{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T03:16:42Z","timestamp":1782875802973,"version":"3.54.5"},"publisher-location":"Singapore","reference-count":40,"publisher":"Springer Nature Singapore","isbn-type":[{"value":"9789819541546","type":"print"},{"value":"9789819541553","type":"electronic"}],"license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026]]},"DOI":"10.1007\/978-981-95-4155-3_33","type":"book-chapter","created":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T07:59:32Z","timestamp":1767340772000},"page":"473-488","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":1,"title":["CyberLLM: Enable Mapping CVE to\u00a0Tactics and\u00a0Techniques of\u00a0Cyber Threats via\u00a0LLM"],"prefix":"10.1007","author":[{"given":"Ziming","family":"Zhao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhaoxuan","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tingting","family":"Li","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Fan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,1,3]]},"reference":[{"key":"33_CR1","volume-title":"Cyber threat intelligence\u2013issue and challenges","author":"S Abu","year":"2018","unstructured":"Abu, S., et al.: Cyber threat intelligence\u2013issue and challenges. Indonesian J. Electr. Eng. Comput, Sci (2018)"},{"key":"33_CR2","unstructured":"Ampel, B., et\u00a0al.: Linking common vulnerabilities and exposures to the mitre ATT &CK framework: a self-distillation approach. arXiv arXiv:2108.01696 (2021)"},{"key":"33_CR3","doi-asserted-by":"crossref","unstructured":"Atre, N., et\u00a0al.: Surgeprotector: mitigating temporal algorithmic complexity attacks using adversarial scheduling. In: SIGCOMM, pp. 723\u2013738. ACM (2022)","DOI":"10.1145\/3544216.3544250"},{"key":"33_CR4","doi-asserted-by":"crossref","unstructured":"Bozorgi, M., et\u00a0al.: Beyond heuristics: learning to classify vulnerabilities and predict exploits. In: ACM KDD (2010)","DOI":"10.1145\/1835804.1835821"},{"key":"33_CR5","doi-asserted-by":"crossref","unstructured":"Brown, S., et\u00a0al.: From cyber security information sharing to threat management. In: WISCS@CCS. ACM (2015)","DOI":"10.1145\/2808128.2808133"},{"key":"33_CR6","doi-asserted-by":"crossref","unstructured":"Chen, T., et\u00a0al.: XGBoost: a scalable tree boosting system. In: KDD. ACM (2016)","DOI":"10.1145\/2939672.2939785"},{"key":"33_CR7","unstructured":"Chen, T., et\u00a0al.: The lottery ticket hypothesis for pre-trained BERT networks. In: NeurIPS (2020)"},{"key":"33_CR8","unstructured":"Doersch, C.: Tutorial on variational autoencoders. arXiv arXiv:1606.05908 (2016)"},{"key":"33_CR9","doi-asserted-by":"crossref","unstructured":"Gao, P., et\u00a0al.: Enabling efficient cyber threat hunting with cyber threat intelligence. In: ICDE. IEEE (2021)","DOI":"10.1109\/ICDE51399.2021.00024"},{"key":"33_CR10","doi-asserted-by":"publisher","DOI":"10.1145\/3422622","volume-title":"Generative adversarial networks","author":"I Goodfellow","year":"2020","unstructured":"Goodfellow, I., et al.: Generative adversarial networks. ACM, Commun (2020)"},{"key":"33_CR11","doi-asserted-by":"crossref","unstructured":"Grigorescu, O., et\u00a0al.: CVE2ATT &CK: bert-based mapping of CVES to mitre ATT &CK techniques. Algorithms (2022)","DOI":"10.3390\/a15090314"},{"key":"33_CR12","unstructured":"Hanna, M., et\u00a0al.: How does GPT-2 compute greater-than?: interpreting mathematical abilities in a pre-trained language model. In: NeurIPS (2023)"},{"key":"33_CR13","unstructured":"Ji, H., et\u00a0al.: SEvenLLM: benchmarking, eliciting, and enhancing abilities of large language models in cyber threat intelligence. arXiv arXiv:2405.03446 (2024)"},{"key":"33_CR14","doi-asserted-by":"publisher","unstructured":"Kiesling, E., Ekelhart, A., Kurniawan, K., Ekaputra, F.: