{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T15:48:58Z","timestamp":1775922538507,"version":"3.50.1"},"reference-count":47,"publisher":"Elsevier BV","license":[{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/tdm\/userlicense\/1.0\/"},{"start":{"date-parts":[[2026,6,1]],"date-time":"2026-06-01T00:00:00Z","timestamp":1780272000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.elsevier.com\/legal\/tdmrep-license"},{"start":{"date-parts":[[2026,3,20]],"date-time":"2026-03-20T00:00:00Z","timestamp":1773964800000},"content-version":"vor","delay-in-days":0,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":["elsevier.com","sciencedirect.com"],"crossmark-restriction":true},"short-container-title":["Journal of Information Security and Applications"],"published-print":{"date-parts":[[2026,6]]},"DOI":"10.1016\/j.jisa.2026.104447","type":"journal-article","created":{"date-parts":[[2026,3,27]],"date-time":"2026-03-27T08:33:55Z","timestamp":1774600435000},"page":"104447","update-policy":"https:\/\/doi.org\/10.1016\/elsevier_cm_policy","source":"Crossref","is-referenced-by-count":0,"special_numbering":"C","title":["Graph-based detection of multi-step attacks using graph convolutional networks"],"prefix":"10.1016","volume":"99","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-5674-5499","authenticated-orcid":false,"given":"S.U.","family":"Shaukat","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-8613-8200","authenticated-orcid":false,"given":"Saad","family":"Khan","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1747-9914","authenticated-orcid":false,"given":"Simon","family":"Parkinson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"78","reference":[{"key":"10.1016\/j.jisa.2026.104447_bib0001","series-title":"Proc. 2024 international russian smart industry conference (SmartIndustryCon)","article-title":"L\/STIM: a framework for detecting multi-stage cyber attacks","author":"Zelichenok","year":"2024"},{"key":"10.1016\/j.jisa.2026.104447_bib0002","doi-asserted-by":"crossref","DOI":"10.1016\/j.eswa.2023.120991","article-title":"Context-based irregular activity detection in event logs for forensic investigations: an itemset mining approach","volume":"233","author":"Khan","year":"2023","journal-title":"Expert Syst Appl"},{"key":"10.1016\/j.jisa.2026.104447_bib0003","unstructured":"Kavadias N., Silent intruders: understanding living-off-the-land techniques, threats, countermeasures and emerging solutions, 2026."},{"key":"10.1016\/j.jisa.2026.104447_bib0004","series-title":"Proc. 2019 6th international conference on information science and control engineering (ICISCE)","article-title":"A distributed vulnerability scanning on machine learning","author":"Tian","year":"2019"},{"key":"10.1016\/j.jisa.2026.104447_bib0005","series-title":"Proc. 2023 RIVF international conference on computing and communication technologies (RIVF)","article-title":"Deep nested clustering auto-encoder for anomaly-based network intrusion detection","author":"Nguyen","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0006","series-title":"Proc. 2019 IEEE european symposium on security and privacy (EuroS&P)","article-title":"Discovering correlations: a formal definition of causal dependency among heterogeneous events","author":"Xosanavongsa","year":"2019"},{"issue":"5","key":"10.1016\/j.jisa.2026.104447_bib0007","doi-asserted-by":"crossref","first-page":"3546","DOI":"10.1109\/TDSC.2021.3101649","article-title":"Poirot: causal correlation aided semantic analysis for advanced persistent threat detection","volume":"19","author":"Yang","year":"2022","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.jisa.2026.104447_bib0008","doi-asserted-by":"crossref","DOI":"10.1007\/s10586-024-04510-7","article-title":"K-means and meta-heuristic algorithms for intrusion detection systems","author":"Maazalahi","year":"2024","journal-title":"Cluster Comput"},{"key":"10.1016\/j.jisa.2026.104447_bib0009","series-title":"Proc. 2023 13th international conference on information technology in Asia (CITA)","article-title":"Fingerprinting generation for advanced persistent threats (APT) detection using machine learning