{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,3]],"date-time":"2026-07-03T06:37:16Z","timestamp":1783060636403,"version":"3.54.6"},"publisher-location":"New York, NY, USA","reference-count":32,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,4,15]],"date-time":"2024-04-15T00:00:00Z","timestamp":1713139200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"name":"MUR National Recovery and Resilience Plan funded by the European Union - NextGenerationEU","award":["SERICS (PE00000014)"],"award-info":[{"award-number":["SERICS (PE00000014)"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,4,15]]},"DOI":"10.1145\/3643662.3643962","type":"proceedings-article","created":{"date-parts":[[2024,8,26]],"date-time":"2024-08-26T18:16:08Z","timestamp":1724696168000},"page":"29-36","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":7,"title":["Building a Cybersecurity Knowledge Graph with CyberGraph"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-1933-5348","authenticated-orcid":false,"given":"Paolo","family":"Falcarin","sequence":"first","affiliation":[{"name":"Dipartimento di Scienze Ambientali, Informatica e Statistica, Ca' Foscari University of Venice, Venice, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0004-8902-5729","authenticated-orcid":false,"given":"Fabio","family":"Dainese","sequence":"additional","affiliation":[{"name":"Dipartimento di Scienze Ambientali, Informatica e Statistica, Ca' Foscari University of Venice, Venice, Italy"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2024,8,26]]},"reference":[{"key":"e_1_3_2_1_1_1","volume-title":"Linking common vulnerabilities and exposures to the mitre att&ck framework: A self-distillation approach. arXiv preprint arXiv:2108.01696","author":"Ampel Benjamin","year":"2021","unstructured":"Benjamin Ampel, Sagar Samtani, Steven Ullman, and Hsinchun Chen. 2021. Linking common vulnerabilities and exposures to the mitre att&ck framework: A self-distillation approach. arXiv preprint arXiv:2108.01696 (2021)."},{"key":"e_1_3_2_1_2_1","volume-title":"Proceedings of the 7th linguistic annotation workshop and interoperability with discourse. 178--186","author":"Banarescu Laura","year":"2013","unstructured":"Laura Banarescu, Claire Bonial, Shu Cai, Madalina Georgescu, Kira Griffitt, Ulf Hermjakob, Kevin Knight, Philipp Koehn, Martha Palmer, and Nathan Schneider. 2013. Abstract meaning representation for sembanking. In Proceedings of the 7th linguistic annotation workshop and interoperability with discourse. 178--186."},{"key":"e_1_3_2_1_3_1","first-page":"1","article-title":"Standardizing cyber threat intelligence information with the structured threat information expression (stix)","volume":"11","author":"Barnum Sean","year":"2012","unstructured":"Sean Barnum. 2012. Standardizing cyber threat intelligence information with the structured threat information expression (stix). Mitre Corporation 11 (2012), 1--22.","journal-title":"Mitre Corporation"},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2018.12.025"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10639-022-11261-8"},{"key":"e_1_3_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/ICPC.2017.2"},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1007\/s10664-018-9625-6"},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/TSG.2011.2160000"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/1533057.1533084"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/SANER.2018.8330232"},{"key":"e_1_3_2_1_11_1","doi-asserted-by":"crossref","unstructured":"International Business Machines Corporation (IBM). 2022. Cost of a Data Breach - 2022 Report. arXiv:https:\/\/www.ibm.com\/downloads\/cas\/3R8N1DZJ https:\/\/www.ibm.com\/reports\/data-breach","DOI":"10.12968\/S1353-4858(22)70049-9"},{"key":"e_1_3_2_1_12_1","unstructured":"SonicWall Inc. 2022. 2022 Cyber Threat Report. https:\/\/www.sonicwall.com\/medialibrary\/en\/white-paper\/2022-sonicwall-cyber-threat-report.pdf"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"crossref","unstructured":"Verizon Communications Inc. 2022. 2022 Data Breach Investigations Report. arXiv:https:\/\/www.verizon.com\/business\/resources\/T6a\/reports\/dbir\/2022-data-breach-investigations-report-dbir.pdf https:\/\/www.verizon.com\/business\/resources\/reports\/dbir\/","DOI":"10.12968\/S1361-3723(22)70578-7"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyaa015"},{"key":"e_1_3_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.eng.2018.01.004"},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/2746266.2746277"},{"key":"e_1_3_2_1_17_1","volume-title":"Security and Privacy in Digital Economy: First International Conference, SPDE 2020, Quzhou, China, October 30-November 1, 2020, Proceedings 1. Springer, 100--113","author":"Li Kun","year":"2020","unstructured":"Kun Li, Huachun Zhou, Zhe Tu, and Bohao Feng. 2020. CSKB: a cyber security knowledge base based on knowledge graph. In Security and Privacy in Digital Economy: First International Conference, SPDE 2020, Quzhou, China, October 30-November 1, 2020, Proceedings 1. Springer, 100--113."