{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,9]],"date-time":"2026-06-09T16:12:27Z","timestamp":1781021547694,"version":"3.54.1"},"reference-count":41,"publisher":"Wiley","issue":"1","license":[{"start":{"date-parts":[[2021,3,30]],"date-time":"2021-03-30T00:00:00Z","timestamp":1617062400000},"content-version":"vor","delay-in-days":88,"URL":"http:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["61962015"],"award-info":[{"award-number":["61962015"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["onlinelibrary.wiley.com"],"crossmark-restriction":true},"short-container-title":["Wireless Communications and Mobile Computing"],"published-print":{"date-parts":[[2021,1]]},"abstract":"<jats:p>Internet of Things (IoT) brought great convenience to people\u2019s daily lives. Meanwhile, the IoT devices are facing severe attacks from hackers and malicious attackers. Hackers and malicious attackers use various methods to invade the Internet of Things system, causing the Internet of Things to face a large number of targeted, concealed, and penetrating potential threats, which makes the privacy problem of the Internet of Things suffers serious challenges. But the existing methods and technologies cannot fully identify the attacker\u2019s attack process and protect the privacy of the Internet of Things. Alarm correlation method can construct a complete attack scenario and identify the attacker\u2019s intention by alarming the alarm data which provides an effective protection for user privacy. However, the existing alarm correlation methods still have the disadvantages of low correlation accuracy, poor correlation efficiency, and strong dependence on the knowledge base. To address these issues, we propose an alarm correlation method based on Affinity Propagation (AP) clustering algorithm and causal relationship. Our method considers that the alarm data triggered by the same attack process has high similarity characteristics, adopts the AP algorithm to improve the correlation efficiency, and at the same time constructs a complete attack process based on the causal correlation idea. The new alarm correlation method has a high correlation effect and builds a complete attack process to help managers identify attack intentions and prevent attacks.<\/jats:p>","DOI":"10.1155\/2021\/5576504","type":"journal-article","created":{"date-parts":[[2021,3,31]],"date-time":"2021-03-31T00:05:29Z","timestamp":1617149129000},"update-policy":"https:\/\/doi.org\/10.1002\/crossmark_policy","source":"Crossref","is-referenced-by-count":11,"title":["A Hybrid Alarm Association Method Based on AP Clustering and Causality"],"prefix":"10.1155","volume":"2021","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-6573-2291","authenticated-orcid":false,"given":"Xiao-ling","family":"Tao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6634-1647","authenticated-orcid":false,"given":"Lan","family":"Shi","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5730-2208","authenticated-orcid":false,"given":"Feng","family":"Zhao","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-7233-1552","authenticated-orcid":false,"given":"Shen","family":"Lu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-4043-8165","authenticated-orcid":false,"given":"Yang","family":"Peng","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"311","published-online":{"date-parts":[[2021,3,30]]},"reference":[{"key":"e_1_2_10_1_2","first-page":"7","article-title":"Opportunities and challenges facing the security development of the Internet of Things","volume":"39","author":"Wang Y. B.","year":"2017","journal-title":"Information Security and Communication Confidentiality"},{"key":"e_1_2_10_2_2","doi-asserted-by":"publisher","DOI":"10.3390\/s19184045"},{"key":"e_1_2_10_3_2","doi-asserted-by":"crossref","unstructured":"CaiZ.andHeZ. Trading private range counting over big IoT data 2019 IEEE 39th International Conference on Distributed Computing Systems (ICDCS) 2019 Dallas TX USA 144\u2013153 https:\/\/doi.org\/10.1109\/icdcs.2019.00023.","DOI":"10.1109\/ICDCS.2019.00023"},{"key":"e_1_2_10_4_2","article-title":"2019 China cybersecurity development white paper","author":"CCID Consulting","year":"2019","journal-title":"China Computer