{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,10]],"date-time":"2026-07-10T19:40:35Z","timestamp":1783712435513,"version":"3.55.0"},"reference-count":163,"publisher":"Springer Science and Business Media LLC","issue":"8","license":[{"start":{"date-parts":[[2023,1,7]],"date-time":"2023-01-07T00:00:00Z","timestamp":1673049600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2023,1,7]],"date-time":"2023-01-07T00:00:00Z","timestamp":1673049600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/100020409","name":"Analytical Center for the Government of the Russian Federation","doi-asserted-by":"crossref","award":["70-2021-00141"],"award-info":[{"award-number":["70-2021-00141"]}],"id":[{"id":"10.13039\/100020409","id-type":"DOI","asserted-by":"crossref"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Artif Intell Rev"],"published-print":{"date-parts":[[2023,8]]},"DOI":"10.1007\/s10462-022-10381-4","type":"journal-article","created":{"date-parts":[[2023,1,7]],"date-time":"2023-01-07T00:04:56Z","timestamp":1673049896000},"page":"8547-8590","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":38,"title":["A survey on artificial intelligence techniques for security event correlation: models, challenges, and opportunities"],"prefix":"10.1007","volume":"56","author":[{"given":"Diana","family":"Levshun","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Igor","family":"Kotenko","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2023,1,7]]},"reference":[{"issue":"100","key":"10381_CR1","first-page":"067","volume":"10","author":"FJ Abdullayeva","year":"2021","unstructured":"Abdullayeva FJ (2021) Advanced persistent threat attack detection method in cloud computing based on autoencoder and softmax regression algorithm. Array 10(100):067","journal-title":"Array"},{"key":"10381_CR2","unstructured":"Ahmad F (2017) Web application firewall. https:\/\/github.com\/faizann24\/Fwaf-Machine-Learning-driven-Web-Application-Firewall (Accessed 03-July-2022)"},{"issue":"4","key":"10381_CR3","doi-asserted-by":"crossref","first-page":"1494","DOI":"10.3390\/s22041494","volume":"22","author":"H Albasheer","year":"2022","unstructured":"Albasheer H, Md Siraj M, Mubarakali A et al (2022) Cyber-attack prediction based on network intrusion detection systems for alert correlation techniques: a survey. Sensors 22(4):1494","journal-title":"Sensors"},{"issue":"2","key":"10381_CR4","doi-asserted-by":"crossref","first-page":"575","DOI":"10.18517\/ijaseit.9.2.7591","volume":"9","author":"M Almseidin","year":"2019","unstructured":"Almseidin M, Piller I, Al-Kasassbeh M et al (2019) Fuzzy automaton as a detection mechanism for the multi-step attack. Int J Adv Sci Eng Inf Technol 9(2):575\u2013586","journal-title":"Int J Adv Sci Eng Inf Technol"},{"issue":"2","key":"10381_CR5","doi-asserted-by":"crossref","first-page":"1851","DOI":"10.1109\/COMST.2019.2891891","volume":"21","author":"A Alshamrani","year":"2019","unstructured":"Alshamrani A, Myneni S, Chowdhary A et al (2019) A survey on advanced persistent threats: techniques, solutions, challenges, and research opportunities. IEEE Commun Surve Tutor 21(2):1851\u20131877","journal-title":"IEEE Commun Surve Tutor"},{"key":"10381_CR6","doi-asserted-by":"crossref","unstructured":"Amza C, Cecchet E, Chanda A, et\u00a0al (2002) Specification and implementation of dynamic web site benchmarks. In: 2002 IEEE international workshop on workload characterization, pp 3\u201313","DOI":"10.1109\/WWC.2002.1226489"},{"key":"10381_CR7","unstructured":"Asuncion A, Newman D (2007) Uci machine learning repository. http:\/\/archive.ics.uci.edu\/ml\/index.php, (accessed 03-July-2022)"},{"key":"10381_CR8","doi-asserted-by":"crossref","first-page":"151","DOI":"10.1007\/978-3-030-31328-9_8","volume-title":"Recent developments on industrial control systems resilience","author":"T Bajto\u0161","year":"2020","unstructured":"Bajto\u0161 T, Sokol P, M\u00e9ze\u0161ov\u00e1 T (2020) Multi-stage cyber-attacks detection in the industrial control systems. Recent developments on industrial control systems resilience. Springer, Cham, pp 151\u2013173"},{"key":"10381_CR9","unstructured":"Barrett M (2018) Framework for improving critical infrastructure cybersecurity. Version 1.1. NIST Special Publication"},{"key":"10381_CR10","doi-asserted-by":"crossref","first-page":"119","DOI":"10.1016\/j.eswa.2018.04.030","volume":"108","author":"M Barzegar","year":"2018","unstructured":"Barzegar M, Shajari M (2018) Attack scenario reconstruction using intrusion semantics. Expert Syst Appl 108:119\u2013133","journal-title":"Expert Syst Appl"},{"key":"10381_CR11","doi-asserted-by":"crossref","unstructured":"Beer F, B\u00fchler U (2017) Feature selection for flow-based intrusion detection using rough set theory. In: 2017 IEEE 14th international conference on networking. Sensing and Control (ICNSC), IEEE, pp 617\u2013624","DOI":"10.1109\/ICNSC.2017.8000162"},{"issue":"1","key":"10381_CR12","doi-asserted-by":"crossref","first-page":"427","DOI":"10.1214\/20-EJS1792","volume":"15","author":"C B\u00e9nard","year":"2021","unstructured":"B\u00e9nard C, Biau G, Da Veiga S et al (2021) SIRIUS: stable and interpretable rule set for classification. Electron J Stat 15(1):427\u2013505","journal-title":"Electron J Stat"},{"key":"10381_CR13","doi-asserted-by":"crossref","unstructured":"Bhattacharjya D, Shanmugam K, Gao T, et\u00a0al (2020) Event-driven continuous time Bayesian networks. In: Proceedings of the AAAI conference on artificial intelligence, pp 3259\u20133266","DOI":"10.1609\/aaai.v34i04.5725"},{"key":"10381_CR14","doi-asserted-by":"crossref","first-page":"135","DOI":"10.1162\/tacl_a_00051","volume":"5","author":"P Bojanowski","year":"2017","unstructured":"Bojanowski P, Grave E, Joulin A et al (2017) Enriching word vectors with subword information. Trans Assoc Comput Linguist 5:135\u2013146","journal-title":"Trans Assoc Comput Linguist"},{"key":"10381_CR15","doi-asserted-by":"crossref","unstructured":"Bollacker K, Evans C, Paritosh P, et\u00a0al (2008) Freebase: a collaboratively created graph database for structuring human knowledge. In: Proceedings of the 2008 ACM SIGMOD international conference on Management of data, pp 1247\u20131250","DOI":"10.1145\/1376616.1376746"},{"key":"10381_CR16","doi-asserted-by":"crossref","unstructured":"Chang YC, Wang SD (2016) The concept of attack scenarios and its applications in Android malware detection. In: 2016 IEEE 18th international conference on high performance computing and communications, IEEE, pp 1485\u20131492","DOI":"10.1109\/HPCC-SmartCity-DSS.2016.0211"},{"key":"10381_CR17","doi-asserted-by":"crossref","unstructured":"chen h, xiao r, jin s (2020a) real-time detection of cloud tenant malicious behavior based on CNN. In: 2020 IEEE international conference on parallel & distributed processing