},{"key":"e_1_3_2_1_18_1","volume-title":"2017 Fifth International Conference on Advanced Cloud and Big Data (CBD). IEEE, 296--301","author":"Li Xiang","year":"2017","unstructured":"Xiang Li, Jinfu Chen, Zhechao Lin, Lin Zhang, Zibin Wang, Minmin Zhou, and Wanggen Xie. 2017. A mining approach to obtain the software vulnerability characteristics. In 2017 Fifth International Conference on Advanced Cloud and Big Data (CBD). IEEE, 296--301."},{"key":"e_1_3_2_1_19_1","volume-title":"2022 26th International Conference on Pattern Recognition (ICPR). IEEE, 1557--1563","author":"Liu Peipei","year":"2022","unstructured":"Peipei Liu, Hong Li, Zuoguang Wang, Jie Liu, Yimo Ren, and Hongsong Zhu. 2022. Multi-features based Semantic Augmentation Networks for Named Entity Recognition in Threat Intelligence. In 2022 26th International Conference on Pattern Recognition (ICPR). IEEE, 1557--1563."},{"key":"e_1_3_2_1_20_1","unstructured":"SS Jeremy Long S Springett and W Stranathan. 2015. Owasp dependency check. https:\/\/owasp.org\/www-project-dependency-check\/"},{"key":"e_1_3_2_1_21_1","unstructured":"Leo Obrst Penny Chase and Richard Markeloff. 2012. Developing an Ontology of the Cyber Security Domain.. In STIDS. 49--56."},{"key":"e_1_3_2_1_22_1","volume-title":"Robert J Walls, and Patrick D McDaniel.","author":"Oltramari Alessandro","year":"2014","unstructured":"Alessandro Oltramari, Lorrie Faith Cranor, Robert J Walls, and Patrick D McDaniel. 2014. Building an Ontology of Cyber Security.. In STIDS. Citeseer, 54--61."},{"key":"e_1_3_2_1_23_1","volume-title":"Proceedings of the 2019 IEEE\/ACM International Conference on Advances in Social Networks Analysis and Mining. 879--886","author":"Pingle Aditya","year":"2019","unstructured":"Aditya Pingle, Aritran Piplai, Sudip Mittal, Anupam Joshi, James Holt, and Richard Zak. 2019. Relext: Relation extraction using deep learning approaches for cyber-security knowledge graph improvement. In Proceedings of the 2019 IEEE\/ACM International Conference on Advances in Social Networks Analysis and Mining. 879--886."},{"key":"e_1_3_2_1_24_1","unstructured":"The Software Security Project. 2023. Zed Attack Proxy. https:\/\/www.zaproxy.org\/"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1145\/3424672"},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1609\/aaai.v34i05.6401"},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1155\/2020\/8883696"},{"key":"e_1_3_2_1_28_1","volume-title":"Technical report","author":"Strom Blake E","unstructured":"Blake E Strom, Andy Applebaum, Doug P Miller, Kathryn C Nickels, Adam G Pennington, and Cody B Thomas. 2018. Mitre att&ck: Design and philosophy. In Technical report. The MITRE Corporation."},{"key":"e_1_3_2_1_29_1","volume-title":"Workshops at the thirtieth AAAI conference on artificial intelligence.","author":"Syed Zareen","year":"2016","unstructured":"Zareen Syed, Ankur Padia, Tim Finin, Lisa Mathews, and Anupam Joshi. 2016. UCO: A unified cybersecurity ontology. In Workshops at the thirtieth AAAI conference on artificial intelligence."},{"key":"e_1_3_2_1_30_1","volume-title":"Neural Information Processing: 26th International Conference, ICONIP 2019, Sydney, NSW, Australia, December 12-15, 2019, Proceedings, Part III 26","author":"Xiao Hongbo","year":"2019","unstructured":"Hongbo Xiao, Zhenchang Xing, Xiaohong Li, and Hao Guo. 2019. Embedding and predicting software security entity relationships: A knowledge graph based approach. In Neural Information Processing: 26th International Conference, ICONIP 2019, Sydney, NSW, Australia, December 12-15, 2019, Proceedings, Part III 26. Springer, 50--63."},{"key":"e_1_3_2_1_31_1","volume-title":"Predicting entity relations across different security databases by using graph attention network. In 2021 IEEE 45th Annual Computers, Software, and Applications Conference (COMPSAC)","author":"Yuan Liu","unstructured":"Liu Yuan, Yude Bai, Zhenchang Xing, Sen Chen, Xiaohong Li, and Zhidong Deng. 2021. Predicting entity relations across different security databases by using graph attention network. In 2021 IEEE 45th Annual Computers, Software, and Applications Conference (COMPSAC). IEEE, 834--843."},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/CyberSecPODS.2016.7502352"}],"event":{"name":"EnCyCriS\/SVM '24: 2024 ACM\/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE\/ACM Second International Workshop on Software Vulnerability","location":"Lisbon Portugal","acronym":"EnCyCriS\/SVM '24","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering","IEEE CS","Faculty of Engineering of University of Porto"]},"container-title":["Proceedings of the 2024 ACM\/IEEE 4th International Workshop on Engineering and Cybersecurity of Critical Systems (EnCyCriS) and 2024 IEEE\/ACM Second International Workshop on Software Vulnerability"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643662.3643962","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3643662.3643962","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T00:05:32Z","timestamp":1750291532000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3643662.3643962"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,4,15]]},"references-count":32,"alternative-id":["10.1145\/3643662.3643962","10.1145\/3643662"],"URL":"https:\/\/doi.org\/10.1145\/3643662.3643962","relation":{},"subject":[],"published":{"date-parts":[[2024,4,15]]},"assertion":[{"value":"2024-08-26","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}