News"},{"key":"e_1_2_10_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2018.2830307"},{"key":"e_1_2_10_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2020.2980802"},{"key":"e_1_2_10_7_2","doi-asserted-by":"publisher","DOI":"10.1002\/cpe.6001"},{"key":"e_1_2_10_8_2","doi-asserted-by":"publisher","DOI":"10.1177\/1550147718814471"},{"key":"e_1_2_10_9_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2017.2694844"},{"key":"e_1_2_10_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2004.21"},{"key":"e_1_2_10_11_2","doi-asserted-by":"crossref","unstructured":"QinX.andLeeW. Statistical causality analysis of INFOSEC alert data International Symposium on Research in Attacks Intrusions and Defenses (RAID) 2003 Pittsburgh USA 73\u201393.","DOI":"10.1007\/978-3-540-45248-5_5"},{"key":"e_1_2_10_12_2","first-page":"1538","article-title":"A real - time alarm correlation method based on attack plan diagram","volume":"36","author":"Zhang J.","year":"2016","journal-title":"Computer Application"},{"key":"e_1_2_10_13_2","doi-asserted-by":"crossref","unstructured":"LiZ. LeiJ. WangL. andLiD. A data mining approach to generating network attack graph for intrusion prediction 2007 4th International Conference on Fuzzy Systems and Knowledge Discovery (FSKD) 2007 Haikou China 307\u2013311 https:\/\/doi.org\/10.1109\/fskd.2007.15 2-s2.0-44049099987.","DOI":"10.1109\/FSKD.2007.15"},{"key":"e_1_2_10_14_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2014.10.006"},{"key":"e_1_2_10_15_2","first-page":"210","article-title":"An association analysis method of ASON alarm based on hierarchical attribute similarity clustering","volume":"15","author":"Gao H. S.","year":"2015","journal-title":"Science and Technology and Engineering"},{"key":"e_1_2_10_16_2","doi-asserted-by":"crossref","unstructured":"HostiadiD. P. SusilaM. D. andHuizenR. R. A new alert correlation model based on similarity approach 2019 1st International Conference on Cybernetics and Intelligent System (ICORIS) 2019 Denpasar Indonesia 133\u2013137 https:\/\/doi.org\/10.1109\/icoris.2019.8874899.","DOI":"10.1109\/ICORIS.2019.8874899"},{"key":"e_1_2_10_17_2","doi-asserted-by":"crossref","unstructured":"TaoX. PengY. ZhaoF. WangS. F. andLiuZ. An improved parallel network traffic anomaly detection method based on bagging and GRU 2020 15th International Conference on Wireless Algorithms Systems and Applications (WASA) 2020 Qingdao China 420\u2013431.","DOI":"10.1007\/978-3-030-59016-1_35"},{"key":"e_1_2_10_18_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2018.03.001"},{"key":"e_1_2_10_19_2","first-page":"9","article-title":"Research on security alarm association technology","volume":"37","author":"Fu X.","year":"2010","journal-title":"Computer Science"},{"key":"e_1_2_10_20_2","doi-asserted-by":"crossref","unstructured":"ChengL. WangY. andMaX. K. GSLAC: A general scalable and low-overhead alert correlation method 2016 IEEE Trustcom\/BigDataSE\/ISPA 2016 Tianjin China 316\u2013323 https:\/\/doi.org\/10.1109\/TrustCom.2016.0079 2-s2.0-85015230408.","DOI":"10.1109\/TrustCom.2016.0079"},{"key":"e_1_2_10_21_2","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1756"},{"key":"e_1_2_10_22_2","doi-asserted-by":"crossref","unstructured":"HaasS.andFischerM. GAC: graph-based alert correlation for the detection of distributed multi-step attacks SAC 2018: Symposium on Applied Computing 2018 Pau France 979\u2013988 https:\/\/doi.org\/10.1145\/3167132.3167239 2-s2.0-85050525079.","DOI":"10.1145\/3167132.3167239"},{"key":"e_1_2_10_23_2","doi-asserted-by":"publisher","DOI":"10.4028\/www.scientific.net\/AMR.926-930.3063"},{"key":"e_1_2_10_24_2","doi-asserted-by":"crossref","unstructured":"LiK. Y. LiY. LiuJ. Y. ZhangR. andDuanX. Attack pattern mining algorithm based on security log 2017 IEEE International Conference on Intelligence and Security Informatics (ISI) 2017 Beijing China 205\u2013205 https:\/\/doi.org\/10.1109\/isi.2017.8004918 2-s2.0-85030228386.","DOI":"10.1109\/ISI.2017.8004918"},{"key":"e_1_2_10_25_2","doi-asserted-by":"publisher","DOI":"10.1002\/sec.1483"},{"key":"e_1_2_10_26_2","first-page":"2493","article-title":"A method for mining causal knowledge based on Markov properties","volume":"51","author":"Feng X. W.","year":"2014","journal-title":"Computer Research and Development"},{"key":"e_1_2_10_27_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2012.04.001"},{"key":"e_1_2_10_28_2","doi-asserted-by":"crossref","unstructured":"ZhangY. ZhaoS. andZhangJ. RTMA: real time mining algorithm for multi-step attack scenarios reconstruction 2019 IEEE 21st International Conference on High Performance Computing and Communications; IEEE 17th International Conference on Smart City; IEEE 5th International Conference on Data Science and Systems (HPCC\/SmartCity\/DSS) 2019 Zhangjiajie China 2103\u20132110 https:\/\/doi.org\/10.1109\/hpcc\/smartcity\/dss.2019.00291 2-s2.0-85073500421.","DOI":"10.1109\/HPCC\/SmartCity\/DSS.2019.00291"},{"key":"e_1_2_10_29_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2018.04.030"},{"key":"e_1_2_10_30_2","doi-asserted-by":"crossref","unstructured":"TianJ.