{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T19:48:24Z","timestamp":1784404104342,"version":"3.55.0"},"reference-count":40,"publisher":"Springer Science and Business Media LLC","issue":"10","license":[{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T00:00:00Z","timestamp":1738022400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Front. Comput. Sci."],"published-print":{"date-parts":[[2025,10]]},"DOI":"10.1007\/s11704-024-40610-8","type":"journal-article","created":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T12:50:34Z","timestamp":1738068634000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":8,"title":["Advanced persistent threat detection via mining long-term features in provenance graphs"],"prefix":"10.1007","volume":"19","author":[{"given":"Fan","family":"Xu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qinxin","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xiaoxiao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Nan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Meiqi","family":"Gao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xuezhi","family":"Wen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Dalin","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2025,1,28]]},"reference":[{"issue":"3","key":"40610_CR1","doi-asserted-by":"publisher","first-page":"472","DOI":"10.1109\/TCC.2015.2489211","volume":"5","author":"T F J M Pasquier","year":"2017","unstructured":"Pasquier T F J M, Singh J, Eyers D, Bacon J. Camflow: managed data-sharing for cloud services. IEEE Transactions on Cloud Computing, 2017, 5(3): 472\u2013484","journal-title":"IEEE Transactions on Cloud Computing"},{"key":"40610_CR2","first-page":"9214","volume-title":"Proceedings of the 38th AAAI Conference on Artificial Intelligence","author":"F Xu","year":"2024","unstructured":"Xu F, Wang N, Wu H, Wen X, Zhao X, Wan H. Revisiting graph-based fraud detection in sight of heterophily and spectrum. In: Proceedings of the 38th AAAI Conference on Artificial Intelligence. 2024, 9214\u20139222"},{"key":"40610_CR3","doi-asserted-by":"publisher","first-page":"101734","DOI":"10.1016\/j.cose.2020.101734","volume":"92","author":"B Stojanovi\u0107","year":"2020","unstructured":"Stojanovi\u0107 B, Hofer-Schmitz K, Kleb U. Apt datasets and attack modeling for automated detection methods: a review. Computers & Security, 2020, 92: 101734","journal-title":"Computers & Security"},{"issue":"10","key":"40610_CR4","doi-asserted-by":"publisher","first-page":"1684","DOI":"10.3390\/electronics9101684","volume":"9","author":"H Hindy","year":"2020","unstructured":"Hindy H, Atkinson R, Tachtatzis C, Colin J N, Bayne E, Bellekens X. Utilising deep learning techniques for effective zero-day attack detection. Electronics, 2020, 9(10): 1684","journal-title":"Electronics"},{"issue":"1","key":"40610_CR5","doi-asserted-by":"publisher","first-page":"495","DOI":"10.1109\/TDSC.2020.2973992","volume":"19","author":"F Erlacher","year":"2022","unstructured":"Erlacher F, Dressler F. On high-speed flow-based intrusion detection using snort-compatible signatures. IEEE Transactions on Dependable and Secure Computing, 2022, 19(1): 495\u2013506","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"40610_CR6","doi-asserted-by":"publisher","first-page":"102282","DOI":"10.1016\/j.cose.2021.102282","volume":"106","author":"Z Li","year":"2021","unstructured":"Li Z, Chen Q A, Yang R, Chen Y, Ruan W. Threat detection and investigation with system-level provenance graphs: a survey. Computers & Security, 2021, 106: 102282","journal-title":"Computers & Security"},{"key":"40610_CR7","first-page":"498","volume-title":"Proceedings of the 7th IEEE International Conference on Data Science in Cyberspace","author":"Y Lv","year":"2022","unstructured":"Lv Y, Qin S, Zhu Z, Yu Z, Li S, Han W. A review of provenance graph based apt attack detection: applications and developments. In: Proceedings of the 7th IEEE International Conference on Data Science in Cyberspace. 