{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,26]],"date-time":"2026-07-26T06:33:13Z","timestamp":1785047593733,"version":"3.55.0"},"reference-count":84,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T00:00:00Z","timestamp":1753142400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T00:00:00Z","timestamp":1753142400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Knowl Inf Syst"],"published-print":{"date-parts":[[2025,10]]},"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>Cyberthreat intelligence (CTI) reports on past cyberattacks describe the sequence of actions of attackers in terms of time. The sequence contains temporal relations among attack actions, such as <jats:italic>a malware is first downloaded and then executed<\/jats:italic>. Information related to temporal relations enables cybersecurity practitioners to investigate past cyberattack incidents and analyze attackers\u2019 behavior. However, cybersecurity practitioners must extract such information automatically, in a structured manner, through a common vocabulary to reduce human effort and enable sharing, and collaboration. <jats:italic>The goal of this paper is to aid security practitioners in proactive defense against attacks by automatic information extraction of temporal relations among attack actions from cyberthreat intelligence reports<\/jats:italic>. We propose <jats:bold>ChronoCTI<\/jats:bold>, an automated pipeline for extracting temporal relations among attack actions from CTI reports. The attack actions are represented as MITRE ATT&amp;CK techniques, and the relations are represented as a knowledge graph. To construct <jats:bold>ChronoCTI<\/jats:bold>, we build a ground truth dataset of temporal relations and apply large language models, natural language processing, and machine learning techniques. <jats:bold>ChronoCTI<\/jats:bold> demonstrates higher precision but lower recall performance on a real-world dataset of 94 CTI reports. We apply <jats:bold>ChronoCTI<\/jats:bold> on a set of 713 CTI reports, where we identify 9 categories of temporal attack patterns consisting of 124 temporal attack patterns. We identify that the most prevalent pattern category is to trick victim users into executing malicious code to initiate the attack, followed by bypassing the anti-malware system in the victim software systems. Based on the observed patterns, we advocate for training users about cybersecurity best practices, introducing appropriate warning messages for end-users, introducing immutable operating systems, and enforcing multi-user authentications. Moreover, we advocate that practitioners leverage the automated mining capability of <jats:bold>ChronoCTI<\/jats:bold> and design countermeasures against recurring attack patterns.<\/jats:p>","DOI":"10.1007\/s10115-025-02491-6","type":"journal-article","created":{"date-parts":[[2025,7,22]],"date-time":"2025-07-22T08:03:19Z","timestamp":1753171399000},"page":"8941-8981","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Mining temporal attack patterns from cyberthreat intelligence reports"],"prefix":"10.1007","volume":"67","author":[{"given":"Md Rayhanur","family":"Rahman","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brandon","family":"Wroblewski","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Quinn","family":"Matthews","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Brantley","family":"Morgan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Timothy","family":"Menzies","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Laurie","family":"Williams","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,7,22]]},"reference":[{"key":"2491_CR1","unstructured":"Muggah R, Margolis M (2023) Cybercrime To Cost The World 10.5 Trillion Annually By 