{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,3,27]],"date-time":"2025-03-27T02:36:56Z","timestamp":1743043016008,"version":"3.40.3"},"publisher-location":"Singapore","reference-count":19,"publisher":"Springer Nature Singapore","isbn-type":[{"type":"print","value":"9789811982842"},{"type":"electronic","value":"9789811982859"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2022,12,10]],"date-time":"2022-12-10T00:00:00Z","timestamp":1670630400000},"content-version":"vor","delay-in-days":343,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>With the continuous emergence of new network threat means, how to turn passive defense into active prediction, the rise of Cyber Threat Intelligence (CTI) technology provides a new idea. CTI technology can timely and effectively obtain all kinds of network security threat intelligence information to help security personnel quickly identify all kinds of attacks and make effective decisions in time. However, there are not only a large number of redundant information in threat intelligence information, but also the problems of Chinese English mixing, fuzzy boundary, and polysemy of related security entities. Therefore, identifying complex and valuable information from this information has become a great challenge. Through the research on the above problems, a named entity recognition model in the field of Network Threat Intelligence Based on BERT-BiLSTM-Self-Attention-CRF is proposed to identify the complex network threat intelligence entities in the text. Firstly, the dynamic word vector is obtained through Bert to fully represent the semantic information and solve the problem of polysemy of a word. Then the obtained word vector is used as the input of BiLSTM, and the context feature vector is obtained by BiLSTM. Then the output result is introduced into the self-attention mechanism to capture the correlation within the data or features, and finally the result is input into CRF for annotation. To verify the effectiveness of the model, experiments are carried out on the constructed network threat intelligence data set. The results show that the model significantly improves the effect of Threat Intelligence named entity recognition compared with several other classical models.<\/jats:p>","DOI":"10.1007\/978-981-19-8285-9_16","type":"book-chapter","created":{"date-parts":[[2022,12,9]],"date-time":"2022-12-09T20:02:48Z","timestamp":1670616168000},"page":"213-224","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["Research on Named Entity Recognition Method of Network Threat Intelligence"],"prefix":"10.1007","author":[{"given":"Keke","family":"Zhang","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xu","family":"Chen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yongjun","family":"Jing","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Shuyang","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lijun","family":"Tang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2022,12,10]]},"reference":[{"key":"16_CR1","doi-asserted-by":"crossref","unstructured":"Han, X., Li, C., Li, X., Lu, T.: Research on APT attack detection technology based on DenseNet convolutional neural network. In: 2021 International Conference on Computer Information Science and Artificial Intelligence (CISAI), pp. 440\u2013448 (2021)","DOI":"10.1109\/CISAI54367.2021.00091"},{"issue":"4","key":"16_CR2","doi-asserted-by":"publisher","first-page":"111","DOI":"10.1145\/3543146.3543171","volume":"49","author":"D Pujol-Perich","year":"2021","unstructured":"Pujol-Perich, D., Su\u00e1rez-Varela, J., Cabellos-Aparicio, A., et al.: Unveiling the potential of graph neural networks for robust intrusion detection. ACM SIGMETRICS Perf. Eval. Rev. 49(4), 111\u2013117 (2021)","journal-title":"ACM SIGMETRICS Perf. Eval. Rev."},{"issue":"4","key":"16_CR3","doi-asserted-by":"publisher","first-page":"2525","DOI":"10.1109\/COMST.2021.3117338","volume":"23","author":"D Schlette","year":"2021","unstructured":"Schlette, D., Caselli, M., Pernul, G.: A comparative study on cyber threat intelligence: the security incident response perspective. IEEE Commun. Surv. Tutor. 23(4), 2525\u20132556 (2021)","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"3","key":"16_CR4","doi-asserted-by":"publisher","first-page":"102537","DOI":"10.1016\/j.ipm.2021.102537","volume":"58","author":"D Nozza","year":"2021","unstructured":"Nozza, D., Manchanda, P., Fersini, E., et al.: Learning to adapt with word embeddings: domain adaptation of named entity recognition systems. Inf. Process. Manag. 58(3), 102537 (2021)","journal-title":"Inf. Process. Manag."},{"issue":"2","key":"16_CR5","doi-asserted-by":"publisher","first-page":"494","DOI":"10.1109\/TNNLS.2021.3070843","volume":"33","author":"S Ji","year":"2022","unstructured":"Ji, S., Pan, S., Cambria, E., Marttinen, P., Yu, P.S.: A survey on knowledge graphs: representation, acquisition, and applications. IEEE Trans. Neural Netw. Learn. Syst. 33(2), 494\u2013514 (2022)","journal-title":"IEEE Trans. Neural Netw. Learn. Syst."