2022, 498\u2013505"},{"key":"40610_CR8","doi-asserted-by":"publisher","first-page":"79","DOI":"10.1016\/j.knosys.2016.05.015","volume":"108","author":"L Sterckx","year":"2016","unstructured":"Sterckx L, Demeester T, Deleu J, Develder C. Knowledge base population using semantic label propagation. Knowledge-Based Systems, 2016, 108: 79\u201391","journal-title":"Knowledge-Based Systems"},{"issue":"1","key":"40610_CR9","doi-asserted-by":"publisher","first-page":"120","DOI":"10.1109\/TVCG.2018.2865024","volume":"25","author":"H Stitz","year":"2019","unstructured":"Stitz H, Gratzl S, Piringer H, Zichner T, Streit M. KnowledgePearls: provenance-based visualization retrieval. IEEE Transactions on Visualization and Computer Graphics, 2019, 25(1): 120\u2013130","journal-title":"IEEE Transactions on Visualization and Computer Graphics"},{"issue":"1","key":"40610_CR10","doi-asserted-by":"publisher","first-page":"155","DOI":"10.1017\/S1351324916000334","volume":"23","author":"K W Church","year":"2017","unstructured":"Church K W. Word2Vec. Natural Language Engineering, 2017, 23(1): 155\u2013162","journal-title":"Natural Language Engineering"},{"key":"40610_CR11","first-page":"337","volume-title":"Proceedings of European Conference on Machine Learning and Knowledge Discovery in Databases","author":"F Xu","year":"2024","unstructured":"Xu F, Wang N, Wu H, Wen X, Zhang D, Lu S, Li B, Gong W, Wan H, Zhao X. Gladformer: a mixed perspective for graph-level anomaly detection. In: Proceedings of European Conference on Machine Learning and Knowledge Discovery in Databases. 2024, 337\u2013353"},{"issue":"4","key":"40610_CR12","doi-asserted-by":"publisher","first-page":"276","DOI":"10.1007\/s007780050029","volume":"5","author":"V Kashyap","year":"1996","unstructured":"Kashyap V, Sheth A. Semantic and schematic similarities between database objects: a context-based approach. The VLDB Journal, 1996, 5(4): 276\u2013304","journal-title":"The VLDB Journal"},{"key":"40610_CR13","doi-asserted-by":"publisher","first-page":"1137","DOI":"10.1109\/SP.2019.00026","volume-title":"Proceedings of 2019 IEEE Symposium on Security and Privacy","author":"S M Milajerdi","year":"2019","unstructured":"Milajerdi S M, Gjomemo R, Eshete B, Sekar R, Venkatakrishnan V N. HOLMES: real-time APT detection through correlation of suspicious information flows. In: Proceedings of 2019 IEEE Symposium on Security and Privacy. 2019, 1137\u20131152"},{"key":"40610_CR14","volume-title":"Proceedings of the 26th Annual Network and Distributed System Security Symposium","author":"W U Hassan","year":"2019","unstructured":"Hassan W U, Guo S, Li D, Chen Z, Jee K, Li Z, Bates A. NoDoze: combatting threat alert fatigue with automated provenance triage. In: Proceedings of the 26th Annual Network and Distributed System Security Symposium. 2019"},{"key":"40610_CR15","first-page":"487","volume-title":"Proceedings of the 26th USENIX Conference on Security Symposium","author":"N Hossain","year":"2017","unstructured":"Hossain N, Milajerdi S M, Wang J, Eshete B, Gjomemo R, Sekar R, Stoller S D, Venkatakrishnan V N. SLEUTH: real-time attack scenario reconstruction from COTS audit data. In: Proceedings of the 26th USENIX Conference on Security Symposium. 2017, 487\u2013504"},{"key":"40610_CR16","doi-asserted-by":"publisher","first-page":"1139","DOI":"10.1109\/SP40000.2020.00064","volume-title":"Proceedings of 2020 IEEE Symposium on Security and Privacy","author":"N Hossain","year":"2020","unstructured":"Hossain N, Sheikhi S, Sekar R. Combating dependence explosion in forensic analysis using alternative tag propagation semantics. In: Proceedings of 2020 IEEE Symposium on Security and Privacy. 2020, 1139\u20131155"},{"key":"40610_CR17","first-page":"1795","volume-title":"Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"S M Milajerdi","year":"2019","unstructured":"Milajerdi S M, Eshete B, Gjomemo R, Venkatakrishnan V N. POIROT: aligning attack behavior with kernel audit records for cyber threat hunting. In: Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security. 2019, 1795\u20131812"},{"key":"40610_CR18","volume-title":"Proceedings of the 27th Annual Network and Distributed System Security Symposium","author":"X Han","year":"2020","unstructured":"Han X, Pasquier T F J M, Bates A, Mickens J, Seltzer M I. Unicorn: runtime provenance-based detector for advanced persistent threats. In: Proceedings of the 27th Annual Network and Distributed System Security Symposium. 2020"},{"issue":"8","key":"40610_CR19","doi-asserted-by":"publisher","first-page":"1463","DOI":"10.1360\/SSI-2021-0252","volume":"52","author":"R Liang","year":"2022","unstructured":"Liang R, Gao Y, Zhao X. Sequence feature extraction-based apt attack detection method with provenance graphs. Scientia Sinica Informationis, 2022, 52(8): 1463\u20131480","journal-title":"Scientia Sinica Informationis"},{"key":"40610_CR20","first-page":"1597","volume-title":"Proceedings of the 60th IEEE International Midwest Symposium on Circuits and Systems","author":"R Dey","year":"2017","unstructured":"Dey R, Salem F M. Gate-variants of gated recurrent unit (GRU) neural networks. In: Proceedings of the 60th IEEE International Midwest Symposium on Circuits and Systems. 