{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:53:57Z","timestamp":1782161637301,"version":"3.54.5"},"publisher-location":"Cham","reference-count":30,"publisher":"Springer Nature Switzerland","isbn-type":[{"value":"9783032299208","type":"print"},{"value":"9783032299215","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-3-032-29921-5_18","type":"book-chapter","created":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:17:52Z","timestamp":1782159472000},"page":"261-275","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["From Alert Flood to\u00a0Actionable Intelligence: Reconstructing Attack Chains via\u00a0TTP Sequences Using LLMs and\u00a0RAG"],"prefix":"10.1007","author":[{"given":"Ruijie","family":"Qi","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenxin","family":"Le","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Ruiqi","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingxiao","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yepeng","family":"Yao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhengwei","family":"Jiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,6,23]]},"reference":[{"key":"18_CR1","doi-asserted-by":"crossref","unstructured":"Kokulu, F.B., et al.: Matched and mismatched SOCs: a qualitative study on security operations center issues. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 1955\u20131970 (2019)","DOI":"10.1145\/3319535.3354239"},{"key":"18_CR2","doi-asserted-by":"crossref","unstructured":"Zengy, J., et al.: Shadewatcher: recommendation-guided cyber threat analysis using system audit records. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 489\u2013506 (2022)","DOI":"10.1109\/SP46214.2022.9833669"},{"key":"18_CR3","unstructured":"Bouwman, X., Griffioen, H., Egbers, J., Doerr, C., Klievink, B., Van Eeten, M.: A different cup of $$\\{$$TI$$\\}$$? The added value of commercial threat intelligence. In: 29th USENIX Security Symposium (USENIX Security 2020), pp. 433\u2013450 (2020)"},{"key":"18_CR4","doi-asserted-by":"crossref","unstructured":"Jiang, Y., et al.: Xpert: empowering incident management with query recommendations via large language models. In: 2024 IEEE\/ACM 46th International Conference on Software Engineering (ICSE), pp. 1121\u20131133 (2023)","DOI":"10.1145\/3597503.3639081"},{"key":"18_CR5","doi-asserted-by":"crossref","unstructured":"van Ede, T., et al.: DEEPCASE: semi-supervised contextual analysis of security events. In: 43rd IEEE Symposium on Security and Privacy, SP 2022, pp. 522\u2013539. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833671"},{"key":"18_CR6","doi-asserted-by":"crossref","unstructured":"Fu, C., Li, Q., Xu, K., Wu, J.: Point cloud analysis for ml-based malicious traffic detection: reducing majorities of false positive alarms. In: Proceedings of the 2023 ACM SIGSAC Conference on Computer and Communications Security, pp. 1005\u20131019 (2023)","DOI":"10.1145\/3576915.3616631"},{"key":"18_CR7","doi-asserted-by":"crossref","unstructured":"Landauer, M., Skopik, F., Wurzenberger, M., Rauber, A.: Dealing with security alert flooding: using machine learning for domain-independent alert aggregation. ACM Trans. Priv. Secur. 25(3), 18:1\u201318:36 (2022)","DOI":"10.1145\/3510581"},{"key":"18_CR8","doi-asserted-by":"crossref","unstructured":"Jalalvand, F., Baruwal Chhetri, M., Nepal, S., Paris, C.: Alert prioritisation in security operations centres: a systematic survey on criteria and methods. ACM Comput. Surv. 57(2), 1\u201336 (2024)","DOI":"10.1145\/3695462"},{"key":"18_CR9","doi-asserted-by":"crossref","unstructured":"Jiang, J., Wang, Q., Shi, Z., Lv, B., Fan, W., Peng, X.: The parameter optimization based on LVPSO algorithm for detecting multi-step attacks. In: Proceedings of the 16th ACM International Conference on Computing Frontiers, pp. 24\u201331 (2019)","DOI":"10.1145\/3310273.3323048"},{"key":"18_CR10","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2021.102203","volume":"105","author":"P Zhou","year":"2021","unstructured":"Zhou, P., Zhou, G., Dakui, W., Fei, M.: Detecting multi-stage attacks using sequence-to-sequence model. Comput. Secur. 105, 102203 (2021)","journal-title":"Comput. Secur."},{"key":"18_CR11","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103583","volume":"137","author":"X Wang","year":"2024","unstructured":"Wang, X., Yang, X., Liang, X., Zhang, X., Zhang, W., Gong, X.: Combating alert fatigue with AlertPro: context-aware alert prioritization using reinforcement learning for multi-step attack detection. Comput. Secur. 137, 103583 (2024)","journal-title":"Comput. Secur."},{"issue":"18","key":"18_CR12","doi-asserted-by":"publisher","first-page":"4045","DOI":"10.3390\/s19184045","volume":"19","author":"X Cheng","year":"2019","unstructured":"Cheng, X., Zhang, J., Chen, B.: Cyber situation comprehension for IoT systems based on apt alerts and logs correlation. Sensors 19(18), 4045 (2019)","journal-title":"Sensors"},{"key":"18_CR13","doi-asserted-by":"crossref","unstructured":"Ning, P., Cui, Y., Reeves, D.S.: Constructing attack scenarios through correlation of intrusion alerts. In: Proceedings of the 9th ACM Conference on Computer and Communications Security, pp. 245\u2013254 (2002)","DOI":"10.1145\/586110.586144"},{"key":"18_CR14","doi-asserted-by":"publisher","first-page":"206","DOI":"10.1016\/j.cose.2014.10.006","volume":"49","author":"AA Ramaki","year":"2015","unstructured":"Ramaki, A.A., Amini, M., Atani, R.E.: RTECA: real time episode correlation algorithm for multi-step attack scenarios detection. Comput. Secur. 49, 206\u2013219 (2015)","journal-title":"Comput. Secur."