{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,20]],"date-time":"2026-06-20T21:41:59Z","timestamp":1781991719860,"version":"3.54.5"},"reference-count":27,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2021,5,3]],"date-time":"2021-05-03T00:00:00Z","timestamp":1620000000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2021,5,3]],"date-time":"2021-05-03T00:00:00Z","timestamp":1620000000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecur"],"published-print":{"date-parts":[[2021,12]]},"abstract":"<jats:title>Abstract<\/jats:title><jats:p>Named Entity Recognition (NER) for cyber security aims to identify and classify cyber security terms from a large number of heterogeneous multisource cyber security texts. In the field of machine learning, deep neural networks automatically learn text features from a large number of datasets, but this data-driven method usually lacks the ability to deal with rare entities. Gasmi et al. proposed a deep learning method for named entity recognition in the field of cyber security, and achieved good results, reaching an F1 value of 82.8%. But it is difficult to accurately identify rare entities and complex words in the text.To cope with this challenge, this paper proposes a new model that combines data-driven deep learning methods with knowledge-driven dictionary methods to build dictionary features to assist in rare entity recognition. In addition, based on the data-driven deep learning model, an attention mechanism is adopted to enrich the local features of the text, better models the context, and improves the recognition effect of complex entities. Experimental results show that our method is better than the baseline model. Our model is more effective in identifying cyber security entities. The Precision, Recall and F1 value reached 90.19%, 86.60% and 88.36% respectively.<\/jats:p>","DOI":"10.1186\/s42400-021-00072-y","type":"journal-article","created":{"date-parts":[[2021,5,3]],"date-time":"2021-05-03T14:54:51Z","timestamp":1620053691000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":47,"title":["Data and knowledge-driven named entity recognition for cyber security"],"prefix":"10.1186","volume":"4","author":[{"given":"Chen","family":"Gao","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2929-2126","authenticated-orcid":false,"given":"Xuan","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hui","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2021,5,3]]},"reference":[{"key":"72_CR1","unstructured":"Bridges, R, Jones C, MD. Iannacone KT, Goodall J (2013) Automatic labeling for entity extraction in cyber security. arXiv preprint arXiv:1308.4941."},{"key":"72_CR2","first-page":"2493","volume":"12","author":"R Collobert","year":"2011","unstructured":"Collobert, R, Weston J, Bottou L, Karlen M, Kavukcuoglu K, Kuksa P (2011) Natural language processing (almost) from scratch. J Mach Learn Res 12:2493\u20132537.","journal-title":"J Mach Learn Res"},{"key":"72_CR3","first-page":"1","volume-title":"2019 International Joint Conference on Neural Networks (IJCNN)","author":"N Dion\u00edsio","year":"2019","unstructured":"Dion\u00edsio, N, Alves F, Ferreira P, Bessani A (2019) Cyber threat detection from twitter using deep neural networks In: 2019 International Joint Conference on Neural Networks (IJCNN), 1\u20138.. IEEE, Budapest."},{"key":"72_CR4","unstructured":"Gasmi, H, Bouras A, Laval J (2018) Lstm recurrent neural networks for cyber security named entity recognition In: Proceedings of the Thirteenth International Conference on Software Engineering Advances, Nice."},{"key":"72_CR5","first-page":"245","volume":"47","author":"X Gu","year":"2018","unstructured":"Gu, X, Liu J, Cheng P, He X (2018) Tweet malware name recognition based on enhanced bilstmcrf model(in chinese). Comput Sci 47:245\u2013250.","journal-title":"Comput Sci"},{"key":"72_CR6","doi-asserted-by":"publisher","first-page":"1735","DOI":"10.1162\/neco.1997.9.8.1735","volume":"9","author":"S Hochreiter","year":"1997","unstructured":"Hochreiter, S, Schmidhuber J (1997) Long short-term memory. Neural Comput 9:1735\u20131780.","journal-title":"Neural Comput"},{"key":"72_CR7","unstructured":"Huang, Z, Xu W, Yu K (2015) Bidirectional lstm-crf models for sequence tagging. International Symposium on Foundations and Practice of Security. arXiv preprint."