{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T23:16:10Z","timestamp":1778109370348,"version":"3.51.4"},"publisher-location":"Cham","reference-count":44,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032160911","type":"print"},{"value":"9783032160928","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-16092-8_34","type":"book-chapter","created":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:59:08Z","timestamp":1778108348000},"page":"617-635","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Security Management of\u00a0Threats with\u00a0CyberGraph"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0004-7386-6910","authenticated-orcid":false,"given":"Ettore","family":"Carbone","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Bruno","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-8902-5729","authenticated-orcid":false,"given":"Fabio","family":"Dainese","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0003-4022-9766","authenticated-orcid":false,"given":"Purbasha","family":"Chowdhury","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1933-5348","authenticated-orcid":false,"given":"Paolo","family":"Falcarin","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2026,5,1]]},"reference":[{"key":"34_CR1","doi-asserted-by":"crossref","unstructured":"Aghaei, E., Niu, X., Shadid, W., Al-Shaer, E.: Securebert: a domain-specific language model for cybersecurity. In: International Conference on Security and Privacy in Communication Systems, pp. 39\u201356. Springer, Cham (2022)","DOI":"10.1007\/978-3-031-25538-0_3"},{"key":"34_CR2","doi-asserted-by":"publisher","unstructured":"Agrawal, G., Pal, K., Deng, Y., Liu, H., Chen, Y.C.: Cyberq: generating questions and answers for cybersecurity education using knowledge graph-augmented LLMs. In: Proceedings of the AAAI Conference on Artificial Intelligence, vol. 38, no. 21, pp. 23164\u201323172 (2024). https:\/\/doi.org\/10.1609\/aaai.v38i21.30362. https:\/\/ojs.aaai.org\/index.php\/AAAI\/article\/view\/30362","DOI":"10.1609\/aaai.v38i21.30362"},{"issue":"3","key":"34_CR3","doi-asserted-by":"publisher","first-page":"1563","DOI":"10.1007\/s10586-021-03330-3","volume":"25","author":"I Alsmadi","year":"2022","unstructured":"Alsmadi, I., Dwekat, Z., Cantu, R., Al-Ahmad, B.: Vulnerability assessment of industrial systems using Shodan. Clust. Comput. 25(3), 1563\u20131573 (2022)","journal-title":"Clust. Comput."},{"key":"34_CR4","unstructured":"Arnaert, M., Bertrand, Y., Boudaoud, K.: Modeling vulnerable internet of things on Shodan and Censys: an ontology for cyber security. In: Proceedings of the Tenth International Conference on Emerging Security Information, Systems and Technologies (SECUREWARE 2016), pp. 299\u2013302 (2016)"},{"issue":"2","key":"34_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3587255","volume":"7","author":"M Asiri","year":"2023","unstructured":"Asiri, M., Saxena, N., Gjomemo, R., Burnap, P.: Understanding indicators of compromise against cyber-attacks in industrial control systems: a security perspective. ACM Trans. Cyber-Phys. Syst. 7(2), 1\u201333 (2023)","journal-title":"ACM Trans. Cyber-Phys. Syst."},{"key":"34_CR6","first-page":"1","volume":"11","author":"S Barnum","year":"2012","unstructured":"Barnum, S.: Standardizing cyber threat intelligence information with the structured threat information expression (STIX). Mitre Corporation 11, 1\u201322 (2012)","journal-title":"Mitre Corporation"},{"key":"34_CR7","doi-asserted-by":"publisher","unstructured":"Basile, C., Canavese, D., Regano, L., Falcarin, P., De Sutter, B.: A meta-model for software protections and reverse engineering attacks. J. Syst. Softw. 150, 3\u201321 (2019). https:\/\/doi.org\/10.1016\/j.jss.2018.12.025. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0164121218302838","DOI":"10.1016\/j.jss.2018.12.025"},{"key":"34_CR8","doi-asserted-by":"publisher","unstructured":"Ceccato, M., et al.: How professional hackers understand protected code while performing attack tasks. In: 2017 IEEE\/ACM 25th International Conference on Program Comprehension (ICPC), pp. 154\u2013164 (2017). https:\/\/doi.org\/10.1109\/ICPC.2017.2","DOI":"10.1109\/ICPC.2017.2"},{"key":"34_CR9","doi-asserted-by":"publisher","first-page":"240","DOI":"10.1007\/s10664-018-9625-6","volume":"24","author":"M Ceccato","year":"2019","unstructured":"Ceccato, M., Tonella, P., Basile, C., Falcarin, P., Torchiano, M., Coppens, B., De Sutter, B.: Understanding the behaviour of hackers while performing attack tasks in a professional setting and in a public challenge. Empir. Softw. Eng. 24, 240\u2013286 (2019)","journal-title":"Empir. Softw. Eng."},{"key":"34_CR10","unstructured":"CyberEdge Group: 2023 State of Threat Intelligence (2023). https:\/\/www.recordedfuture.com\/state-of-threat-intelligence"},{"key":"34_CR11","doi-asserted-by":"publisher","unstructured":"Das, S.S., Serra, E., Halappanavar, M., Pothen, A., Al-Shaer, E.: V2w-BERT: a framework for effective hierarchical multiclass classification of software vulnerabilities. In: 2021 IEEE 8th International Conference on Data Science and Advanced Analytics (DSAA), pp. 1\u201312 (2021). https:\/\/doi.org\/10.1109\/DSAA53316.2021.9564227","DOI":"10.1109\/DSAA53316.2021.9564227"},{"key":"34_CR12","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M.: Intelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains (2011). https:\/\/www.lockheedmartin.com\/content\/dam\/lockheed-martin\/rms\/documents\/cyber\/LM-White-Paper-Intel-Driven-Defense.pdf"},{"key":"34_CR13","doi-asserted-by":"crossref","unstructured":"Falcarin, P., Dainese, F.: Building a cybersecurity knowledge graph with cybergraph. In: Proceedings of the 2024 ACM\/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE\/ACM Second International Workshop on Software Vulnerability, pp. 29\u201336 (2024)","DOI":"10.1145\/3643662.3643962"},{"key":"34_CR14","doi-asserted-by":"crossref","unstructured":"Fenz, S., Ekelhart, A.: Formalizing information security knowledge. In: Proceedings of the 4th international Symposium on information, Computer, and Communications Security, pp. 183\u2013194 (2009)","DOI":"10.1145\/1533057.1533084"},{"key":"34_CR15","doi-asserted-by":"crossref","unstructured":"Han, Z., Li, X., Liu, H., Xing, Z., Feng, Z.: Deepweak: reasoning common software weaknesses via knowledge graph embedding. In: 2018 IEEE 25th International Conference on Software Analysis, Evolution and Reengineering (SANER), pp. 456\u2013466. IEEE (2018)","DOI":"10.1109\/SANER.2018.8330232"},{"issue":"1","key":"34_CR16","first-page":"80","volume":"1","author":"EM Hutchins","year":"2011","unstructured":"Hutchins, E.M., Cloppert, M.J., Amin, R.M., et al.: Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains. Leading Issues Inf. Warfare Secur. Res. 1(1), 80 (2011)","journal-title":"Leading Issues Inf. Warfare Secur. Res."},{"key":"34_CR17","unstructured":"V.C. Inc.: 2024 Data Breach Investigations Report\u2014verizon.com (2024). https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/"},{"key":"34_CR18","doi-asserted-by":"publisher","unstructured":"Jia, Y., Qi, Y., Shang, H., Jiang, R., Li, A.: A practical approach to constructing a knowledge graph for cybersecurity. Engineering 4(1), 53\u201360 (2018). https:\/\/doi.org\/10.1016\/j.eng.2018.01.004. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S2095809918301097, cybersecurity","DOI":"10.1016\/j.eng.2018.01.004"},{"key":"34_CR19","unstructured":"Joe, S.: Formulating a Robust Pivoting Methodology. https:\/\/pylos.co\/wp-content\/uploads\/2021\/02\/pivoting.pdf"},{"key":"34_CR20","doi-asserted-by":"crossref","unstructured":"Jones, C.L., Bridges, R.A., Huffer, K.M., Goodall, J.R.: Towards a relation extraction framework for cyber-security concepts. In: Proceedings of the 10th Annual Cyber and Information Security Research Conference, pp.