The SEPSES knowledge graph: an integrated resource for cybersecurity. In: Ghidini, C., et al. (eds.) The Semantic Web\u2013ISWC 2019. ISWC 2019. Lecture Notes in Computer Science, vol. 11779. Springer, Cham (2019). https:\/\/doi.org\/10.1007\/978-3-030-30796-7_13","DOI":"10.1007\/978-3-030-30796-7_13"},{"key":"33_CR15","doi-asserted-by":"crossref","unstructured":"Kuppa, A., et\u00a0al.: Linking CVE\u2019s to MITRE ATT &CK techniques. In: ARES (2021)","DOI":"10.1145\/3465481.3465758"},{"key":"33_CR16","doi-asserted-by":"crossref","unstructured":"Li, L., et\u00a0al.: An automated alert cross-verification system with graph neural networks for ids events. In: CSCWD. IEEE (2024)","DOI":"10.1109\/CSCWD61410.2024.10580010"},{"key":"33_CR17","doi-asserted-by":"crossref","unstructured":"Li, Z., et\u00a0al.: AttacKG: constructing technique knowledge graph from cyber threat intelligence reports. In: ESORICS. Springer (2022)","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"33_CR18","volume-title":"metaNet: interpretable unknown mobile malware identification with a novel meta-features mining algorithm","author":"Z Li","year":"2024","unstructured":"Li, Z., et al.: metaNet: interpretable unknown mobile malware identification with a novel meta-features mining algorithm. Comput, Netw (2024)"},{"key":"33_CR19","doi-asserted-by":"publisher","unstructured":"Ling, X., et al.: DDoSMiner: an automated framework for DDoS attack characterization and vulnerability mining. In: P pper, C., Batina, L. (eds.) Applied Cryptography and Network Security. ACNS 2024. Lecture Notes in Computer Science, vol. 14584. Springer, Cham (2024). https:\/\/doi.org\/10.1007\/978-3-031-54773-7_12","DOI":"10.1007\/978-3-031-54773-7_12"},{"key":"33_CR20","unstructured":"Liu, Y., et\u00a0al.: Roberta: a robustly optimized BERT pretraining approach. CoRR arXiv:1907.11692 (2019)"},{"key":"33_CR21","doi-asserted-by":"crossref","unstructured":"Liu, Y., et\u00a0al.: CacheGen: KV cache compression and streaming for fast large language model serving. In: SIGCOMM. ACM (2024)","DOI":"10.1145\/3651890.3672274"},{"key":"33_CR22","doi-asserted-by":"crossref","unstructured":"Lu, J., Huang, S.: PR-GNN: enhancing PoC report recommendation with graph neural network. In: ICDE. IEEE (2024)","DOI":"10.1109\/ICDE60146.2024.00451"},{"key":"33_CR23","unstructured":"Mendsaikhan, O., et\u00a0al.: Automatic mapping of vulnerability information to adversary techniques. In: SECURWARE (2020)"},{"key":"33_CR24","doi-asserted-by":"crossref","unstructured":"Park, Y., et\u00a0al.: A pretrained language model for cyber threat intelligence (2023)","DOI":"10.18653\/v1\/2023.emnlp-industry.12"},{"key":"33_CR25","unstructured":"Prokhorenkova, L.O., et\u00a0al.: CatBoost: unbiased boosting with categorical features. In: NeurIPS (2018)"},{"key":"33_CR26","doi-asserted-by":"crossref","unstructured":"Read, J., et\u00a0al.: Classifier chains: a review and perspectives. In: JAIR (2021)","DOI":"10.1613\/jair.1.12376"},{"key":"33_CR27","unstructured":"Ribeiro, M.T., et\u00a0al.: Model-agnostic interpretability of machine learning. CoRR arXiv:1606.05386 (2016)"},{"key":"33_CR28","doi-asserted-by":"crossref","unstructured":"Song, Z., et\u00a0al.: I2RNN: an incremental and interpretable recurrent neural network for encrypted traffic classification. In: IEEE TDSC (2023)","DOI":"10.1109\/TDSC.2023.3245411"},{"key":"33_CR29","unstructured":"Strom, B.E., et\u00a0al.: Mitre ATT &CK: design and philosophy. Technical report. The MITRE Corporation (2018)"},{"key":"33_CR30","doi-asserted-by":"crossref","unstructured":"Sun, T., et\u00a0al.: An automatic generation approach of the cyber threat intelligence records based on multi-source information fusion. Future