2025. https:\/\/www.weforum.org\/agenda\/2023\/01\/global-rules-crack-down-cybercrime\/"},{"key":"2491_CR2","doi-asserted-by":"crossref","unstructured":"Ren Y, Xiao Y, Zhou Y, Zhang Z, Tian Z (2022) Cskg4apt: A cybersecurity knowledge graph for advanced persistent threat organization attribution. IEEE Transactions on Knowledge and Data Engineering","DOI":"10.1109\/TKDE.2022.3175719"},{"issue":"12","key":"2491_CR3","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3571726","volume":"55","author":"MR Rahman","year":"2023","unstructured":"Rahman MR, Hezaveh RM, Williams L (2023) What are the attackers doing now? automating cyberthreat intelligence extraction from text on pace with the changing threat landscape: A survey. ACM Computing Surveys 55(12):1\u201336","journal-title":"ACM Computing Surveys"},{"key":"2491_CR4","unstructured":"McMillan R (2013) Definition: threat intelligence. https:\/\/www.gartner.com\/en\/documents\/2487216"},{"key":"2491_CR5","unstructured":"Biancho D (2014) The Pyramid of Pain. http:\/\/detect-respond.blogspot.com\/2013\/03\/the-pyramid-of-pain.html"},{"key":"2491_CR6","unstructured":"Collect, Exfiltrate, Sleep, Repeat. https:\/\/thedfirreport.com\/2023\/02\/06\/collect-exfiltrate-sleep-repeat\/ (2014)"},{"key":"2491_CR7","unstructured":"IcedID Macro Ends in Nokoyawa Ransomware. https:\/\/thedfirreport.com\/2023\/05\/22\/icedid-macro-ends-in-nokoyawa-ransomware\/ (2014)"},{"key":"2491_CR8","unstructured":"Ryuk\u2019s Return. https:\/\/thedfirreport.com\/2020\/10\/08\/ryuks-return\/ (2014)"},{"key":"2491_CR9","unstructured":"MITRE ATT &CK. https:\/\/attack.mitre.org (2022)"},{"key":"2491_CR10","unstructured":"tactics, techniques, and procedures (TTP). https:\/\/csrc.nist.gov\/glossary\/term\/tactics_techniques_and_procedures (2022)"},{"key":"2491_CR11","unstructured":"What are Tactics, Techniques, and Procedures (TTPs)? https:\/\/www.feroot.com\/education-center\/what-are-tactics-techniques-and-procedures-ttps\/ (2022)"},{"key":"2491_CR12","unstructured":"Credential Access Tactic TA0006 - Enterprise | MITRE ATT &CK. https:\/\/attack.mitre.org\/tactics\/TA0006\/ (2022)"},{"key":"2491_CR13","volume-title":"Mitre att &ck: Design and philosophy","author":"B Strom","year":"2020","unstructured":"Strom B, Applebaum A, Miller D, Nickels K, Pennington A, Thomas C (2020) Mitre att &ck: Design and philosophy. Technical report, MITRE"},{"key":"2491_CR14","unstructured":"Input capture T1056 - Enterprise | MITRE ATT &CK. https:\/\/attack.mitre.org\/techniques\/T1056\/ (2022)"},{"key":"2491_CR15","unstructured":"FlawedAmmyy | Software 0381 | MITRE ATT &CK. https:\/\/attack.mitre.org\/software\/S0381\/ (2022)"},{"key":"2491_CR16","first-page":"28","volume":"3","author":"J Pustejovsky","year":"2003","unstructured":"Pustejovsky J, Castano JM, Ingria R, Sauri R, Gaizauskas RJ, Setzer A, Katz G, Radev DR (2003) Timeml: Robust specification of event and temporal expressions in text. New directions in question answering 3:28\u201334","journal-title":"New directions in question answering"},{"key":"2491_CR17","unstructured":"TimeML Markup Language for Temporal and Event Expressions. https:\/\/timeml.github.io\/site\/publications\/timeMLdocs\/annguide_1.2.1.pdf"},{"key":"2491_CR18","unstructured":"Pustejovsky J, Hanks P, Sauri R, See A, Gaizauskas R, Setzer A, Radev D, Sundheim B, Day D, Ferro L (2003) The timebank corpus. In: Corpus Linguistics, vol. 2003, p. 40. Lancaster, UK"},{"key":"2491_CR19","unstructured":"UzZaman N, Llorens H, Derczynski L, Allen J, Verhagen M, Pustejovsky J (2013) Semeval-2013 task 1: Tempeval-3: Evaluating time expressions, events, and temporal relations. In: Second Joint Conference on Lexical and Computational Semantics (* SEM), Volume 2: Proceedings of the Seventh International Workshop on Semantic Evaluation (SemEval 2013), pp. 1\u20139"},{"key":"2491_CR20","unstructured":"Verhagen