{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,12]],"date-time":"2026-06-12T09:08:03Z","timestamp":1781255283739,"version":"3.54.1"},"reference-count":34,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2024,12,26]],"date-time":"2024-12-26T00:00:00Z","timestamp":1735171200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2024,12,26]],"date-time":"2024-12-26T00:00:00Z","timestamp":1735171200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"published-print":{"date-parts":[[2025,1]]},"DOI":"10.1007\/s11227-024-06465-3","type":"journal-article","created":{"date-parts":[[2024,12,26]],"date-time":"2024-12-26T10:39:02Z","timestamp":1735209542000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":2,"title":["PRIORITI: scoring and categorization-based threat prioritization"],"prefix":"10.1007","volume":"81","author":[{"given":"Rajendra","family":"Patil","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Sivaanandh","family":"Muneeswaran","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Vinay","family":"Sachidananda","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Peng","family":"Hongyi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohan","family":"Gurusamy","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2024,12,26]]},"reference":[{"key":"6465_CR1","first-page":"137","volume":"2020","author":"J Ministr","year":"2020","unstructured":"Ministr J (2020) Principles of creation a cyber attack response plan. IT Pract 2020:137","journal-title":"IT Pract"},{"key":"6465_CR2","doi-asserted-by":"crossref","unstructured":"Aminanto ME, Zhu L, Ban T, Isawa R, Takahashi T, Inoue D (2019) Automated threat-alert screening for battling alert fatigue with temporal isolation forest. In: 17th International Conference on Privacy, Security and Trust (PST), pp 1\u20133. IEEE","DOI":"10.1109\/PST47121.2019.8949029"},{"key":"6465_CR3","doi-asserted-by":"crossref","unstructured":"Hassan WU, Bates A, Marino D (2020) Tactical provenance analysis for endpoint detection and response systems. In: IEEE Symposium on Security and Privacy (SP), pp 1172\u20131189. IEEE","DOI":"10.1109\/SP40000.2020.00096"},{"key":"6465_CR4","doi-asserted-by":"crossref","unstructured":"Hassan WU, Guo S, Li D, Chen Z, Jee K, Li Z, Bates A (2019) Nodoze: combatting threat alert fatigue with automated provenance triage. In: Network and Distributed Systems Security Symposium","DOI":"10.14722\/ndss.2019.23349"},{"key":"6465_CR5","doi-asserted-by":"crossref","unstructured":"McElwee S, Heaton J, Fraley J, Cannady J (2017) Deep learning for prioritizing and responding to intrusion detection alerts. In: Military Communications Conference (MILCOM), pp 1\u20135. IEEE","DOI":"10.1109\/MILCOM.2017.8170757"},{"key":"6465_CR6","first-page":"172","volume":"15","author":"M Bromiley","year":"2016","unstructured":"Bromiley M (2016) Threat intelligence: what it is, and how to use it effectively. SANS Inst InfoSec Reading Room 15:172","journal-title":"SANS Inst InfoSec Reading Room"},{"key":"6465_CR7","doi-asserted-by":"crossref","unstructured":"Conti M, Dargahi T, Dehghantanha A (2018) Cyber threat intelligence: challenges and opportunities. Cyber Threat Intelligence, Springer International Publishing, pp 1\u20136","DOI":"10.1007\/978-3-319-73951-9_1"},{"key":"6465_CR8","unstructured":"Shackleford D (2015) Who\u2019s using cyberthreat intelligence and how. SANS Institute"},{"key":"6465_CR9","first-page":"1","volume":"11","author":"S Barnum","year":"2012","unstructured":"Barnum S (2012) Standardizing cyber threat intelligence information with the structured threat information expression (stix). Mitre Corpor 11:1\u201322","journal-title":"Mitre Corpor"},{"key":"6465_CR10","unstructured":"McAfee (2017) McAfee, alert fatigue: 31.9% of IT security professionals ignore alerts"},{"key":"6465_CR11","doi-asserted-by":"crossref","unstructured":"Suwanda A, Lim C (2020) Mal-tscore: a threat score framework based on static and dynamic analysis features. In: Proceedings of the International Conference on Engineering and Information Technology for Sustainable Industry, pp 1\u20136","DOI":"10.1145\/3429789.3429819"},{"key":"6465_CR12","doi-asserted-by":"crossref","unstructured":"Walker A, Amjad MF, Sengupta