{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,2,21]],"date-time":"2026-02-21T20:32:43Z","timestamp":1771705963447,"version":"3.50.1"},"reference-count":36,"publisher":"Springer Science and Business Media LLC","issue":"4","license":[{"start":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T00:00:00Z","timestamp":1740873600000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T00:00:00Z","timestamp":1740873600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["J Supercomput"],"DOI":"10.1007\/s11227-025-07051-x","type":"journal-article","created":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T19:22:56Z","timestamp":1740943376000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":3,"title":["Research on APT group classification method based on graph attention networks"],"prefix":"10.1007","volume":"81","author":[{"given":"Yazhou","family":"Du","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Weiwu","family":"Ren","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xintong","family":"Song","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Wenjuan","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,3,2]]},"reference":[{"issue":"12","key":"7051_CR1","doi-asserted-by":"publisher","first-page":"1533","DOI":"10.1587\/transinf.2024EDL8046","volume":"E107","author":"S Lee","year":"2024","unstructured":"Lee S, Kim C, Park H (2024) Practical apt group hash unit profiling framework using ttps. IEICE Trans Inform Syst E107(12):1533\u20131537. https:\/\/doi.org\/10.1587\/transinf.2024EDL8046","journal-title":"IEICE Trans Inform Syst"},{"issue":"1","key":"7051_CR2","doi-asserted-by":"publisher","first-page":"740","DOI":"10.1109\/TDSC.2022.3143551","volume":"20","author":"T Li","year":"2023","unstructured":"Li T, Jiang Y, Lin C, Obaidat MSS, Shen Y, Ma J (2023) Deepag: attack graph construction and threats prediction with bi-directional deep learning. IEEE Trans Depend Secure Comput 20(1):740\u2013757. https:\/\/doi.org\/10.1109\/TDSC.2022.3143551","journal-title":"IEEE Trans Depend Secure Comput"},{"issue":"7","key":"7051_CR3","doi-asserted-by":"publisher","first-page":"9355","DOI":"10.1007\/s12652-023-04603-y","volume":"14","author":"A Sharma","year":"2023","unstructured":"Sharma A, Gupta BB, Singh AK, Saraswat V (2023) Advanced persistent threats (apt): evolution, anatomy, attribution and countermeasures. J Ambient Intell Humaniz Comput 14(7):9355\u20139381","journal-title":"J Ambient Intell Humaniz Comput"},{"key":"7051_CR4","doi-asserted-by":"publisher","first-page":"1179","DOI":"10.1109\/TDSC.2023.3273918","volume":"21","author":"T Li","year":"2023","unstructured":"Li T, Liu X, Qiao W, Zhu X, Shen Y, Ma J (2023) T-trace: constructing the apts provenance graphs through multiple syslogs correlation. IEEE Trans Depend Secure Comput 21:1179\u20131195","journal-title":"IEEE Trans Depend Secure Comput"},{"key":"7051_CR5","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1080\/23742917.2023.2240606","volume":"8","author":"S Yadav","year":"2024","unstructured":"Yadav S (2024) Social automation and apt attributions in national cybersecurity. J Cyber Secur Technol 8:1\u201326","journal-title":"J Cyber Secur Technol"},{"key":"7051_CR6","doi-asserted-by":"crossref","unstructured":"Yuan Y, Adhatarao SS, Lin M, Yuan Y, Liu Z, Fu X (2020) Ada: adaptive deep log anomaly detector. In IEEE INFOCOM 2020-IEEE Conference on Computer Communications, pp 2449\u20132458. IEEE","DOI":"10.1109\/INFOCOM41043.2020.9155487"},{"issue":"3","key":"7051_CR7","doi-asserted-by":"publisher","first-page":"76","DOI":"10.3390\/technologies11030076","volume":"11","author":"Z Muhammad","year":"2023","unstructured":"Muhammad Z, Anwar