M, Pustejovsky J (2008) Temporal processing with the tarsqi toolkit. In: COLING 2008: Companion Volume: Demonstrations, pp. 189\u2013192"},{"key":"2491_CR21","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1162\/tacl_a_00182","volume":"2","author":"N Chambers","year":"2014","unstructured":"Chambers N, Cassidy T, McDowell B, Bethard S (2014) Dense event ordering with a multi-pass architecture. Transactions of the Association for Computational Linguistics 2:273\u2013284","journal-title":"Transactions of the Association for Computational Linguistics"},{"key":"2491_CR22","unstructured":"Mirza P, Tonelli S (2016) Catena: Causal and temporal relation extraction from natural language texts. In: The 26th International Conference on Computational Linguistics, pp. 64\u201375. ACL"},{"key":"2491_CR23","unstructured":"Bethard S (2013) ClearTK-TimeML: A minimalist approach to TempEval 2013. In: Manandhar, S., Yuret, D. (eds.) Second Joint Conference on Lexical and Computational Semantics (*SEM), Volume 2: Proceedings of the Seventh International Workshop on Semantic Evaluation (SemEval 2013), pp. 10\u201314. Association for Computational Linguistics, Atlanta, Georgia, USA. https:\/\/aclanthology.org\/S13-2002"},{"key":"2491_CR24","unstructured":"Ocal M, Perez A, Radas A, Finlayson M (2022) Holistic evaluation of automatic timeml annotators. In: Proceedings of the Thirteenth Language Resources and Evaluation Conference, pp. 1444\u20131453"},{"issue":"7","key":"2491_CR25","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3462475","volume":"54","author":"YB Gumiel","year":"2021","unstructured":"Gumiel YB, Oliveira LE, Claveau V, Grabar N, Paraiso EC, Moro C, Carvalho DR (2021) Temporal relation extraction in clinical texts: a systematic review. ACM Computing Surveys (CSUR) 54(7):1\u201336","journal-title":"ACM Computing Surveys (CSUR)"},{"key":"2491_CR26","doi-asserted-by":"crossref","unstructured":"Zhu Z, Dumitras T (2018) Chainsmith: Automatically learning the semantics of malicious campaigns by mining threat intelligence reports. In: 2018 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 458\u2013472. IEEE","DOI":"10.1109\/EuroSP.2018.00039"},{"issue":"1","key":"2491_CR27","doi-asserted-by":"publisher","first-page":"8","DOI":"10.1186\/s42400-022-00110-3","volume":"5","author":"J Liu","year":"2022","unstructured":"Liu J, Yan J, Jiang J, He Y, Wang X, Jiang Z, Yang P, Li N (2022) Tricti: an actionable cyber threat intelligence discovery system via trigger-enhanced neural network. Cybersecurity 5(1):8","journal-title":"Cybersecurity"},{"key":"2491_CR28","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103369","volume":"132","author":"W Ge","year":"2023","unstructured":"Ge W, Wang J, Lin T, Tang B, Li X (2023) Explainable cyber threat behavior identification based on self-adversarial topic generation. Computers & Security 132:103369","journal-title":"Computers & Security"},{"key":"2491_CR29","doi-asserted-by":"crossref","unstructured":"Orbinato V, Barbaraci M, Natella R, Cotroneo D (2022) Automatic mapping of unstructured cyber threat intelligence: An experimental study:(practical experience report). In: 2022 IEEE 33rd International Symposium on Software Reliability Engineering (ISSRE), pp. 181\u2013192. IEEE","DOI":"10.1109\/ISSRE55969.2022.00027"},{"issue":"1","key":"2491_CR30","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1186\/s42400-021-00106-5","volume":"5","author":"Y You","year":"2022","unstructured":"You Y, Jiang J, Jiang Z, Yang P, Liu B, Feng H, Wang X, Li N (2022) Tim: threat context-enhanced ttp intelligence mining on unstructured threat data. Cybersecurity 5(1):3","journal-title":"Cybersecurity"},{"key":"2491_CR31","unstructured":"Wu Y, Liu Q, Liao X, Ji S, Wang P, Wang X, Wu C, Li Z (2021) Price