2017, 1597\u20131600"},{"key":"40610_CR21","first-page":"1777","volume-title":"Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security","author":"F Liu","year":"2019","unstructured":"Liu F, Wen Y, Zhang D, Jiang X, Xing X, Meng D. Log2vec: a heterogeneous graph embedding based approach for detecting cyber threats within enterprise. In: Proceedings of 2019 ACM SIGSAC Conference on Computer and Communications Security. 2019, 1777\u20131794"},{"issue":"6","key":"40610_CR22","doi-asserted-by":"publisher","first-page":"1283","DOI":"10.1109\/TDSC.2018.2867595","volume":"17","author":"Y Xie","year":"2020","unstructured":"Xie Y, Feng D, Hu Y, Li Y, Sample S, Long D. Pagoda: a hybrid approach to enable efficient real-time provenance based intrusion detection in big data environments. IEEE Transactions on Dependable and Secure Computing, 2020, 17(6): 1283\u20131296","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"40610_CR23","first-page":"1310","volume-title":"Proceedings of the 30th International Conference on Machine Learning","author":"R Pascanu","year":"2013","unstructured":"Pascanu R, Mikolov T, Bengio Y. On the difficulty of training recurrent neural networks. In: Proceedings of the 30th International Conference on Machine Learning. 2013, 1310\u20131318"},{"issue":"8","key":"40610_CR24","doi-asserted-by":"publisher","first-page":"30","DOI":"10.1109\/MC.2009.263","volume":"42","author":"Y Koren","year":"2009","unstructured":"Koren Y, Bell R, Volinsky C. Matrix factorization techniques for recommender systems. Computer, 2009, 42(8): 30\u201337","journal-title":"Computer"},{"key":"40610_CR25","first-page":"2539","volume":"12","author":"N Shervashidze","year":"2011","unstructured":"Shervashidze N, Schweitzer P, van Leeuwen E J, Mehlhorn K, Borgwardt K M. Weisfeiler-Lehman graph kernels. The Journal of Machine Learning Research, 2011, 12: 2539\u20132561","journal-title":"The Journal of Machine Learning Research"},{"key":"40610_CR26","doi-asserted-by":"publisher","first-page":"943","DOI":"10.1613\/jair.1.13225","volume":"72","author":"G Nikolentzos","year":"2021","unstructured":"Nikolentzos G, Siglidis G, Vazirgiannis M. Graph kernels: a survey. Journal of Artificial Intelligence Research, 2021, 72: 943\u20131027","journal-title":"Journal of Artificial Intelligence Research"},{"key":"40610_CR27","volume-title":"Proceedings of the 5th International Conference on Learning Representations","author":"T N Kipf","year":"2017","unstructured":"Kipf T N, Welling M. Semi-supervised classification with graph convolutional networks. In: Proceedings of the 5th International Conference on Learning Representations. 2017"},{"key":"40610_CR28","doi-asserted-by":"publisher","first-page":"354","DOI":"10.1016\/j.patcog.2017.10.013","volume":"77","author":"J Gu","year":"2018","unstructured":"Gu J, Wang Z, Kuen J, Ma L, Shahroudy A, Shuai B, Liu T, Wang X, Wang G, Cai J, Chen T. Recent advances in convolutional neural networks. Pattern Recognition, 2018, 77: 354\u2013377","journal-title":"Pattern Recognition"},{"issue":"1","key":"40610_CR29","doi-asserted-by":"publisher","first-page":"2","DOI":"10.1080\/07468342.1996.11973744","volume":"27","author":"D Kalman","year":"1996","unstructured":"Kalman D. A singularly valuable decomposition: the SVD of a matrix. The College Mathematics Journal, 1996, 27(1): 2\u201323","journal-title":"The College Mathematics Journal"},{"key":"40610_CR30","first-page":"626","volume-title":"Proceedings of the 10th International Conference on Neural Information Processing Systems","author":"S Roweis","year":"1997","unstructured":"Roweis S. EM algorithms for PCA and SPCA. In: Proceedings of the 10th International Conference on Neural Information Processing Systems. 1997, 626\u2013632"},{"key":"40610_CR31","doi-asserted-by":"publisher","first-page":"701","DOI":"10.1145\/2623330.2623732","volume-title":"Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"B Perozzi","year":"2014","unstructured":"Perozzi B, Al-Rfou R, Skiena S. DeepWalk: online learning of social representations. In: Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2014, 701\u2013710"},{"key":"40610_CR32","doi-asserted-by":"publisher","first-page":"855","DOI":"10.1145\/2939672.2939754","volume-title":"Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining","author":"A Grover","year":"2016","unstructured":"Grover A, Leskovec J. node2vec: scalable feature learning for networks. In: Proceedings of the 22nd ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. 