with applications, big data & cloud computing, sustainable computing & communications, social computing & networking (ISPA\/BDCloud\/SocialCom\/SustainCom), IEEE, pp 998\u20131005","DOI":"10.1109\/ISPA-BDCloud-SocialCom-SustainCom51426.2020.00151"},{"key":"10381_CR18","doi-asserted-by":"crossref","unstructured":"Chen R, Zhang S, Li D, et\u00a0al (2020b) Logtransfer: Cross-system log anomaly detection for software systems with transfer learning. In: 2020 IEEE 31st international symposium on software reliability engineering (ISSRE), IEEE, pp 37\u201347","DOI":"10.1109\/ISSRE5003.2020.00013"},{"key":"10381_CR19","doi-asserted-by":"crossref","first-page":"117,883","DOI":"10.1109\/ACCESS.2019.2937098","volume":"7","author":"H Cheng","year":"2019","unstructured":"Cheng H, Xie Z, Shi Y et al (2019) Multi-step data prediction in wireless sensor networks based on one-dimensional CNN and bidirectional LSTM. IEEE Access 7:117,883-117,896","journal-title":"IEEE Access"},{"issue":"61","key":"10381_CR20","first-page":"1","volume":"800","author":"P Cichonski","year":"2012","unstructured":"Cichonski P, Millar T, Grance T et al (2012) Computer security incident handling guide. Special Publication 800-61. NIST Spec Publ 800(61):1\u2013147","journal-title":"NIST Spec Publ"},{"key":"10381_CR21","doi-asserted-by":"crossref","first-page":"668","DOI":"10.1016\/j.future.2019.09.005","volume":"111","author":"M Cinque","year":"2020","unstructured":"Cinque M, Della Corte R, Pecchia A (2020) Contextual filtering and prioritization of computer application logs for security situational awareness. Future Gener Comput Syst 111:668\u2013680","journal-title":"Future Gener Comput Syst"},{"key":"10381_CR22","unstructured":"CNSS (2022) Committee on National Security Systems (CNSS) Glossary. Committee on National Security Systems Instruction (CNSSI) No. 4009. Committee on National Security Systems"},{"key":"10381_CR23","unstructured":"Contagio Mobile (2011) Contagiodump. mobile malware sample. http:\/\/contagiominidump.blogspot.com\/. (accessed 03-July-2022)"},{"key":"10381_CR24","doi-asserted-by":"crossref","unstructured":"Cook K, Grinstein G, Whiting M, et\u00a0al (2012) Vast challenge 2012: visual analytics for big data. In: 2012 IEEE conference on visual analytics science and technology (VAST), IEEE, pp 251\u2013255","DOI":"10.1109\/VAST.2012.6400529"},{"issue":"4","key":"10381_CR25","doi-asserted-by":"crossref","first-page":"807","DOI":"10.1109\/TC.2013.13","volume":"63","author":"G Creech","year":"2013","unstructured":"Creech G, Hu J (2013) A semantic approach to host-based intrusion detection systems using contiguous and discontiguous system call patterns. IEEE Trans Comput 63(4):807\u2013819","journal-title":"IEEE Trans Comput"},{"key":"10381_CR26","unstructured":"DARPA TC (2020) Transparent computing engagement 3 data release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing, (accessed 03-July-2022)"},{"key":"10381_CR27","unstructured":"DEF CON Communications, Inc. (2021) Defcon21 ctf dataset. https:\/\/media.defcon.org\/DEF%20CON%2021\/. (accessed 03-July-2022)"},{"key":"10381_CR28","doi-asserted-by":"crossref","first-page":"57","DOI":"10.1007\/978-3-540-44792-4_3","volume-title":"Upper and lower probabilities induced by a multivalued mapping. Classic works of the Dempster\u2013Shafer theory of belief functions","author":"AP Dempster","year":"2008","unstructured":"Dempster AP (2008) Upper and lower probabilities induced by a multivalued mapping. Classic works of the Dempster\u2013Shafer theory of belief functions. Springer, Berlin, Heidelberg, pp 57\u201372"},{"issue":"5","key":"10381_CR29","first-page":"4027","volume":"35","author":"A Deng","year":"2021","unstructured":"Deng A, Hooi B (2021) Graph neural network-based anomaly detection in multivariate time series. Proc. AAAI Conf. Artif. Intell. 35(5):4027\u20134035","journal-title":"Proc. AAAI Conf. Artif. Intell."},{"key":"10381_CR30","doi-asserted-by":"crossref","unstructured":"Deng S, Zhang N, Li L, et\u00a0al (2021) OntoED: Low-resource event detection with ontology embedding. In: Proceedings of the 59th annual meeting of the association for computational linguistics, pp 2828\u20132839","DOI":"10.18653\/v1\/2021.acl-long.220"},{"key":"10381_CR31","unstructured":"Devlin J, Chang MW, Lee K, et\u00a0al (2019) BERT: Pre-training of deep bidirectional transformers for language understanding. In: Proceedings of the 2019 conference of the north american chapter of the association for computational linguistics: human language technologies (NAACL-HLT), pp 4171\u20134186"},{"key":"10381_CR32","doi-asserted-by":"crossref","unstructured":"Dhaou A, Bertoncello A, Gourv\u00e9nec S, et\u00a0al (2021) Causal and interpretable rules for time series analysis. In: Proceedings of the 27th ACM SIGKDD conference on knowledge discovery & data mining, pp 2764\u20132772","DOI":"10.1145\/3447548.3467161"},{"issue":"20","key":"10381_CR33","doi-asserted-by":"crossref","first-page":"13,251","DOI":"10.1007\/s00521-021-05952-5","volume":"33","author":"C Do Xuan","year":"2021","unstructured":"Do Xuan C, Dao MH (2021) A novel approach for APT attack detection based on combined deep learning model. Neural Comput Appl 33(20):13,251-13,264","journal-title":"Neural Comput Appl"},{"key":"10381_CR34","doi-asserted-by":"crossref","unstructured":"Du M, Li F, Zheng G, et\u00a0al (2017) Deeplog: Anomaly detection and diagnosis from system logs through deep learning. In: Proceedings of the 2017 ACM SIGSAC conference on computer and communications security, pp 1285\u20131298","DOI":"10.1145\/3133956.3134015"},{"key":"10381_CR35","doi-asserted-by":"crossref","unstructured":"Dwivedi N, Tripathi A (2015) Event correlation for intrusion detection systems. In: 2015 IEEE international conference on computational intelligence & communication technology, IEEE, pp 133\u2013139","DOI":"10.1109\/CICT.2015.111"},{"issue":"1\u20132","key":"10381_CR36","doi-asserted-by":"crossref","first-page":"71","DOI":"10.3233\/JCS-2002-101-204","volume":"10","author":"ST Eckmann","year":"2002","unstructured":"Eckmann ST, Vigna G, Kemmerer RA (2002) Statl: an attack language for state-based intrusion detection. J Comput Secur 10(1\u20132):71\u2013103","journal-title":"J Comput Secur"},{"key":"10381_CR37","first-page":"1","volume":"800","author":"JT Force","year":"2018","unstructured":"Force JT (2018) Risk management framework for information systems and organizations. Special publication 800\u201337 rev. 2. NIST Spec Publ 800:1\u201337","journal-title":"NIST Spec Publ"},{"key":"10381_CR38","doi-asserted-by":"crossref","first-page":"100","DOI":"10.1016\/j.cose.2014.05.011","volume":"45","author":"S Garcia","year":"2014","unstructured":"Garcia S, Grill M, Stiborek J et al (2014) An empirical comparison of botnet detection methods. Comput Secur 