{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T06:58:09Z","timestamp":1782975489047,"version":"3.54.5"},"reference-count":52,"publisher":"IEEE","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"DOI":"10.13039\/501100001809","name":"NSFC","doi-asserted-by":"publisher","award":["6212780016"],"award-info":[{"award-number":["6212780016"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012245","name":"Guangdong S&T Programme","doi-asserted-by":"publisher","award":["2024B0101030002"],"award-info":[{"award-number":["2024B0101030002"]}],"id":[{"id":"10.13039\/501100012245","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100012166","name":"National Key Research and Development Program of China","doi-asserted-by":"publisher","award":["2023YFB3307500"],"award-info":[{"award-number":["2023YFB3307500"]}],"id":[{"id":"10.13039\/501100012166","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2026,5,18]]},"DOI":"10.1109\/sp63933.2026.00016","type":"proceedings-article","created":{"date-parts":[[2026,7,1]],"date-time":"2026-07-01T19:34:20Z","timestamp":1782934460000},"page":"4072-4088","source":"Crossref","is-referenced-by-count":0,"title":["APIECHO: Training-Less Anomaly Detection via Intra-API Behavioral Comparison for Web Applications"],"prefix":"10.1109","author":[{"given":"Yihao","family":"Peng","sequence":"first","affiliation":[{"name":"BNRist, KLISS, School of Software, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yiming","family":"Wu","sequence":"additional","affiliation":[{"name":"BNRist, KLISS, School of Software, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Du","family":"Wu","sequence":"additional","affiliation":[{"name":"BNRist, KLISS, School of Software, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shouling","family":"Ji","sequence":"additional","affiliation":[{"name":"Zhejiang University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hai","family":"Wan","sequence":"additional","affiliation":[{"name":"BNRist, KLISS, School of Software, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Xibin","family":"Zhao","sequence":"additional","affiliation":[{"name":"BNRist, KLISS, School of Software, Tsinghua University"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"OWASP Top Ten"},{"issue":"1","key":"ref2","first-page":"129","article-title":"Anomaly Detection for Web Log Data Analysis: A Review","volume":"13","author":"Siwach","year":"2022","journal-title":"JOURNAL OF ALGEBRAIC STATISTICS"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1007\/s00450-009-0092-6"},{"key":"ref4","volume-title":"Falco: container native runtime security."},{"key":"ref5","volume-title":"Sysdig Secure."},{"key":"ref6","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2024.24286","article-title":"ReplicaWatcher: Training-less Anomaly Detection in Containerized Microservices","volume-title":"Proceedings 2024 Network and Distributed System Security Symposium","author":"El Khairi"},{"key":"ref7","article-title":"KAIROS: Practical Intrusion Detection and Investigation using Whole-system Provenance","volume-title":"2024 IEEE Symposium on Security and Privacy (SP)","author":"Cheng","year":"2023"},{"key":"ref8","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2020.24167","article-title":"You Are What You Do: Hunting Stealthy Malware via Data Provenance Analysis","volume-title":"Proceedings 2020 Network and Distributed System Security Symposium","author":"Wang"},{"key":"ref9","first-page":"489","article-title":"SHADEWATCHER: Recommendation-guided Cyber Threat Analysis using System Audit Records","volume-title":"2022 IEEE Symposium on Security and Privacy (SP)","author":"Zengy"},{"key":"ref10","doi-asserted-by":"crossref","first-page":"3972","DOI":"10.1109\/TIFS.2022.3208815","article-title":"THREATRACE: Detecting and Tracing Host-Based Threats in Node Level Through Provenance Graph Learning","volume":"17","author":"Wang","year":"2022","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"ref11","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2020.24046","article-title":"Unicorn: Runtime Provenance-Based Detector for Advanced Persistent Threats","volume-title":"Proceedings 2020 Network and Distributed System Security Symposium","author":"Han"},{"key":"ref12","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2018.23141","article-title":"Towards Scalable Cluster Auditing through Grammatical Inference over Provenance Graphs","volume-title":"Proceedings 2018 Network and Distributed System Security Symposium","author":"Hassan"},{"key":"ref13","doi-asserted-by":"crossref","first-page":"26","DOI":"10.1016\/j.future.2016.02.005","article-title":"Unifying intrusion detection and forensic analysis via provenance awareness","volume":"61","author":"Xie","year":"2016","journal-title":"Future Generation Computer Systems"},{"key":"ref14","volume-title":"akto-api-security\/akto."},{"key":"ref15","doi-asserted-by":"crossref","first-page":"2799","DOI":"10.1109\/SP46215.2023.10179402","article-title":"TeSec: Accurate Server-side Attack Investigation for Web Applications","volume-title":"2023 IEEE Symposium on Security and Privacy (SP)","author":"Wang","year":"2023"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2020.24065"},{"key":"ref17","first-page":"319","article-title":"Trustworthy {Whole-System} provenance for the linux kernel","volume-title":"24th USENIX Security Symposium (USENIX Security 15)","author":"Bates","year":"2015"},{"key":"ref18","volume-title":"trie","author":"Black","year":"2009"},{"key":"ref19","volume-title":"Introduction of System Call","year":"2019"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1038\/234034a0"},{"key":"ref21","first-page":"248","article-title":"The redundancy of english","volume-title":"Cybernetics; Transactions of the 7th Conference","author":"Shannon"},{"key":"ref22","volume-title":"pgadmin."