Z, Javed AR, Saleem B, Abbas S, Gadekallu TR (2023) Smartphone security and privacy: a survey on apts, sensor-based attacks, side-channel attacks, google play attacks, and defenses. Technologies 11(3):76","journal-title":"Technologies"},{"key":"7051_CR8","doi-asserted-by":"publisher","first-page":"141851","DOI":"10.1109\/ACCESS.2024.3469552","volume":"12","author":"Z-S Chen","year":"2024","unstructured":"Chen Z-S, Vaitheeshwari R, Wu EH-K, Lin Y-D, Hwang R-H, Lin P-C, Lai Y-C, Ali A (2024) Clustering apt groups through cyber threat intelligence by weighted similarity measurement. IEEE Access 12:141851\u2013141865","journal-title":"IEEE Access"},{"issue":"5","key":"7051_CR9","doi-asserted-by":"publisher","first-page":"2894","DOI":"10.3390\/app13052894","volume":"13","author":"K Lee","year":"2023","unstructured":"Lee K, Lee J, Yim K (2023) Classification and analysis of malicious code detection techniques based on the apt attack. Appl Sci 13(5):2894","journal-title":"Appl Sci"},{"issue":"4","key":"7051_CR10","first-page":"865","volume":"15","author":"PN Bahrami","year":"2019","unstructured":"Bahrami PN, Dehghantanha A, Dargahi T, Parizi RM, Choo K-KR, Javadi HH (2019) Cyber kill chain-based taxonomy of advanced persistent threat actors: Analogy of tactics, techniques, and procedures. J Inform Process Syst 15(4):865\u2013889","journal-title":"J Inform Process Syst"},{"issue":"6","key":"7051_CR11","doi-asserted-by":"publisher","first-page":"1106","DOI":"10.3390\/electronics13061106","volume":"13","author":"J Li","year":"2024","unstructured":"Li J, Liu J, Zhang R (2024) Advanced persistent threat group correlation analysis via attack behavior patterns and rough sets. Electronics 13(6):1106","journal-title":"Electronics"},{"key":"7051_CR12","volume-title":"Supply chain analysis: from quartermaster to Sunshop","author":"N Moran","year":"2013","unstructured":"Moran N, Bennett JT (2013) Supply chain analysis: from quartermaster to Sunshop, vol 11. FireEye, Milpitas, CA"},{"key":"7051_CR13","unstructured":"Pandazhengzheng (2024) Analysis and defense strategies of APT attacks. Accessed: Dec 21, 2024. https:\/\/blog.csdn.net\/pandazhengzheng\/article\/details\/136267327"},{"key":"7051_CR14","doi-asserted-by":"crossref","unstructured":"Burita L, Le DT (2021) Cyber security and apt groups. In 2021 Communication and Information Technologies (KIT), pp 1\u20137. IEEE","DOI":"10.1109\/KIT52904.2021.9583744"},{"key":"7051_CR15","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104209","volume":"149","author":"J-S Lee","year":"2025","unstructured":"Lee J-S, Fan Y-Y, Cheng C-H, Chew C-J, Kuo C-W (2025) Ml-based intrusion detection system for precise apt cyber-clustering. Comput Secur 149:104209","journal-title":"Comput Secur"},{"key":"7051_CR16","doi-asserted-by":"publisher","DOI":"10.1007\/s44196-023-00369-5","author":"W Ren","year":"2023","unstructured":"Ren W, Song X, Hong Y, Lei Y, Yao J, Du Y, Li W (2023) Apt attack detection based on graph convolutional neural networks. Int J Comput Intell Syst. https:\/\/doi.org\/10.1007\/s44196-023-00369-5","journal-title":"Int J Comput Intell Syst"},{"key":"7051_CR17","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104263","volume":"150","author":"L Xu","year":"2024","unstructured":"Xu L, Zhao Z, Zhao D, Li X, Lu X, Yan D (2024) Ajsage: a intrusion detection scheme based on jump-knowledge connection to graphsage. Comput Secur 150:104263","journal-title":"Comput Secur"},{"key":"7051_CR18","doi-asserted-by":"publisher","first-page":"699","DOI":"10.1109\/TIFS.2022.3228493","volume":"18","author":"G Duan","year":"2023","unstructured":"Duan G, Lv H, Wang H, Feng G (2023) Application of a dynamic line graph