{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,23]],"date-time":"2026-05-23T04:06:29Z","timestamp":1779509189725,"version":"3.53.1"},"reference-count":49,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2026,5,23]],"date-time":"2026-05-23T00:00:00Z","timestamp":1779494400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2026,5,23]],"date-time":"2026-05-23T00:00:00Z","timestamp":1779494400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"funder":[{"DOI":"10.13039\/501100012226","name":"Fundamental Research Funds for the Central Universities","doi-asserted-by":"publisher","award":["2242022k60005"],"award-info":[{"award-number":["2242022k60005"]}],"id":[{"id":"10.13039\/501100012226","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Netw Syst Manage"],"published-print":{"date-parts":[[2026,10]]},"DOI":"10.1007\/s10922-026-10077-y","type":"journal-article","created":{"date-parts":[[2026,5,23]],"date-time":"2026-05-23T03:47:58Z","timestamp":1779508078000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Structured Representation Learning from Network Behavior for Attribute-Based Access Control"],"prefix":"10.1007","volume":"34","author":[{"given":"Junjun","family":"Ding","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yunxue","family":"Zhong","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Haofei","family":"Meng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenwu","family":"Yu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yubo","family":"Song","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2026,5,23]]},"reference":[{"issue":"6","key":"10077_CR1","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3533703","volume":"55","author":"S Parkinson","year":"2022","unstructured":"Parkinson, S., Khan, S.: A survey on empirical security analysis of access-control systems: a real-world perspective. ACM Comput. Surv. 55(6), 1\u201328 (2022)","journal-title":"ACM Comput. Surv."},{"issue":"162","key":"10077_CR2","first-page":"1","volume":"800","author":"VC Hu","year":"2013","unstructured":"Hu, V.C., Ferraiolo, D., Kuhn, R., Friedman, A.R., Lang, A.J., Cogdell, M.M., Schnitzer, A., Sandlin, K., Miller, R., Scarfone, K.: Guide to attribute based access control (ABAC) definition and considerations (draft). NIST Spec. Publ. 800(162), 1\u201354 (2013)","journal-title":"NIST Spec. Publ."},{"key":"10077_CR3","doi-asserted-by":"crossref","unstructured":"Jin, X., Krishnan, R., Sandhu, R.: A unified attribute-based access control model covering dac, mac and rbac. In: IFIP Annual Conference on Data and Applications Security and Privacy, 41\u201355 (2012). Springer","DOI":"10.1007\/978-3-642-31540-4_4"},{"key":"10077_CR4","doi-asserted-by":"publisher","first-page":"17596","DOI":"10.1109\/JIOT.2025.3537980","volume":"12","author":"T Wu","year":"2025","unstructured":"Wu, T., Li, G., Wang, J., Xiao, B., Song, Y.: Ppca: privacy-preserving continuous authentication scheme with consistency proof for zero-trust architecture networks. IEEE Internet Things J. 12, 17596\u201317609 (2025)","journal-title":"IEEE Internet Things J."},{"issue":"4","key":"10077_CR5","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3007204","volume":"49","author":"D Servos","year":"2017","unstructured":"Servos, D., Osborn, S.L.: Current research and open problems in attribute-based access control. ACM Comput. Surv. 49(4), 1\u201345 (2017)","journal-title":"ACM Comput. Surv."},{"issue":"1","key":"10077_CR6","doi-asserted-by":"publisher","first-page":"90","DOI":"10.1109\/TCE.2018.2883382","volume":"65","author":"G Fedrecheski","year":"2018","unstructured":"Fedrecheski, G., De Biase, L.C.C., Calcina-Ccori, P.C., Zuffo, M.K.: Attribute-based access control for the swarm with distributed policy management. IEEE Trans. Consum. Electron. 