},{"key":"16_CR6","doi-asserted-by":"crossref","unstructured":"Mulwad, V., Li, W., Joshi, A., et al.: Extracting information about security vulnerabilities from web text. In: 2011 IEEE\/WIC\/ACM International Conferences on Web Intelligence and Intelligent Agent Technology, pp. 257\u2013260 (2011)","DOI":"10.1109\/WI-IAT.2011.26"},{"key":"16_CR7","doi-asserted-by":"crossref","unstructured":"Joshi, A., Lal, R., Finin, T., et al.: Extracting cybersecurity-related linked data from tex. In: 2013 IEEE Seventh International Conference on Semantic Computing, pp. 252\u2013259 (2013)","DOI":"10.1109\/ICSC.2013.50"},{"key":"16_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1007\/978-3-319-17040-4_24","volume-title":"Foundations and Practice of Security","author":"S Weerawardhana","year":"2015","unstructured":"Weerawardhana, S., Mukherjee, S., Ray, I., Howe, A.: Automated extraction of vulnerability information for home computer security. In: Cuppens, F., Garcia-Alfaro, J., Zincir Heywood, N., Fong, P.W.L. (eds.) FPS 2014. LNCS, vol. 8930, pp. 356\u2013366. Springer, Cham (2015). https:\/\/doi.org\/10.1007\/978-3-319-17040-4_24"},{"key":"16_CR9","doi-asserted-by":"crossref","unstructured":"Zhao, Q., Sun, J., Ren, H., Sun, G.: Machine-learning based TCP security action prediction. In: 2020 5th International Conference on Mechanical, Control and Computer Engineering (ICMCCE), pp. 1329\u20131333 (2020)","DOI":"10.1109\/ICMCCE51767.2020.00291"},{"issue":"3","key":"16_CR10","doi-asserted-by":"publisher","first-page":"259","DOI":"10.26599\/TST.2019.9010033","volume":"26","author":"P Ma","year":"2020","unstructured":"Ma, P., Jiang, B., Lu, Z., et al.: Cybersecurity named entity recognition using bidirectional long short-term memory with conditional random fields. Tsinghua Sci. Technol. 26(3), 259\u2013265 (2020)","journal-title":"Tsinghua Sci. Technol."},{"key":"16_CR11","doi-asserted-by":"crossref","unstructured":"Wu, H., Li, X., Gao, Y.: An effective approach of named entity recognition for cyber threat intelligence. In: 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC), pp. 1370\u20131374 (2020)","DOI":"10.1109\/ITNEC48623.2020.9085102"},{"issue":"6","key":"16_CR12","doi-asserted-by":"publisher","first-page":"872","DOI":"10.1631\/FITEE.1800520","volume":"20","author":"Y Qin","year":"2019","unstructured":"Qin, Y., Shen, G.-W., Zhao, W., Chen, Y.-P., Yu, M., Jin, X.: A network security entity recognition method based on feature template and CNN-BiLSTM-CRF. Front. Inf. Technol. Electron. Eng. 20(6), 872\u2013884 (2019). https:\/\/doi.org\/10.1631\/FITEE.1800520","journal-title":"Front. Inf. Technol. Electron. Eng."},{"key":"16_CR13","doi-asserted-by":"crossref","unstructured":"Li, T., Guo, Y., Ju, A.: A self-attention-based approach for named entity recognition in cybersecurity. In: 2019 15th International Conference on Computational Intelligence and Security (CIS), pp. 147\u2013150 (2019)","DOI":"10.1109\/CIS.2019.00039"},{"issue":"9","key":"16_CR14","first-page":"8","volume":"56","author":"H Zhang","year":"2019","unstructured":"Zhang, H., Guo, Y., Li, T.: Domain named entity recognition combining Gan and BiLSTM-Attention-CRF. Comput. Res. Dev. 56(9), 8 (2019)","journal-title":"Comput. Res. Dev."},{"key":"16_CR15","doi-asserted-by":"crossref","unstructured":"Evangelatos, P., et al.: Named entity recognition in cyber threat intelligence using transformer-based models. In: 2021 IEEE International Conference on Cyber Security and Resilience (CSR), pp. 348\u2013353 (2021)","DOI":"10.1109\/CSR51186.2021.9527981"},{"key":"16_CR16","doi-asserted-by":"crossref","unstructured":"Wang, X., et al.: DNRTI: a large-scale dataset for named entity recognition in threat intelligence. In: 2020 IEEE 19th International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 1842\u20131848 (2020)","DOI":"10.1109\/TrustCom50675.2020.00252"},{"key":"16_CR17","unstructured":"Devlin, J., Chang, M.W., Lee, K., et al.: BERT: pre-training of deep bidirectional transformers for language understanding (2018)"},{"key":"16_CR18","doi-asserted-by":"crossref","unstructured":"Ren, F., Jiang, Z., Liu, J.: A bi-directional LSTM model with attention for malicious URL detection. In: 2019 IEEE 4th Advanced Information Technology, Electronic and Automation Control Conference (IAEAC), pp. 300\u2013305 (2019)","DOI":"10.1109\/IAEAC47372.2019.8997947"},{"key":"16_CR19","doi-asserted-by":"crossref","unstructured":"Pennington, J., Socher, R., Manning, C.: Glove: global vectors for word representation. In: Conference on Empirical Methods in Natural Language Processing (2014)","DOI":"10.3115\/v1\/D14-1162"}],"container-title":["Communications in Computer and Information Science","Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-19-8285-9_16","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,12,24]],"date-time":"2022-12-24T00:04:40Z","timestamp":1671840280000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-19-8285-9_16"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9789811982842","9789811982859"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-981-19-8285-9_16","relation":{},"ISSN":["1865-0929","1865-0937"],"issn-type":[{"type":"print","value":"1865-0929"},{"type":"electronic","value":"1865-0937"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"10 December 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"CNCERT","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China Cyber Security Annual Conference","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"16 August 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 August 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"cncert2022","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/conf.cert.org.cn","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}