45:100\u2013123","journal-title":"Comput Secur"},{"key":"10381_CR39","doi-asserted-by":"crossref","unstructured":"Ghafouri A, Vorobeychik Y, Koutsoukos X (2018) Adversarial regression for detecting attacks in cyber-physical systems. In: Proceedings of the 27th International joint conference on artificial intelligence. AAAI Press, Stockholm, IJCAI\u201918, pp 3769\u20133775","DOI":"10.24963\/ijcai.2018\/524"},{"key":"10381_CR40","unstructured":"Gim\u00e9nez CT, Villegas AP, Mara\u00f1\u00f3n G\u00c1 (2010) Http data set csic 2010. https:\/\/www.isi.csic.es\/dataset\/. (accessed 03-July-2022)"},{"key":"10381_CR41","doi-asserted-by":"crossref","unstructured":"Glasser J, Lindauer B (2013) Bridging the gap: A pragmatic approach to generating insider threat data. In: 2013 IEEE security and privacy workshops, IEEE, pp 98\u2013104","DOI":"10.1109\/SPW.2013.37"},{"key":"10381_CR42","doi-asserted-by":"crossref","unstructured":"Goh J, Adepu S, Junejo KN, et\u00a0al (2016) A dataset to support research in the design of secure water treatment systems. In: International conference on critical information infrastructures security. Springer, Cham, pp 88\u201399","DOI":"10.1007\/978-3-319-71368-7_8"},{"key":"10381_CR43","doi-asserted-by":"crossref","unstructured":"Guan S, Jin X, Wang Y, et\u00a0al (2019) Link prediction on n-ary relational data. In: Proceedings of the 28th International Conference on World Wide Web (WWW\u201919), pp 583\u2013593","DOI":"10.1145\/3308558.3313414"},{"key":"10381_CR44","doi-asserted-by":"crossref","unstructured":"Guo H, Yuan S, Wu X (2021) LogBERT: Log anomaly detection via BERT. In: 2021 international joint conference on neural networks (IJCNN), pp 1\u20138","DOI":"10.1109\/IJCNN52387.2021.9534113"},{"issue":"1","key":"10381_CR45","doi-asserted-by":"crossref","first-page":"5","DOI":"10.1145\/3325061.3325062","volume":"19","author":"S Haas","year":"2019","unstructured":"Haas S, Fischer M (2019) On the alert correlation process for the detection of multi-step attacks and a graph-based realization. ACM SIGAPP Appl Comput Rev 19(1):5\u201319","journal-title":"ACM SIGAPP Appl Comput Rev"},{"key":"10381_CR46","doi-asserted-by":"crossref","unstructured":"Hamed T, Ernst JB, Kremer SC (2018) A survey and taxonomy of classifiers of intrusion detection systems. Computer and network security essentials, pp 21\u201339","DOI":"10.1007\/978-3-319-58424-9_2"},{"key":"10381_CR47","doi-asserted-by":"crossref","unstructured":"Han X, Pasquier T, Bates A, et\u00a0al (2020) UNICORN: Runtime provenance-based detector for advanced persistent threats. In: Network and distributed system security symposium, pp 1\u201318","DOI":"10.14722\/ndss.2020.24046"},{"key":"10381_CR48","doi-asserted-by":"crossref","unstructured":"Hassan WU, Guo S, Li D, et\u00a0al (2019) Nodoze: Combatting threat alert fatigue with automated provenance triage. In: Network and distributed systems security symposium, pp 1\u201315","DOI":"10.14722\/ndss.2019.23349"},{"key":"10381_CR49","doi-asserted-by":"crossref","unstructured":"Hassan WU, Noureddine MA, Datta P, et\u00a0al (2020) OmegaLog: High-fidelity attack investigation via transparent multi-layer log analysis. In: Network and distributed system security symposium, pp 1\u201316","DOI":"10.14722\/ndss.2020.24270"},{"issue":"17","key":"10381_CR50","doi-asserted-by":"crossref","first-page":"2160","DOI":"10.3390\/electronics10172160","volume":"10","author":"M Heigl","year":"2021","unstructured":"Heigl M, Weigelt E, Urmann A et al (2021) Exploiting the outcome of outlier detection for novel attack pattern recognition on streaming data. Electronics 10(17):2160","journal-title":"Electronics"},{"issue":"1","key":"10381_CR51","doi-asserted-by":"crossref","first-page":"134","DOI":"10.1109\/TDSC.2017.2751478","volume":"17","author":"P Holgado","year":"2017","unstructured":"Holgado P, Villagr\u00e1 VA, Vazquez L (2017) Real-time multistep attack prediction based on hidden Markov models. IEEE Trans Depend Secure Comput 17(1):134\u2013147","journal-title":"IEEE Trans Depend Secure Comput"},{"issue":"1","key":"10381_CR52","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1109\/TCCN.2020.2968324","volume":"6","author":"M Hossain","year":"2020","unstructured":"Hossain M, Xie J (2020) Third eye: context-aware detection for hidden terminal emulation attacks in cognitive radio-enabled IoT networks. IEEE Trans Cogn Commun Netw 6(1):214\u2013228","journal-title":"IEEE Trans Cogn Commun Netw"},{"key":"10381_CR53","doi-asserted-by":"crossref","unstructured":"Hostiadi DP, Susila MD, Huizen RR (2019) A new alert correlation model based on similarity approach. In: 2019 1st international conference on cybernetics and intelligent system (ICORIS), IEEE, pp 133\u2013137","DOI":"10.1109\/ICORIS.2019.8874899"},{"key":"10381_CR54","doi-asserted-by":"crossref","unstructured":"Huang L, Ji H, Cho K, et\u00a0al (2018) Zero-shot transfer learning for event extraction. In: Proceedings of the 56th annual meeting of the association for computational linguistics, pp 2160\u20132170","DOI":"10.18653\/v1\/P18-1201"},{"issue":"106","key":"10381_CR55","first-page":"601","volume":"213","author":"Y Huang","year":"2021","unstructured":"Huang Y, Sun H, Xu K et al (2021) CoRelatE: learning the correlation in multi-fold relations for knowledge graph embedding. Knowl-Based Syst 213(106):601","journal-title":"Knowl-Based Syst"},{"issue":"1","key":"10381_CR56","doi-asserted-by":"crossref","first-page":"640","DOI":"10.1109\/COMST.2018.2871866","volume":"21","author":"M Hus\u00e1k","year":"2018","unstructured":"Hus\u00e1k M, Kom\u00e1rkov\u00e1 J, Bou-Harb E et al (2018) Survey of attack projection, prediction, and forecasting in cyber security. IEEE Commun Surv Tutor 21(1):640\u2013660","journal-title":"IEEE Commun Surv Tutor"},{"key":"10381_CR57","unstructured":"ISO (2015a) CISO\/IEC 27039:2015. Information technology - Security techniques - Selection, deployment and operations of intrusion detection systems (IDPS). ISO\/IEC International Standards Organization"},{"key":"10381_CR58","unstructured":"ISO (2015b) ISO\/IEC\/IEEE 15288:2015. Software Life Cycle Processes. ISO\/IEC International Standards Organization, Systems and Software Engineering"},{"key":"10381_CR59","unstructured":"ISO (2022) ISO\/IEC 27001:2022. Information technology-Security techniques\u2014Information security management systems\u2014Requirements, ISO\/IEC International Standards Organization"},{"key":"10381_CR60","doi-asserted-by":"crossref","unstructured":"Jaeger D, Ussath M, Cheng F, et\u00a0al (2015) Multi-step attack pattern detection on normalized event logs. In: 2015 IEEE 2nd international conference on cyber security and cloud computing, IEEE, pp 390\u2013398","DOI":"10.1109\/CSCloud.2015.26"},{"key":"10381_CR61","doi-asserted-by":"crossref","unstructured":"Johnson C, Badger