{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,12,23]],"date-time":"2025-12-23T10:36:53Z","timestamp":1766486213708,"version":"3.37.3"},"reference-count":23,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/OAPA.html"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61772229","61472162"],"award-info":[{"award-number":["61772229","61472162"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"Scientific and Technological Research Planning Projects in Colleges and Universities of Jilin Province","award":["JJKH20190168KJ"],"award-info":[{"award-number":["JJKH20190168KJ"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Access"],"published-print":{"date-parts":[[2019]]},"DOI":"10.1109\/access.2019.2894509","type":"journal-article","created":{"date-parts":[[2019,1,24]],"date-time":"2019-01-24T00:51:28Z","timestamp":1548291088000},"page":"13917-13926","source":"Crossref","is-referenced-by-count":21,"title":["Discovering Suspicious APT Families Through a Large-Scale Domain Graph in Information-Centric IoT"],"prefix":"10.1109","volume":"7","author":[{"given":"Zhen","family":"Ma","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7510-4718","authenticated-orcid":false,"given":"Qiang","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Xiangyu","family":"Meng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1145\/3132847.3132854"},{"journal-title":"Operation KE3CHANG Targeted Attacks Against Ministries of Foreign Affairs","year":"2013","author":"villeneuve","key":"ref11"},{"journal-title":"Regional Advanced Threat Report Europe Middle East and Africa 1H2014","year":"2014","key":"ref12"},{"key":"ref13","first-page":"63","article-title":"State of the art analysis of defense techniques against advanced persistent threats","volume":"63","author":"john","year":"2017","journal-title":"Proc Future Internet (FI) Innov Internet Technol Mobile Commun (IITM) Focal Topic Adv Persistent Threats"},{"key":"ref14","doi-asserted-by":"crossref","first-page":"663","DOI":"10.1145\/2897845.2897877","article-title":"Discovering malicious domains through passive DNS data graph analysis","author":"khalil","year":"2016","journal-title":"Proc ACM Asia Conf Comput Commun Secur"},{"journal-title":"Protecting Your Critical Assets - Lessons Learned from \"Operation Aurora\"","year":"2010","key":"ref15"},{"key":"ref16","doi-asserted-by":"crossref","first-page":"366","DOI":"10.1007\/978-3-319-60876-1_17","article-title":"Unsupervised detection of APT C&C channels using Web request graphs","author":"lamprakis","year":"2017","journal-title":"Proc Int'l Conf Detection of Intrusions and Malware and Vulnerability Assessment (DIMVA)"},{"journal-title":"Best practices for detecting and mitigating advanced threats 2016 Update","year":"2016","author":"pingree","key":"ref17"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.3390\/sym6040997"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-49148-6_32"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2018.2799000"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2016.2517321"},{"key":"ref6","first-page":"45","article-title":"Detection of early-stage enterprise infection by mining large-scale log data","author":"oprea","year":"2014","journal-title":"Proc IEEE\/IFIP Int Conf Dependable Syst Netw"},{"key":"ref5","doi-asserted-by":"crossref","first-page":"13","DOI":"10.1145\/2804345.2804349","article-title":"Detecting Android malware using sequences of system calls","author":"canfora","year":"2015","journal-title":"Proc Int Workshop Softw Develop Lifecycle Mobile"},{"journal-title":"Operation SnowMan DeputyDog Actor Compromises US Veterans of Foreign Wars Website","year":"2014","author":"kindlund","key":"ref8"},{"key":"ref7","first-page":"63","article-title":"A study on advanced persistent threats","author":"chen","year":"2014","journal-title":"Proc IFIP Int Conf Commun Multimedia Secur"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/TETC.2017.2747158"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/SRDS.2017.31"},{"journal-title":"Revealed Operation Shady RAT","year":"2012","author":"alperovitch","key":"ref9"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1007\/s11063-017-9666-7"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2686451"},{"key":"ref21","article-title":"NLES: A novel lifetime extension scheme for safety-critical cyber-physical systems using SDN and NFV","author":"wu","year":"0","journal-title":"IEEE Internet of Things Journal"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/s12083-017-0559-3"}],"container-title":["IEEE Access"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6287639\/8600701\/08624251.pdf?arnumber=8624251","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,27]],"date-time":"2022-01-27T08:02:11Z","timestamp":1643270531000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/8624251\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"references-count":23,"URL":"https:\/\/doi.org\/10.1109\/access.2019.2894509","relation":{},"ISSN":["2169-3536"],"issn-type":[{"type":"electronic","value":"2169-3536"}],"subject":[],"published":{"date-parts":[[2019]]}}}