},{"key":"72_CR8","doi-asserted-by":"crossref","unstructured":"Jones, C, Bridges R, Huffer K, Goodall J (2015) Towards a relation extraction framework for cyber-security concepts In: Proceedings of the 10th Annual Cyber and Information Security Research Conference, 1\u20134.","DOI":"10.1145\/2746266.2746277"},{"key":"72_CR9","doi-asserted-by":"publisher","first-page":"252","DOI":"10.1109\/ICSC.2013.50","volume-title":"Proceedings of the 2013 IEEE Seventh International Conference on Semantic Computing","author":"A Joshi","year":"2013","unstructured":"Joshi, A, Lal R, Finin T, Joshi A (2013) Extracting cybersecurity related linked data from text In: Proceedings of the 2013 IEEE Seventh International Conference on Semantic Computing, 252\u2013259.. IEEE, Irvine."},{"key":"72_CR10","unstructured":"Lal, R (2013) Information extraction of security related entities and concepts from unstructured text. Dissertation. University of Maryland Baltimore County."},{"key":"72_CR11","doi-asserted-by":"publisher","first-page":"436","DOI":"10.1038\/nature14539","volume":"521","author":"Y LeCun","year":"2015","unstructured":"LeCun, Y, Bengio Y, Hinton G (2015) Deep learning. Nature 521:436\u2013444.","journal-title":"Nature"},{"key":"72_CR12","first-page":"147","volume-title":"Proceedings of the 15th International Conference on Computational Intelligence and Security","author":"T Li","year":"2019","unstructured":"Li, T, Guo Y, Ju A (2019) A self-attention-based approach for named entity recognition in cybersecurity In: Proceedings of the 15th International Conference on Computational Intelligence and Security, 147\u2013150.. IEEE, Macao."},{"key":"72_CR13","first-page":"1687","volume-title":"Data Processing Techniques and Applications for Cyber-Physical Systems","author":"W Liu","year":"2020","unstructured":"Liu, W (2020) Network security entity recognition methods based on the deep neural network In: Data Processing Techniques and Applications for Cyber-Physical Systems, 1687\u20131692.. Springer, Singapore."},{"key":"72_CR14","unstructured":"Mazharov, I, Dobrov B (2018) Named entity recognition for information security domain In: Proceedings of the Data Analytics and Management in Data Intensive Domains, Moscow."},{"key":"72_CR15","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1109\/WI-IAT.2011.26","volume-title":"Proceedings of the 2011 IEEE\/WIC\/ACM International Conferences on Web Intelligence and Intelligent Agent Technology","author":"V Mulwad","year":"2011","unstructured":"Mulwad, V, Li W, Joshi A, Finin T, Viswanathan K (2011) Extracting information about security vulnerabilities from web text In: Proceedings of the 2011 IEEE\/WIC\/ACM International Conferences on Web Intelligence and Intelligent Agent Technology, 257\u2013260.. IEEE, Lyon."},{"key":"72_CR16","doi-asserted-by":"publisher","first-page":"872","DOI":"10.1631\/FITEE.1800520","volume":"20","author":"Y Qin","year":"2019","unstructured":"Qin, Y, Shen G, Zhao W, Chen Y, Yu M, Jin X (2019) A network security entity recognition method based on feature template and cnn-bilstm-crf. Frontiers Inf Technol Electronic Eng 20:872\u2013884.","journal-title":"Frontiers Inf Technol Electronic Eng"},{"key":"72_CR17","first-page":"245","volume":"47","author":"A Roy","year":"2017","unstructured":"Roy, A, Park Y, Pan S (2017) Learning domain-specific word embeddings from sparse cybersecurity texts. arXiv preprint arXiv:1709.07470 47:245\u2013250.","journal-title":"arXiv preprint arXiv:1709.07470"},{"key":"72_CR18","first-page":"163","volume-title":"International Symposium on Signal Processing and Intelligent Recognition Systems","author":"K Simran","year":"2019","unstructured":"Simran, K, Sriram S, Vinayakumar R, Soman K (2019) Deep learning approach for intelligent named entity recognition of cyber security In: International Symposium on Signal Processing and Intelligent Recognition Systems, 163\u2013172.. Springer, Singapore."