{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,24]],"date-time":"2026-06-24T15:04:16Z","timestamp":1782313456808,"version":"3.54.5"},"reference-count":35,"publisher":"IEEE","license":[{"start":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T00:00:00Z","timestamp":1757289600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,9,8]],"date-time":"2025-09-08T00:00:00Z","timestamp":1757289600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2025,9,8]]},"DOI":"10.1109\/cns66487.2025.11195068","type":"proceedings-article","created":{"date-parts":[[2025,10,15]],"date-time":"2025-10-15T17:34:49Z","timestamp":1760549689000},"page":"1-9","source":"Crossref","is-referenced-by-count":1,"title":["CAPTure: Classifying APT Stages and Techniques via Graph-Enhanced Network Flow Representations"],"prefix":"10.1109","author":[{"given":"Md Taef Uddin","family":"Nadim","sequence":"first","affiliation":[{"name":"University of Arkansas"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Qinghua","family":"Li","sequence":"additional","affiliation":[{"name":"University of Arkansas"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2891891"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-59621-7_8"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1016\/j.dim.2023.100064"},{"key":"ref4","article-title":"Toward a knowledge graph of cybersecurity countermeasures","author":"Kaloroumakis","year":"2021","journal-title":"The MITRE Corporation"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2023.109688"},{"key":"ref6","first-page":"6575","article-title":"{DISTDET}: A {Cost-Effective} distributed cyber threat detection system","volume-title":"USENIX Security Symposium","author":"Dong"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24046"},{"key":"ref8","first-page":"4355","article-title":"{PROGRAPHER}: An anomaly detection system based on provenance graph embedding","volume-title":"USENIX Security Symposium","author":"Yang"},{"key":"ref9","first-page":"3005","article-title":"{ATLAS}: A sequence-based learning approach for attack investigation","volume-title":"USENIX security symposium","author":"Alsaheel"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.13052\/jwe1540-9589.2019"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/CNS62487.2024.10735484"},{"key":"ref12","first-page":"5197","article-title":"{MAGIC}: Detecting advanced persistent threats via masked graph representation learning","volume-title":"USENIX Security Symposium","author":"Jia"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/SP54263.2024.00139"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.23204"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1145\/3559768"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/PST58708.2023.10320192"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/ICPS58381.2023.10128062"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/CSNet64211.2024.10851720"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1109\/ACAIT53529.2021.9731169"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3221789"},{"key":"ref22","article-title":"Pro apt: Projection of apt threats with deep reinforcement learning","author":"Dehghan","year":"2022","journal-title":"arXiv preprint"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1002\/spy2.70011"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1016\/j.asoc.2024.112447"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104185"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1016\/j.compeleceng.2024.109249"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690221"},{"key":"ref28","volume-title":"Elastic","year":"2021"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.5220\/0006105602530262"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.25080\/TCWV9851"},{"key":"ref31","volume-title":"Mitre att&ck: Design and philosophy","author":"Strom","year":"2018"},{"key":"ref32","article-title":"Ratcliff\/Obershelp Pattern Recognition","volume-title":"Dictionary of Algorithms and Data Structures","author":"Black","year":"2021"},{"key":"ref33","article-title":"Digraph-mmb: A directed graph-based multimodal model for multi-stage apt attack detection","author":"Zhang","journal-title":"Available at SSRN 5226068"},{"key":"ref34","volume-title":"MITRE ATT&CK\u00ae: ATT&CK Data & Tools","year":"2025"},{"key":"ref35","volume-title":"MITRE D3FEND\u2122 Ontology Resources","year":"2025"}],"event":{"name":"2025 IEEE Conference on Communications and Network Security (CNS)","location":"Avignon, France","start":{"date-parts":[[2025,9,8]]},"end":{"date-parts":[[2025,9,11]]}},"container-title":["2025 IEEE Conference on Communications and Network Security (CNS)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11194903\/11194169\/11195068.pdf?arnumber=11195068","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T04:51:03Z","timestamp":1760590263000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11195068\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,8]]},"references-count":35,"URL":"https:\/\/doi.org\/10.1109\/cns66487.2025.11195068","relation":{},"subject":[],"published":{"date-parts":[[2025,9,8]]}}}