{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,9]],"date-time":"2026-04-09T14:40:04Z","timestamp":1775745604994,"version":"3.50.1"},"reference-count":38,"publisher":"Springer Science and Business Media LLC","issue":"1","license":[{"start":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T00:00:00Z","timestamp":1737936000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"},{"start":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T00:00:00Z","timestamp":1737936000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0"}],"funder":[{"name":"the National Key R&D Program of China under Grant","award":["No.2022YFB4501300"],"award-info":[{"award-number":["No.2022YFB4501300"]}]},{"name":"Shenzhen Science and Technology Programe","award":["No. JCYJ20230807143706014"],"award-info":[{"award-number":["No. JCYJ20230807143706014"]}]}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Cybersecurity"],"abstract":"<jats:title>Abstract<\/jats:title>\n          <jats:p>As modern attack methods become more concealed and complex, obtaining many labeled samples in big data streams is difficult. Active learning has long been used to achieve better intrusion detection performance by using only a small number of training samples. Intrusion behaviors can be described by provenance graphs that record the dependency relationships between intrusion processes and the infected files. It is a challenge to develop active learning strategies that consider defining and selecting the most valuable provenance and ensure that the strategy for querying provenance is efficient. We present Angus, an active learning framework for provenance-based intrusion detection. We propose two novel active learning strategies: the most similar graph query strategy and the maximum difference query strategy. They either select samples to update the training set according to similarities of provenance graphs or preferentially select samples with low redundancy and large differences from the current training set. Besides, we also improve the above query strategies by using the parallel query to reduce detection time overheads. The experiments on various real-world applications demonstrate their performance and efficiency.<\/jats:p>","DOI":"10.1186\/s42400-024-00311-y","type":"journal-article","created":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T02:02:46Z","timestamp":1737943366000},"update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Angus: efficient active learning strategies for provenance based intrusion detection"],"prefix":"10.1186","volume":"8","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-6498-6173","authenticated-orcid":false,"given":"Lin","family":"Wu","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yulai","family":"Xie","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jin","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Feng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jinyuan","family":"Liang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yafeng","family":"Wu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2025,1,27]]},"reference":[{"issue":"8","key":"311_CR1","doi-asserted-by":"publisher","first-page":"1155","DOI":"10.3844\/jcssp.2018.1155.1173","volume":"14","author":"GM Alqaralleh","year":"2018","unstructured":"Alqaralleh GM, Alshraideh MA, Alrodan A (2018) A comparison study between different sampling strategies for intrusion detection system of active learning model. J Comput Sci 14(8):1155\u20131173","journal-title":"J Comput Sci"},{"key":"311_CR2","doi-asserted-by":"crossref","unstructured":"Anjum MM, Iqbal S, Hamelin B (2021) Analyzing the usefulness of the DARPA OpTC dataset in cyber threat detection research. In:\u00a0Proceedings of the 26th ACM symposium on access control models and technologies, pp 27\u201332","DOI":"10.1145\/3450569.3463573"},{"key":"311_CR3","doi-asserted-by":"crossref","unstructured":"Barnab\u00e9-Lortie V, Bellinger C, Japkowicz N (2015) Active learning for one-class classification. In\u00a02015 IEEE 14th international conference on machine learning and applications (ICMLA), 390\u2013395.","DOI":"10.1109\/ICMLA.2015.167"},{"key":"311_CR4","doi-asserted-by":"crossref","unstructured":"Beaugnon A, Chifflier P, Bach