023). https:\/\/doi.org\/10.1109\/TDSC.2022.3160879","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"14_CR26","doi-asserted-by":"publisher","unstructured":"Xiang, Z., Guo, D., Li, Q.: Detecting mobile advanced persistent threats based on large-scale DNS logs. Comput. Secur. 96 (2020). https:\/\/doi.org\/10.1016\/j.cose.2020.101933","DOI":"10.1016\/j.cose.2020.101933"},{"issue":"1","key":"14_CR27","doi-asserted-by":"publisher","first-page":"551","DOI":"10.1109\/TDSC.2020.2971484","volume":"19","author":"C Xiong","year":"2022","unstructured":"Xiong, C., et al.: CONAN: a practical real-time apt detection system with high accuracy and efficiency. IEEE Trans. Dependable Secur. Comput. 19(1), 551\u2013565 (2022). https:\/\/doi.org\/10.1109\/TDSC.2020.2971484","journal-title":"IEEE Trans. Dependable Secur. Comput."}],"container-title":["Lecture Notes of the Institute for Computer Sciences, Social Informatics and Telecommunications Engineering","Digital Forensics and Cyber Crime"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-031-89363-6_14","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,5,24]],"date-time":"2025-05-24T07:44:34Z","timestamp":1748072674000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-031-89363-6_14"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025]]},"ISBN":["9783031893629","9783031893636"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-031-89363-6_14","relation":{},"ISSN":["1867-8211","1867-822X"],"issn-type":[{"value":"1867-8211","type":"print"},{"value":"1867-822X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025]]},"assertion":[{"value":"25 May 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICDF2C","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Digital Forensics and Cyber Crime","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Dubrovnik","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Croatia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2024","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"9 October 2024","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10 October 2024","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icdf2c2024","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/icdf2c.eai-conferences.org\/2024\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}