{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,3]],"date-time":"2026-05-03T05:46:39Z","timestamp":1777787199537,"version":"3.51.4"},"reference-count":54,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"funder":[{"name":"National Cybersecurity Consortium and the Government of Canada"},{"name":"Ericsson Research and the Security Research Centre of Concordia University."}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Netw. Serv. Manage."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tnsm.2026.3684808","type":"journal-article","created":{"date-parts":[[2026,4,23]],"date-time":"2026-04-23T19:59:09Z","timestamp":1776974349000},"page":"4260-4277","source":"Crossref","is-referenced-by-count":0,"title":["Automating Threat-Aligned Testflows Generation Using Ontology-Grounded RAG From CTI Reports"],"prefix":"10.1109","volume":"23","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-0198-9653","authenticated-orcid":false,"given":"Faissal","family":"Ahmadou","sequence":"first","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-5609-856X","authenticated-orcid":false,"given":"Boubakr","family":"Nour","sequence":"additional","affiliation":[{"name":"Ericsson Security Research, Ericsson, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-9775-6231","authenticated-orcid":false,"given":"Makan","family":"Pourzandi","sequence":"additional","affiliation":[{"name":"Ericsson Security Research, Ericsson, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3015-3043","authenticated-orcid":false,"given":"Mourad","family":"Debbabi","sequence":"additional","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3161-1846","authenticated-orcid":false,"given":"Chadi","family":"Assi","sequence":"additional","affiliation":[{"name":"Gina Cody School of Engineering and Computer Science, Concordia Institute for Information Systems Engineering, Concordia University, Montreal, Canada"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3299519"},{"key":"ref2","first-page":"2333","article-title":"An interview study on third-party cyber threat hunting processes in the U.S. department of homeland security","volume-title":"Proc. USENIX Secur. Symp.","author":"Maxam III"},{"key":"ref3","doi-asserted-by":"publisher","DOI":"10.1109\/CNS66487.2025.11194953"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/IOTM.001.2400061"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1145\/3538969.3544420"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-57540-2_5"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP51992.2021.00046"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/NoF66640.2025.11223332"},{"key":"ref9","article-title":"IC-SECURE: Intelligent system for assisting security experts in generating playbooks for automated incident response","author":"Kremer","year":"2023","journal-title":"arXiv:2311.03825"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104016"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSPW54576.2021.00032"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1145\/3607199.3607208"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3273282"},{"key":"ref14","first-page":"54","article-title":"Building an ontology of cyber security","volume":"2014","author":"Oltramari","year":"2014","journal-title":"STIDS"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-98842-9_1"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1007\/s10270-022-01013-0"},{"key":"ref17","doi-asserted-by":"publisher","DOI":"10.1145\/3571730"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/IDSTA66210.2025.11202778"},{"key":"ref19","first-page":"195","article-title":"UCO: A unified cybersecurity ontology","volume-title":"Proc. AAAI Workshop Artif. Intell. Cyber Secur. (AICS)","author":"Syed"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/2025.emnlp-main.1674"},{"key":"ref21","volume-title":"This Is Not a Test: APT41 Initiates Global Intrusion Campaign Using Multiple Exploits","author":"Glyer et al","year":"2024"},{"key":"ref22","first-page":"1","article-title":"Standardizing cyber threat intelligence information with the structured threat information expression (STIX)","volume-title":"Proc. MITRE Corp.","volume":"11","author":"Barnum"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1155\/2019\/6268476"},{"key":"ref24","article-title":"SECURE: Benchmarking generative large language models for cybersecurity advisory","author":"Bhusal","year":"2024","journal-title":"arXiv:2405.20441"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.52202\/079017-1607"},{"key":"ref26","article-title":"Attack tactic identification by transfer learning of language model","author":"Lin","year":"2022","journal-title":"arXiv:2209.00263"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-37586-6_15"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.103815"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-64171-8_17"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2023.103371"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/IEMCON56893.2022.9946567"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/MeditCom58224.2023.10266600"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TSC.2011.38"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/ICICTA51737.2020.00013"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/MSEC.2024.3492132"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/ICCCI56745.2023.10128641"},{"key":"ref37","first-page":"1669","article-title":"Evaluating LLM-based personal information extraction and countermeasures","volume-title":"Proc. USENIX Secur. Symp.","author":"Liu"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1075\/li.30.1.03nad"},{"key":"ref39","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/N16-1030"},{"key":"ref40","first-page":"56","article-title":"A proposal to automatically build and maintain gazetteers for named entity recognition by using Wikipedia","volume-title":"Proc. Workshop NEW TEXT Wikis blogs Other Dyn. Text Sour.","author":"Toral"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.48550\/arXiv.1810.04805"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-63479-7_22"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1145\/1567274.1567278"},{"key":"ref44","first-page":"91","article-title":"HermiT: A highly-efficient OWL reasoner","volume-title":"Proc. Owled","volume":"432","author":"Shearer"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1109\/TBDATA.2025.3618474"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1145\/3746281"},{"key":"ref47","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2025.07.135"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.26615\/978-954-452-071-7_006"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1145\/3134600.3134646"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-031-17140-6_29"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v40i35.40210"},{"key":"ref52","article-title":"A survey on LLM-as-a-judge","author":"Gu","year":"2024","journal-title":"arXiv:2411.15594"},{"key":"ref53","article-title":"Recent advances in natural language inference: A survey of benchmarks, resources, and approaches","author":"Storks","year":"2019","journal-title":"arXiv:1904.01172"},{"key":"ref54","first-page":"165","article-title":"Mapping the security events to the MITRE ATT &CK attack patterns to forecast attack propagation","volume-title":"Proc. Int. Workshop Attacks Defenses Internet Things","author":"Kryukov"}],"container-title":["IEEE Transactions on Network and Service Management"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/4275028\/11319294\/11493951.pdf?arnumber=11493951","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,29]],"date-time":"2026-04-29T19:49:55Z","timestamp":1777492195000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11493951\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":54,"URL":"https:\/\/doi.org\/10.1109\/tnsm.2026.3684808","relation":{},"ISSN":["1932-4537","2373-7379"],"issn-type":[{"value":"1932-4537","type":"electronic"},{"value":"2373-7379","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}