F (2017) Ilab: an interactive labelling strategy for intrusion detection. In: International symposium on research in attacks, intrusions, and defenses. Springer, Berlin, pp 120\u2013140","DOI":"10.1007\/978-3-319-66332-6_6"},{"key":"311_CR5","unstructured":"Gasteiger J, Bojchevski A, G\u00fcnnemann S (2018) Predict then propagate: graph neural networks meet personalized pagerank. arXiv preprint arXiv:1810.05997"},{"key":"311_CR6","volume-title":"SPADE: support for provenance auditing in distributed environments","author":"A Gehani","year":"2012","unstructured":"Gehani A, Tariq D (2012) SPADE: support for provenance auditing in distributed environments. Springer, Berlin"},{"key":"311_CR7","doi-asserted-by":"publisher","first-page":"235","DOI":"10.1613\/jair.3623","volume":"46","author":"N G\u00f6rnitz","year":"2013","unstructured":"G\u00f6rnitz N, Kloft M, Rieck K, Brefeld U (2013) Toward supervised anomaly detection. J Artif Intell Res 46:235\u2013262","journal-title":"J Artif Intell Res"},{"key":"311_CR8","doi-asserted-by":"crossref","unstructured":"G\u00f6rnitz N, Kloft M, Rieck K, Brefeld U (2009) Active learning for network intrusion detection. In: Proceedings of the 2nd ACM workshop on security and artificial intelligence, pp 47\u201354","DOI":"10.1145\/1654988.1655002"},{"key":"311_CR9","unstructured":"Han X, Pasquier T, Ranjan T, Goldstein M, Seltzer M (2017) FRAPpuccino: fault-detection through runtime analysis of provenance. In: Workshop on hot topics in cloud computing"},{"key":"311_CR10","unstructured":"Han X, Pasquier T, Seltzer M (2018) Provenance-based intrusion detection: opportunities and challenges. In: Workshop on theory and practice of provenance"},{"key":"311_CR11","doi-asserted-by":"crossref","unstructured":"Han X, Pasquier T, Bates A, Mickens J, Seltzer M (2020) Unicorn: runtime provenance-based detector for advanced persistent threats. arXiv preprint arXiv:2001.01525","DOI":"10.14722\/ndss.2020.24046"},{"key":"311_CR12","doi-asserted-by":"publisher","DOI":"10.1016\/j.eswa.2019.113024","volume":"142","author":"A Hashemi","year":"2020","unstructured":"Hashemi A, Dowlatshahi MB, Nezamabadi-Pour H (2020) MGFS: a multi-label graph-based feature selection algorithm via PageRank centrality. Expert Syst Appl 142:113024","journal-title":"Expert Syst Appl"},{"key":"311_CR13","doi-asserted-by":"crossref","unstructured":"Hassan WU, Aguse L, Aguse N, Bates A, Moyer T (2018) Towards scalable cluster auditing through grammatical inference over provenance graphs. In: Network and distributed systems security symposium","DOI":"10.14722\/ndss.2018.23141"},{"key":"311_CR14","doi-asserted-by":"crossref","unstructured":"Hassan WU, Guo S, Li D, Chen Z, Jee K, Li Z, Bates A (2019) NoDoze: combatting threat alert fatigue with automated provenance triage. In: Network and distributed system security symposium","DOI":"10.14722\/ndss.2019.23349"},{"key":"311_CR15","doi-asserted-by":"publisher","first-page":"401","DOI":"10.1016\/j.ins.2018.05.014","volume":"454","author":"S Kee","year":"2018","unstructured":"Kee S, Del Castillo E, Runger G (2018) Query-by-committee improvement with diversity and density in batch active learning. Inf Sci 454:401\u2013418","journal-title":"Inf Sci"},{"key":"311_CR16","doi-asserted-by":"crossref","unstructured":"Kumari VV, Varma PR (2017) A semi-supervised intrusion detection system using active learning SVM and fuzzy c-means clustering. In: 2017 international conference on I-SMAC (IoT in Social, Mobile, Analytics and Cloud) (I-SMAC) 2017 Feb 10. IEEE, pp 481\u2013485","DOI":"10.1109\/I-SMAC.2017.8058397"},{"key":"311_CR17","unstructured":"Lemay M, Hassan WU, Moyer T, Schear N, Smith W (2017) Automated provenance analytics: a regular grammar based approach with applications in security. In: 9th USENIX workshop on the theory and practice of provenance"},{"issue":"5","key":"311_CR18","first-page":"1274","volume":"9","author":"H Liang","year":"2014","unstructured":"Liang H (2014) An improved intrusion detection based on neural network and fuzzy algorithm. J Netw 9(5):1274","journal-title":"J Netw"},{"key":"311_CR19","doi-asserted-by":"crossref","unstructured":"Liu Y, Zhang M, Li D, Jee K, Li Z, Wu Z, Rhee J, Mittal P (2018) Towards a timely causality analysis