{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,13]],"date-time":"2026-03-13T17:03:17Z","timestamp":1773421397103,"version":"3.50.1"},"reference-count":35,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2017,5,1]],"date-time":"2017-05-01T00:00:00Z","timestamp":1493596800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"funder":[{"name":"Technological District on Cyber Security"},{"name":"PON","award":["PON03PE_00032_2"],"award-info":[{"award-number":["PON03PE_00032_2"]}]},{"name":"Italian Ministry of University and Research"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Knowl. Data Eng."],"published-print":{"date-parts":[[2017,5,1]]},"DOI":"10.1109\/tkde.2017.2658621","type":"journal-article","created":{"date-parts":[[2017,1,25]],"date-time":"2017-01-25T19:53:35Z","timestamp":1485374015000},"page":"1115-1128","source":"Crossref","is-referenced-by-count":11,"title":["Malevolent Activity Detection with Hypergraph-Based Models"],"prefix":"10.1109","volume":"29","author":[{"given":"Antonella","family":"Guzzo","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Andrea","family":"Pugliese","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antonino","family":"Rullo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Domenico","family":"Sacca","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Antonio","family":"Piccolo","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref33","first-page":"58","article-title":"Intrusion detection with hypergraph-based attack models","author":"guzzo","year":"2013","journal-title":"Proc 3rd Int Workshop Graph Structures Knowl Representation Reasoning"},{"key":"ref32","first-page":"1","article-title":"BotHunter: Detecting malware infection through IDS-driven dialog correlation","volume":"7","author":"gu","year":"2007","journal-title":"Proc 16th USENIX Security Symp"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/CISIS.2014.30"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2003.1254330"},{"key":"ref35","article-title":"PuTTY SSH and telnet client","author":"tatham","year":"2016"},{"key":"ref34","author":"garey","year":"1979","journal-title":"Computers and Intractability A Guide to the Theory of NP-Completeness"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/CSAC.2004.11"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2006.06.018"},{"key":"ref12","first-page":"58","article-title":"A new alert correlation algorithm based on attack graph","author":"roschke","year":"2011","journal-title":"Proc 4th Int Conf Comput Intell Secur Inf Syst"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2006.04.001"},{"key":"ref14","first-page":"78","article-title":"SBAD: Sequence based attack detection via sequence comparison","author":"mao","year":"2010","journal-title":"Proc Int ECML\/PKDD Conf Privacy Secur Issues Data Mining Mach Learn"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1145\/1029208.1029225"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2012.09.013"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-18467-8_23"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-24858-5_7"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2014.07.001"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2013.171"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1117\/12.604240"},{"key":"ref27","article-title":"Automatic management of logging infrastructure","author":"johnson","year":"2010"},{"key":"ref3","first-page":"234","article-title":"Modeling and detection of complex attacks","author":"\u00e7amtepe","year":"2007","journal-title":"Proc 3rd Int Conf Secur Privacy Commun Netw Workshops"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2002.1004377"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/MITP.2009.89"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/1456362.1456368"},{"key":"ref8","first-page":"416","article-title":"Scalable analysis of attack scenarios","author":"albanese","year":"2011","journal-title":"Proc 16th Eur Conf Res Comput Secur"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1145\/586139.586140"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.2001.924295"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2011.246"},{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1007\/3-540-39945-3_5"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1155\/2014\/818957"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1145\/1529282.1529294"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45236-2_49"},{"key":"ref24","doi-asserted-by":"crossref","first-page":"115","DOI":"10.1007\/3-540-36084-0_7","article-title":"M2D2: A formal data model for IDS alert correlation","author":"morin","year":"2002","journal-title":"Proceedings of the 5th International Conference on Recent Advances in Intrusion Detection"},{"key":"ref23","article-title":"ANKH: Information threat analysis with actor-network hypergraphs","author":"pieters","year":"2010"},{"key":"ref26","doi-asserted-by":"crossref","first-page":"563","DOI":"10.1109\/TPAMI.2008.232","article-title":"Hypergraph-based anomaly detection of high-dimensional co-occurrences","volume":"31","author":"silva","year":"2009","journal-title":"IEEE Trans Pattern Anal Mach Intell"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1016\/j.ress.2009.02.001"}],"container-title":["IEEE Transactions on Knowledge and Data Engineering"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/69\/7891084\/07833129.pdf?arnumber=7833129","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,1,12]],"date-time":"2022-01-12T16:27:20Z","timestamp":1642004840000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/7833129\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2017,5,1]]},"references-count":35,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tkde.2017.2658621","relation":{},"ISSN":["1041-4347"],"issn-type":[{"value":"1041-4347","type":"print"}],"subject":[],"published":{"date-parts":[[2017,5,1]]}}}