},{"key":"ref23","volume-title":"Owasp juice shop."},{"key":"ref24","volume-title":"mongo-express."},{"key":"ref25","volume-title":"Gitlist."},{"key":"ref26","volume-title":"Apache solr."},{"key":"ref27","volume-title":"Apache ofbiz."},{"key":"ref28","first-page":"547","article-title":"{AutoLabel}: Automated {Fine-Grained} log labeling for cyber attack dataset generation","volume-title":"34th USENIX Security Symposium (USENIX Security 25)","author":"Peng","year":"2025"},{"key":"ref29","volume-title":"Fastapi."},{"key":"ref30","volume-title":"Libuv."},{"key":"ref31","doi-asserted-by":"crossref","first-page":"1137","DOI":"10.1109\/SP.2019.00026","article-title":"HOLMES: Real-Time APT Detection through Correlation of Suspicious Information Flows","volume-title":"2019 IEEE Symposium on Security and Privacy (SP)","author":"Milajerdi","year":"2019"},{"key":"ref32","first-page":"1139","article-title":"Combating Dependence Explosion in Forensic Analysis Using Alternative Tag Propagation Semantics","volume-title":"2020 IEEE Symposium on Security and Privacy (SP)","author":"Hossain"},{"issue":"1","key":"ref33","first-page":"551","article-title":"Conan: A Practical Real-Time APT Detection System With High Accuracy and Efficiency","volume-title":"IEEE Transactions on Dependable and Secure Computing","volume":"19","author":"Xiong","year":"2022"},{"key":"ref34","first-page":"1","article-title":"P-Gaussian: Provenance-Based Gaussian Distribution for Detecting Intrusion Behavior Variants Using High Efficient and Real Time Memory Databases","author":"Xie","year":"2020","journal-title":"IEEE Transactions on Dependable and Secure Computing"},{"key":"ref35","first-page":"3515","article-title":"R-CAID: Embedding Root Cause Analysis within Provenance-based Intrusion Detection","volume-title":"2024 IEEE Symposium on Security and Privacy (SP)","author":"Goyal"},{"key":"ref36","article-title":"SIGL: Securing Software Installations Through Deep Graph Learning","volume-title":"30th USENIX Security Symposium (USENIX Security 21)","author":"Han","year":"2021"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3363224"},{"key":"ref38","first-page":"487","article-title":"{SLEUTH}: Real-time attack scenario reconstruction from {COTS} audit data","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Hossain","year":"2017"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134015"},{"key":"ref40","article-title":"High Accuracy Attack Provenance via Binary-based Execution Partition","volume-title":"Proceedings 2013 Network and Distributed System Security Symposium","author":"Lee","year":"2013"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2021.24445"},{"key":"ref42","article-title":"MPI: Multiple Perspective Attack Investigation with Semantics Aware Execution Partitioning","volume-title":"26th USENIX Security Symposium (USENIX Security 17)","author":"Ma","year":"2017"},{"issue":"4","key":"ref43","doi-asserted-by":"crossref","first-page":"2761","DOI":"10.1109\/TSE.2022.3231242","article-title":"autoMPI: Automated Multiple Perspective Attack Investigation With Semantics Aware Execution Partitioning","volume":"49","author":"Alhanahnah","year":"2023","journal-title":"IEEE Transactions on Software Engineering"},{"key":"ref44","doi-asserted-by":"crossref","DOI":"10.14722\/ndss.2020.24270","article-title":"OmegaLog: High-Fidelity Attack Investigation via Transparent Multi-layer Log Analysis","volume-title":"Proceedings 2020 Network and Distributed System Security Symposium","author":"Hassan"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1145\/3548606.3560570"},{"key":"ref46","first-page":"1705","article-title":"Enabling refinable cross-host attack investigation with efficient data flow tagging and tracking","volume-title":"27th USENIX Security Symposium, USENIX Security 2018","author":"Ji","year":"2018"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818039"},{"key":"ref48","volume-title":"Chrome extension: Openapi spec generator."},{"key":"ref49","volume-title":"Exploring apis with zap."},{"key":"ref50","volume-title":"Kiterunner: Contextual content discovery tool."},{"key":"ref51","volume-title":"Automatically discovering api endpoints and generating schemas using machine learning."},{"key":"ref52","volume-title":"email-validator: A robust email address syntax and deliverability validation library.","author":"Tauberer","year":"2024"}],"event":{"name":"2026 IEEE Symposium on Security and Privacy (SP)","location":"San Francisco, CA, USA","start":{"date-parts":[[2026,5,18]]},"end":{"date-parts":[[2026,5,21]]}},"container-title":["2026 IEEE Symposium on Security and Privacy (SP)"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/11573355\/11573356\/11573362.pdf?arnumber=11573362","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,7,2]],"date-time":"2026-07-02T05:25:32Z","timestamp":1782969932000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11573362\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":52,"URL":"https:\/\/doi.org\/10.1109\/sp63933.2026.00016","relation":{},"subject":[],"published":{"date-parts":[[2026,5,18]]}}}