-w. LiX. TianZ. andQiW.-h. Network attack path reconstruction based on similarity computation 2017 13th International Conference on Natural Computation Fuzzy Systems and Knowledge Discovery (ICNC-FSKD) 2017 Guilin China 2457\u20132461 https:\/\/doi.org\/10.1109\/fskd.2017.8393160 2-s2.0-85050244269.","DOI":"10.1109\/FSKD.2017.8393160"},{"key":"e_1_2_10_31_2","doi-asserted-by":"publisher","DOI":"10.1021\/acs.iecr.8b05906"},{"key":"e_1_2_10_32_2","doi-asserted-by":"publisher","DOI":"10.1126\/science.1136800"},{"key":"e_1_2_10_33_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.mcm.2011.01.055"},{"key":"e_1_2_10_34_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.comnet.2011.03.005"},{"key":"e_1_2_10_35_2","first-page":"1291","article-title":"Intrusion detection method based on principal component analysis and Simhash","volume":"43","author":"Zhou L. Q.","year":"2015","journal-title":"Computer and Digital Engineering"},{"key":"e_1_2_10_36_2","doi-asserted-by":"crossref","unstructured":"Bal\u00e1\u017eA. \u00c1d\u00e1mN. Pietrikov\u00e1E. andMado\u0161B. ModSecurity IDMEF module 2018 IEEE 16th World Symposium on Applied Machine Intelligence and Informatics (SAMI) 2018 Kosice and Herlany Slovakia 43\u201348 https:\/\/doi.org\/10.1109\/SAMI.2018.8323984 2-s2.0-85050966503.","DOI":"10.1109\/SAMI.2018.8323984"},{"key":"e_1_2_10_37_2","first-page":"908","article-title":"An OSSEC alarm data aggregation method based on classification","volume":"41","author":"Tao X. L.","year":"2020","journal-title":"Computer Engineering and Design"},{"key":"e_1_2_10_38_2","doi-asserted-by":"crossref","unstructured":"NingP. YunC. andReevesD. Analyzing intensive intrusion alerts via correlation International Symposium on Research in Attacks Intrusions and Defenses (RAID) 2002 Zurich Switzerland 74\u201394.","DOI":"10.1007\/3-540-36084-0_5"},{"key":"e_1_2_10_39_2","article-title":"Research on active defence application based on honeypot","volume":"4","author":"Yang D. Q.","year":"2018","journal-title":"Journal of Network and Information Security"},{"key":"e_1_2_10_40_2","first-page":"2620","article-title":"Construction method of attack scenario based on causal knowledge network","volume":"55","author":"Wang S.","year":"2018","journal-title":"Computer Research and Development"},{"key":"e_1_2_10_41_2","doi-asserted-by":"crossref","unstructured":"KawakaniC. T. JuniorS. B. andMianiR. S. Intrusion alert correlation to support security management Brazilian Symposium on Information Systems (SBSI) 2016 Florian\u00f3polis Brazil 313\u2013320 https:\/\/doi.org\/10.5753\/sbsi.2016.5977.","DOI":"10.5753\/sbsi.2016.5977"}],"container-title":["Wireless Communications and Mobile Computing"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2021\/5576504.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"http:\/\/downloads.hindawi.com\/journals\/wcmc\/2021\/5576504.xml","content-type":"application\/xml","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/pdf\/10.1155\/2021\/5576504","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,8,7]],"date-time":"2024-08-07T10:14:14Z","timestamp":1723025654000},"score":1,"resource":{"primary":{"URL":"https:\/\/onlinelibrary.wiley.com\/doi\/10.1155\/2021\/5576504"}},"subtitle":[],"editor":[{"given":"Zhuojun","family":"Duan","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"editor"}]}],"short-title":[],"issued":{"date-parts":[[2021,1]]},"references-count":41,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,1]]}},"alternative-id":["10.1155\/2021\/5576504"],"URL":"https:\/\/doi.org\/10.1155\/2021\/5576504","archive":["Portico"],"relation":{},"ISSN":["1530-8669","1530-8677"],"issn-type":[{"value":"1530-8669","type":"print"},{"value":"1530-8677","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,1]]},"assertion":[{"value":"2021-01-06","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-03-15","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2021-03-30","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}],"article-number":"5576504"}}