L, Waltermire D, et\u00a0al (2016) Guide to cyber threat information sharing. Special Publication 800-150. NIST special publication 800 (150)","DOI":"10.6028\/NIST.SP.800-150"},{"key":"10381_CR62","doi-asserted-by":"crossref","first-page":"186,125","DOI":"10.1109\/ACCESS.2020.3029202","volume":"8","author":"JH Joloudari","year":"2020","unstructured":"Joloudari JH, Haderbadi M, Mashmool A et al (2020) Early detection of the advanced persistent threat attack using performance analysis of deep learning. IEEE Access 8:186,125-186,137","journal-title":"IEEE Access"},{"key":"10381_CR63","doi-asserted-by":"crossref","unstructured":"Katipally R, Yang L, Liu A (2011) Attacker behavior analysis in multi-stage attack detection system. In: Proceedings of the seventh annual workshop on cyber security and information intelligence research, pp 1\u20134","DOI":"10.1145\/2179298.2179369"},{"key":"10381_CR64","doi-asserted-by":"crossref","unstructured":"Kent AD (2016) Cyber security data sources for dynamic network research. In: Dynamic networks and cyber-security. WSPC (Europe), pp 37\u201365","DOI":"10.1142\/9781786340757_0002"},{"key":"10381_CR65","doi-asserted-by":"crossref","unstructured":"Kent KA, Souppaya M (2006) Guide to Computer Security Log Management: Recommendations of the National Institute of Standards and Technology. Special Publication 800-92. NIST special publication pp 1\u201372","DOI":"10.6028\/NIST.SP.800-92"},{"issue":"6","key":"10381_CR66","doi-asserted-by":"crossref","first-page":"6236","DOI":"10.1007\/s11227-020-03513-6","volume":"77","author":"MA Khan","year":"2021","unstructured":"Khan MA, Abuhasel KA (2021) An evolutionary multi-hidden Markov model for intelligent threat sensing in industrial Internet of things. J Supercomput 77(6):6236\u20136250","journal-title":"J Supercomput"},{"key":"10381_CR67","doi-asserted-by":"crossref","first-page":"162,642","DOI":"10.1109\/ACCESS.2020.3021499","volume":"8","author":"M Khosravi","year":"2020","unstructured":"Khosravi M, Ladani BT (2020) Alerts correlation and causal analysis for APT based cyber attack detection. IEEE Access 8:162,642-162,656","journal-title":"IEEE Access"},{"key":"10381_CR68","unstructured":"Kim M, Park Y, Han I, et\u00a0al (2020) A fast alert correlation method with Bayesian feature constraints. In: International conference on cyber warfare and security, academic conferences international limited, pp 277\u2013285"},{"key":"10381_CR69","doi-asserted-by":"crossref","unstructured":"Kotenko I, Fedorchenko A, Saenko I et al (2018a) Parallelization of security event correlation based on accounting of event type links. In: 2018 26th euromicro international conference on parallel. distributed and network-based processing (PDP), IEEE, pp 462\u2013469","DOI":"10.1109\/PDP2018.2018.00080"},{"issue":"72","key":"10381_CR70","first-page":"714","volume":"6","author":"I Kotenko","year":"2018","unstructured":"Kotenko I, Saenko I, Branitskiy A (2018) Framework for mobile Internet of things security monitoring based on Big Data processing and machine learning. IEEE Access 6(72):714\u2013723","journal-title":"IEEE Access"},{"issue":"104","key":"10381_CR71","first-page":"935","volume":"185","author":"I Kotenko","year":"2019","unstructured":"Kotenko I, Saenko I, Ageev S (2019) Hierarchical fuzzy situational networks for online decision-making: application to telecommunication systems. Knowl-Based Syst 185(104):935","journal-title":"Knowl-Based Syst"},{"key":"10381_CR72","doi-asserted-by":"crossref","first-page":"79","DOI":"10.1007\/978-3-030-19353-9_5","volume-title":"Advances in cyber security analytics and decision systems","author":"I Kotenko","year":"2020","unstructured":"Kotenko I, Fedorchenko A, Doynikova E (2020) Data analytics for security management of complex heterogeneous systems: event correlation and security assessment tasks. Advances in cyber security analytics and decision systems. Springer, Cham, pp 79\u2013116"},{"key":"10381_CR73","doi-asserted-by":"crossref","first-page":"43,387","DOI":"10.1109\/ACCESS.2022.3168976","volume":"10","author":"I Kotenko","year":"2022","unstructured":"Kotenko I, Gaifulina D, Zelichenok I (2022) Systematic literature review of security event correlation methods. IEEE Access 10:43,387-43,420","journal-title":"IEEE Access"},{"issue":"10","key":"10381_CR74","doi-asserted-by":"crossref","first-page":"1722","DOI":"10.3390\/electronics9101722","volume":"9","author":"I Kova\u010devi\u0107","year":"2020","unstructured":"Kova\u010devi\u0107 I, Gro\u0161 S, Slovenec K (2020) Systematic review and quantitative comparison of cyberattack scenario detection and projection. Electronics 9(10):1722","journal-title":"Electronics"},{"key":"10381_CR75","doi-asserted-by":"crossref","unstructured":"Kushwah D, Singh RR, Tomar DS (2019) An approach to meta-alert generation for anomalous tcp traffic. In: International conference on security & privacy. Springer, Cham, pp 193\u2013216","DOI":"10.1007\/978-981-13-7561-3_15"},{"issue":"100","key":"10381_CR76","first-page":"219","volume":"35","author":"HS Lallie","year":"2020","unstructured":"Lallie HS, Debattista K, Bal J (2020) A review of attack graph and attack tree visual syntax in cyber security. Comput Sci Rev 35(100):219","journal-title":"Comput Sci Rev"},{"key":"10381_CR77","doi-asserted-by":"crossref","unstructured":"Lanoe D, Hurfin M, Totel E (2018) A scalable and efficient correlation engine to detect multi-step attacks in distributed systems. In: 2018 IEEE 37th symposium on reliable distributed systems (SRDS). IEEE, pp 31\u201340","DOI":"10.1109\/SRDS.2018.00014"},{"key":"10381_CR78","unstructured":"Le Q, Mikolov T (2014) Distributed representations of sentences and documents. In: International conference on machine learning, PMLR, pp 1188\u20131196"},{"key":"10381_CR79","unstructured":"Lee Y, Kim J, Kang P (2021) LAnoBERT: system log anomaly detection based on BERT masked language model. arXiv preprint arXiv:2111.09564 pp 1\u201315"},{"issue":"13","key":"10381_CR80","doi-asserted-by":"crossref","first-page":"5861","DOI":"10.3390\/app11135861","volume":"11","author":"G Li","year":"2021","unstructured":"Li G, Nguyen TH, Jung JJ (2021a) Traffic incident detection based on dynamic graph embedding in vehicular edge computing. Appl Sci 11(13):5861","journal-title":"Appl Sci"},{"key":"10381_CR81","first-page":"1","volume":"2021","author":"S Li","year":"2021","unstructured":"Li S, Zhang Q, Wu X et al (2021b) Attribution classification method of APT malware in IoT using machine learning techniques. Secur Commun Netw 2021:1\u201312","journal-title":"Secur Commun Netw"},{"key":"10381_CR82","unstructured":"Limmer T, Dressler F (2008) Survey of event correlation techniques for attack detection in early warning systems. University of Erlangen, Dept of Computer Science, Technical Report pp 