{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T11:05:20Z","timestamp":1784027120152,"version":"3.55.0"},"publisher-location":"Cham","reference-count":33,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032207319","type":"print"},{"value":"9783032207326","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-20732-6_21","type":"book-chapter","created":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T10:28:43Z","timestamp":1784024923000},"page":"336-352","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Context-Aware Entity-Relation Extraction for\u00a0Threat Intelligence Knowledge Graphs"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-8024-7631","authenticated-orcid":false,"given":"Inoussa","family":"Mouiche","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5506-5261","authenticated-orcid":false,"given":"Sherif","family":"Saad","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,2]]},"reference":[{"key":"21_CR1","unstructured":"MITRE: MITRE Response to Cyber Attack in One of Its R&D Networks. https:\/\/www.mitre.org\/news-insights\/news-release\/mitre-response-cyber-attack-one-its-rd-networks. Accessed 02 June 2024"},{"key":"21_CR2","unstructured":"Crumpton, L., Clancy, C.: Advanced cyber threats impact even the most prepared. https:\/\/medium.com\/mitre-engenuity\/advanced-cyber-threats-impact-even-the-most-prepared-56444e980dc8. Accessed 02 June 2024"},{"key":"21_CR3","doi-asserted-by":"crossref","unstructured":"Pingle, A., Piplai, A., Mittal, S., Joshi, A., Holt, J., Zak, R.: RelExt: relation extraction using deep learning approaches for cybersecurity knowledge graph improvement. In: ASONAM \u201919: Proceedings of the 2019 IEEE\/ACM International Conference on Advances in Social Networks Analysis and Mining, vol. 2, pp. 879\u2013886, ACM, Vancouver, British Columbia, Canada (2020)","DOI":"10.1145\/3341161.3343519"},{"key":"21_CR4","doi-asserted-by":"publisher","unstructured":"Sarhan, I., Spruit, M.: Open-CyKG: an open cyber threat intelligence knowledge graph. Knowl. Based Syst. 233 (2021). https:\/\/doi.org\/10.1016\/j.knosys.2021.107524","DOI":"10.1016\/j.knosys.2021.107524"},{"key":"21_CR5","doi-asserted-by":"publisher","unstructured":"Zuo, J., Gao, Y., Li, X., Yuan, J.: An end-to-end entity and relation joint extraction model for cyber threat intelligence. In: 2022 the 7th International Conference on Big Data Analytics (ICBDA), pp. 204\u2013209. IEEE, Guangzhou, China (2022). https:\/\/doi.org\/10.1109\/ICBDA55095.2022.9760342","DOI":"10.1109\/ICBDA55095.2022.9760342"},{"key":"21_CR6","doi-asserted-by":"crossref","unstructured":"Zhong, Z., Chen, D.: A frustratingly easy approach for entity and relation extraction. In Proceedings of the 2021 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, ACL, pp. 50\u201361 (2021)","DOI":"10.18653\/v1\/2021.naacl-main.5"},{"key":"21_CR7","doi-asserted-by":"crossref","unstructured":"Yan, Z., Jia, Z., Tu, K.: An empirical study of pipeline vs. joint approaches to entity and relation extraction. In: Proceedings of the 2nd Conference of the Asia-Pacific Chapter of the Association for Computational Linguistics and the 12th International Joint Conference on Natural Language Processing, ACL, pp. 437\u2013443 (2022)","DOI":"10.18653\/v1\/2022.aacl-short.55"},{"key":"21_CR8","doi-asserted-by":"publisher","unstructured":"Ahmed, K., Khurshid, S., K., Hina, S.: CyberEntRel: joint extraction of cyber entities and relations using deep learning. Comput. Securi. 136 (2024). https:\/\/doi.org\/10.1016\/j.cose.2023.103579","DOI":"10.1016\/j.cose.2023.103579"},{"key":"21_CR9","doi-asserted-by":"publisher","unstructured":"Guo, Y., Liu, Z., Huang, C., Liu, J., Jing, W., Wang, Z., Wang, Y.: CyberRel: joint entity and relation extraction for cybersecurity concepts. In: Information and Communications Security: 23rd International Conference, ICICS 2021, pp. 447\u2014463, Springer, Chongqing, China (2021). https:\/\/doi.org\/10.1007\/978-3-030-86890-1_25","DOI":"10.1007\/978-3-030-86890-1_25"},{"key":"21_CR10","doi-asserted-by":"publisher","unstructured":"Mouiche, I., Saad, S.: Entity and relation extractions for threat intelligence knowledge graphs. Comput. Secur., 148 (2025). https:\/\/doi.org\/10.1016\/j.cose.2024.104120","DOI":"10.1016\/j.cose.2024.104120"},{"key":"21_CR11","unstructured":"Hugging Face. https:\/\/huggingface.co\/ehsanaghaei\/SecureBERT_Plu, Accessed 25 Feb 2025"},{"key":"21_CR12","doi-asserted-by":"publisher","unstructured":"Aghaei, E., Niu, X., Shadid, W., Al-Shaer, E.: SecureBERT: a domain-specific language model for cybersecurity. Security and Privacy in Communication Networks, vol. 462 (2023) https:\/\/doi.org\/10.1109\/TrustCom50675.2020.00083","DOI":"10.1109\/TrustCom50675.2020.00083"},{"key":"21_CR13","doi-asserted-by":"crossref","unstructured":"Lample, G., Ballesteros, M., Subramanian, S., Kawakami, K., Dyer, C.: Neural architectures for named entity recognition. In: Proceedings of NAACL-HLT (2016)","DOI":"10.18653\/v1\/N16-1030"},{"key":"21_CR14","doi-asserted-by":"publisher","unstructured":"Wang, X. et al.: DNRTI: a large-scale dataset for named entity recognition in threat intelligence. In: 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1842\u20131848. IEEE, Guangzhou, China, (2020). https:\/\/doi.org\/10.1109\/TrustCom50675.2020.00252","DOI":"10.1109\/TrustCom50675.2020.00252"},{"key":"21_CR15","unstructured":"Bridges, R.A., Jones, C.L., Iannacone, M.D., Goodall, J.R.: Automatic labeling for entity extraction in cyber security. In: The Third ASE International Conference on Cyber Security 2014 (2014)"},{"key":"21_CR16","unstructured":"Wang, X., Liu, Z., Liu, J.: Information extraction of cybersecurity concepts: an LSTM approach. Comput. Secur. 144 (2024)"},{"key":"21_CR17","doi-asserted-by":"publisher","unstructured":"Guo, Z., et al.: A framework for threat intelligence extraction and fusion. Comput. Secur. 132 (2024). https:\/\/doi.org\/10.1016\/j.cose.2023.103371","DOI":"10.1016\/j.cose.2023.103371"},{"key":"21_CR18","doi-asserted-by":"publisher","unstructured":"Liu, Y., Han, X., Zuo, W., Lv, H., Guo, J.: CTI-JE: a joint extraction framework of entities and relations in unstructured cyber threat intelligence. In: 27th International Conference on Computer Supported Cooperative Work in Design (CSCWD), pp. 2728\u20132733. IEEE, Tianjin, China (2024). https:\/\/doi.org\/10.1109\/CSCWD61410.2024.10580210","DOI":"10.1109\/CSCWD61410.2024.10580210"},{"key":"21_CR19","doi-asserted-by":"publisher","unstructured":"Lv, H., Han, X., Cui, H., Wang, P., Zuo, W., Zhou, Z.: Joint extraction of entities and relationships from cyber threat intelligence based on task-specific fourier network. In: 2024 International Joint Conference on Neural Networks (IJCNN), pp. 1\u20138, IEEE, Yokohama, Japan (2024). https:\/\/doi.org\/10.1109\/IJCNN60899.2024.10650942","DOI":"10.1109\/IJCNN60899.2024.10650942"},{"key":"21_CR20","doi-asserted-by":"publisher","unstructured":"Zhu, F., Cheng, Z., Li, P., Xu, H.: ITIRel: joint entity and relation extraction for internet of things threat intelligence. In: IEEE Internet of Things Journal, pp. 20867\u201320878 (2024). https:\/\/doi.org\/10.1109\/JIOT.2024.3373799","DOI":"10.1109\/JIOT.2024.3373799"},{"key":"21_CR21","doi-asserted-by":"publisher","unstructured":"Mouiche, I., Saad, S.: TIJERE: a novel threat intelligence joint extraction model based on analyst expert knowledge. TechRxiv (2024). https:\/\/doi.org\/10.36227\/techrxiv.174286575.55673704\/v1","DOI":"10.36227\/techrxiv.174286575.55673704\/v1"},{"key":"21_CR22","doi-asserted-by":"crossref","unstructured":"Gasmi, H., Laval, J., Bouras, A.: Information extraction of cybersecurity concepts: an LSTM approach. Appl. Sci. 9 (2019)","DOI":"10.3390\/app9193945"},{"key":"21_CR23","unstructured":"Zhao, J., Yan, Q., Liu, X., Li, B., Zuo, G.: Cyber threat intelligence modeling based on heterogeneous graph convolutional network. In: In Proceedings of the 23rd International Symposium on Research in Attacks, Intrusions and Defenses (RAID 2020), pp. 241\u2013256, USENIX, San Sebastian (2020)"},{"key":"21_CR24","doi-asserted-by":"crossref","unstructured":"Jo, H., Lee, Y., Shin, S.:Vulcan: automatic extraction and analysis of cyber threat intelligence from unstructured text. Comput. Secur. 