{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:53:57Z","timestamp":1782161637321,"version":"3.54.5"},"publisher-location":"Cham","reference-count":17,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032299208","type":"print"},{"value":"9783032299215","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-29921-5_11","type":"book-chapter","created":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:18:06Z","timestamp":1782159486000},"page":"157-171","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Modeling Semantic Ambiguity: A Knowledge-Driven Framework for\u00a0Security Attack Technique Extraction"],"prefix":"10.1007","author":[{"given":"Cheng","family":"Meng","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhengwei","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xinyi","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fangming","family":"Dong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qiuyun","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fangli","family":"Ren","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Baoxu","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,23]]},"reference":[{"key":"11_CR1","unstructured":"B\u00fcchel, M., et\u00a0al.: $$\\{$$SoK$$\\}$$: Automated $$\\{$$TTP$$\\}$$ extraction from $$\\{$$CTI$$\\}$$ reports\u2013are we there yet? In: 34th USENIX security symposium (USENIX Security 25), pp. 4621\u20134641 (2025)"},{"key":"11_CR2","doi-asserted-by":"publisher","unstructured":"Chen, M., Zhu, K., Lu, B., Li, D., Yuan, Q., Zhu, Y.: Aecr: Automatic attack technique intelligence extraction based on fine-tuned large language model. Computers & Security 150, 104213 (2025). https:\/\/doi.org\/10.1016\/j.cose.2024.104213, https:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404824005194","DOI":"10.1016\/j.cose.2024.104213"},{"key":"11_CR3","doi-asserted-by":"crossref","unstructured":"Dong, F., et al.: From threat report to att&ck: automated extraction and reasoning of TTPs using large language models. In: 2025 28th International Conference on Computer Supported Cooperative Work in Design (CSCWD), pp. 860\u2013865. IEEE (2025)","DOI":"10.1109\/CSCWD64889.2025.11033281"},{"key":"11_CR4","doi-asserted-by":"publisher","unstructured":"Fayyazi, R., Taghdimi, R., Yang, S.J.: Advancing TTP analysis: harnessing the power of large language models with retrieval augmented generation. In: 2024 Annual Computer Security Applications Conference Workshops (ACSAC Workshops), pp. 255\u2013261. (2024). https:\/\/doi.org\/10.1109\/ACSACW65225.2024.00036","DOI":"10.1109\/ACSACW65225.2024.00036"},{"issue":"7","key":"11_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3644073","volume":"56","author":"Y Gao","year":"2024","unstructured":"Gao, Y., Gu, S., Jiang, J., Hong, S.R., Yu, D., Zhao, L.: Going beyond XAI: a systematic survey for explanation-guided learning. ACM Comput. Surv. 56(7), 1\u201339 (2024)","journal-title":"ACM Comput. Surv."},{"key":"11_CR6","doi-asserted-by":"crossref","unstructured":"Lange, L., et al.: Annoctr: a dataset for detecting and linking entities, tactics, and techniques in cyber threat reports. In: Proceedings of the 2024 Joint International Conference on Computational Linguistics, Language Resources and Evaluation (LREC-COLING 2024), pp. 1147\u20131160. (2024)","DOI":"10.63317\/4esp6coivous"},{"key":"11_CR7","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103815","volume":"140","author":"L Li","year":"2024","unstructured":"Li, L., Huang, C., Chen, J.: Automated discovery and mapping att&ck tactics and techniques for unstructured cyber threat intelligence. Comput. Secur. 140, 103815 (2024)","journal-title":"Comput. Secur."