},{"key":"18_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.compind.2022.103741","volume":"142","author":"Z Jadidi","year":"2022","unstructured":"Jadidi, Z., Hagemann, J., Quevedo, D.: Multi-step attack detection in industrial control systems using causal analysis. Comput. Ind. 142, 103741 (2022)","journal-title":"Comput. Ind."},{"key":"18_CR16","volume":"54","author":"H Hao","year":"2020","unstructured":"Hao, H., Liu, J., Zhang, Y., Liu, Y., Xiaoyu, X., Tan, J.: Attack scenario reconstruction approach using attack graph and alert data mining. J. Inf. Secur. Appl. 54, 102522 (2020)","journal-title":"J. Inf. Secur. Appl."},{"key":"18_CR17","unstructured":"Qin, X., Lee, W.: Attack plan recognition and prediction using causal networks. In: 20th Annual Computer Security Applications Conference, pp. 370\u2013379. IEEE (2004)"},{"key":"18_CR18","doi-asserted-by":"crossref","unstructured":"Wang, Y., Hallgren, K., Larson, J.: A graph-based framework for reducing false positives in authentication alerts in security systems. In: Companion Proceedings of the ACM Web Conference 2024, pp. 274\u2013283 (2024)","DOI":"10.1145\/3589335.3648325"},{"issue":"2","key":"18_CR19","first-page":"731","volume":"19","author":"A Nadeem","year":"2021","unstructured":"Nadeem, A., Verwer, S., Moskal, S., Yang, S.J.: Alert-driven attack graph generation using S-PDFA. IEEE Trans. Dependable Secure Comput. 19(2), 731\u2013746 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"18_CR20","doi-asserted-by":"crossref","unstructured":"Adanza, D., et al.: Leveraging generative AI for intent-based networking operations in network slices. Comput. Netw. 111647 (2025)","DOI":"10.1016\/j.comnet.2025.111647"},{"key":"18_CR21","doi-asserted-by":"crossref","unstructured":"Du, M., Li, F., Zheng, G., Srikumar, V.: Deeplog: anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, CCS 2017, pp. 1285\u20131298. ACM (2017)","DOI":"10.1145\/3133956.3134015"},{"key":"18_CR22","doi-asserted-by":"crossref","unstructured":"Han, D., et al.: Deepaid: interpreting and improving deep learning-based anomaly detection in security applications. In: CCS 2021: 2021 ACM SIGSAC Conference on Computer and Communications Security, pp. 3197\u20133217. ACM (2021)","DOI":"10.1145\/3460120.3484589"},{"key":"18_CR23","unstructured":"Yang, L., et al.: CADE: detecting and explaining concept drift samples for security applications. In: 30th USENIX Security Symposium, USENIX Security 2021, pp. 2327\u20132344. USENIX Association (2021)"},{"key":"18_CR24","doi-asserted-by":"crossref","unstructured":"Gardella, M., Mus\u00e9, P., Morel, J.M., Colom, M.: Noisesniffer: a fully automatic image forgery detector based on noise analysis. In: 2021 IEEE International Workshop on Biometrics and Forensics (IWBF), pp. 1\u20136 (2021)","DOI":"10.1109\/IWBF50991.2021.9465095"},{"key":"18_CR25","doi-asserted-by":"crossref","unstructured":"Ingale, S., Paraye, M., Ambawade, D.: A survey on methodologies for multi-step attack prediction. In: 2020 Fourth International Conference on Inventive Systems and Control (ICISC), pp. 37\u201345 (2020)","DOI":"10.1109\/ICISC47916.2020.9171106"},{"key":"18_CR26","unstructured":"CyberMonitor. APT cybercriminal campagin collections (2024)"},{"issue":"1","key":"18_CR27","doi-asserted-by":"publisher","first-page":"134","DOI":"10.1109\/TDSC.2017.2751478","volume":"17","author":"P Holgado","year":"2017","unstructured":"Holgado, P., Villagr\u00e1, V.A., Vazquez, L.: Real-time multistep attack prediction based on hidden Markov models. IEEE Trans. Dependable Secure Comput. 17(1), 134\u2013147 (2017)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"18_CR28","doi-asserted-by":"publisher","first-page":"636","DOI":"10.1016\/j.future.2020.03.014","volume":"108","author":"T Chadza","year":"2020","unstructured":"Chadza, T., Kyriakopoulos, K.G., Lambotharan, S.: Analysis of hidden Markov model learning algorithms for the detection and prediction of multi-stage network attacks. Futur. Gener. Comput. Syst. 108, 636\u2013649 (2020)","journal-title":"Futur. Gener. Comput. Syst."},{"issue":"9","key":"18_CR29","first-page":"160","volume":"41","author":"X Zhiyong Luo","year":"2020","unstructured":"Zhiyong Luo, X., Yang, J.L., Rui, X.: Network intrusion intention analysis model based on Bayesian attack graph. J. Commun. 41(9), 160\u2013169 (2020)","journal-title":"J. Commun."},{"key":"18_CR30","unstructured":"Ruff, L., et al.: Deep one-class classification. In: International Conference on Machine Learning, pp. 4393\u20134402. PMLR (2018)"}],"container-title":["Lecture Notes in Computer Science","Computational Science \u2013 ICCS 2026"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-032-29921-5_18","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,6,22]],"date-time":"2026-06-22T20:18:05Z","timestamp":1782159485000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-032-29921-5_18"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9783032299208","9783032299215"],"references-count":30,"URL":"https:\/\/doi.org\/10.1007\/978-3-032-29921-5_18","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"23 June 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICCS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Computational Science","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Hamburg","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Germany","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 June 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"1 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iccs-computsci2026","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/www.iccs-meeting.org\/iccs2026\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}