{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,1]],"date-time":"2026-05-01T18:01:58Z","timestamp":1777658518661,"version":"3.51.4"},"reference-count":56,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2024,10,1]],"date-time":"2024-10-01T00:00:00Z","timestamp":1727740800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"Ericsson Research and the Security Research Centre of Concordia University"},{"name":"National Cybersecurity Consortium (NCC) under the Cyber Security Innovation Network"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Serv. Manage."],"published-print":{"date-parts":[[2024,10]]},"DOI":"10.1109\/tnsm.2024.3378972","type":"journal-article","created":{"date-parts":[[2024,3,21]],"date-time":"2024-03-21T18:24:36Z","timestamp":1711045476000},"page":"5178-5196","source":"Crossref","is-referenced-by-count":13,"title":["AUTOMA: Automated Generation of Attack Hypotheses and Their Variants for Threat Hunting Using Knowledge Discovery"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5609-856X","authenticated-orcid":false,"given":"Boubakr","family":"Nour","sequence":"first","affiliation":[{"name":"GFTL Security Research, Ericsson, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[{"name":"GFTL Security Research, Ericsson, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0007-0032-7846","authenticated-orcid":false,"given":"Rushaan Kamran","family":"Qureshi","sequence":"additional","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Technical Requirements for the ArcSight Platform","year":"2021"},{"key":"ref2","article-title":"That escalated quickly: An ML framework for alert prioritization","author":"Gelman","year":"2023","journal-title":"arXiv:2302.06648"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3299519"},{"key":"ref4","volume-title":"A framework for cyber threat hunting","year":"2018"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_34"},{"key":"ref7","first-page":"3005","article-title":"ATLAS: A sequence-based learning approach for attack investigation","volume-title":"Proc. USENIX Security Symp. (USENIX Security)","author":"Alsaheel"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.02.005"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243829"},{"key":"ref10","article-title":"ATHAFI: Agile threat hunting and forensic investigation","author":"Puzis","year":"2020","journal-title":"arXiv:2003.03663"},{"key":"ref11","volume-title":"APT41: A Dual Espionage and Cyber Crime Operation","year":"2022"},{"key":"ref12","volume-title":"Threat Horizons-April 2023 Threat Horizons Report","year":"2023"},{"key":"ref13","article-title":"IoT virtualization: A survey of software definition & function virtualization techniques for Internet of Things","author":"Alam","year":"2019","journal-title":"arXiv:1902.10910"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"ref15","volume-title":"SIEM Capabilities Through FireEye Helix","year":"2019"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/TSE.2022.3176674"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/NOMS.2008.4575114"},{"key":"ref18","article-title":"Cybersecurity threat hunting and vulnerability analysis using a Neo4j graph database of open source intelligence","author":"Pelofske","year":"2023","journal-title":"arXiv:2301.12013"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3135639"},{"key":"ref20","article-title":"Evidential Cyber threat hunting","author":"Araujo","year":"2021","journal-title":"arXiv:2104.10319"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2019.2907247"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/GCAT52182.2021.9587507"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1016\/j.dcan.2022.09.008"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1145\/2991079.2991122"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00046"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3056999"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1145\/3170521.3170522"},{"key":"ref28","first-page":"3093","article-title":"Hopper: Modeling and detecting lateral movement","volume-title":"Proc. USENIX Security Symp. (USENIX Security)","author":"Ho"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1109\/CSR51186.2021.9527936"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2021.3104260"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/SOLI54607.2021.9672347"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/AINA.2018.00132"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1145\/1639714.1639740"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1145\/3488932.3523261"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1016\/j.jnca.2015.11.016"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.06.055"},{"key":"ref37","first-page":"165","article-title":"Mapping the security events to the MITRE ATT &CK attack patterns to forecast attack propagation","volume-title":"Proc. Int. Workshop Attacks Defenses Internet Things","author":"Kryukov"},{"key":"ref38","first-page":"1","article-title":"Accurify: Automated new testflows generation for attack variants in threat hunting","volume-title":"Proc. Found. Pract. Security (FPS)","author":"Nour"},{"key":"ref39","volume-title":"MITRE ATT&CK: Design and philosophy","author":"Strom","year":"2020"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3233703"},{"issue":"3","key":"ref41","first-page":"57","article-title":"Knowledge discovery in databases: An overview","volume":"13","author":"Frawley","year":"1992","journal-title":"AI Mag."},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TKDE.2018.2807452"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1007\/978-1-4419-6045-0_16"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1142\/S0218001404003228"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.aml.2007.01.006"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2015.02.024"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2006.145"},{"key":"ref48","article-title":"Graph theory: Measures and indices","volume-title":"Geography of Transport System","author":"Ducruet"},{"key":"ref49","volume-title":"Efficient Computation of PageRank","author":"Haveliwala","year":"1999"},{"key":"ref50","article-title":"To softmax, or not to softmax: That is the question when applying active learning for transformer models","author":"Gonsior","year":"2022","journal-title":"arXiv:2210.03005"},{"key":"ref51","volume-title":"Bayes\u2019 theorem","author":"Joyce","year":"2021"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-37439-6"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1186\/s13059-020-02157-2"},{"key":"ref54","doi-asserted-by":"publisher","DOI":"10.1016\/0304-3975(86)90084-8"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1145\/2939672.2939754"},{"key":"ref56","volume-title":"FiGHT (5G Hierarchy of Threats)","year":"2023"}],"container-title":["IEEE Transactions on Network and Service Management"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/4275028\/10714905\/10477575.pdf?arnumber=10477575","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,10,12]],"date-time":"2024-10-12T04:26:48Z","timestamp":1728707208000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/10477575\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,10]]},"references-count":56,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tnsm.2024.3378972","relation":{},"ISSN":["1932-4537","2373-7379"],"issn-type":[{"value":"1932-4537","type":"electronic"},{"value":"2373-7379","type":"electronic"}],"subject":[],"published":{"date-parts":[[2024,10]]}}}