2016, 855\u2013864"},{"key":"40610_CR33","doi-asserted-by":"publisher","first-page":"194","DOI":"10.1016\/j.tsep.2018.04.004","volume":"6","author":"L Chen","year":"2018","unstructured":"Chen L, Asai K, Nonomura T, Xi G, Liu T. A review of backward-facing step (BFS) flow mechanisms, heat transfer and control. Thermal Science and Engineering Progress, 2018, 6: 194\u2013216","journal-title":"Thermal Science and Engineering Progress"},{"key":"40610_CR34","first-page":"447","volume-title":"Proceedings of the 14th International Conference on Communication Systems & Networks","author":"S Agarwal","year":"2022","unstructured":"Agarwal S, Sable A, Sawant D, Kahalekar S, Hanawal M K. Threat detection and response in Linux endpoints. In: Proceedings of the 14th International Conference on Communication Systems & Networks. 2022, 447\u2013449"},{"key":"40610_CR35","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1145\/2818000.2818039","volume-title":"Proceedings of the 31st Annual Computer Security Applications Conference","author":"S Ma","year":"2015","unstructured":"Ma S, Lee K H, Kim C H, Rhee J, Zhang X, Xu D. Accurate, low cost and instrumentation-free security audit logging for windows. In: Proceedings of the 31st Annual Computer Security Applications Conference. 2015, 401\u2013410"},{"key":"40610_CR36","doi-asserted-by":"publisher","first-page":"333","DOI":"10.1145\/2714576.2714614","volume-title":"Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security","author":"F Zhang","year":"2015","unstructured":"Zhang F, Leach K, Wang H, Stavrou A. TrustLogin: securing password-login on commodity operating systems. In: Proceedings of the 10th ACM Symposium on Information, Computer and Communications Security. 2015, 333\u2013344"},{"key":"40610_CR37","doi-asserted-by":"publisher","first-page":"259","DOI":"10.1145\/2420950.2420989","volume-title":"Proceedings of the 28th Annual Computer Security Applications Conference","author":"D J Pohly","year":"2012","unstructured":"Pohly D J, McLaughlin S, McDaniel P, Butler K. Hi-Fi: collecting high-fidelity whole-system provenance. In: Proceedings of the 28th Annual Computer Security Applications Conference. 2012, 259\u2013268"},{"key":"40610_CR38","first-page":"6000","volume-title":"Proceedings of the 31st International Conference on Neural Information Processing Systems","author":"A Vaswani","year":"2017","unstructured":"Vaswani A, Shazeer N, Parmar N, Uszkoreit J, Jones L, Gomez A N, Kaiser L, Polosukhin I. Attention is all you need. In: Proceedings of the 31st International Conference on Neural Information Processing Systems. 2017, 6000\u20136010"},{"issue":"4","key":"40610_CR39","doi-asserted-by":"publisher","first-page":"291","DOI":"10.23919\/JCC.2022.04.021","volume":"19","author":"C Hou","year":"2022","unstructured":"Hou C, Xie Y, Zhang Z. An improved convolutional neural network based indoor localization by using Jenks natural breaks algorithm. China Communications, 2022, 19(4): 291\u2013301","journal-title":"China Communications"},{"key":"40610_CR40","volume-title":"Scalable transparency architecture for research collaboration (STARC)-DARPA transparent computing (TC) program","author":"J Griffith","year":"2020","unstructured":"Griffith J, Kong D, Caro A, Benyo B, Khoury J, Upthegrove T, Christovich T, Ponomorov S, Sydney A, Saini A, Shurbanov V, Willig C, Levin D, Dietz J. Scalable transparency architecture for research collaboration (STARC)-DARPA transparent computing (TC) program. Cambridge: Raytheon BBN Technologies Corp, 2020"}],"container-title":["Frontiers of Computer Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-024-40610-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11704-024-40610-8\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11704-024-40610-8.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,28]],"date-time":"2025-01-28T12:50:42Z","timestamp":1738068642000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11704-024-40610-8"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,28]]},"references-count":40,"journal-issue":{"issue":"10","published-print":{"date-parts":[[2025,10]]}},"alternative-id":["40610"],"URL":"https:\/\/doi.org\/10.1007\/s11704-024-40610-8","relation":{},"ISSN":["2095-2228","2095-2236"],"issn-type":[{"value":"2095-2228","type":"print"},{"value":"2095-2236","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,28]]},"assertion":[{"value":"18 June 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"8 September 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 January 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"Competing interests The authors declare that they have no competing interests or financial conflicts to disclose.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Ethics"}}],"article-number":"1910809"}}