neural network for intrusion detection with semisupervised learning. IEEE Trans Inform For Secur 18:699\u2013714. https:\/\/doi.org\/10.1109\/TIFS.2022.3228493","journal-title":"IEEE Trans Inform For Secur"},{"issue":"9","key":"7051_CR19","doi-asserted-by":"publisher","first-page":"3113","DOI":"10.1007\/s13042-023-01824-7","volume":"14","author":"G Tang","year":"2023","unstructured":"Tang G, Yang L, Zhang L, Cao W, Meng L, He H, Kuang H, Yang F, Wang H (2023) An attention-based automatic vulnerability detection approach with ggnn. Int J Mach Learn Cyber 14(9):3113\u20133127. https:\/\/doi.org\/10.1007\/s13042-023-01824-7","journal-title":"Int J Mach Learn Cyber"},{"key":"7051_CR20","doi-asserted-by":"crossref","unstructured":"Cai Y, Gu Z, Wang L, Li S, Han W (2020) An apt group knowledge model based on mdata. In Proceedings of the 2020 International Conference on Cyberspace Innovation of Advanced Technologies, pp 374\u2013378","DOI":"10.1145\/3444370.3444600"},{"issue":"2","key":"7051_CR21","doi-asserted-by":"publisher","first-page":"10","DOI":"10.13705\/j.issn.1671-6841.20221417","volume":"55","author":"Y Lyu","year":"2023","unstructured":"Lyu Y, Wang Z, Yang X, Song W, Peng G (2023) A novel apt malware classification method based on feature function code. J Zhengzhou Univ (Natur Sci Ed) 55(2):10\u201318. https:\/\/doi.org\/10.13705\/j.issn.1671-6841.20221417","journal-title":"J Zhengzhou Univ (Natur Sci Ed)"},{"key":"7051_CR22","doi-asserted-by":"publisher","DOI":"10.1016\/j.jisa.2022.103207","author":"J Liu","year":"2022","unstructured":"Liu J, Liu Y, Li J, Sun W, Cheng J, Zhang R, Huang X, Pang J (2022) Two statistical traffic features for certain apt group identification. J Inform Secur Appl. https:\/\/doi.org\/10.1016\/j.jisa.2022.103207","journal-title":"J Inform Secur Appl"},{"key":"7051_CR23","doi-asserted-by":"crossref","unstructured":"Saha A, Blasco J, Cavallaro L, Lindorfer M (2024) Adapt it! automating apt campaign and group attribution by leveraging and linking heterogeneous files. In Proceedings of the 27th International Symposium on Research in Attacks, Intrusions and Defenses, pp 114\u2013129","DOI":"10.1145\/3678890.3678909"},{"issue":"2","key":"7051_CR24","doi-asserted-by":"publisher","first-page":"2675","DOI":"10.32604\/cmc.2024.052447","volume":"80","author":"S Krishnapriya","year":"2024","unstructured":"Krishnapriya S, Singh S (2024) A comprehensive survey on advanced persistent threat (apt) detection techniques. CMC-Comput Mater Contin 80(2):2675\u20132719. https:\/\/doi.org\/10.32604\/cmc.2024.052447","journal-title":"CMC-Comput Mater Contin"},{"issue":"2","key":"7051_CR25","first-page":"84","volume":"1","author":"M Fahad","year":"2023","unstructured":"Fahad M, Kumar A, Arif H, Hussain HK (2023) Mastering apt defense: strategies, technologies, and collaboration. BIN: Bull Inform 1(2):84\u201394","journal-title":"BIN: Bull Inform"},{"key":"7051_CR26","unstructured":"Cybersecurity and Infrastructure Security Agency (CISA) (2023) CISA cybersecurity advisory: AA23-108A - APT actors exploiting CVE-2023-23397 and other vulnerabilities. Accessed: 2025-02-01. https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa23-108"},{"key":"7051_CR27","unstructured":"Kaspersky (2023) Lazarus Group\u2019s new malware: a detailed analysis. Accessed: 2025-02-01. https:\/\/securelist.com\/lazarus-new-malware\/115059\/"},{"key":"7051_CR28","volume-title":"Motives and tactics, techniques, and procedures: making sense of the activities of Russian advanced persistent threat groups","author":"J Mancuso","year":"2023","unstructured":"Mancuso J (2023) Motives and tactics, techniques, and procedures: making sense of the activities