techniques","author":"Yi","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0010","doi-asserted-by":"crossref","first-page":"161779","DOI":"10.1109\/ACCESS.2025.3607497","article-title":"A review on multi-step attack detection","volume":"13","author":"Shaukat","year":"2025","journal-title":"IEEE Access"},{"issue":"1","key":"10.1016\/j.jisa.2026.104447_bib0011","article-title":"Event log correlation for multi-step attack detection","volume":"9","author":"Shaukat","year":"2026","journal-title":"Secur Privacy"},{"key":"10.1016\/j.jisa.2026.104447_bib0012","series-title":"Proc. 2008 international symposium on computer science and computational technology","article-title":"Applying data fusion in collaborative alerts correlation","author":"Zhuang","year":"2008"},{"key":"10.1016\/j.jisa.2026.104447_bib0013","series-title":"Proc. 2nd international conference on computer science and network technolog","article-title":"A multi-step attack pattern discovery method based on graph mining","author":"Xu","year":"2012"},{"key":"10.1016\/j.jisa.2026.104447_bib0014","doi-asserted-by":"crossref","unstructured":"Alserhani F.. A framework for multi-stage attack detection. In: 2013 Saudi International Electronics, Communications and Photonics Conference. 2013.","DOI":"10.1109\/SIECPC.2013.6550973"},{"key":"10.1016\/j.jisa.2026.104447_bib0015","series-title":"Proc. 2015 IEEE symposium on visualization for cyber security (VizSec)","article-title":"Visual analytics for cyber red teaming","author":"Yuen","year":"2015"},{"key":"10.1016\/j.jisa.2026.104447_bib0016","doi-asserted-by":"crossref","first-page":"349","DOI":"10.1016\/j.future.2018.06.055","article-title":"Detection of advanced persistent threat using machine-learning correlation analysis","volume":"89","author":"Ghafir","year":"2018","journal-title":"Future Gener Comput Syst"},{"key":"10.1016\/j.jisa.2026.104447_bib0017","doi-asserted-by":"crossref","unstructured":"Kwon Y., et al., MCI: modelling-based causality inference in audit logging for attack investigation, In: NDSS symposium. San Diego, CA, 2018, 438\u2013452.","DOI":"10.14722\/ndss.2018.23306"},{"key":"10.1016\/j.jisa.2026.104447_bib0018","series-title":"Proc. 2019 IEEE 21st international conference on high performance computing and communications; IEEE 17th international conference on smart city; IEEE 5th international conference on data science and systems (HPCC\/SmartCity\/DSS)","article-title":"RTMA: real time mining algorithm for multi-step attack scenarios reconstruction","author":"Zhang","year":"2019"},{"key":"10.1016\/j.jisa.2026.104447_bib0019","doi-asserted-by":"crossref","first-page":"57260","DOI":"10.1109\/ACCESS.2020.2982057","article-title":"Method for extracting patterns of coordinated network attacks on electric power CPS based on temporal-topological correlation","volume":"8","author":"Wang","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104447_bib0020","series-title":"APT attack detection based on flow network analysis techniques using deep learning","first-page":"4785","volume":"39","author":"Cho","year":"2020"},{"key":"10.1016\/j.jisa.2026.104447_bib0021","series-title":"Proc. 2021 IEEE 20th international conference on trust, security and privacy in computing and communications (trustcom)","article-title":"MAAC: novel alert correlation method to detect multi-step attack","author":"Wang","year":"2021"},{"key":"10.1016\/j.jisa.2026.104447_bib0022","series-title":"2023 IEEE 22nd international conference on trust, security and privacy in computing and communications (TrustCom)","first-page":"1266","article-title":"Temporal-gated graph neural network with graph sampling for multi-step attack detection","author":"Chen","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0023","series-title":"Proc. 2023 IEEE 22nd international conference on trust, security and privacy in computing and communications (TrustCom)","article-title":"Temporal-gated graph neural network with graph sampling for multi-step attack detection","author":"Chen","year":"2023"},{"issue":"1","key":"10.1016\/j.jisa.2026.104447_bib0024","doi-asserted-by":"crossref","first-page":"22","DOI":"10.1186\/s42400-023-00155-y","article-title":"Optimal monitoring and attack detection of networks modeled by Bayesian attack