},{"key":"72_CR19","first-page":"16","volume-title":"International Conference on Applications of Natural Language to Information Systems","author":"M Tikhomirov","year":"2020","unstructured":"Tikhomirov, M, Loukachevitch N, Sirotina A, Dobrov B (2020) Using BERT and Augmentation in Named Entity Recognition for Cybersecurity Domain In: International Conference on Applications of Natural Language to Information Systems, 16\u201324.. Springer, Cham."},{"key":"72_CR20","unstructured":"Vaswani, A, Shazeer N, Parmar N (2017) Attention is all you need. Attention is all you need. Advances in neural information processing systems. Curran Associates, Inc, 5998\u20136008."},{"key":"72_CR21","first-page":"157","volume-title":"CCF International Conference on Natural Language Processing and Chinese Computing","author":"X Wang","year":"2020","unstructured":"Wang, X, Xiong Z, Du X, Jiang J, Jiang Z (2020) NER in Threat Intelligence Domain with TSFL In: CCF International Conference on Natural Language Processing and Chinese Computing, 157\u2013169.. Springer, Cham."},{"key":"72_CR22","doi-asserted-by":"publisher","first-page":"356","DOI":"10.1007\/978-3-319-17040-4_24","volume":"8930","author":"S Weerawardhana","year":"2014","unstructured":"Weerawardhana, S, Mukherjee S, Ray I, Howe A (2014) Automated extraction of vulnerability information for home computer security. Int Symp Found Pract Secur 8930:356\u2013366.","journal-title":"Int Symp Found Pract Secur"},{"key":"72_CR23","doi-asserted-by":"publisher","first-page":"1370","DOI":"10.1109\/ITNEC48623.2020.9085102","volume-title":"2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC)","author":"H Wu","year":"2020","unstructured":"Wu, H, Li X, Gao Y (2020) An effective approach of named entity recognition for cyber threat intelligence In: 2020 IEEE 4th Information Technology, Networking, Electronic and Automation Control Conference (ITNEC), 1370\u20131374.. IEEE, Chongqing."},{"key":"72_CR24","first-page":"2161","volume-title":"Proceedings of the 13th International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery","author":"Z Xiao","year":"2017","unstructured":"Xiao, Z (2017) Towards a two-phase unsupervised system for cybersecurity concepts extraction In: Proceedings of the 13th International Conference on Natural Computation, Fuzzy Systems and Knowledge Discovery, 2161\u20132168.. IEEE, Guilin."},{"key":"72_CR25","first-page":"1","volume":"2","author":"H Zhang","year":"2019","unstructured":"Zhang, H, Guo Y, Li T (2019) Multifeature named entity recognition in information security based on adversarial learning. Secur Commun Netw 2:1\u20139.","journal-title":"Secur Commun Netw"},{"key":"72_CR26","doi-asserted-by":"publisher","first-page":"98","DOI":"10.1016\/j.cpc.2016.07.005","volume":"211","author":"X Zhang","year":"2017","unstructured":"Zhang, X, Liu X, Li X, Pan D (2017) Mmkg: an approach to generate metallic materials knowledge graph based on dbpedia and wikipedia. Comput Phys Commun 211:98\u2013112.","journal-title":"Comput Phys Commun"},{"key":"72_CR27","unstructured":"Zhou, S, Long Z, Tan L, Guo H (2018) Automatic identification of indicators of compromise using neural-based sequence labelling. arXiv preprint arXiv:1810.10156."}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00072-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-021-00072-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-021-00072-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,5,3]],"date-time":"2021-05-03T15:23:32Z","timestamp":1620055412000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-021-00072-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2021,5,3]]},"references-count":27,"journal-issue":{"issue":"1","published-print":{"date-parts":[[2021,12]]}},"alternative-id":["72"],"URL":"https:\/\/doi.org\/10.1186\/s42400-021-00072-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2021,5,3]]},"assertion":[{"value":"21 October 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"11 January 2021","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"3 May 2021","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"The authors declare that they have no competing interests.","order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"9"}}