120 (2022)","DOI":"10.1016\/j.cose.2022.102763"},{"key":"21_CR25","doi-asserted-by":"publisher","unstructured":"Marchiori, F., Conti, M., Verde, N., V.: STIXnet: a novel and modular solution for extracting all STIX objects in CTI reports. In: ARES \u201923: Proceedings of the 18th International Conference on Availability, Reliability, and Security (2023). https:\/\/doi.org\/10.1145\/3600160.3600182","DOI":"10.1145\/3600160.3600182"},{"key":"21_CR26","doi-asserted-by":"publisher","unstructured":"Mulwad, V., Li, W., Joshi, A., Finin, T., Viswanathan, K.: Extracting information about security vulnerabilities from web text. In: 2011 IEEE\/WIC\/ACM International Conferences on Web Intelligence and Intelligent Agent Technology, Lyon, France, pp. 257\u2013260 (2011). https:\/\/doi.org\/10.1109\/WI-IAT.2011.26","DOI":"10.1109\/WI-IAT.2011.26"},{"key":"21_CR27","doi-asserted-by":"publisher","DOI":"10.1155\/2022\/8477260","author":"Y Li","year":"2022","unstructured":"Li, Y., Guo, Y., Fang, C., Liu, Y., Chen, Q.: A novel threat intelligence information extraction system combining multiple models. Secur. Commun. Netw. (2022). https:\/\/doi.org\/10.1155\/2022\/8477260","journal-title":"Secur. Commun. Netw."},{"key":"21_CR28","doi-asserted-by":"publisher","first-page":"211691","DOI":"10.1109\/ACCESS.2020.3039234","volume":"8","author":"A Piplai","year":"2020","unstructured":"Piplai, A., Mittal, S., Joshi, A., Finin, T., Holt, J., Zak, R.: Creating cybersecurity knowledge graphs from malware after action reports. IEEE Access 8, 211691\u2013211703 (2020)","journal-title":"IEEE Access"},{"key":"21_CR29","unstructured":"Lafferty, JJ., McCallum, A., Pereira, F.: Conditional random fields: probabilistic models for segmenting and labeling sequence data. In: ICML \u201901: Proceedings of the Eighteenth International Conference on Machine Learning, pp. 282\u2013289 (2001)"},{"key":"21_CR30","doi-asserted-by":"crossref","unstructured":"Mouiche, I., Saad, S.: TI-NERmerger: semi-automated framework for integrating NER Datasets in cybersecurity. In: Proceedings of the 21st International Conference on Security and Cryptography, vol. 1, pp. 357\u2013370, SciTePress, Dijon, France (2024)","DOI":"10.5220\/0012867900003767"},{"key":"21_CR31","unstructured":"OASIS OPEN. https:\/\/docs.oasis-open.org\/cti\/stix\/v2.1\/cs02\/stix-v2.1-cs02.html. Accessed 10 Feb 2025"},{"key":"21_CR32","first-page":"2825","volume":"12","author":"F Pedregosa","year":"2011","unstructured":"Pedregosa, F., Varoquaux, G., et al.: Scikit-learn: machine learning in Python. J. Mach. Learn. Res. 12, 2825\u20132830 (2011)","journal-title":"J. Mach. Learn. Res."},{"key":"21_CR33","unstructured":"Syed, Z., Padia, A., Finin, T., Mathews, L., Joshi, A.: UCO: a unified cybersecurity ontology. In: Proceedings of the AAAI Workshop on Artificial Intelligence for Cyber Security, pp. 195\u2013202, AAAI Press (2016)"}],"container-title":["Lecture Notes in Computer Science","Risks and Security of Internet and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-20732-6_21","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,14]],"date-time":"2026-07-14T10:28:46Z","timestamp":1784024926000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-20732-6_21"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032207319","9783032207326"],"references-count":33,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-20732-6_21","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"2 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"The camera-ready version of this paper was partially edited using AI-assisted tools to meet conference page limits and formatting requirements. The authors remain fully responsible for the accuracy, validity, and integrity of the content presented.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Disclaimer"}},{"value":"CRiSIS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Risks and Security of Internet and Systems","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Gatineau, QC","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 October 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"20","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"crisis2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/crisis2025.uqo.ca\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}