graphs","volume":"6","author":"Kazeminajafabadi","year":"2023","journal-title":"Cybersecurity"},{"key":"10.1016\/j.jisa.2026.104447_bib0025","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1109\/TVT.2017.2723881","article-title":"MS-ZeroWall: detecting zero-day multi-step attack in smart home using vae and HMM","author":"Li","year":"2024","journal-title":"IEEE Trans Veh Technol"},{"issue":"10","key":"10.1016\/j.jisa.2026.104447_bib0026","doi-asserted-by":"crossref","DOI":"10.3390\/math12101447","article-title":"Key vulnerable nodes discovery based on Bayesian attack subgraphs and improved fuzzy C-means clustering","volume":"12","author":"Xu","year":"2024","journal-title":"Mathematics"},{"key":"10.1016\/j.jisa.2026.104447_bib0027","series-title":"Security and communication networks","article-title":"DL-IDS: extracting features using CNN-LSTM hybrid network for intrusion detection system","volume":"2020","author":"Sun","year":"2020"},{"key":"10.1016\/j.jisa.2026.104447_bib0028","series-title":"Emerging technologies in computer engineering, ICETCE 2019, communications in computer and information science","article-title":"Advance persistent threat detection using long short term memory (LSTM) neural networks","volume":"985","author":"Sai Charan","year":"2019"},{"key":"10.1016\/j.jisa.2026.104447_bib0029","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2019.101681","article-title":"Model of the intrusion detection system based on the integration of spatial-temporal features","volume":"89","author":"Zhang","year":"2020","journal-title":"Comput Secur"},{"key":"10.1016\/j.jisa.2026.104447_bib0030","series-title":"Proc. 2023 IEEE 22nd international conference on trust, security and privacy in computing and communications (TrustCom)","article-title":"Multi-stage attack detection and prediction using graph neural networks: an IoT feasibility study","author":"Friji","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0031","series-title":"Proc. 2023 RIVF international conference on computing and communication technologies (RIVF)","article-title":"Using inference and graph convolutional networks for apt attack detection","author":"Cuong","year":"2023"},{"issue":"3","key":"10.1016\/j.jisa.2026.104447_bib0032","first-page":"4785","article-title":"Apt attack detection based on flow network analysis techniques using deep learning","volume":"39","author":"Cho","year":"2020","journal-title":"J Intell Fuzzy Syst"},{"key":"10.1016\/j.jisa.2026.104447_bib0033","doi-asserted-by":"crossref","first-page":"64","DOI":"10.1016\/j.future.2019.01.056","article-title":"A semantic-based correlation approach for detecting hybrid and low-level apts","volume":"96","author":"Lajevardi","year":"2019","journal-title":"Future Gener Comput Syst"},{"key":"10.1016\/j.jisa.2026.104447_bib0034","doi-asserted-by":"crossref","first-page":"501","DOI":"10.1016\/j.future.2020.01.032","article-title":"Modelling and detection of the multi-stages of advanced persistent threats attacks based on semi-supervised learning and complex networks characteristics","volume":"106","author":"Zimba","year":"2020","journal-title":"Future Gener Comput Syst"},{"issue":"6","key":"10.1016\/j.jisa.2026.104447_bib0035","doi-asserted-by":"crossref","first-page":"5215","DOI":"10.1007\/s10115-025-02387-5","article-title":"GC-PTRANSE: multi-step attack inference method based on graph convolutional neural network and translation embedding","volume":"67","author":"Ren","year":"2025","journal-title":"Knowl Inf Syst"},{"key":"10.1016\/j.jisa.2026.104447_bib0036","series-title":"Proc. 2020 IEEE symposium on security and privacy (SP)","article-title":"Tactical provenance analysis for endpoint detection and response systems","author":"Hassan","year":"2020"},{"key":"10.1016\/j.jisa.2026.104447_bib0037","series-title":"Proc. IEEE international conference on big data (big data)","article-title":"A framework for cyber threat intelligence extraction from raw log data","author":"Landauer","year":"2019"},{"key":"10.1016\/j.jisa.2026.104447_bib0038","doi-asserted-by":"crossref","first-page":"1031","DOI":"10.1109\/ACCESS.2019.2961517","article-title":"A multi-step attack detection model based on alerts of smart grid monitoring