65(1), 90\u201398 (2018)","journal-title":"IEEE Trans. Consum. Electron."},{"issue":"5","key":"10077_CR7","doi-asserted-by":"publisher","first-page":"533","DOI":"10.1109\/TDSC.2014.2369048","volume":"12","author":"Z Xu","year":"2014","unstructured":"Xu, Z., Stoller, S.D.: Mining attribute-based access control policies. IEEE Trans. Dependable Secure Comput. 12(5), 533\u2013545 (2014)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10077_CR8","doi-asserted-by":"crossref","unstructured":"Chen, Q., Song, Y., Jennings, B., Zhang, F., Xiao, B., Gao, S.: IoT-id: robust IoT device identification based on feature drift adaptation. In: 2021 IEEE Global Communications Conference (GLOBECOM), 1\u20136 (2021). IEEE","DOI":"10.1109\/GLOBECOM46510.2021.9685693"},{"key":"10077_CR9","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104303","volume":"150","author":"Y Song","year":"2025","unstructured":"Song, Y., Wang, K., Sun, X., Qin, Z., Dai, H., Chen, W., Lv, B., Chen, J.: A multi-source log semantic analysis-based attack investigation approach. Comput. Secur. 150, 104303 (2025)","journal-title":"Comput. Secur."},{"issue":"5","key":"10077_CR10","doi-asserted-by":"publisher","first-page":"664","DOI":"10.1016\/j.dcan.2022.09.002","volume":"8","author":"M Yu","year":"2022","unstructured":"Yu, M., Li, F., Yu, N., Wang, X., Guo, Y.: Detecting conflict of heterogeneous access control policies. Digital Commun. Netw. 8(5), 664\u2013679 (2022)","journal-title":"Digital Commun. Netw."},{"issue":"3","key":"10077_CR11","doi-asserted-by":"publisher","first-page":"2269","DOI":"10.1109\/TNSM.2022.3175710","volume":"19","author":"L Yang","year":"2022","unstructured":"Yang, L., Song, Y., Gao, S., Hu, A., Xiao, B.: Griffin: real-time network intrusion detection system via ensemble of autoencoder in sdn. IEEE Trans. Netw. Serv. Manage. 19(3), 2269\u20132281 (2022)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"10077_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103729","volume":"139","author":"S Aboukadri","year":"2024","unstructured":"Aboukadri, S., Ouaddah, A., Mezrioui, A.: Machine learning in identity and access management systems: survey and deep dive. Comput. Secur. 139, 103729 (2024)","journal-title":"Comput. Secur."},{"key":"10077_CR13","volume":"93","author":"C Fu","year":"2025","unstructured":"Fu, C., Shen, G., Huang, Z., Xie, J., Fu, J.: Automatic IoT permission assignment with transformer models under spatiotemporal constraints. J. Inf. Secur. Appl. 93, 104099 (2025)","journal-title":"J. Inf. Secur. Appl."},{"key":"10077_CR14","doi-asserted-by":"publisher","DOI":"10.1016\/j.adhoc.2025.103919","volume":"178","author":"Y Song","year":"2025","unstructured":"Song, Y., Liu, W., Zhu, H., Gong, Y., Li, Y., Huang, J., Deng, Y.: Enhancing wircless channel authentication in industrial control: attack-resistant csi-based puf. Ad Hoc Netw. 178, 103919 (2025)","journal-title":"Ad Hoc Netw."},{"issue":"3","key":"10077_CR15","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/1380584.1380587","volume":"40","author":"PC Chapin","year":"2008","unstructured":"Chapin, P.C., Skalka, C., Wang, X.S.: Authorization in trust management: features and foundations. ACM Comput. Surv. 40(3), 1\u201348 (2008)","journal-title":"ACM Comput. Surv."