tag: towards semi-automatically discovery tactics, techniques and procedures of e-commerce cyber threat intelligence. IEEE Transactions on Dependable and Secure Computing"},{"key":"2491_CR32","unstructured":"Legoy V, Caselli M, Seifert C, Peter A (2020) Automated retrieval of att &ck tactics and techniques for cyber threat reports. arXiv preprint arXiv:2004.14322"},{"key":"2491_CR33","doi-asserted-by":"crossref","unstructured":"Husari G, Al-Shaer E, Ahmed M, Chu B, Niu X (2017) Ttpdrill: Automatic and accurate extraction of threat actions from unstructured text of cti sources. In: Proceedings of the 33rd Annual Computer Security Applications Conference, pp. 103\u2013115","DOI":"10.1145\/3134600.3134646"},{"key":"2491_CR34","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103579","volume":"136","author":"K Ahmed","year":"2024","unstructured":"Ahmed K, Khurshid SK, Hina S (2024) Cyberentrel: Joint extraction of cyber entities and relations using deep learning. Computers & Security 136:103579","journal-title":"Computers & Security"},{"key":"2491_CR35","doi-asserted-by":"crossref","unstructured":"Li Z, Zeng J, Chen Y, Liang Z (2022) Attackg: Constructing technique knowledge graph from cyber threat intelligence reports. In: European Symposium on Research in Computer Security, pp. 589\u2013609. Springer","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"2491_CR36","doi-asserted-by":"crossref","unstructured":"Huang C-C, Huang P-Y, Kuo Y-R, Wong G-W, Huang Y-T, Sun YS, Chen MC (2022) Building cybersecurity ontology for understanding and reasoning adversary tactics and techniques. In: 2022 IEEE International Conference on Big Data (Big Data), pp. 4266\u20134274. IEEE","DOI":"10.1109\/BigData55660.2022.10021134"},{"key":"2491_CR37","doi-asserted-by":"crossref","unstructured":"Satvat K, Gjomemo R, Venkatakrishnan V (2021) Extractor: Extracting attack behavior from threat reports. In: 2021 IEEE European Symposium on Security and Privacy (EuroS &P), pp. 598\u2013615. IEEE","DOI":"10.1109\/EuroSP51992.2021.00046"},{"key":"2491_CR38","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104125","volume":"148","author":"K Mai","year":"2025","unstructured":"Mai K, Lee J, Beuran R, Hotchi R, Ooi SE, Kuroda T, Tan Y (2025) Raf-ag: Report analysis framework for attack path generation. Computers & Security 148:104125","journal-title":"Computers & Security"},{"key":"2491_CR39","doi-asserted-by":"crossref","unstructured":"Zhang Y, Du T, Ma Y, Wang X, Xie Y, Yang G, Lu Y, Chang E-C (2024) Attackg+: Boosting attack knowledge graph construction with large language models. arXiv preprint arXiv:2405.04753","DOI":"10.1016\/j.cose.2024.104220"},{"key":"2491_CR40","doi-asserted-by":"crossref","unstructured":"Zhao X, Jiang R, Han Y, Li A, Peng Z (2023) A survey on cybersecurity knowledge graph construction. Computers & Security, 103524","DOI":"10.1016\/j.cose.2023.103524"},{"key":"2491_CR41","doi-asserted-by":"crossref","unstructured":"Rahman MR, Mahdavi-Hezaveh R, Williams L (2020) A literature review on mining cyberthreat intelligence from unstructured texts. In: 2020 International Conference on Data Mining Workshops (ICDMW), pp. 516\u2013525. IEEE","DOI":"10.1109\/ICDMW51313.2020.00075"},{"key":"2491_CR42","doi-asserted-by":"crossref","unstructured":"Shin C, Lee I, Choi C (2023) Exploiting ttp co-occurrence via glove-based embedding with mitre att &ck framework. IEEE Access","DOI":"10.1109\/ACCESS.2023.3315121"},{"key":"2491_CR43","doi-asserted-by":"crossref","unstructured":"Al-Shaer R, Spring JM, Christou E (2020) Learning the associations of mitre att & ck adversarial techniques. In: 2020 IEEE Conference on Communications and Network Security (CNS), pp. 1\u20139. IEEE","DOI":"10.1109\/CNS48642.2020.9162207"},{"key":"2491_CR44","unstructured":"Rahman MR, Williams L (2022) Investigating co-occurrences of mitre att$$\\backslash $$ &ck techniques. arXiv preprint arXiv:2211.06495"},{"key":"2491_CR45","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103518","volume":"136","author":"T Chen","year":"2024","unstructured":"Chen T, Zeng H, Lv M, Zhu T (2024) Ctimd: Cyber threat intelligence enhanced malware detection using api call sequences with parameters. Computers & Security 136:103518","journal-title":"Computers & Security"},{"key":"2491_CR46","doi-asserted-by":"crossref","unstructured":"Gao P, Shao F, Liu X, Xiao X, Qin Z, Xu F, Mittal P, Kulkarni SR, Song D (2021) Enabling efficient cyber threat hunting with cyber threat intelligence. In: 2021 IEEE 37th International Conference on Data Engineering (ICDE), pp. 193\u2013204. IEEE","DOI":"10.1109\/ICDE51399.2021.00024"},{"issue":"2","key":"2491_CR47","doi-asserted-by":"publisher","first-page":"1321","DOI":"10.1109\/TNSM.2021.3056999","volume":"18","author":"A Berady","year":"2021","unstructured":"Berady A, Jaume M, Tong VVT, Guette G (2021) From ttp to ioc: Advanced persistent graphs for threat hunting. IEEE Transactions on Network and Service Management 18(2):1321\u20131333","journal-title":"IEEE Transactions on Network and Service Management"},{"issue":"2","key":"2491_CR48","first-page":"776","volume":"19","author":"Y-T Huang","year":"2021","unstructured":"Huang Y-T, Lin CY, Guo Y-R, Lo K-C, Sun YS, Chen MC (2021) Open source intelligence for malicious behavior discovery and interpretation. IEEE Transactions on Dependable and Secure Computing 19(2):776\u2013789","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"2491_CR49","doi-asserted-by":"crossref","unstructured":"Milajerdi SM, Gjomemo R, Eshete B, Sekar R, Venkatakrishnan V (2019) Holmes: real-time apt detection through correlation of suspicious information flows. In: 2019 IEEE Symposium on Security and Privacy (SP), pp. 1137\u20131152. IEEE","DOI":"10.1109\/SP.2019.00026"},{"key":"2491_CR50","doi-asserted-by":"crossref","unstructured":"Milajerdi SM, Eshete B, Gjomemo R, Venkatakrishnan V (2019) Poirot: Aligning attack behavior with kernel audit records for cyber threat hunting. In: Proceedings of the 2019 ACM SIGSAC Conference on Computer and Communications Security, pp. 1795\u20131812","DOI":"10.1145\/3319535.3363217"},{"key":"2491_CR51","doi-asserted-by":"crossref","unstructured":"Rahman MR, Wroblewski B, Matthews Q, Morgan B, Menzies T, Williams L (2024) Chronocti: Mining knowledge graph of temporal relations among cyberattack actions. In: IEEE International Conference on Data Mining","DOI":"10.1109\/ICDM59182.2024.00049"},{"key":"2491_CR52","unstructured":"Martin L. Cyber Kill-Chain. https:\/\/www.lockheedmartin.com\/en-us\/capabilities\/cyber\/cyber-kill-chain.html"},{"key":"2491_CR53","unstructured":"The VERIS Framework. https:\/\/verisframework.org\/"},{"key":"2491_CR54","unstructured":"MITRE: CAPEC - Common Attack Pattern and Enumeration. https:\/\/capec.mitre.org\/"},{"key":"2491_CR55","unstructured":"Strom BE, Applebaum A, Miller DP, Nickels KC, Pennington AG, Thomas CB (2018) Mitre att &ck: Design and philosophy. In: Technical Report. The MITRE Corporation, ???"},{"key":"2491_CR56","unstructured":"Grootendorst M. Creating a class-based TF-IDF with Scikit-Learn. https:\/\/towardsdatascience.com\/creating-a-class-based-tf-idf-with-scikit-learn-caea7b15b858"},{"key":"2491_CR57","doi-asserted-by":"crossref","unstructured":"McHugh ML (2012) Interrater reliability: the kappa statistic. Biochemia Medica, 276\u2013282","DOI":"10.11613\/BM.2012.031"},{"key":"2491_CR58","unstructured":"Opitz J, Burst S (2019) Macro f1 and macro f1. arXiv preprint arXiv:1911.03347"},{"key":"2491_CR59","unstructured":"Rubinstein RY, Kroese DP (2004) The Cross-entropy Method: a Unified Approach to Combinatorial Optimization, Monte-Carlo Simulation, and Machine Learning vol. 133. Springer, ???"