system","volume":"8","author":"Zhang","year":"2020","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104447_bib0039","series-title":"Rank: AI-assisted end-to-end architecture for detecting persistent attacks in enterprise networks","first-page":"1","author":"Soliman","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0040","series-title":"Proc. 2022 15th international conference on security of information and networks (SIN)","article-title":"A NLP-inspired method to predict multi-step cyberattacks","author":"Fredj","year":"2022"},{"key":"10.1016\/j.jisa.2026.104447_bib0041","doi-asserted-by":"crossref","DOI":"10.1016\/j.compeleceng.2024.109249","article-title":"A multi-step attack identification and correlation method based on multi-information fusion","volume":"117","author":"Liao","year":"2024","journal-title":"Comput Electr Eng"},{"key":"10.1016\/j.jisa.2026.104447_bib0042","series-title":"Proc. 2020 international symposium on networks, computers and communications (ISNCC)","article-title":"An optimization approach to graph partitioning for detecting persistent attacks in enterprise networks","author":"Soliman","year":"2020"},{"issue":"6","key":"10.1016\/j.jisa.2026.104447_bib0043","doi-asserted-by":"crossref","first-page":"5070","DOI":"10.1109\/TDSC.2023.3240315","article-title":"Prism: a hierarchical intrusion detection architecture for large-scale cyber networks","volume":"20","author":"Javed","year":"2023","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"10.1016\/j.jisa.2026.104447_bib0044","doi-asserted-by":"crossref","first-page":"43387","DOI":"10.1109\/ACCESS.2022.3168976","article-title":"Systematic literature review of security event correlation methods","volume":"10","author":"Kotenko","year":"2022","journal-title":"IEEE Access"},{"key":"10.1016\/j.jisa.2026.104447_bib0045","series-title":"Proc. IEEE SmartWorld","article-title":"Inferring attack paths in networks with periodic topology changes","author":"Hao","year":"2022"},{"key":"10.1016\/j.jisa.2026.104447_bib0046","series-title":"Proc. 2023 38th IEEE\/ACM international conference on automated software engineering workshops (ASEW)","first-page":"54","article-title":"A human-centric cyber security training tool for prioritizing msnas","author":"Depassier","year":"2023"},{"key":"10.1016\/j.jisa.2026.104447_bib0047","doi-asserted-by":"crossref","unstructured":"Altidor J.B., Talhi C.. Enhancing port scan and ddos attack detection using genetic and machine learning algorithms, In: Proc. 2024 7th Conference on Cloud and Internet of Things (CIoT), Montreal, QC, Canada, 2024, 1\u20137. 10.1109\/CIoT63799.2024.10757005.","DOI":"10.1109\/CIoT63799.2024.10757005"}],"container-title":["Journal of Information Security and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000773?httpAccept=text\/xml","content-type":"text\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/api.elsevier.com\/content\/article\/PII:S2214212626000773?httpAccept=text\/plain","content-type":"text\/plain","content-version":"vor","intended-application":"text-mining"}],"deposited":{"date-parts":[[2026,4,11]],"date-time":"2026-04-11T15:25:20Z","timestamp":1775921120000},"score":1,"resource":{"primary":{"URL":"https:\/\/linkinghub.elsevier.com\/retrieve\/pii\/S2214212626000773"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,6]]},"references-count":47,"alternative-id":["S2214212626000773"],"URL":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104447","relation":{},"ISSN":["2214-2126"],"issn-type":[{"value":"2214-2126","type":"print"}],"subject":[],"published":{"date-parts":[[2026,6]]},"assertion":[{"value":"Elsevier","name":"publisher","label":"This article is maintained by"},{"value":"Graph-based detection of multi-step attacks using graph convolutional networks","name":"articletitle","label":"Article Title"},{"value":"Journal of Information Security and Applications","name":"journaltitle","label":"Journal Title"},{"value":"https:\/\/doi.org\/10.1016\/j.jisa.2026.104447","name":"articlelink","label":"CrossRef DOI link to publisher maintained version"},{"value":"article","name":"content_type","label":"Content Type"},{"value":"\u00a9 2026 The Author(s). Published by Elsevier Ltd.","name":"copyright","label":"Copyright"}],"article-number":"104447"}}