1\u201337"},{"key":"10381_CR83","doi-asserted-by":"crossref","unstructured":"Liu F, Wen Y, Zhang D, et\u00a0al (2019a) Log2vec: A heterogeneous graph embedding based approach for detecting cyber threats within enterprise. In: Proceedings of the 2019 ACM SIGSAC conference on computer and communications security, pp 1777\u20131794","DOI":"10.1145\/3319535.3363224"},{"issue":"01","key":"10381_CR84","first-page":"6754","volume":"33","author":"J Liu","year":"2019","unstructured":"Liu J, Chen Y, Liu K (2019b) Exploiting the ground-truth: an adversarial imitation based knowledge distillation approach for event detection. Proc AAAI Conf Artif Intell 33(01):6754\u20136761","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"10381_CR85","doi-asserted-by":"crossref","unstructured":"Liu L, Chen C, Zhang J et al (2020) Doc2vec-based insider threat detection through behaviour analysis of multi-source security logs. In: 2020 IEEE 19th international conference on trust. security and privacy in computing and communications (TrustCom), IEEE, pp 301\u2013309","DOI":"10.1109\/TrustCom50675.2020.00050"},{"key":"10381_CR86","first-page":"1","volume":"2020","author":"X Liu","year":"2020","unstructured":"Liu X (2020) A network attack path prediction method using attack graph. J Ambient Intell Hum Comput 2020:1\u20138","journal-title":"J Ambient Intell Hum Comput"},{"key":"10381_CR87","unstructured":"LL-MIT (1998) 1998 darpa intrusion detection evaluation dataset. https:\/\/www.ll.mit.edu\/r-d\/datasets\/1998-darpa-intrusion-detection-evaluation-dataset (accessed 03-July-2022)"},{"key":"10381_CR88","unstructured":"LL-MIT (2000) 2000 darpa intrusion detection scenario specific dataset. https:\/\/www.ll.mit.edu\/r-d\/datasets\/2000-darpa-intrusion-detection-scenario-specific-datasets (accessed 03-July-2022)"},{"key":"10381_CR89","doi-asserted-by":"crossref","unstructured":"Luo W, Zhang H, Yang X, et\u00a0al (2020) Dynamic heterogeneous graph neural network for real-time event prediction. In: Proceedings of the 26th ACM SIGKDD international conference on knowledge discovery & data mining, pp 3213-3223","DOI":"10.1145\/3394486.3403373"},{"key":"10381_CR90","doi-asserted-by":"crossref","unstructured":"Lv S, Qian W, Huang L, et\u00a0al (2019) Sam-net: Integrating event-level and chain-level attentions to predict what happens next. In: Proceedings of the AAAI conference on artificial intelligence, pp 6802\u20136809","DOI":"10.1609\/aaai.v33i01.33016802"},{"issue":"5","key":"10381_CR91","first-page":"15501329221097,","volume":"18","author":"Y Ma","year":"2022","unstructured":"Ma Y, Wu Y, Yu D et al (2022) Vulnerability association evaluation of internet of thing devices based on attack graph. Int J Distrib Sens Netw 18(5):15501329221097,817","journal-title":"Int J Distrib Sens Netw"},{"issue":"101","key":"10381_CR92","first-page":"661","volume":"89","author":"E Mahdavi","year":"2020","unstructured":"Mahdavi E, Fanian A, Amini F (2020) A real-time alert correlation method based on code-books for intrusion detection systems. Comput Secur 89(101):661","journal-title":"Comput Secur"},{"issue":"108","key":"10381_CR93","first-page":"340","volume":"198","author":"B Mao","year":"2021","unstructured":"Mao B, Liu J, Lai Y et al (2021) Mif: a multi-step attack scenario reconstruction and attack chains extraction method based on multi-information fusion. Comput Netw 198(108):340","journal-title":"Comput Netw"},{"issue":"3","key":"10381_CR94","doi-asserted-by":"crossref","first-page":"12","DOI":"10.1109\/MPRV.2018.03367731","volume":"17","author":"Y Meidan","year":"2018","unstructured":"Meidan Y, Bohadana M, Mathov Y et al (2018) N-baiot-network-based detection of IoT botnet attacks using deep autoencoders. IEEE Pervasive Comput 17(3):12\u201322","journal-title":"IEEE Pervasive Comput"},{"key":"10381_CR95","first-page":"559","volume-title":"SHEDEL: a simple hierarchical event description language for specifying attack signatures. Security in the Information Society","author":"M Meier","year":"2002","unstructured":"Meier M, Bischof N, Holz T (2002) SHEDEL: a simple hierarchical event description language for specifying attack signatures. Security in the Information Society. Springer, Boston, pp 559\u2013571"},{"key":"10381_CR96","unstructured":"Microsoft (2021) Microsoft Windows App Development. Event Types. https:\/\/learn.microsoft.com\/en-us\/windows\/win32\/eventlog\/event-types (accessed 12-November-2022)"},{"key":"10381_CR97","unstructured":"Mikolov T, Chen K, Corrado G, et\u00a0al (2013a) Efficient estimation of word representations in vector space. In: 1st International Conference on Learning Representations. ICLR 2013, Scottsdale, Arizona, May 2\u20134, pp 1\u201312"},{"key":"10381_CR98","first-page":"1","volume":"26","author":"T Mikolov","year":"2013","unstructured":"Mikolov T, Sutskever I, Chen K et al (2013b) Distributed representations of words and phrases and their compositionality. Adv Neural Inf Process Syst 26:1\u20139","journal-title":"Adv Neural Inf Process Syst"},{"key":"10381_CR99","doi-asserted-by":"crossref","unstructured":"Milajerdi SM, Gjomemo R, Eshete B, et\u00a0al (2019) Holmes: real-time apt detection through correlation of suspicious information flows. In: 2019 IEEE symposium on security and privacy (SP), IEEE, pp 1137\u20131152","DOI":"10.1109\/SP.2019.00026"},{"issue":"11","key":"10381_CR100","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1145\/219717.219748","volume":"38","author":"GA Miller","year":"1995","unstructured":"Miller GA (1995) Wordnet: a lexical database for English. Commun ACM 38(11):39\u201341","journal-title":"Commun ACM"},{"key":"10381_CR101","doi-asserted-by":"crossref","first-page":"104,695","DOI":"10.1109\/ACCESS.2021.3100087","volume":"9","author":"B Min","year":"2021","unstructured":"Min B, Yoo J, Kim S et al (2021) Network anomaly detection using memory-augmented deep autoencoder. IEEE Access 9:104,695-104,706","journal-title":"IEEE Access"},{"key":"10381_CR102","doi-asserted-by":"crossref","first-page":"183","DOI":"10.1007\/978-3-319-03584-0_14","volume-title":"International symposium on cyberspace safety and security","author":"SA Mirheidari","year":"2013","unstructured":"Mirheidari SA, Arshad S, Jalili R (2013) Alert correlation algorithms: a survey and taxonomy. International symposium on cyberspace safety and security. Springer, Cham, pp 183\u2013197"},{"key":"10381_CR103","unstructured":"Morzeux (2020) Httpparamsdataset. https:\/\/github.com\/Morzeux\/HttpParamsDataset (accessed 03-July-2022)"},{"key":"10381_CR104","doi-asserted-by":"crossref","unstructured":"Moustafa N, Slay J (2015) UNSW-NB15: a comprehensive data set for network intrusion detection systems (UNSW-NB15 network data set). In: 2015 Military communications and information systems conference (MilCIS), pp 1\u20136","DOI":"10.1109\/MilCIS.2015.7348942"},{"key":"10381_CR105","doi-asserted-by":"crossref","first-page":"175,194","DOI":"10.1109\/ACCESS.2020.3017009","volume":"8","author":"M Nasir","year":"2020","unstructured":"Nasir M, Muhammad K, Bellavista P et al (2020) Prioritization and alert fusion in distributed IoT sensors using Kademlia based distributed hash tables. IEEE Access 8:175,194-175,204","journal-title":"IEEE Access"},{"key":"10381_CR106","doi-asserted-by":"crossref","unstructured":"Nasr M, Bahramali A, Houmansadr A (2018) Deepcorr: strong flow correlation attacks on tor using deep learning. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 1962\u20131976","DOI":"10.1145\/3243734.3243824"},{"key":"10381_CR107","doi-asserted-by":"crossref","first-page":"214","DOI":"10.1016\/j.cose.2018.03.001","volume":"76","author":"J Navarro","year":"2018","unstructured":"Navarro J, Deruyver A, Parrend P (2018) A systematic survey on multi-step attack detection. Comput Secur 76:214\u2013249","journal-title":"Comput Secur"},{"key":"10381_CR108","unstructured":"NETRESEC (2000) Mid-atlantic collegiate cyber defense competition. https:\/\/www.netresec.com\/?page=MACCDC (accessed 03-July-2022)"},{"key":"10381_CR109","unstructured":"NETRESEC (2015) 4sics geek lounge. https:\/\/www.netresec.com\/?page=PCAP4SICS (accessed 03-July-2022)"},{"issue":"1","key":"10381_CR110","first-page":"5900","volume":"32","author":"T Nguyen","year":"2018","unstructured":"Nguyen T, Grishman R (2018) Graph convolutional networks with argument-aware pooling for event detection. Proc AAAI Conf Artif Intell 32(1):5900\u20135907","journal-title":"Proc AAAI Conf Artif Intell"},{"issue":"1","key":"10381_CR111","first-page":"7786","volume":"32","author":"M Oki","year":"2018","unstructured":"Oki M, Takeuchi K, Uematsu Y (2018) Mobile network failure event detection and forecasting with multiple user activity data sets. Proc AAAI Conf Artif Intell 32(1):7786\u20137792","journal-title":"Proc AAAI Conf Artif Intell"},{"key":"10381_CR112","doi-asserted-by":"crossref","unstructured":"Oliner A, Stearley J (2007) What supercomputers say: A study of five system logs. In: 37th annual IEEE\/IFIP international conference on dependable systems and networks (DSN\u201907), IEEE, pp 575\u2013584","DOI":"10.1109\/DSN.2007.103"},{"key":"10381_CR113","doi-asserted-by":"crossref","unstructured":"Pennington J, Socher R, Manning CD (2014) Glove: Global vectors for word representation. In: Proceedings of the 2014 conference on empirical methods in natural language processing (EMNLP), pp 1532\u20131543","DOI":"10.3115\/v1\/D14-1162"},{"key":"10381_CR114","doi-asserted-by":"crossref","unstructured":"Peters ME, Neumann M, Iyyer M, et\u00a0al (2018) Deep contextualized word representations. In: Proceedings of the 2018 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies. ACL, New Orleans, pp 2227\u20132237","DOI":"10.18653\/v1\/N18-1202"},{"issue":"11","key":"10381_CR115","doi-asserted-by":"crossref","first-page":"3874","DOI":"10.3390\/app10113874","volume":"10","author":"S Quintero-Bonilla","year":"2020","unstructured":"Quintero-Bonilla S, Mart\u00edn del Rey A (2020) A new proposal on the advanced persistent threat: a survey. Appl Sci 10(11):3874","journal-title":"Appl Sci"},{"issue":"3","key":"10381_CR116","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1145\/3184898","volume":"51","author":"AA Ramaki","year":"2018","unstructured":"Ramaki AA, Rasoolzadegan A, Bafghi AG (2018) A systematic mapping study on intrusion alert analysis in intrusion detection systems. ACM Comput Surv (CSUR) 51(3):1\u201341","journal-title":"ACM Comput Surv (CSUR)"},{"key":"10381_CR117","unstructured":"Ramilli M (2016) Malware training sets: a machine learning dataset for everyone. https:\/\/marcoramilli.com\/2016\/12\/16\/malware-training-sets-a-machine-learning-dataset-for-everyone\/ (accessed 03-July-2022)"},{"issue":"102","key":"10381_CR118","first-page":"389","volume":"109","author":"M Ring","year":"2021","unstructured":"Ring M, Schl\u00f6r D, Wunderlich S et al (2021) Malware detection on windows audit logs using LSTMs. Comput Secur 109(102):389","journal-title":"Comput Secur"},{"key":"10381_CR119","unstructured":"Ross R, Stoneburner G, Fabius-Greene J, et\u00a0al (2011) Managing information security risk: organization, mission, and information system view. Special Publication 800-39. NIST special publication pp 1\u201388"},{"issue":"10","key":"10381_CR120","doi-asserted-by":"crossref","first-page":"5089","DOI":"10.3390\/app12105089","volume":"12","author":"P Ryciak","year":"2022","unstructured":"Ryciak P, Wasielewska K, Janicki A (2022) Anomaly detection in log files using selected natural language processing methods. Appl Sci 12(10):5089","journal-title":"Appl Sci"},{"issue":"5","key":"10381_CR121","doi-asserted-by":"crossref","first-page":"1289","DOI":"10.1016\/j.comnet.2012.10.022","volume":"57","author":"S Salah","year":"2013","unstructured":"Salah S, Maci\u00e1-Fern\u00e1ndez G, D\u00edaz-Verdejo JE (2013) A model-based survey of alert correlation techniques. Comput Netw 57(5):1289\u20131317","journal-title":"Comput Netw"},{"issue":"3","key":"10381_CR122","first-page":"1","volume":"2","author":"IH Sarker","year":"2021","unstructured":"Sarker IH, Furhad MH, Nowrozy R (2021) AI-driven cybersecurity: an overview, security intelligence modeling and research directions. SN Comput Sci 2(3):1\u201318","journal-title":"SN Comput Sci"},{"issue":"115","key":"10381_CR123","first-page":"2","volume":"800","author":"K Scarfone","year":"2008","unstructured":"Scarfone K, Souppaya M, Cody A et al (2008) Technical guide to information security testing and assessment. NIST Spec Publ 800(115):2\u201325","journal-title":"NIST Spec Publ"},{"issue":"100","key":"10381_CR124","first-page":"821","volume":"32","author":"\u00d6 Sen","year":"2022","unstructured":"Sen \u00d6, van der Velde D, Wehrmeister KA et al (2022) On using contextual correlation to detect multi-stage cyber attacks in smart grids. Sustain Energy Grids Netw 32(100):821","journal-title":"Sustain Energy Grids Netw"},{"key":"10381_CR125","doi-asserted-by":"crossref","unstructured":"Seyyar YE, Yavuz AG, Unver HM (2022) An attack detection framework based on BERT and deep learning. IEEE Access Early Access, pp 1\u201313","DOI":"10.1109\/ACCESS.2022.3185748"},{"key":"10381_CR126","doi-asserted-by":"crossref","unstructured":"Sharafaldin I, Lashkari AH, Ghorbani AA (2018) Toward generating a new intrusion detection dataset and intrusion traffic characterization. In: Proceedings of the 4th international conference on information systems security and privacy (ICISSP 2018), pp 108\u2013116","DOI":"10.5220\/0006639801080116"},{"issue":"5","key":"10381_CR127","first-page":"2316","volume":"18","author":"T Shawly","year":"2019","unstructured":"Shawly T, Elghariani A, Kobes J et al (2019) Architectures for detecting interleaved multi-stage network attacks using hidden Markov models. IEEE Trans Depend Secure Comput 18(5):2316\u20132330","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"10381_CR128","doi-asserted-by":"crossref","unstructured":"Shen Y, Mariconti E, Vervier PA, et\u00a0al (2018) Tiresias: predicting security events through deep learning. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 592\u2013605","DOI":"10.1145\/3243734.3243811"},{"issue":"3","key":"10381_CR129","doi-asserted-by":"crossref","first-page":"357","DOI":"10.1016\/j.cose.2011.12.012","volume":"31","author":"A Shiravi","year":"2012","unstructured":"Shiravi A, Shiravi H, Tavallaee M et al (2012) Toward developing a systematic approach to generate benchmark datasets for intrusion detection. Comput Secur 31(3):357\u2013374","journal-title":"Comput Secur"},{"key":"10381_CR130","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2014.12.003","volume":"50","author":"R Shittu","year":"2015","unstructured":"Shittu R, Healing A, Ghanea-Hercock R et al (2015) Intrusion alert prioritisation and attack detection using post-correlation analysis. Comput Secur 50:1\u201315","journal-title":"Comput Secur"},{"issue":"1","key":"10381_CR131","doi-asserted-by":"crossref","first-page":"17","DOI":"10.1007\/s10586-020-03153-8","volume":"24","author":"AJ Siddiqui","year":"2021","unstructured":"Siddiqui AJ, Boukerche A (2021) TempoCode-IoT: temporal codebook-based encoding of flow features for intrusion detection in internet of things. Clust Comput 24(1):17\u201335","journal-title":"Clust Comput"},{"issue":"3","key":"10381_CR132","volume":"3","author":"LF Sikos","year":"2021","unstructured":"Sikos LF (2021) Ai in digital forensics: ontology engineering for cybercrime investigations. Wiley Interdiscip Rev 3(3):e1394","journal-title":"Wiley Interdiscip Rev"},{"key":"10381_CR133","doi-asserted-by":"crossref","first-page":"51","DOI":"10.1007\/3-540-70894-4_3","volume-title":"Knowledge representation and ontologies. Semantic web services: concepts, technologies, and applications","author":"G Stephan","year":"2007","unstructured":"Stephan G, Pascal H, Andreas A et al (2007) Knowledge representation and ontologies. Semantic web services: concepts, technologies, and applications. Springer, Berlin, Heidelberg, pp 51\u2013105"},{"key":"10381_CR134","doi-asserted-by":"crossref","unstructured":"Stouffer K, Stouffer K, Zimmerman T, et\u00a0al (2017) Cybersecurity framework manufacturing profile. NISTIR 8183 Rev. 1. US Department of Commerce, National Institute of Standards and Technology","DOI":"10.6028\/NIST.IR.8183"},{"issue":"3","key":"10381_CR135","doi-asserted-by":"crossref","first-page":"324","DOI":"10.3390\/e22030324","volume":"22","author":"J Sun","year":"2020","unstructured":"Sun J, Gu L, Chen K (2020) An efficient alert aggregation method based on conditional rough entropy and knowledge granularity. Entropy 22(3):324","journal-title":"Entropy"},{"issue":"10","key":"10381_CR136","doi-asserted-by":"crossref","first-page":"2506","DOI":"10.1109\/TIFS.2018.2821095","volume":"13","author":"X Sun","year":"2018","unstructured":"Sun X, Dai J, Liu P et al (2018) Using Bayesian networks for probabilistic identification of zero-day attack paths. IEEE Trans Inf Forensics Secur 13(10):2506\u20132521","journal-title":"IEEE Trans Inf Forensics Secur"},{"issue":"07","key":"10381_CR137","first-page":"2274","volume":"2","author":"P Tanwar","year":"2010","unstructured":"Tanwar P, Prasad T, Aswal MS (2010) Comparative study of three declarative knowledge representation techniques. Int J Comput Sci Eng 2(07):2274\u20132281","journal-title":"Int J Comput Sci Eng"},{"issue":"5","key":"10381_CR138","first-page":"1","volume":"2021","author":"Tao Xl","year":"2021","unstructured":"Xl Tao, Shi L, Zhao F et al (2021) A hybrid alarm association method based on AP clustering and causality. Wirel Commun Mobile Comput 2021(5):1\u201310","journal-title":"Wirel Commun Mobile Comput"},{"key":"10381_CR139","doi-asserted-by":"crossref","unstructured":"Tavallaee M, Bagheri E, Lu W, et\u00a0al (2009) A detailed analysis of the KDD CUP 99 data set. In: 2009 IEEE symposium on computational intelligence for security and defense applications, IEEE, pp 1\u20136","DOI":"10.1109\/CISDA.2009.5356528"},{"key":"10381_CR140","doi-asserted-by":"crossref","first-page":"1397","DOI":"10.1007\/978-3-030-44041-1_118","volume-title":"International conference on advanced information networking and applications","author":"LN Tidjon","year":"2020","unstructured":"Tidjon LN, Frappier M, Mammar A (2020) Intrusion detection using ASTDs. International conference on advanced information networking and applications. Springer, Cham, pp 1397\u20131411"},{"issue":"2","key":"10381_CR141","doi-asserted-by":"crossref","first-page":"260","DOI":"10.1109\/TIT.1967.1054010","volume":"13","author":"A Viterbi","year":"1967","unstructured":"Viterbi A (1967) Error bounds for convolutional codes and an asymptotically optimum decoding algorithm. IEEE Trans Inf Theory 13(2):260\u2013269","journal-title":"IEEE Trans Inf Theory"},{"key":"10381_CR142","doi-asserted-by":"crossref","first-page":"86","DOI":"10.1016\/j.eswa.2017.10.013","volume":"93","author":"G Vlahakis","year":"2018","unstructured":"Vlahakis G, Apostolou D, Kopanaki E (2018) Enabling situation awareness with supply chain event management. Expert Syst Appl 93:86\u2013103","journal-title":"Expert Syst Appl"},{"key":"10381_CR143","first-page":"45","volume":"57","author":"C Walker","year":"2006","unstructured":"Walker C, Strassel S, Medero J et al (2006) Ace 2005 multilingual training corpus. Linguist Data Consort 57:45","journal-title":"Linguist Data Consort"},{"issue":"9","key":"10381_CR144","doi-asserted-by":"crossref","first-page":"2451","DOI":"10.3390\/s20092451","volume":"20","author":"J Wang","year":"2020","unstructured":"Wang J, Tang Y, He S et al (2020) LogEvent2vec: logevent-to-vector based anomaly detection for large-scale logs in internet of things. Sensors 20(9):2451","journal-title":"Sensors"},{"issue":"3","key":"10381_CR145","doi-asserted-by":"crossref","first-page":"1207","DOI":"10.32604\/csse.2022.022365","volume":"41","author":"J Wang","year":"2022","unstructured":"Wang J, Zhao C, He S et al (2022) LogUAD: log unsupervised anomaly detection based on Word2Vec. Comput Syst Sci Eng 41(3):1207\u20131222","journal-title":"Comput Syst Sci Eng"},{"key":"10381_CR146","doi-asserted-by":"crossref","unstructured":"Wang Q, Jiang J, Shi Z, et\u00a0al (2018) A novel multi-source fusion model for known and unknown attack scenarios. In: 2018 17th IEEE international conference on trust, security and privacy in computing and communications\/12th IEEE international conference on big data science and engineering (TrustCom\/BigDataSE), IEEE, pp 