of Russian advanced persistent threat groups. Utica University, Utica, NY"},{"key":"7051_CR29","doi-asserted-by":"crossref","unstructured":"Abbas-Escribano M, Debar H (2023) An improved honeypot model for attack detection and analysis. In Proceedings of the 18th International Conference on Availability, Reliability and Security, pp 1\u201310","DOI":"10.1145\/3600160.3604993"},{"issue":"2","key":"7051_CR30","doi-asserted-by":"publisher","first-page":"595","DOI":"10.1007\/s12559-023-10222-8","volume":"16","author":"Z La","year":"2024","unstructured":"La Z, Qian Y, Leng H, Gu T, Gong W, Chen J (2024) Mc-gat: multi-channel graph attention networks for capturing diverse information in complex graphs. Cogn Comput 16(2):595\u2013607","journal-title":"Cogn Comput"},{"key":"7051_CR31","doi-asserted-by":"crossref","unstructured":"Ling Y, Li X, Bin D, Yang C, Han S, Lu J, Ming S, Li J (2024) Graph attention mechanism-based method for tracing apt attacks in power systems. In 2024 IEEE 4th International Conference on Power, Electronics and Computer Applications (ICPECA), pp 23\u201327. IEEE","DOI":"10.1109\/ICPECA60615.2024.10471063"},{"key":"7051_CR32","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103524","volume":"136","author":"X Zhao","year":"2024","unstructured":"Zhao X, Jiang R, Han Y, Li A, Peng Z (2024) A survey on cybersecurity knowledge graph construction. Comput Secur 136:103524","journal-title":"Comput Secur"},{"issue":"9","key":"7051_CR33","doi-asserted-by":"publisher","first-page":"3511","DOI":"10.1007\/s10115-023-01860-3","volume":"65","author":"LF Sikos","year":"2023","unstructured":"Sikos LF (2023) Cybersecurity knowledge graphs. Knowl Inf Syst 65(9):3511\u20133531","journal-title":"Knowl Inf Syst"},{"key":"7051_CR34","unstructured":"Mandiant (2021) APT28: A window into Russia\u2019s cyber espionage group. Accessed: 2024-12-27. https:\/\/www.mandiant.com\/sites\/default\/files\/2021-09\/APT28-Center-of-Storm-2017.pdf"},{"key":"7051_CR35","unstructured":"FreeBuf (2019) Analysis and attribution of the first APT attack using the \"Double Kill\" 0day vulnerability (CVE-2018-8174) by APT-C-06. Accessed: 2024-12-27. https:\/\/www.freebuf.com\/articles\/paper\/171254.html"},{"key":"7051_CR36","unstructured":"Microsoft (2024) Analyzing forest Blizzard\u2019s custom post-compromise tool for exploiting CVE-2022-38028 to obtain credentials. Accessed: 2024-12-27. https:\/\/www.microsoft.com\/en-us\/security\/blog\/2024\/04\/22\/analyzing-forest-blizzards-custom-post-compromise-tool-for-exploiting-cve-2022-38028-to-obtain-credentials"}],"container-title":["The Journal of Supercomputing"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-025-07051-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11227-025-07051-x\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11227-025-07051-x.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,3,2]],"date-time":"2025-03-02T19:23:06Z","timestamp":1740943386000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11227-025-07051-x"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,3,2]]},"references-count":36,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,3]]}},"alternative-id":["7051"],"URL":"https:\/\/doi.org\/10.1007\/s11227-025-07051-x","relation":{},"ISSN":["1573-0484"],"issn-type":[{"value":"1573-0484","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,3,2]]},"assertion":[{"value":"12 February 2025","order":1,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"2 March 2025","order":2,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare no Conflict of interest.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Conflict of interest"}}],"article-number":"563"}}