},{"key":"10077_CR16","doi-asserted-by":"crossref","unstructured":"Cotrini, C., Weghorn, T., Basin, D.: Mining ABAC rules from sparse logs. In: 2018 IEEE European Symposium on Security and Privacy (EuroS&P), 31\u201346 (2018). IEEE","DOI":"10.1109\/EuroSP.2018.00011"},{"key":"10077_CR17","doi-asserted-by":"crossref","unstructured":"Abu\u00a0Jabal, A., Bertino, E., Lobo, J., Law, M., Russo, A., Calo, S., Verma, D.: Polisma-a framework for learning attribute-based access control policies. In: Computer Security\u2013ESORICS 2020: 25th European Symposium on Research in Computer Security, ESORICS 2020, Guildford, UK, September 14\u201318, 2020, Proceedings, Part I 25, 523\u2013544 (2020). Springer","DOI":"10.1007\/978-3-030-58951-6_26"},{"issue":"1","key":"10077_CR18","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1186\/s42400-018-0019-2","volume":"2","author":"M Alohaly","year":"2019","unstructured":"Alohaly, M., Takabi, H., Blanco, E.: Automated extraction of attributes from natural language attribute-based access control (ABAC) policies. Cybersecurity 2(1), 2 (2019)","journal-title":"Cybersecurity"},{"key":"10077_CR19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103717","volume":"139","author":"S Shang","year":"2024","unstructured":"Shang, S., Wang, X., Liu, A.: ABAC policy mining method based on hierarchical clustering and relationship extraction. Comput. Secur. 139, 103717 (2024)","journal-title":"Comput. Secur."},{"issue":"9","key":"10077_CR20","doi-asserted-by":"publisher","first-page":"1065","DOI":"10.1007\/s11227-025-07539-6","volume":"81","author":"S Siyuan","year":"2025","unstructured":"Siyuan, S., Aodi, L., Xuehui, D., Xiaohan, W., Ming, T.: ABAC policy mining method for heterogeneous access control system: S. Siyuan et al. J. Supercomput. 81(9), 1065 (2025)","journal-title":"J. Supercomput."},{"issue":"1","key":"10077_CR21","doi-asserted-by":"publisher","first-page":"339","DOI":"10.1109\/TR.2021.3089511","volume":"71","author":"C Togay","year":"2021","unstructured":"Togay, C., Kasif, A., Catal, C., Tekinerdogan, B.: A firewall policy anomaly detection framework for reliable network security. IEEE Trans. Reliab. 71(1), 339\u2013347 (2021)","journal-title":"IEEE Trans. Reliab."},{"issue":"1","key":"10077_CR22","doi-asserted-by":"publisher","first-page":"6476274","DOI":"10.1155\/2022\/6476274","volume":"2022","author":"Y He","year":"2022","unstructured":"He, Y., Huang, D., Chen, L., Ni, Y., Ma, X.: A survey on zero trust architecture: challenges and future trends. Wirel. Commun. Mob. Comput. 2022(1), 6476274 (2022)","journal-title":"Wirel. Commun. Mob. Comput."},{"key":"10077_CR23","doi-asserted-by":"crossref","unstructured":"Bui, T., Stoller, S.D.: Learning attribute-based and relationship-based access control policies with unknown values. In: International Conference on Information Systems Security, 23\u201344 (2020). Springer","DOI":"10.1007\/978-3-030-65610-2_2"},{"key":"10077_CR24","doi-asserted-by":"crossref","unstructured":"Alohaly, M., Takabi, H., Blanco, E.: A deep learning approach for extracting attributes of ABAC policies. In: Proceedings of the 23nd ACM on Symposium on Access Control Models and Technologies, 137\u2013148 (2018)","DOI":"10.1145\/3205977.3205984"},{"key":"10077_CR25","unstructured":"Mocanu, D., Turkmen, F., Liotta, A.: Towards ABAC policy mining from logs with deep learning. In: The 18th International Multiconference, IS2015, Intelligent Systems, Ljubljana, Slovenia. (2015)"},{"issue":"11","key":"10077_CR26","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3663366","volume":"56","author":"C N\u00fa\u00f1ez-Molina","year":"2024","unstructured":"N\u00fa\u00f1ez-Molina, C., Mesejo, P., Fern\u00e1ndez-Olivares, J.: A review of symbolic, subsymbolic and hybrid methods for sequential decision making. ACM Comput. Surv. 56(11), 1\u201336 (2024)","journal-title":"ACM Comput. Surv."},{"key":"10077_CR27","doi-asserted-by":"crossref","unstructured":"Nobi, M.N., Krishnan, R., Huang, Y., Sandhu, R.: Administration of machine learning based access control. In: European Symposium on Research in Computer Security, 189\u2013210 (2022). Springer","DOI":"10.1007\/978-3-031-17146-8_10"},{"issue":"6","key":"10077_CR28","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/3645103","volume":"56","author":"G Ciatto","year":"2024","unstructured":"Ciatto, G., Sabbatini, F., Agiollo, A., Magnini, M., Omicini, A.: Symbolic knowledge extraction and injection with sub-symbolic predictors: a systematic literature review. ACM Comput. Surv. 56(6), 1\u201335 (2024)","journal-title":"ACM Comput. Surv."