{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T19:18:52Z","timestamp":1761333532247,"version":"build-2065373602"},"publisher-location":"Cham","reference-count":27,"publisher":"Springer Nature Switzerland","isbn-type":[{"type":"print","value":"9783032018229"},{"type":"electronic","value":"9783032018236"}],"license":[{"start":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T00:00:00Z","timestamp":1761350400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,10,25]],"date-time":"2025-10-25T00:00:00Z","timestamp":1761350400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-01823-6_10","type":"book-chapter","created":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T19:14:18Z","timestamp":1761333258000},"page":"162-176","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Standardized and\u00a0Usage-Controlled Alert Analysis for\u00a0Improved Cyber Threat Intelligence"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-5837-8730","authenticated-orcid":false,"given":"Hendrik","family":"Meyer Zum Felde","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9123-933X","authenticated-orcid":false,"given":"Radhouene","family":"Azzabi","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1298-7845","authenticated-orcid":false,"given":"C\u00e9dric","family":"Gouy-Pailler","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0001-7483-8952","authenticated-orcid":false,"given":"Gilles","family":"Lehmann","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0760-8479","authenticated-orcid":false,"given":"Amaia","family":"Gil","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,10,25]]},"reference":[{"key":"10_CR1","unstructured":"et\u00a0al., N.W.G.J.C.: Request for comments: 3410 - introduction and applicability statements for internet standard management framework (2025). https:\/\/datatracker.ietf.org\/doc\/html\/rfc3410\/. Accessed 02 June 2025"},{"key":"10_CR2","unstructured":"Anomil: Anomali threatstream (2025). https:\/\/www.anomali.com\/products\/threatstream. Accessed 27 Mar 2025"},{"key":"10_CR3","unstructured":"Cloud, I.: Ibm x-force threat intelligence api documentation (2025). https:\/\/api.xforce.ibmcloud.com\/doc\/. Accessed 27 Mar 2025"},{"key":"10_CR4","unstructured":"Committee, O.C.T.I.T.: Introduction to stix (2025). https:\/\/oasis-open.github.io\/cti-documentation\/stix\/intro. Accessed 27 Mar 2025"},{"key":"10_CR5","unstructured":"Committee, O.C.T.I.T.: Introduction to taxii (2025). https:\/\/oasis-open.github.io\/cti-documentation\/taxii\/intro.html. Accessed 27 Mar 2025"},{"key":"10_CR6","unstructured":"Corporation, O.T.: Implementing arcsight common event format (cef) - version 26 (2023). https:\/\/www.microfocus.com\/documentation\/arcsight\/arcsight-smartconnectors-8.4\/pdfdoc\/cef-implementation-standard\/cef-implementation-standard.pdf. Accessed 27 Mar 2025"},{"key":"10_CR7","unstructured":"Corporation, T.M.: Att &ck matrix for enterprise (2025). https:\/\/attack.mitre.org\/. Accessed 27 Mar 2025"},{"key":"10_CR8","unstructured":"Cybersecurity, (CISA), I.S.A.: Home page (2025). https:\/\/www.cisa.gov\/. Accessed 27 Mar 2025"},{"key":"10_CR9","doi-asserted-by":"crossref","unstructured":"Danyliw, e.a.: The incident object description exchange format (2007). https:\/\/datatracker.ietf.org\/doc\/html\/rfc5070. Accessed 27 Mar 2025","DOI":"10.17487\/rfc5070"},{"key":"10_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.patcog.2023.110130","volume":"147","author":"X Echeberria-Barrio","year":"2024","unstructured":"Echeberria-Barrio, X., Gil-Lerchundi, A., Mendialdua, I., Orduna-Urrutia, R.: Topological safeguard for evasion attack interpreting the neural networks\u2019 behavior. Pattern Recogn. 147, 110130 (2024)","journal-title":"Pattern Recogn."