{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,14]],"date-time":"2026-05-14T12:22:12Z","timestamp":1778761332336,"version":"3.51.4"},"reference-count":14,"publisher":"IEEE","license":[{"start":{"date-parts":[[2024,2,7]],"date-time":"2024-02-07T00:00:00Z","timestamp":1707264000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,2,7]],"date-time":"2024-02-07T00:00:00Z","timestamp":1707264000000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2024,2,7]]},"DOI":"10.1109\/icaic60265.2024.10433846","type":"proceedings-article","created":{"date-parts":[[2024,2,16]],"date-time":"2024-02-16T18:57:05Z","timestamp":1708109825000},"page":"1-6","source":"Crossref","is-referenced-by-count":1,"title":["Link-based Anomaly Detection with Sysmon and Graph Neural Networks"],"prefix":"10.1109","author":[{"given":"Charlie","family":"Grimshaw","sequence":"first","affiliation":[{"name":"Naval Platform Systems,Department of National Defence,Ottawa,Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brian","family":"Lachine","sequence":"additional","affiliation":[{"name":"Royal Military College,Electrical and Computer Engineering,Kingston,Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Taylor","family":"Perkins","sequence":"additional","affiliation":[{"name":"Deloitte Canada,Cyber &amp; Strategic Risk,Toronto,Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Emilie","family":"Coote","sequence":"additional","affiliation":[{"name":"Deloitte Canada,Cyber &amp; Strategic Risk,Toronto,Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"System monitor","author":"Russinovich","year":"2023"},{"key":"ref2","volume-title":"Understanding sysmon events using sysmon-simulator","author":"Raina","year":"2022"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2022.3211306"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1145\/3588771"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3570906"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.2200\/s01045ed1v01y202009aim046"},{"key":"ref7","first-page":"1","article-title":"A comprehensive survey on graph anomaly detection with deep learning","volume-title":"IEEE Transactions on Knowledge and Data Engineering","author":"Ma","year":"2021"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.14711\/thesis-991012757468803412"},{"key":"ref9","article-title":"How attentive are graph attention networks?","volume-title":"International Conference on Learning Representations","author":"Brody"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.epsr.2020.106795"},{"key":"ref11","article-title":"Semi-supervised classification with graph convolutional networks","volume-title":"5th International Conference on Learning Representations, ICLR 2017, Toulon, France, April 24-26, 2017, Conference Track Proceedings","author":"Kipf"},{"key":"ref12","article-title":"pandas: A foundational python library for data analysis and statistics","volume-title":"version 1.3.3","author":"McKinney","year":"2010"},{"key":"ref13","volume-title":"Apache parquet","year":"2023"},{"key":"ref14","article-title":"NetworkX: A python library for studying networks","author":"Hagberg","year":"2008"}],"event":{"name":"2024 IEEE 3rd International Conference on AI in Cybersecurity (ICAIC)","location":"Houston, TX, USA","start":{"date-parts":[[2024,2,7]]},"end":{"date-parts":[[2024,2,9]]}},"container-title":["2024 IEEE 3rd International Conference on AI in Cybersecurity (ICAIC)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/10433797\/10433798\/10433846.pdf?arnumber=10433846","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,2,29]],"date-time":"2024-02-29T22:44:44Z","timestamp":1709246684000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10433846\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,2,7]]},"references-count":14,"URL":"https:\/\/doi.org\/10.1109\/icaic60265.2024.10433846","relation":{},"subject":[],"published":{"date-parts":[[2024,2,7]]}}}