\u00a01\u20134 (2015)","DOI":"10.1145\/2746266.2746277"},{"key":"34_CR21","first-page":"2021","volume":"11","author":"PE Kaloroumakis","year":"2021","unstructured":"Kaloroumakis, P.E., Smith, M.J.: Toward a knowledge graph of cybersecurity countermeasures. MITRE Corporation 11, 2021 (2021)","journal-title":"MITRE Corporation"},{"key":"34_CR22","doi-asserted-by":"crossref","unstructured":"Li, K., Zhou, H., Tu, Z., Feng, B.: CSKB: a cyber security knowledge base based on knowledge graph. In: Security and Privacy in Digital Economy: First International Conference, SPDE 2020, Quzhou, China, 30 October\u20131 November 2020, Proceedings 1, pp. 100\u2013113. Springer, Cham (2020)","DOI":"10.1007\/978-981-15-9129-7_8"},{"key":"34_CR23","doi-asserted-by":"crossref","unstructured":"Li, X., et al.: A mining approach to obtain the software vulnerability characteristics. In: 2017 Fifth International Conference on Advanced Cloud and Big Data (CBD), pp. 296\u2013301. IEEE (2017)","DOI":"10.1109\/CBD.2017.58"},{"key":"34_CR24","doi-asserted-by":"crossref","unstructured":"Li, Z., Zeng, J., Chen, Y., Liang, Z.: Attackg: constructing technique knowledge graph from cyber threat intelligence reports. In: European Symposium on Research in Computer Security, pp. 589\u2013609. Springer, Cham (2022)","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"34_CR25","doi-asserted-by":"crossref","unstructured":"van Liebergen, K., Caballero, J., Kotzias, P., Gates, C.: A deep dive into virustotal: characterizing and clustering a massive file feed. arXiv preprint arXiv:2210.15973 (2022)","DOI":"10.1007\/978-3-031-35504-2_8"},{"key":"34_CR26","doi-asserted-by":"crossref","unstructured":"Liu, P., Li, H., Wang, Z., Liu, J., Ren, Y., Zhu, H.: Multi-features based semantic augmentation networks for named entity recognition in threat intelligence. In: 2022 26th International Conference on Pattern Recognition (ICPR), pp. 1557\u20131563. IEEE (2022)","DOI":"10.1109\/ICPR56361.2022.9956373"},{"key":"34_CR27","unstructured":"Long, S.J., Springett, S., Stranathan, W.: OWASP dependency check (2015). https:\/\/owasp.org\/www-project-dependency-check\/"},{"key":"34_CR28","doi-asserted-by":"publisher","unstructured":"Mouiche, I., Saad, S.: Entity and relation extractions for threat intelligence knowledge graphs. Comput. Secur. 148, 104120 (2025). https:\/\/doi.org\/10.1016\/j.cose.2024.104120. https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404824004255","DOI":"10.1016\/j.cose.2024.104120"},{"key":"34_CR29","doi-asserted-by":"publisher","unstructured":"Mulero-Palencia, S., Monzon\u00a0Baeza, V.: Detection of vulnerabilities in smart buildings using the Shodan tool. Electronics 12(23) (2023). https:\/\/doi.org\/10.3390\/electronics12234815. https:\/\/www.mdpi.com\/2079-9292\/12\/23\/4815","DOI":"10.3390\/electronics12234815"},{"key":"34_CR30","unstructured":"Lukova-Chuikoa, N., Fesenkoa, A., Papirnaa, H., Gnatyukb, S.: Threat Hunting as a Method of Protection Against Cyber Threats. https:\/\/ceur-ws.org\/Vol-2833\/Paper_10.pdf"},{"key":"34_CR31","unstructured":"Obrst, L., Chase, P., Markeloff, R.: Developing an ontology of the cyber security domain. In: STIDS, pp. 49\u201356 (2012)"},{"key":"34_CR32","unstructured":"Oltramari, A., Cranor, L.F., Walls, R.J., McDaniel, P.D.: Building an ontology of cyber security. In: STIDS, pp. 54\u201361. Citeseer (2014)"},{"key":"34_CR33","doi-asserted-by":"crossref","unstructured":"Pingle, A., Piplai, A., Mittal, S., Joshi, A., Holt, J., Zak, R.: Relext: relation extraction using deep learning approaches for cybersecurity knowledge graph improvement. In: Proceedings of the 2019 IEEE\/ACM International Conference on Advances in Social Networks Analysis and Mining, pp. 879\u2013886 (2019)","DOI":"10.1145\/3341161.3343519"},{"key":"34_CR34","doi-asserted-by":"publisher","DOI":"10.1016\/j.knosys.2021.107524","volume":"233","author":"I Sarhan","year":"2021","unstructured":"Sarhan, I., Spruit, M.: Open-CYKG: an open cyber threat intelligence knowledge graph. Knowl.-Based Syst. 233, 107524 (2021)","journal-title":"Knowl.-Based Syst."