{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T21:02:15Z","timestamp":1784408535593,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":24,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819234028","type":"print"},{"value":"9789819234035","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-3403-5_33","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T20:08:26Z","timestamp":1784405306000},"page":"417-433","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["MDFA: LLM-Based Multi-dimensional Fusion Reasoning for Threat Actor Attribution"],"prefix":"10.1007","author":[{"given":"Nan","family":"Xiao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Bo","family":"Lang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tan","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuxing","family":"Long","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Huishu","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yikai","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nan","family":"Hu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jie","family":"Jiao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yi","family":"Wei","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,19]]},"reference":[{"key":"33_CR1","first-page":"1","volume":"298","author":"S Caltagirone","year":"2013","unstructured":"Caltagirone, S., Pendergast, A., Betz, C.: The diamond model of intrusion analysis. Threat Connect. 298, 1\u201361 (2013)","journal-title":"Threat Connect."},{"key":"33_CR2","doi-asserted-by":"publisher","first-page":"4","DOI":"10.1080\/01402390.2014.977382","volume":"38","author":"T Rid","year":"2015","unstructured":"Rid, T., Buchanan, B.: Attributing cyber attacks. J. Strateg. Stud. 38, 4\u201337 (2015)","journal-title":"J. Strateg. Stud."},{"issue":"8","key":"33_CR3","first-page":"1","volume":"3","author":"F Skopik","year":"2020","unstructured":"Skopik, F., Pahi, T.: Under false flag: using technical artifacts for cyber attack attribution. Cybersecurity. 3(8), 1\u201320 (2020)","journal-title":"Cybersecurity"},{"key":"33_CR4","series-title":"Intrusions and Defenses (RAID 2024)","first-page":"114","volume-title":"Research in Attacks","author":"A Saha","year":"2024","unstructured":"Saha, A., Blasco, J., Cavallaro, L., Lindorfer, M.: ADAPT it! automating APT campaign and group attribution by leveraging and linking heterogeneous files. In: Research in Attacks Intrusions and Defenses (RAID 2024), pp. 114\u2013129. ACM, New York (2024)"},{"key":"33_CR5","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103862","volume":"142","author":"G Shenderovitz","year":"2024","unstructured":"Shenderovitz, G., Nissim, N.: Bon-APT: detection, attribution, and explainability of APT malware using temporal segmentation of API calls. Comput. Secur. 142, 103862 (2024)","journal-title":"Comput. Secur."},{"key":"33_CR6","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"78","DOI":"10.1007\/978-3-031-63749-0_6","volume-title":"Computational Science \u2013 ICCS 2024","author":"R Jing","year":"2024","unstructured":"Jing, R., Jiang, Z., Wang, Q., Wang, S., Li, H., Chen, X.: From fine-grained to refined: apt malware knowledge graph construction and attribution analysis driven by multi-stage graph computation. In: Computational Science \u2013 ICCS 2024 Lecture Notes in Computer Science, vol. 14832, pp. 78\u201393. Springer, Cham (2024)"},{"key":"33_CR7","doi-asserted-by":"publisher","first-page":"1024","DOI":"10.1109\/TDSC.2024.3418958","volume":"22","author":"Y Sun","year":"2025","unstructured":"Sun, Y., Chen, S., Lin, S., Sun, A., Long, S., Li, Z.: MGAP3: Malware group attribution based on PerceiverIO and polytype pre-training. IEEE Trans. Dependable Secure Comput. 22, 1024\u20131039 (2025)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"33_CR8","unstructured":"Choi, S., et al.: I can find you in seconds! leveraging large language models for code authorship attribution. arXiv preprint arXiv:2501.08165. https:\/\/arxiv.org\/abs\/2501.08165 (2025)"},{"key":"33_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103960","volume":"144","author":"N Xiao","year":"2024","unstructured":"Xiao, N., Lang, B., Wang, T., Chen, Y.: APT-MMF: an advanced persistent threat actor attribution method based on multimodal and multilevel feature fusion. Comput. Secur. 144, 103960 (2024)","journal-title":"Comput. Secur."},{"key":"33_CR10","doi-asserted-by":"publisher","first-page":"1207","DOI":"10.1109\/ICDE65448.2025.00095","volume-title":"2025 IEEE 41st International Conference on Data Engineering (ICDE)","author":"IJ King","year":"2025","unstructured":"King, I.J., Ramirez, R., Bowman, B., Huang, H.H.: Trail: a knowledge graph-based approach for attributing advanced persistent threats. In: 2025 IEEE 41st International Conference on Data Engineering (ICDE), pp. 1207\u20131220. IEEE Computer Society, Los Alamitos (2025)"},{"key":"33_CR11","doi-asserted-by":"crossref","unstructured":"Xiao, N., Lang, B., Chen, Y., Zhao, S., Yan, Y.: TAA-EPLMR: threat actor attribution via evidence path-enhanced large language model reasoning. In: 2025 IEEE International Conference on Big Data (BigData), pp. 2064\u20132073 (2025)","DOI":"10.1109\/BigData66926.2025.11402113"},{"issue":"3","key":"33_CR12","doi-asserted-by":"publisher","first-page":"381","DOI":"10.1080\/19393555.2025.2543450","volume":"35","author":"N Rani","year":"2025","unstructured":"Rani, N., Saha, B., Maurya, V., Shukla, S.K.: Decoding shadows: towards tactics, techniques, and procedures (TTP)-based advanced persistent threat (APT) attribution. Inf. Secur. J. Glob. Perspect. 