},{"key":"2491_CR60","unstructured":"Github aptnotes. https:\/\/github.com\/aptnotes\/data"},{"key":"2491_CR61","doi-asserted-by":"crossref","unstructured":"Derczynski LR (2017) Automatically ordering events and times in text, p. 80. Springer, ???","DOI":"10.1007\/978-3-319-47241-6"},{"key":"2491_CR62","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-57315-1","volume-title":"Dictionary of mathematical geosciences","author":"RJ Howarth","year":"2017","unstructured":"Howarth RJ (2017) Dictionary of mathematical geosciences. Springer, Cham"},{"key":"2491_CR63","unstructured":"Jurafsky D, Martin JH (2023) Speech and Language Processing, 3rd edn. Pearson, ??? . Draft of Jan 7, 2023"},{"key":"2491_CR64","unstructured":"Doron Karmi (2020) A Look Into Konni 2019 Campaign. https:\/\/medium.com\/d-hunter\/a-look-into-konni-2019-campaign-b45a0f321e9b"},{"key":"2491_CR65","unstructured":"Piatetsky-Shapiro G (1991) Discovery, analysis, and presentation of strong rules. Knowledge Discovery in Data-bases, 229\u2013248"},{"key":"2491_CR66","unstructured":"Hahsler M. A Probabilistic Comparison of Commonly Used Interest Measures for Association Rules. https:\/\/mhahsler.github.io\/arules\/docs\/measures.pdf"},{"key":"2491_CR67","doi-asserted-by":"crossref","unstructured":"Harris S, Harris D (2015) Digital Design and Computer Architecture. Morgan Kaufmann, ???","DOI":"10.1016\/B978-0-12-800056-4.00006-6"},{"key":"2491_CR68","doi-asserted-by":"publisher","first-page":"6679","DOI":"10.1609\/aaai.v35i8.16826","volume":"35","author":"S\u00d6 Arik","year":"2021","unstructured":"Arik S\u00d6, Pfister T (2021) Tabnet: Attentive interpretable tabular learning. Proceedings of the AAAI Conference on Artificial Intelligence 35:6679\u20136687","journal-title":"Proceedings of the AAAI Conference on Artificial Intelligence"},{"key":"2491_CR69","doi-asserted-by":"crossref","unstructured":"Schlichtkrull M, Kipf TN, Bloem P, Van Den\u00a0Berg R, Titov I, Welling M (2018) Modeling relational data with graph convolutional networks. In: The Semantic Web: 15th International Conference, ESWC 2018, Heraklion, Crete, Greece, June 3\u20137, 2018, Proceedings 15, pp. 593\u2013607. Springer","DOI":"10.1007\/978-3-319-93417-4_38"},{"key":"2491_CR70","doi-asserted-by":"crossref","unstructured":"Chinchor N, Sundheim BM (1993) Muc-5 evaluation metrics. In: Fifth Message Understanding Conference (MUC-5): Proceedings of a Conference Held in Baltimore, Maryland, August 25-27, 1993","DOI":"10.3115\/1072017.1072023"},{"issue":"6","key":"2491_CR71","doi-asserted-by":"publisher","first-page":"1113","DOI":"10.1016\/j.jbi.2011.08.006","volume":"44","author":"J Zheng","year":"2011","unstructured":"Zheng J, Chapman WW, Crowley RS, Savova GK (2011) Coreference resolution: A review of general methodologies and applications in the clinical domain. Journal of biomedical informatics 44(6):1113\u20131122","journal-title":"Journal of biomedical informatics"},{"issue":"6","key":"2491_CR72","first-page":"1","volume":"16","author":"Y Wang","year":"2022","unstructured":"Wang Y, Tong H, Zhu Z, Li Y (2022) Nested named entity recognition: a survey. ACM Transactions on Knowledge Discovery from Data (TKDD) 16(6):1\u201329","journal-title":"ACM Transactions on Knowledge Discovery from Data (TKDD)"},{"key":"2491_CR73","unstructured":"Lundberg SM, Lee S-I (2017) A unified approach to interpreting model predictions. In: Guyon, I., Luxburg, U.V., Bengio, S., Wallach, H., Fergus, R., Vishwanathan, S., Garnett, R. (eds.) Advances in Neural Information Processing Systems 30, pp. 4765\u20134774. Curran Associates, Inc., ???. http:\/\/papers.nips.cc\/paper\/7062-a-unified-approach-to-interpreting-model-predictions.pdf"},{"key":"2491_CR74","unstructured":"Chen Y, Calabrese R, Martin-Barragan B (2022) Effects of imbalanced datasets on interpretable machine learning"},{"key":"2491_CR75","unstructured":"Salda\u00f1a J (2015) The Coding Manual for Qualitative Researchers. Sage, ???"