},{"key":"10_CR11","unstructured":"Filigran: Opencti documentation space (2025). https:\/\/docs.opencti.io\/latest\/. Accessed 27 Mar 2025"},{"key":"10_CR12","unstructured":"Force, I.T.: Idmefv2 in a nutshell (2025). https:\/\/idmefv2.github.io\/index.php\/idmefv2-in-a-nutshell\/. Accessed 27 Mar 2025"},{"key":"10_CR13","unstructured":"Framework, V.: Veris the vocabulary for event recording and incident sharing (2019). https:\/\/verisframework.org. Accessed 27 Mar 2025"},{"key":"10_CR14","unstructured":"IBM: Leef overview (2025). https:\/\/www.ibm.com\/docs\/en\/dsm?topic=leef-overview. Accessed 27 Mar 2025"},{"key":"10_CR15","unstructured":"Inc., L.: Open threat exchange (2025). https:\/\/otx.alienvault.com\/. Accessed 27 Mar 2025"},{"key":"10_CR16","unstructured":"LLC, M.U.: About trellix (2025). https:\/\/www.trellix.com\/en-gb\/about\/. Accessed 27 Mar 2025"},{"key":"10_CR17","unstructured":"Luxembourg, C.C.I.R.C.: Our services (2023). https:\/\/www.circl.lu\/. Accessed 27 Mar 2025"},{"key":"10_CR18","unstructured":"MISP-Project: Misp documentation and support (2025). https:\/\/www.misp-project.org\/documentation\/. Accessed 27 Mar 2025"},{"key":"10_CR19","doi-asserted-by":"crossref","unstructured":"Mitchell, M., et al.: Model cards for model reporting. In: Proceedings of the Conference on Fairness, Accountability, and Transparency, pp. 220\u2013229 (2019)","DOI":"10.1145\/3287560.3287596"},{"key":"10_CR20","unstructured":"Networks, P.A.: Anomali threatstream (2025). https:\/\/www.paloaltonetworks.com\/resources\/datasheets\/cortex-xsoar. Accessed 27 Mar 2025"},{"key":"10_CR21","unstructured":"Nilsson, A., Bideh, P.N., Brorsson, J.: A survey of published attacks on intel sgx. arXiv preprint arXiv:2006.13598 (2020)"},{"key":"10_CR22","unstructured":"OASIS: Common alerting protocol version 1.2 (2025). https:\/\/docs.oasis-open.org\/emergency\/cap\/v1.2\/CAP-v1.2-os.html. Accessed 27 Mar 2025"},{"key":"10_CR23","unstructured":"OASIS: Open command and control (openc2) (2025). https:\/\/openc2.org\/. Accessed 02 June 2025"},{"key":"10_CR24","unstructured":"Organization, N.A.T.: Nato cyber defence (2021). https:\/\/www.nato.int\/nato_static_fl2014\/assets\/pdf\/2021\/4\/pdf\/2104-factsheet-cyber-defence-en.pdf. Accessed 27 Mar 2025"},{"issue":"11","key":"10_CR25","doi-asserted-by":"publisher","first-page":"5291","DOI":"10.1007\/s13042-024-02237-w","volume":"15","author":"L Segurola-Gil","year":"2024","unstructured":"Segurola-Gil, L., Moreno-Moreno, M., Irigoien, I., Florez-Tapia, A.M.: Unsupervised anomaly detection approach for cyberattack identification. Int. J. Mach. Learn. Cybern. 15(11), 5291\u20135302 (2024)","journal-title":"Int. J. Mach. Learn. Cybern."},{"key":"10_CR26","unstructured":"StrangeBee: Thehive documentation (2025). https:\/\/docs.strangebee.com\/thehive\/overview\/. Accessed 27 Mar 2025"},{"key":"10_CR27","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2022.102632","volume":"115","author":"F Zola","year":"2022","unstructured":"Zola, F., Segurola-Gil, L., Bruse, J.L., Galar, M., Orduna-Urrutia, R.: Network traffic analysis through node behaviour classification: a graph-based approach with temporal dissection and data-level preprocessing. Comput. Secur. 115, 102632 (2022)","journal-title":"Comput. Secur."}],"container-title":["Lecture Notes in Computer Science","Applied Cryptography and Network Security Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-01823-6_10","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,24]],"date-time":"2025-10-24T19:14:22Z","timestamp":1761333262000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-01823-6_10"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10,25]]},"ISBN":["9783032018229","9783032018236"],"references-count":27,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-01823-6_10","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2025,10,25]]},"assertion":[{"value":"25 October 2025","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ACNS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Applied Cryptography and Network Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Munich","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23 June 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 June 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"23","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"acns2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/acns2025.fordaysec.de\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}