},{"key":"11_CR8","doi-asserted-by":"publisher","unstructured":"Li, Z., Hu, X., Liu, A., Zheng, K., Huang, S., Xiong, H.: $$\\mathit{Refiner}$$: restructure retrieved content efficiently to advance question-answering capabilities. In: Al-Onaizan, Y., Bansal, M., Chen, Y.N. (eds.) Findings of the Association for Computational Linguistics: EMNLP 2024. pp. 8548\u20138572. Association for Computational Linguistics, Miami, Florida, USA (2024).https:\/\/doi.org\/10.18653\/v1\/2024.findings-emnlp.500, https:\/\/aclanthology.org\/2024.findings-emnlp.500\/","DOI":"10.18653\/v1\/2024.findings-emnlp.500"},{"key":"11_CR9","doi-asserted-by":"crossref","unstructured":"Nguyen, T., \u0160rndi\u0107, N., Neth, A.: Noise contrastive estimation-based matching framework for low-resource security attack pattern recognition. In: Graham, Y., Purver, M. (eds.) Findings of the Association for Computational Linguistics: EACL 2024, pp. 355\u2013373. Association for Computational Linguistics, St. Julian\u2019s, Malta (2024). https:\/\/aclanthology.org\/2024.findings-eacl.25\/","DOI":"10.18653\/v1\/2024.findings-eacl.25"},{"issue":"4","key":"11_CR10","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3696427","volume":"5","author":"N Rani","year":"2024","unstructured":"Rani, N., Saha, B., Maurya, V., Shukla, S.K.: Ttpxhunter: actionable threat intelligence extraction as TTPs from finished cyber threat reports. Digital threats: research and practice 5(4), 1\u201319 (2024)","journal-title":"Digital threats: research and practice"},{"key":"11_CR11","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., Thomas, C.B.: Mitre att&ck: Design and philosophy. In: Technical report. The MITRE Corporation (2018)"},{"issue":"3","key":"11_CR12","doi-asserted-by":"publisher","first-page":"1748","DOI":"10.1109\/COMST.2023.3273282","volume":"25","author":"N Sun","year":"2023","unstructured":"Sun, N., Ding, M., Jiang, J., Xu, W., Mo, X., Tai, Y., Zhang, J.: Cyber threat intelligence mining for proactive cybersecurity defense: a survey and new perspectives. IEEE Commun. Surv. Tutorials 25(3), 1748\u20131774 (2023)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"11_CR13","unstructured":"Virkud, A., Inam, M.A., Riddle, A., Liu, J., Wang, G., Bates, A.: How does endpoint detection use the MITRE ATT&CK framework? In: 33rd USENIX Security Symposium (USENIX Security 24), pp. 3891\u20133908 (2024)"},{"key":"11_CR14","unstructured":"Wudali, P.N., Kravchik, M., Malul, E., Gandhi, P.A., Elovici, Y., Shabtai, A.: Rule-att&ck mapper (ram): mapping SIEM rules to TTPs using LLMs (2025). https:\/\/arxiv.org\/abs\/2502.02337"},{"issue":"1","key":"11_CR15","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1186\/s42400-021-00106-5","volume":"5","author":"Y You","year":"2022","unstructured":"You, Y., et al.: Tim: threat context-enhanced TTP intelligence mining on unstructured threat data. Cybersecurity 5(1), 3 (2022)","journal-title":"Cybersecurity"},{"key":"11_CR16","doi-asserted-by":"publisher","unstructured":"Zhang, J., Wen, H., Li, L., Zhu, H.: Unittp: a unified framework for tactics, techniques, and procedures mapping in cyber threats. In: 2024 IEEE 23rd International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1580\u20131588 (2024). https:\/\/doi.org\/10.1109\/TrustCom63139.2024.00218","DOI":"10.1109\/TrustCom63139.2024.00218"},{"key":"11_CR17","doi-asserted-by":"crossref","unstructured":"Zhang, Y., et al.: Teleclass: taxonomy enrichment and LLM-enhanced hierarchical text classification with minimal supervision. In: Proceedings of the ACM on Web Conference 2025, pp. 2032\u20132042 (2025)","DOI":"10.1145\/3696410.3714940"}],"container-title":["Lecture Notes in Computer Science","Computational Science \u2013 ICCS 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-29921-5_11","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:18:13Z","timestamp":1782159493000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-29921-5_11"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032299208","9783032299215"],"references-count":17,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-29921-5_11","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"23 June 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICCS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computational Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hamburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iccs-computsci2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.iccs-meeting.org\/iccs2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}