S (2019) Cuckoo\u2019s malware threat scoring and classification: Friend or foe? In: 9th Annual Computing and Communication Workshop and Conference (CCWC), pp 0678\u20130684. IEEE","DOI":"10.1109\/CCWC.2019.8666454"},{"key":"6465_CR13","doi-asserted-by":"publisher","DOI":"10.1016\/j.sysarc.2021.102073","volume":"117","author":"Q Rouland","year":"2021","unstructured":"Rouland Q, Hamid B, Jaskolka J (2021) Specification, detection, and treatment of stride threats for software components: modeling, formal methods, and tool support. J Syst Architect 117:102073","journal-title":"J Syst Architect"},{"key":"6465_CR14","doi-asserted-by":"publisher","first-page":"488","DOI":"10.1016\/j.future.2020.07.015","volume":"113","author":"JC Sancho","year":"2020","unstructured":"Sancho JC, Caro A, \u00c1vila M, Bravo A (2020) New approach for threat classification and security risk estimations based on security event management. Futur Gener Comput Syst 113:488\u2013505","journal-title":"Futur Gener Comput Syst"},{"key":"6465_CR15","doi-asserted-by":"crossref","unstructured":"Schaad A, Binder D (2020) Ml-supported identification and prioritization of threats in the ovvl threat modelling tool. In: IFIP Annual Conference on Data and Applications Security and Privacy, pp 274\u2013285. Springer","DOI":"10.1007\/978-3-030-49669-2_16"},{"key":"6465_CR16","doi-asserted-by":"crossref","unstructured":"Kim J-Y, Kwon H-Y (2022) Threat classification model for security information event management focusing on model efficiency. Comput Secur 120:102789","DOI":"10.1016\/j.cose.2022.102789"},{"key":"6465_CR17","doi-asserted-by":"crossref","unstructured":"Ahmed T, Shah A, Kolla M, Yellasiri R (2021) Reduction of alert fatigue using extended isolation forest. In: International Conference on Forensics, Analytics, Big Data, Security (FABS), vol. 1, pp 1\u20135 . IEEE","DOI":"10.1109\/FABS52071.2021.9702617"},{"key":"6465_CR18","doi-asserted-by":"publisher","first-page":"217977","DOI":"10.1109\/ACCESS.2020.3041837","volume":"8","author":"ME Aminanto","year":"2020","unstructured":"Aminanto ME, Ban T, Isawa R, Takahashi T, Inoue D (2020) Threat alert prioritization using isolation forest and stacked auto encoder with day-forward-chaining analysis. IEEE Access 8:217977\u2013217986","journal-title":"IEEE Access"},{"key":"6465_CR19","doi-asserted-by":"crossref","unstructured":"Ban T, Samuel N, Takahashi T, Inoue D (2021) Combat security alert fatigue with AI-assisted techniques. In: Cyber Security Experimentation and Test Workshop, pp 9\u201316","DOI":"10.1145\/3474718.3474723"},{"key":"6465_CR20","doi-asserted-by":"crossref","unstructured":"Ndichu S, Ban T, Takahashi T, Inoue D (2021) A machine learning approach to detection of critical alerts from imbalanced multi-appliance threat alert logs. In: International Conference on Big Data, pp 2119\u20132127. IEEE","DOI":"10.1109\/BigData52589.2021.9671956"},{"key":"6465_CR21","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103583","volume":"137","author":"X Wang","year":"2024","unstructured":"Wang X, Yang X, Liang X, Zhang X, Zhang W, Gong X (2024) Combating alert fatigue with Alertpro: context-aware alert prioritization using reinforcement learning for multi-step attack detection. Comput Sec 137:103583","journal-title":"Comput Sec"},{"key":"6465_CR22","doi-asserted-by":"crossref","unstructured":"Reimers N, Gurevych I (2019) Sentence-BERT: sentence embeddings using Siamese BERT-networks","DOI":"10.18653\/v1\/D19-1410"},{"key":"6465_CR23","unstructured":"Devlin J, Chang M-W, Lee K, Toutanova K (2019) BERT: pre-training of deep bidirectional transformers for language understanding"},{"key":"6465_CR24","doi-asserted-by":"crossref","unstructured":"Schroff F, Kalenichenko D, Philbin J (2015) Facenet: A unified embedding for face recognition and clustering. In: Conference on Computer Vision and Pattern Recognition (CVPR). IEEE","DOI":"10.1109\/CVPR.2015.7298682"},{"key":"6465_CR25","doi-asserted-by":"crossref","unstructured":"Ouyang G, Huang Y, Zhang C (2022) Analyzing the usefulness of the darpa transparent computing e5 dataset in apt detection research. In: International Conference on Computer, Artificial Intelligence, and Control Engineering (CAICE 