35(3), 381\u2013408 (2025)","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"33_CR13","series-title":"vol 613","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1007\/978-3-031-89363-6_10","volume-title":"Digital Forensics and Cyber Crime","author":"Y Zhang","year":"2025","unstructured":"Zhang, Y., Yang, P., Jiang, Z., Ma, C., Cui, M., You, Y.: APTChaser: cyber threat attribution via attack technique modeling. In: Digital Forensics and Cyber Crime vol 613, pp. 168\u2013185. Springer, Cham (2025)"},{"key":"33_CR14","doi-asserted-by":"publisher","first-page":"1065","DOI":"10.1016\/j.icte.2023.05.008","volume":"9","author":"I Lee","year":"2023","unstructured":"Lee, I., Choi, C.: Camp2Vec: embedding cyber campaign with ATT&CK framework for attack group analysis. ICT Express. 9, 1065\u20131070 (2023)","journal-title":"ICT Express"},{"key":"33_CR15","doi-asserted-by":"publisher","first-page":"6162","DOI":"10.1109\/TIFS.2025.3578233","volume":"20","author":"I Lee","year":"2025","unstructured":"Lee, I., Choi, C.: MuCamp: generating cyber campaign variants via TTP synonym replacement for group attribution. IEEE Trans. Inf. Forensics Secur. 20, 6162\u20136174 (2025)","journal-title":"IEEE Trans. Inf. Forensics Secur."},{"key":"33_CR16","doi-asserted-by":"crossref","unstructured":"Sachidananda, V., Patil, R., Sachdeva, A., Lam, K.Y., Yang, L.: APTer: towards the investigation of APT attribution. In: 2023 IEEE Conference on Dependable and Secure Computing (DSC). pp. 1\u201310 (2023)","DOI":"10.1109\/DSC61021.2023.10354155"},{"issue":"3","key":"33_CR17","doi-asserted-by":"publisher","first-page":"553","DOI":"10.1016\/j.icte.2024.04.005","volume":"10","author":"E Irshad","year":"2024","unstructured":"Irshad, E., Siddiqui, A.B.: Context-aware cyber-threat attribution based on hybrid features. ICT Express. 10(3), 553\u2013369 (2024)","journal-title":"ICT Express"},{"key":"33_CR18","series-title":"ESORICS 2024 International Workshops","first-page":"238","volume-title":"Computer Security","author":"S Rajapaksha","year":"2025","unstructured":"Rajapaksha, S., Rani, R., Karafili, E.: A RAG-based question-answering solution for cyber-attack investigation and attribution. In: Computer Security ESORICS 2024 International Workshops, pp. 238\u2013256. Springer, Berlin (2025)"},{"key":"33_CR19","volume-title":"MITRE ATT&CK: Design and Philosophy","author":"BE Strom","year":"2020","unstructured":"Strom, B.E., Applebaum, A., Miller, D.P., Nickels, K.C., Pennington, A.G., Thomas, C.B.: MITRE ATT&CK: Design and Philosophy. The MITRE Corporation, Bedford (2020)"},{"key":"33_CR20","doi-asserted-by":"crossref","unstructured":"Saha, A., Lindorfer, M., Caballero, J.: Kitten or Panda? Measuring the specificity of threat group behaviors in public CTI knowledge bases. arXiv preprint arXiv:2506.10645. https:\/\/arxiv.org\/abs\/2506.10645 (2025)","DOI":"10.1145\/3779208.3786258"},{"key":"33_CR21","volume-title":"STIX Version 2.1","author":"B Jordan","year":"2021","unstructured":"Jordan, B., Piazza, R., Darley, T.: STIX Version 2.1. OASIS Open, Burlington (2021)"},{"key":"33_CR22","volume-title":"Intelligence Community Directive 203: Analytic Standards","author":"Office of the Director of National Intelligence","year":"2015","unstructured":"Office of the Director of National Intelligence: Intelligence Community Directive 203: Analytic Standards. Office of the Director of National Intelligence, McLean (2015)"},{"key":"33_CR23","unstructured":"cyber-research: APT malware dataset. GitHub repository. https:\/\/github.com\/cyber-research\/APTMalware. Accessed 7 May 2026"},{"key":"33_CR24","unstructured":"Cherepanov, A., K\u00e1lnai, P.: Lazarus supply-chain attack in South Korea. WeLiveSecurity, ESET Research. https:\/\/www.welivesecurity.com\/2020\/11\/16\/lazarus-supply-chain-attack-south-korea\/ (2020). Accessed 7 May 2026"}],"container-title":["Lecture Notes in Computer Science","Advanced Intelligent Computing Technology and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3403-5_33","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T20:08:29Z","timestamp":1784405309000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3403-5_33"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,19]]},"ISBN":["9789819234028","9789819234035"],"references-count":24,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3403-5_33","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,19]]},"assertion":[{"value":"19 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toronto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icic2026a","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ic-icc.cn\/2026\/index.htm","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}