},{"issue":"3","key":"2491_CR76","doi-asserted-by":"publisher","first-page":"294","DOI":"10.1177\/0049124113500475","volume":"42","author":"JL Campbell","year":"2013","unstructured":"Campbell JL, Quincy C, Osserman J, Pedersen OK (2013) Coding in-depth semistructured interviews: Problems of unitization and intercoder reliability and agreement. Sociological Methods & Research 42(3):294\u2013320. https:\/\/doi.org\/10.1177\/0049124113500475","journal-title":"Sociological Methods & Research"},{"key":"2491_CR77","unstructured":"Adi Peretz and Erick Thek (2021) Earth Vetala MuddyWater Continues to Target Organizations in the Middle East. https:\/\/www.trendmicro.com\/en_us\/research\/21\/c\/earth-vetala---muddywater-continues-to-target-organizations-in-t.html"},{"key":"2491_CR78","unstructured":"BumbleBee Roasts Its Way to Domain Admin. (2022) https:\/\/thedfirreport.com\/2022\/08\/08\/bumblebee-roasts-its-way-to-domain-admin\/"},{"key":"2491_CR79","unstructured":"NIRAJ SHIVTARKAR and AVINASH KUMAR (2022) Lyceum .NET DNS Backdoor. https:\/\/www.zscaler.com\/blogs\/security-research\/lyceum-net-dns-backdoor"},{"key":"2491_CR80","unstructured":"From Zero to Domain Admin. https:\/\/thedfirreport.com\/2021\/11\/01\/from-zero-to-domain-admin\/ (2021)"},{"key":"2491_CR81","unstructured":"Cryptominers Exploiting WebLogic RCE CVE-2020-14882. https:\/\/thedfirreport.com\/2020\/11\/12\/cryptominers-exploiting-weblogic-rce-cve-2020-14882\/ (2020)"},{"key":"2491_CR82","unstructured":"WebLogic RCE Leads to XMRig. https:\/\/thedfirreport.com\/2021\/06\/03\/weblogic-rce-leads-to-xmrig\/ (2021)"},{"key":"2491_CR83","unstructured":"Trickbot Leads Up to Fake 1Password Installation. https:\/\/thedfirreport.com\/2021\/08\/16\/trickbot-leads-up-to-fake-1password-installation\/ (2021)"},{"key":"2491_CR84","unstructured":"Quantum Ransomware. https:\/\/thedfirreport.com\/2022\/04\/25\/quantum-ransomware\/ (2022)"}],"container-title":["Knowledge and Information Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-025-02491-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10115-025-02491-6\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10115-025-02491-6.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T10:58:36Z","timestamp":1760525916000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10115-025-02491-6"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,7,22]]},"references-count":84,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2025,10]]}},"alternative-id":["2491"],"URL":"https:\/\/doi.org\/10.1007\/s10115-025-02491-6","relation":{},"ISSN":["0219-1377","0219-3116"],"issn-type":[{"value":"0219-1377","type":"print"},{"value":"0219-3116","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,7,22]]},"assertion":[{"value":"27 December 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"10 May 2025","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"13 May 2025","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"22 July 2025","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"not applicable","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflicts of Interest"}},{"value":"not applicable","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics approval and consent to participate"}},{"value":"not applicable","order":4,"name":"Ethics","group":{"name":"EthicsHeading","label":"Consent for publication"}},{"value":"Yes,","order":5,"name":"Ethics","group":{"name":"EthicsHeading","label":"Code availability"}},{"value":"Yes,","order":6,"name":"Ethics","group":{"name":"EthicsHeading","label":"Materials availability"}}]}}