},{"key":"34_CR35","doi-asserted-by":"crossref","unstructured":"Satvat, K., Gjomemo, R., Venkatakrishnan, V.: Tipce: a longitudinal threat intelligence platform comprehensiveness analysis. In: Proceedings of the Fourteenth ACM Conference on Data and Application Security and Privacy, pp. 349\u2013360 (2024)","DOI":"10.1145\/3626232.3653278"},{"key":"34_CR36","first-page":"1","volume":"2020","author":"G Shen","year":"2020","unstructured":"Shen, G., Wang, W., Mu, Q., Pu, Y., Qin, Y., Yu, M.: Data-driven cybersecurity knowledge graph construction for industrial control system security. Wirel. Commun. Mob. Comput. 2020, 1\u201313 (2020)","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"34_CR37","doi-asserted-by":"publisher","unstructured":"Shinde, P.S., Ardhapurkar, S.B.: Cyber security analysis using vulnerability assessment and penetration testing. In: 2016 World Conference on Futuristic Trends in Research and Innovation for Social Welfare (Startup Conclave), pp.\u00a01\u20135 (2016). https:\/\/doi.org\/10.1109\/STARTUP.2016.7583912","DOI":"10.1109\/STARTUP.2016.7583912"},{"issue":"9","key":"34_CR38","doi-asserted-by":"publisher","first-page":"3511","DOI":"10.1007\/s10115-023-01860-3","volume":"65","author":"LF Sikos","year":"2023","unstructured":"Sikos, L.F.: Cybersecurity knowledge graphs. Knowl. Inf. Syst. 65(9), 3511\u20133531 (2023)","journal-title":"Knowl. Inf. Syst."},{"key":"34_CR39","unstructured":"Simsek, S., Xia, H., Gluck, J., Medina, D.S., Starobinski, D.: Fixing invalid CVE-CWE mappings in threat databases"},{"issue":"3","key":"34_CR40","doi-asserted-by":"publisher","first-page":"1748","DOI":"10.1109\/COMST.2023.3273282","volume":"25","author":"N Sun","year":"2023","unstructured":"Sun, N., et al.: Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives. IEEE Commun. Surv. Tutor. 25(3), 1748\u20131774 (2023)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"34_CR41","unstructured":"Syed, Z., Padia, A., Finin, T., Mathews, L., Joshi, A.: UCO: a unified cybersecurity ontology. In: Workshops at the Thirtieth AAAI Conference on Artificial Intelligence (2016)"},{"key":"34_CR42","unstructured":"The Software Security Project: Zed attack proxy (2023). https:\/\/www.zaproxy.org\/"},{"key":"34_CR43","doi-asserted-by":"crossref","unstructured":"Xiao, H., Xing, Z., Li, X., Guo, H.: Embedding and predicting software security entity relationships: a knowledge graph based approach. In: Neural Information Processing: 26th International Conference, ICONIP 2019, Sydney, NSW, Australia, 12\u201315 December 2019, Proceedings, Part III 26, pp. 50\u201363. Springer, Cham (2019)","DOI":"10.1007\/978-3-030-36718-3_5"},{"key":"34_CR44","doi-asserted-by":"crossref","unstructured":"Yuan, L., Bai, Y., Xing, Z., Chen, S., Li, X., Deng, Z.: Predicting entity relations across different security databases by using graph attention network. In: 2021 IEEE 45th Annual Computers, Software, and Applications Conference (COMPSAC), pp. 834\u2013843. IEEE (2021)","DOI":"10.1109\/COMPSAC51774.2021.00116"}],"container-title":["Lecture Notes in Computer Science","Computer Security. ESORICS 2025 International Workshops"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-16092-8_34","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,6]],"date-time":"2026-05-06T22:59:12Z","timestamp":1778108352000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-16092-8_34"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032160911","9783032160928"],"references-count":44,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-16092-8_34","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"1 May 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ESORICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"European Symposium on Research in Computer Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toulouse","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"France","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 September 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 September 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"esorics2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.esorics2025.org\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}