2022), vol. 12288, pp 400\u2013409. SPIE","DOI":"10.1117\/12.2641011"},{"issue":"2","key":"6465_CR26","doi-asserted-by":"publisher","first-page":"793","DOI":"10.1109\/TCC.2018.2883063","volume":"9","author":"A Nhlabatsi","year":"2018","unstructured":"Nhlabatsi A, Hong JB, Kim DS, Fernandez R, Hussein A, Fetais N, Khan KM (2018) Threat-specific security risk evaluation in the cloud. IEEE Trans Cloud Comput 9(2):793\u2013806","journal-title":"IEEE Trans Cloud Comput"},{"key":"6465_CR27","doi-asserted-by":"publisher","first-page":"201","DOI":"10.1016\/j.infsof.2018.10.006","volume":"106","author":"A Ampatzoglou","year":"2019","unstructured":"Ampatzoglou A, Bibi S, Avgeriou P, Verbeek M, Chatzigeorgiou A (2019) Identifying, categorizing and mitigating threats to validity in software engineering secondary studies. Inf Softw Technol 106:201\u2013230","journal-title":"Inf Softw Technol"},{"key":"6465_CR28","unstructured":"Donovan F (2020) What is stride and how does it anticipate cyberattacks? https:\/\/securityintelligence.com\/articles\/what-is-stride-threat-modeling-anticipate-cyberattacks\/. IBM"},{"key":"6465_CR29","doi-asserted-by":"crossref","unstructured":"Schlegel R, Obermeier S, Schneider J (2015) Structured system threat modeling and mitigation analysis for industrial automation systems. In: 13th International Conference on Industrial Informatics (INDIN), pp 197\u2013203. IEEE","DOI":"10.1109\/INDIN.2015.7281734"},{"key":"6465_CR30","doi-asserted-by":"publisher","first-page":"489","DOI":"10.1016\/j.procs.2014.05.452","volume":"32","author":"M Jouini","year":"2014","unstructured":"Jouini M, Rabai LBA, Aissa AB (2014) Classification of security threats in information systems. Proc Comput Sci 32:489\u2013496","journal-title":"Proc Comput Sci"},{"key":"6465_CR31","unstructured":"Torrey J (2020) Transparent computing engagement 5 data release. https:\/\/github.com\/darpa-i2o\/Transparent-Computing"},{"key":"6465_CR32","doi-asserted-by":"crossref","unstructured":"Ndichu S, Ban T, Takahashi T, Inoue D (2023) Machine learning\u2013based security alert screening with focal loss. In: International Conference on Big Data, pp 3043\u20133052. IEEE","DOI":"10.1109\/BigData59044.2023.10386263"},{"issue":"10","key":"6465_CR33","doi-asserted-by":"publisher","first-page":"2138","DOI":"10.3390\/sym14102138","volume":"14","author":"G Yang","year":"2022","unstructured":"Yang G, Tang C, Liu X (2022) Dualac2nn: revisiting and alleviating alert fatigue from the detection perspective. Symmetry 14(10):2138","journal-title":"Symmetry"},{"key":"6465_CR34","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103529","volume":"135","author":"J Forsberg","year":"2023","unstructured":"Forsberg J, Frantti T (2023) Technical performance metrics of a security operations center. Comput Sec 135:103529","journal-title":"Comput Sec"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-024-06465-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11227-024-06465-3\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-024-06465-3.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,12,26]],"date-time":"2024-12-26T11:03:55Z","timestamp":1735211035000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11227-024-06465-3"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,26]]},"references-count":34,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2025,1]]}},"alternative-id":["6465"],"URL":"https:\/\/doi.org\/10.1007\/s11227-024-06465-3","relation":{},"ISSN":["0920-8542","1573-0484"],"issn-type":[{"value":"0920-8542","type":"print"},{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,12,26]]},"assertion":[{"value":"7 October 2024","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"26 December 2024","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"This article does not contain any studies with human participants or animals performed by any of the authors.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethical Approval"}},{"value":"The authors declare that they have no known competing financial interests or personal relationships that could have appeared to influence the work reported in this paper.","order":3,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"335"}}