{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T09:09:32Z","timestamp":1784365772058,"version":"3.55.0"},"publisher-location":"Singapore","reference-count":20,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819234226","type":"print"},{"value":"9789819234233","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,7,19]],"date-time":"2026-07-19T00:00:00Z","timestamp":1784419200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2027]]},"DOI":"10.1007\/978-981-92-3423-3_24","type":"book-chapter","created":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:48:52Z","timestamp":1784364532000},"page":"294-305","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["LLM-Powered Log Text Embedding for Automated Attack Investigation"],"prefix":"10.1007","author":[{"given":"Zheng","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiangliang","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"He","family":"Kong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenzhuo","family":"Cui","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Lisong","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yingying","family":"Du","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yu","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,7,19]]},"reference":[{"key":"24_CR1","unstructured":"Alsaheel, A., et al.: ATLAS: a sequence-based learning approach for attack investigation. In: 30th USENIX security symposium (USENIX security 21), pp. 3005\u20133022 (2021)"},{"issue":"2","key":"24_CR2","doi-asserted-by":"publisher","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","volume":"21","author":"A Alshamrani","year":"2019","unstructured":"Alshamrani, A., Myneni, S., Chowdhary, A., Huang, D.: A survey on advanced persistent threats: techniques, solutions, challenges, and research opportunities. IEEE Commun. Surv. Tutorials 21(2), 1851\u20131877 (2019)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"24_CR3","unstructured":"Ding, H., Zhai, J., Nan, Y., Ma, S.: AIRTAG: towards automated attack investigation by unsupervised learning with log texts. In: 32nd USENIX Security Symposium (USENIX Security 23), pp. 373\u2013390 (2023)"},{"key":"24_CR4","doi-asserted-by":"crossref","unstructured":"Du, M., Li, F., Zheng, G., Srikumar, V.: DeepLog: anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1285\u20131298 (2017)","DOI":"10.1145\/3133956.3134015"},{"key":"24_CR5","doi-asserted-by":"crossref","unstructured":"Gao, T., Yao, X., Chen, D.: SimCSE: Simple contrastive learning of sentence embeddings. arXiv preprint arXiv:2104.08821 (2021)","DOI":"10.18653\/v1\/2021.emnlp-main.552"},{"key":"24_CR6","doi-asserted-by":"crossref","unstructured":"Guo, H., Yuan, S., Wu, X.: LogBERT: Log anomaly detection via BERT. In: 2021 International Joint Conference on Neural Networks (IJCNN), pp. 1\u20138. IEEE (2021)","DOI":"10.1109\/IJCNN52387.2021.9534113"},{"key":"24_CR7","doi-asserted-by":"crossref","unstructured":"Han, X., Pasquier, T., Bates, A., Mickens, J., Seltzer, M.: UNICORN: Runtime provenance-based detector for advanced persistent threats. arXiv preprint arXiv:2001.01525 (2020)","DOI":"10.14722\/ndss.2020.24046"},{"key":"24_CR8","doi-asserted-by":"crossref","unstructured":"Hassan, W.U., Guo, S., Li, D., Chen, Z., Jee, K., Li, Z., Bates, A.: NoDoze: combatting threat alert fatigue with automated provenance triage. In: Network and Distributed Systems Security Symposium (2019)","DOI":"10.14722\/ndss.2019.23349"},{"key":"24_CR9","unstructured":"He, J., Rungta, M., Koleczek, D., Sekhon, A., Wang, F.X., Hasan, S.: Does prompt formatting have any impact on LLM performance? arXiv preprint arXiv:2411.10541 (2024)"},{"key":"24_CR10","doi-asserted-by":"crossref","unstructured":"Inam, M.A., et al.: SoK: history is a vast early warning system: Auditing the provenance of system intrusions. In: 2023 IEEE Symposium on Security and Privacy (SP), pp. 2620\u20132638. IEEE (2023)","DOI":"10.1109\/SP46215.2023.10179405"},{"key":"24_CR11","unstructured":"Jiang, A.Q., et al.: Mistral 7B. ArXiv preprint arXiv:2310.06825 (2023)"},{"key":"24_CR12","unstructured":"King, S.T., Mao, Z.M., Lucchetti, D.G., Chen, P.M.: Enriching intrusion alerts through multi-host causality. In: NDSS (2005)"},{"key":"24_CR13","doi-asserted-by":"crossref","unstructured":"Lin, Y., et al.: Collaborative alert ranking for anomaly detection. In: Proceedings of the 27th ACM International Conference on Information and Knowledge Management, pp. 1987\u20131995 (2018)","DOI":"10.1145\/3269206.3272013"},{"key":"24_CR14","doi-asserted-by":"crossref","unstructured":"Liu, Y., Tao, S., Meng, W., Yao, F., Zhao, X., Yang, H.: LogPrompt: prompt engineering towards zero-shot and interpretable log analysis. In: Proceedings of the 2024 IEEE\/ACM 46th International Conference on Software Engineering: Companion Proceedings, pp. 364\u2013365 (2024)","DOI":"10.1145\/3639478.3643108"},{"key":"24_CR15","doi-asserted-by":"crossref","unstructured":"Reimers, N., Gurevych, I.: Sentence-BERT: Sentence embeddings using siamese BERT-netorks. arXiv preprint arXiv:1908.10084 (2019)","DOI":"10.18653\/v1\/D19-1410"},{"key":"24_CR16","unstructured":"Ruff, L., et al.: Deep one-class classification. In: International conference on machine learning, pp. 4393\u20134402. PMLR (2018)"},{"key":"24_CR17","doi-asserted-by":"crossref","unstructured":"Van Ede, T., et al.: DEEPCASE: semi-supervised contextual analysis of security events. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 522\u2013539. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833671"},{"key":"24_CR18","unstructured":"Wang, L., Yang, N., Huang, X., Yang, L., Majumder, R., Wei, F.: Improving text embeddings with large language models. arXiv preprint arXiv:2401.00368 (2023)"},{"key":"24_CR19","doi-asserted-by":"crossref","unstructured":"Yan, N., et al.: Deepro: provenance-based APT campaigns detection via GNN. In: 2022 IEEE International Conference on Trust, Security and Privacy in Computing and Communications (TrustCom), pp. 747\u2013758. IEEE (2022)","DOI":"10.1109\/TrustCom56396.2022.00106"},{"key":"24_CR20","doi-asserted-by":"crossref","unstructured":"Zengy, J., et al.: ShadeWatcher: recommendation-guided cyber threat analysis using system audit records. In: 2022 IEEE Symposium on Security and Privacy (SP), pp. 489\u2013506. IEEE (2022)","DOI":"10.1109\/SP46214.2022.9833669"}],"container-title":["Lecture Notes in Computer Science","Advanced Intelligent Computing Technology and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-92-3423-3_24","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T08:48:55Z","timestamp":1784364535000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-92-3423-3_24"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,7,19]]},"ISBN":["9789819234226","9789819234233"],"references-count":20,"URL":"https:\/\/doi.org\/10.1007\/978-981-92-3423-3_24","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,7,19]]},"assertion":[{"value":"19 July 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICIC","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Computing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Toronto","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Canada","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2026","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 July 2026","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 July 2026","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icic2026a","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.ic-icc.cn\/2026\/index.htm","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}