{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,16]],"date-time":"2025-10-16T07:05:56Z","timestamp":1760598356251,"version":"build-2065373602"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"5","license":[{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2025,10,1]],"date-time":"2025-10-01T00:00:00Z","timestamp":1759276800000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Cybersecurity Consortium and the Government of Canada"},{"name":"Ericsson Research and the Security Research Centre of Concordia University"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Serv. Manage."],"published-print":{"date-parts":[[2025,10]]},"DOI":"10.1109\/tnsm.2025.3581463","type":"journal-article","created":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T13:39:03Z","timestamp":1750340343000},"page":"3978-3994","source":"Crossref","is-referenced-by-count":1,"title":["Threatify: APT Threat Variant Generation Using Graph-Based Machine Learning"],"prefix":"10.1109","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-5609-856X","authenticated-orcid":false,"given":"Boubakr","family":"Nour","sequence":"first","affiliation":[{"name":"Ericsson Security Research, Ericsson, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9775-6231","authenticated-orcid":false,"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[{"name":"Ericsson Security Research, Ericsson, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3015-3043","authenticated-orcid":false,"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, QC, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2943087"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1057\/s41284-024-00435-3"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.3389\/frai.2024.1377011"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2019.2891891"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2019.00026"},{"volume-title":"Nowhere to Hide\u2014Threat hunting report","year":"2023","key":"ref6"},{"volume-title":"APT41: A Dual Espionage and Cyber Crime Operation","year":"2022","key":"ref7"},{"volume-title":"LightBasin: A roaming threat to telecommunications companies","year":"2021","key":"ref8"},{"key":"ref9","first-page":"1","article-title":"An interview study on third-party cyber threat hunting processes in the U.S. Department of Homeland Security","volume-title":"Proc. USENIX Security Symp.","author":"Maxam"},{"volume-title":"Executive Order 14028: Improving the Nation\u2019s Cybersecurity","year":"2021","key":"ref10"},{"volume-title":"The United States Government Manual","year":"2022","key":"ref11"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-88418-5_34"},{"key":"ref13","first-page":"77","article-title":"Attack forecast and prediction","volume-title":"Proc. C&ESAR","volume":"21","author":"Kaiser"},{"volume-title":"Attack vs. Data: What you need to know about threat hunting","year":"2023","key":"ref14"},{"volume-title":"Uncovering an undetected KeyPlug implant attacking industries in Italy","year":"2024","key":"ref15"},{"article-title":"Threat Horizons\u2014April 2023 threat horizons report","volume-title":"Google Cybersecurity Action Team","year":"2023","key":"ref16"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2024.3468914"},{"key":"ref18","article-title":"On the feasibility of using LLMs to execute multistage network attacks","author":"Singer","year":"2025","journal-title":"arXiv:2501.16466"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1145\/3559768"},{"key":"ref20","article-title":"ProAPT: Projection of APT threats with deep reinforcement learning","author":"Dehghan","year":"2022","journal-title":"arXiv:2209.07215"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2024.3378972"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2022.3233703"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-57540-2_5"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3299519"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1109\/FNWF55208.2022.00046"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2017.2751478"},{"key":"ref27","first-page":"1","article-title":"ATLAS: A sequence-based learning approach for attack investigation","volume-title":"Proc. USENIX Security Symp.","author":"Alsaheel"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.23919\/ICACT53585.2022.9728949"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1145\/3678890.3678909"},{"volume-title":"A method of detecting and predicting attack vectors based on genetic programming","year":"2023","author":"Churakova","key":"ref30"},{"issue":"5","key":"ref31","first-page":"61","article-title":"Heuristic multistep attack scenarios construction based on kill chain","volume":"30","author":"Jie","year":"2023","journal-title":"J. China Univ. Posts Telecommun."},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/DSC63325.2024.00013"},{"key":"ref33","article-title":"An automated, end-to-end framework for modeling attacks from vulnerability descriptions","author":"Binyamini","year":"2020","journal-title":"arXiv:2008.04377"},{"key":"ref34","first-page":"1","article-title":"Are cyber attackers thinking fast and slow? Evidence for cognitive biases in red teamers reveals a method for disruption","volume-title":"Proc. Human Factors Ergonomics Society Annu. Meeting","author":"Gutzwiller"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/SP46215.2023.10179341"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2019.101607"},{"key":"ref37","first-page":"165","article-title":"Mapping the security events to the MITRE ATT &CK attack patterns to forecast attack propagation","volume-title":"Proc. Int. Workshop Attacks Defenses Internet-Things","author":"Kryukov"},{"volume-title":"Welcome to Goot Camp: Tracking the Evolution of GOOTLOADER Operations","year":"2023","key":"ref38"},{"volume-title":"Don\u2019t @ Me: URL Obfuscation Through Schema Abuse","year":"2023","key":"ref39"},{"volume-title":"Guide to cyber threat hunting","year":"2022","key":"ref40"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3030076"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-75396-6_5"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/msec.2024.3492132"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1109\/IOTM.001.2400061"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2018.01.004"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2020.3041951"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.3390\/info10040122"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103821"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-981-16-6054-2_10"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1890\/08-1034.1"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1016\/j.physrep.2009.11.002"},{"key":"ref52","doi-asserted-by":"publisher","DOI":"10.1137\/1.9781611972825.10"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3543507.3583340"},{"key":"ref54","article-title":"How powerful are graph neural networks?","author":"Xu","year":"2018","journal-title":"arXiv:1810.00826"},{"key":"ref55","article-title":"A comparative study of similarity-based and GNN-based link prediction approaches","author":"Islam","year":"2020","journal-title":"arXiv:2008.08879"},{"key":"ref56","first-page":"1","article-title":"Inductive representation learning on large graphs","volume-title":"Proc. Adv. Neural Inf. Process. Syst.","volume":"30","author":"Hamilton"},{"volume-title":"MITRE ATT&CK: Design and Philosophy","year":"2020","author":"Strom","key":"ref57"},{"volume-title":"FiGHT (5G Hierarchy of Threats)","year":"2023","key":"ref58"},{"key":"ref59","article-title":"Evidential cyber threat hunting","author":"Araujo","year":"2021","journal-title":"arXiv:2104.10319"},{"volume-title":"Cybersecurity\u2014Attack and Defense Strategies: Infrastructure Security With Red Team and Blue Team Tactics","year":"2018","author":"Diogenes","key":"ref60"},{"volume-title":"The Mandiant cyber threat intelligence (CTI) analyst core competencies framework","year":"2022","key":"ref61"}],"container-title":["IEEE Transactions on Network and Service Management"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/4275028\/11194281\/11045189.pdf?arnumber=11045189","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,8]],"date-time":"2025-10-08T17:38:25Z","timestamp":1759945105000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11045189\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,10]]},"references-count":61,"journal-issue":{"issue":"5"},"URL":"https:\/\/doi.org\/10.1109\/tnsm.2025.3581463","relation":{},"ISSN":["1932-4537","2373-7379"],"issn-type":[{"type":"electronic","value":"1932-4537"},{"type":"electronic","value":"2373-7379"}],"subject":[],"published":{"date-parts":[[2025,10]]}}}