},{"key":"10077_CR29","doi-asserted-by":"crossref","unstructured":"Mazel, J., Casas, P., Labit, Y., Owezarski, P.: Sub-space clustering, inter-clustering results association & anomaly correlation for unsupervised network anomaly detection. In: 2011 7th International Conference on Network and Service Management, 1\u20138 (2011). IEEE","DOI":"10.1007\/978-3-642-20305-3_2"},{"key":"10077_CR30","doi-asserted-by":"crossref","unstructured":"Owezarski, P.: Unsupervised classification and characterization of honeypot attacks. In: 10th International Conference on Network and Service Management (CNSM) and Workshop, 10\u201318 (2014). IEEE","DOI":"10.1109\/CNSM.2014.7014136"},{"issue":"3","key":"10077_CR31","doi-asserted-by":"publisher","first-page":"696","DOI":"10.1109\/TNSM.2016.2597443","volume":"13","author":"D Apiletti","year":"2016","unstructured":"Apiletti, D., Baralis, E., Cerquitelli, T., Garza, P., Giordano, D., Mellia, M., Venturini, L.: Selina: a self-learning insightful network analyzer. IEEE Trans. Netw. Serv. Manage. 13(3), 696\u2013710 (2016)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"issue":"2","key":"10077_CR32","doi-asserted-by":"publisher","first-page":"1601","DOI":"10.1109\/TNSM.2023.3340146","volume":"21","author":"GG Gonzalez","year":"2023","unstructured":"Gonzalez, G.G., Tagliafico, S.M., Fernandez, A., Sena, G.G., Acuna, J., Casas, P.: One model to find them all deep learning for multivariate time-series anomaly detection in mobile network data. IEEE Trans. Netw. Serv. Manage. 21(2), 1601\u20131616 (2023)","journal-title":"IEEE Trans. Netw. Serv. Manage."},{"key":"10077_CR33","doi-asserted-by":"crossref","unstructured":"Al-Shaer, E.S., Hamed, H.H.: Firewall policy advisor for anomaly discovery and rule editing. In: International Symposium on Integrated Network Management, 17\u201330 (2003). Springer","DOI":"10.1007\/978-0-387-35674-7_2"},{"key":"10077_CR34","unstructured":"Hall\u00e9, S., Ngoup\u00e9, \u00c9.L., Villemaire, R., Cherkaoui, O.: Distributed firewall anomaly detection through ltl model checking. In: 2013 IFIP\/IEEE International Symposium on Integrated Network Management (IM 2013), 194\u2013201 (2013). IEEE"},{"issue":"3","key":"10077_CR35","doi-asserted-by":"publisher","first-page":"605","DOI":"10.1007\/s10922-020-09518-z","volume":"28","author":"FN Nife","year":"2020","unstructured":"Nife, F.N., Kotulski, Z.: Application-aware firewall mechanism for software defined networks. J. Netw. Syst. Manage. 28(3), 605\u2013626 (2020)","journal-title":"J. Netw. Syst. Manage."},{"key":"10077_CR36","unstructured":"Pahl, M.-O., Aubet, F.-X.: All eyes on you: distributed multi-dimensional IoT microservice anomaly detection. In: 2018 14th International Conference on Network and Service Management (CNSM), 72\u201380 (2018). IEEE"},{"key":"10077_CR37","doi-asserted-by":"crossref","unstructured":"Burgetov\u00e1, I., Matou\u0161ek, P., Ry\u0161av\u1ef3, O.: Anomaly detection of ics communication using statistical models. In: 2021 17th International Conference on Network and Service Management (CNSM), 166\u2013172 (2021). IEEE","DOI":"10.23919\/CNSM52442.2021.9615510"},{"issue":"1","key":"10077_CR38","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1007\/s10922-023-09782-9","volume":"32","author":"Y Zhang","year":"2024","unstructured":"Zhang, Y., Suleiman, B., Alibasa, M.J., Farid, F.: Privacy-aware anomaly detection in IoT environments using fedgroup: a group-based federated learning approach. J. Netw. Syst. Manage. 32(1), 20 (2024)","journal-title":"J. Netw. Syst. Manage."