Internet (2021)","DOI":"10.3390\/fi13020040"},{"key":"33_CR31","volume-title":"Cybersecurity for critical infrastructures: attack and defense modeling","author":"C Ten","year":"2010","unstructured":"Ten, C., et al.: Cybersecurity for critical infrastructures: attack and defense modeling. IEEE Trans. Syst. Man Cybern, Part A (2010)"},{"key":"33_CR32","doi-asserted-by":"crossref","unstructured":"Vig, J.: A multiscale visualization of attention in the transformer model. arXiv arXiv:1906.05714 (2019)","DOI":"10.18653\/v1\/P19-3007"},{"key":"33_CR33","doi-asserted-by":"crossref","unstructured":"Wei, J.W., et\u00a0al.: EDA: easy data augmentation techniques for boosting performance on text classification tasks. EMNLP\/IJCNLP (1) (2019)","DOI":"10.18653\/v1\/D19-1670"},{"key":"33_CR34","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-021-00898-7","volume-title":"Cyber security threat modeling based on the MITRE enterprise ATT &CK matrix","author":"W Xiong","year":"2022","unstructured":"Xiong, W., et al.: Cyber security threat modeling based on the MITRE enterprise ATT &CK matrix. Softw. Syst, Model (2022)"},{"key":"33_CR35","unstructured":"Zhao, Z., et\u00a0al.: ERNN: error-resilient RNN for encrypted traffic detection towards network-induced phenomena. In: IEEE TDSC (2023)"},{"key":"33_CR36","doi-asserted-by":"crossref","unstructured":"Zhao, Z., et\u00a0al.: DDoS family: a novel perspective for massive types of DDoS attacks. Comput. Secur. (2024)","DOI":"10.1016\/j.cose.2023.103663"},{"key":"33_CR37","doi-asserted-by":"crossref","unstructured":"Zhao, Z., et\u00a0al.: Effective DDoS mitigation via ML-driven in-network traffic shaping. In: IEEE TDSC (2024)","DOI":"10.1109\/TDSC.2023.3349180"},{"key":"33_CR38","doi-asserted-by":"crossref","unstructured":"Zhao, Z., et\u00a0al.: FOSS: towards fine-grained unknown class detection against the open-set attack spectrum with variable legitimate traffic. In: IEEE\/ACM ToN (2024)","DOI":"10.1109\/TNET.2024.3413789"},{"key":"33_CR39","doi-asserted-by":"crossref","unstructured":"Zhao, Z., et\u00a0al.: Trident: a universal framework for fine-grained and class-incremental unknown traffic detection. In: ACM WWW (2024)","DOI":"10.1145\/3589334.3645407"},{"key":"33_CR40","doi-asserted-by":"crossref","unstructured":"Zhong, Q., et\u00a0al.: Knowledge graph augmented network towards multiview representation learning for aspect-based sentiment analysis. In: IEEE TKDE (2023)","DOI":"10.1109\/TKDE.2023.3250499"}],"container-title":["Lecture Notes in Computer Science","Database Systems for Advanced Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-981-95-4155-3_33","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,1,2]],"date-time":"2026-01-02T07:59:38Z","timestamp":1767340778000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-981-95-4155-3_33"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"ISBN":["9789819541546","9789819541553"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-981-95-4155-3_33","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]},"assertion":[{"value":"3 January 2026","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"DASFAA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Database Systems for Advanced Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Singapore","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2025","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"26 May 2025","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"29 May 2025","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"30","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"dasfaa2025","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"https:\/\/dasfaa2025.github.io","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}}]}}