727\u2013736","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00106"},{"key":"10381_CR147","doi-asserted-by":"crossref","unstructured":"Wang X, Gong X, Yu L et al (2021a) MAAC: Novel alert correlation method to detect multi-step attack. In: 2021 IEEE 20th international conference on trust. Security and privacy in computing and communications (TrustCom), IEEE, pp 726\u2013733","DOI":"10.1109\/TrustCom53373.2021.00106"},{"key":"10381_CR148","doi-asserted-by":"crossref","unstructured":"Wang Z, Chen Z, Ni J, et\u00a0al (2021b) Multi-scale one-class recurrent neural networks for discrete event sequence anomaly detection. In: Proceedings of the 27th ACM SIGKDD conference on knowledge discovery & data mining, pp 3726\u20133734","DOI":"10.1145\/3447548.3467125"},{"issue":"4","key":"10381_CR149","first-page":"10","volume":"53","author":"LR Welch","year":"2003","unstructured":"Welch LR (2003) Hidden Markov models and the Baum\u2013Welch algorithm. IEEE Inf Theory Soc Newsl 53(4):10\u201313","journal-title":"IEEE Inf Theory Soc Newsl"},{"key":"10381_CR150","unstructured":"Wen J, Li J, Mao Y, et\u00a0al (2016) On the representation and embedding of knowledge bases beyond binary relations. In: Proceedings of the twenty-fifth international joint conference on artificial intelligence, pp 1300\u20131307"},{"key":"10381_CR151","doi-asserted-by":"crossref","unstructured":"Wood M, Erlinger M (2007) Intrusion detection message exchange requirements. IETF Request for Comment (RFC) 4766","DOI":"10.17487\/rfc4766"},{"key":"10381_CR152","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1016\/j.ins.2018.03.018","volume":"447","author":"T Xie","year":"2018","unstructured":"Xie T, Zheng Q, Zhang W (2018) Mining temporal characteristics of behaviors from interval events in e-learning. Inf Sci 447:169\u2013185","journal-title":"Inf Sci"},{"key":"10381_CR153","doi-asserted-by":"crossref","unstructured":"Xu W, Huang L, Fox A, et\u00a0al (2009) Online system problem detection by mining patterns of console logs. In: 2009 ninth IEEE international conference on data mining, IEEE, pp 588\u2013597","DOI":"10.1109\/ICDM.2009.19"},{"issue":"3","key":"10381_CR154","doi-asserted-by":"crossref","first-page":"233","DOI":"10.1080\/02564602.2014.906864","volume":"31","author":"L Yu Beng","year":"2014","unstructured":"Yu Beng L, Ramadass S, Manickam S et al (2014) A survey of intrusion alert correlation and its design considerations. IETE Tech Rev 31(3):233\u2013240","journal-title":"IETE Tech Rev"},{"issue":"1","key":"10381_CR155","doi-asserted-by":"crossref","first-page":"265","DOI":"10.3390\/make1010017","volume":"1","author":"WK Zegeye","year":"2018","unstructured":"Zegeye WK, Dean RA, Moazzami F (2018) Multi-layer hidden Markov model based intrusion detection system. Mach Learn Knowl Extr 1(1):265\u2013286","journal-title":"Mach Learn Knowl Extr"},{"key":"10381_CR156","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1155\/2019\/2031063","volume":"2019","author":"J Zeng","year":"2019","unstructured":"Zeng J, Wu S, Chen Y et al (2019) Survey of attack graph analysis methods from the perspective of data and knowledge processing. Secur Commun Netw 2019:1\u201316","journal-title":"Secur Commun Netw"},{"key":"10381_CR157","doi-asserted-by":"crossref","unstructured":"Zeng J, Chua ZL, Chen Y, et\u00a0al (2021) Watson: Abstracting behaviors from audit logs via aggregation of contextual semantics. In: Proceedings of the 28th annual network and distributed system security symposium, NDSS, pp 1\u201318","DOI":"10.14722\/ndss.2021.24549"},{"key":"10381_CR158","doi-asserted-by":"crossref","unstructured":"Zhan Y, Haddadi H (2019) Towards automating smart homes: Contextual and temporal dynamics of activity prediction. In: adjunct proceedings of the 2019 ACM international joint conference on pervasive and ubiquitous computing and Proceedings of the 2019 ACM international symposium on wearable computers, pp 413\u2013417","DOI":"10.1145\/3341162.3349307"},{"key":"10381_CR159","doi-asserted-by":"crossref","first-page":"1031","DOI":"10.1109\/ACCESS.2019.2961517","volume":"8","author":"H Zhang","year":"2019","unstructured":"Zhang H, Jin X, Li Y et al (2019) A multi-step attack detection model based on alerts of smart grid monitoring system. IEEE Access 8:1031\u20131047","journal-title":"IEEE Access"},{"issue":"8","key":"10381_CR160","doi-asserted-by":"crossref","first-page":"2874","DOI":"10.3390\/s22082874","volume":"22","author":"X Zhang","year":"2022","unstructured":"Zhang X, Wu T, Zheng Q et al (2022a) Multi-step attack detection based on pre-trained hidden Markov models. Sensors 22(8):2874","journal-title":"Sensors"},{"key":"10381_CR161","doi-asserted-by":"crossref","unstructured":"Zhang Y, Zhao S, Zhang J (2019b) RTMA: Real time mining algorithm for multi-step attack scenarios reconstruction. In: 2019 IEEE 21st international conference on high performance computing and communications, IEEE, pp 2103\u20132110","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00291"},{"key":"10381_CR162","doi-asserted-by":"crossref","unstructured":"Zheng H, Wang Y, Han C et al (2018) Learning and applying ontology for machine learning in cyber attack detection. In: 2018 17th IEEE international conference on trust. Security and privacy in computing and communications, IEEE, pp 1309\u20131315","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00180"},{"key":"10381_CR163","doi-asserted-by":"crossref","first-page":"525","DOI":"10.1016\/j.future.2019.02.045","volume":"96","author":"A Zimba","year":"2019","unstructured":"Zimba A, Chen H, Wang Z (2019) Bayesian network based weighted APT attack paths modeling in cloud computing. Future Gener Comput Syst 96:525\u2013537","journal-title":"Future Gener Comput Syst"}],"container-title":["Artificial Intelligence Review"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-022-10381-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10462-022-10381-4\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10462-022-10381-4.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,6,27]],"date-time":"2023-06-27T22:22:41Z","timestamp":1687904561000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10462-022-10381-4"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2023,1,7]]},"references-count":163,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,8]]}},"alternative-id":["10381"],"URL":"https:\/\/doi.org\/10.1007\/s10462-022-10381-4","relation":{"has-preprint":[{"id-type":"doi","id":"10.21203\/rs.3.rs-1975426\/v1","asserted-by":"object"}]},"ISSN":["0269-2821","1573-7462"],"issn-type":[{"value":"0269-2821","type":"print"},{"value":"1573-7462","type":"electronic"}],"subject":[],"published":{"date-parts":[[2023,1,7]]},"assertion":[{"value":"7 January 2023","order":1,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}