},{"issue":"6","key":"10077_CR39","doi-asserted-by":"publisher","first-page":"461","DOI":"10.1002\/nem.1945","volume":"26","author":"Q Liao","year":"2016","unstructured":"Liao, Q., Li, T.: Effective network management via dynamic network anomaly visualization. Int. J. Network Manage 26(6), 461\u2013491 (2016)","journal-title":"Int. J. Network Manage"},{"key":"10077_CR40","unstructured":"Kim, H., Mnih, A.: Disentangling by factorising. In: International Conference on Machine Learning, 2649\u20132658 (2018). PMLR"},{"key":"10077_CR41","unstructured":"Van Den Oord, A., Vinyals, O., et al.: Neural discrete representation learning. Adv. Neural Inf. Process. Syst. 30 (2017)"},{"key":"10077_CR42","unstructured":"Belghazi, M.I., Baratin, A., Rajeshwar, S., Ozair, S., Bengio, Y., Courville, A., Hjelm, D.: Mutual information neural estimation. In: International Conference on Machine Learning, 531\u2013540 (2018). PMLR"},{"key":"10077_CR43","unstructured":"WSO2: WSO2 Balana. https:\/\/github.com\/wso2\/balana. Accessed: 2025-07-16 (2014)"},{"key":"10077_CR44","unstructured":"OW2: AuthzForce Community Edition. https:\/\/github.com\/authzforce. Accessed: 2025-07-16 (2024)"},{"issue":"2018","key":"10077_CR45","first-page":"108","volume":"1","author":"I Sharafaldin","year":"2018","unstructured":"Sharafaldin, I., Lashkari, A.H., Ghorbani, A.A.: Toward generating a new intrusion detection dataset and intrusion traffic characterization. ICISSp 1(2018), 108\u2013116 (2018)","journal-title":"ICISSp"},{"key":"10077_CR46","doi-asserted-by":"crossref","unstructured":"Sarhan, M., Layeghy, S., Moustafa, N., Portmann, M.: Netflow datasets for machine learning-based network intrusion detection systems. In: International Conference on Big Data Technologies and Applications, 117\u2013135 (2020). Springer","DOI":"10.1007\/978-3-030-72802-1_9"},{"key":"10077_CR47","unstructured":"Moustafa, N.: Designing an online and reliable statistical anomaly detection framework for dealing with large high-speed network traffic. PhD thesis, UNSW Sydney (2017)"},{"issue":"4","key":"10077_CR48","doi-asserted-by":"publisher","first-page":"2304","DOI":"10.1109\/TDSC.2021.3054331","volume":"19","author":"L Karimi","year":"2021","unstructured":"Karimi, L., Aldairi, M., Joshi, J., Abdelhakim, M.: An automatic attribute-based access control policy extraction from access logs. IEEE Trans. Dependable Secure Comput. 19(4), 2304\u20132317 (2021)","journal-title":"IEEE Trans. Dependable Secure Comput."},{"key":"10077_CR49","unstructured":"Lundberg, S.M., Lee, S.-I.: A unified approach to interpreting model predictions. Adv. Neural Inf. Process. Syst. 30 (2017)"}],"container-title":["Journal of Network and Systems Management"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10077-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s10922-026-10077-y","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s10922-026-10077-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,23]],"date-time":"2026-05-23T03:48:03Z","timestamp":1779508083000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s10922-026-10077-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,23]]},"references-count":49,"journal-issue":{"issue":"4","published-print":{"date-parts":[[2026,10]]}},"alternative-id":["10077"],"URL":"https:\/\/doi.org\/10.1007\/s10922-026-10077-y","relation":{},"ISSN":["1064-7570","1573-7705"],"issn-type":[{"value":"1064-7570","type":"print"},{"value":"1573-7705","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,23]]},"assertion":[{"value":"6 January 2026","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 April 2026","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 April 2026","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"23 May 2026","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"99"}}