for enterprise security. In: NDSS 2018 Feb","DOI":"10.14722\/ndss.2018.23254"},{"issue":"99","key":"311_CR20","doi-asserted-by":"publisher","first-page":"292","DOI":"10.1109\/TFUZZ.2017.2654504","volume":"26","author":"E Lughofer","year":"2018","unstructured":"Lughofer E, Pratama M (2018) Online active learning in data stream regression using uncertainty sampling based on evolving generalized fuzzy models. IEEE Trans Fuzzy Syst 26(99):292\u2013309","journal-title":"IEEE Trans Fuzzy Syst"},{"issue":"8","key":"311_CR21","doi-asserted-by":"publisher","first-page":"4045","DOI":"10.1109\/TIP.2019.2906490","volume":"28","author":"J Ma","year":"2019","unstructured":"Ma J, Jiang X, Jiang J, Zhao J, Guo X (2019) LMR: learning a two-class classifier for mismatch removal. IEEE Trans Image Process 28(8):4045\u20134059","journal-title":"IEEE Trans Image Process"},{"issue":"1","key":"311_CR22","first-page":"20220259","volume":"32","author":"L Ouarda","year":"2023","unstructured":"Ouarda L, Malika B, Brahim B (2023) Towards a better similarity algorithm for host-based intrusion detection system. J Intell Syst 32(1):20220259","journal-title":"J Intell Syst"},{"key":"311_CR23","unstructured":"Page L, Brin S, Motwani R, Winograd T (1999) The PageRank citation ranking: bringing order to the web. Technical Report. Stanford InfoLab."},{"issue":"11","key":"311_CR24","doi-asserted-by":"publisher","first-page":"5450","DOI":"10.1109\/TIP.2019.2917862","volume":"28","author":"P Perera","year":"2019","unstructured":"Perera P, Patel VM (2019) Learning deep features for one-class classification. IEEE Trans Image Process 28(11):5450\u20135463","journal-title":"IEEE Trans Image Process"},{"key":"311_CR25","unstructured":"Ruff L, Vandermeulen R, Goernitz N, Deecke L, Siddiqui SA, Binder A, M\u00fcller E, Kloft M (2018) Deep one-class classification. In:\u00a0International conference on machine learning, pp 4393\u20134402"},{"key":"311_CR26","unstructured":"Settles B, Craven M, Ray S (2007) Multiple-instance active learning. In: Advances in neural information processing systems, pp 1289\u20131296"},{"key":"311_CR27","doi-asserted-by":"crossref","unstructured":"Tang Y, Li D, Li Z, Zhang M, Jee K, Xiao X, Wu Z, Rhee J, Xu F, Li Q (2018) Nodemerge: template based efficient data reduction for big-data causality analysis. In: Proceedings of the 2018 ACM SIGSAC conference on computer and communications security, pp 1324\u20131337","DOI":"10.1145\/3243734.3243763"},{"issue":"4","key":"311_CR28","first-page":"820","volume":"11","author":"A Tharwat","year":"2023","unstructured":"Tharwat A, Schenck W (2023) A survey on active learning: stateof-the-art. Pract Chall Res Dir Math 11(4):820","journal-title":"Pract Chall Res Dir Math"},{"issue":"1","key":"311_CR29","first-page":"999","volume":"2","author":"S Tong","year":"2002","unstructured":"Tong S, Koller D (2002) Support vector machine active learning with applications to text classification. J Mach Learn Res 2(1):999\u20131006","journal-title":"J Mach Learn Res"},{"issue":"5","key":"311_CR30","first-page":"51","volume":"23","author":"QA Tran","year":"2002","unstructured":"Tran QA, Zhang QL, Li X (2002) SVM classification-based intrusion detection system. J China Inst Commun 23(5):51\u201356","journal-title":"J China Inst Commun"},{"key":"311_CR31","doi-asserted-by":"crossref","unstructured":"Wan B, He Y, Liu X, Wang S, Qian Y (2023) host intrusion detection method based on short sequence of system call. In: 2023 10th international conference on dependable systems and their applications. IEEE, pp 312\u2013322","DOI":"10.1109\/DSA59317.2023.00045"},{"issue":"4","key":"311_CR32","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1145\/2501986","volume":"9","author":"Y Xie","year":"2013","unstructured":"Xie Y, Muniswamy-Reddy KK, Feng D, Li Y, Long DD (2013) Evaluation of a hybrid approach for efficient provenance storage. ACM Trans Storage 9(4):1\u201329","journal-title":"ACM Trans Storage"},{"key":"311_CR33","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1016\/j.future.2016.02.005","volume":"61","author":"Y Xie","year":"2016","unstructured":"Xie Y, Feng D, Tan Z, Zhou J (2016) Unifying intrusion detection and forensic analysis via provenance awareness. Futur Gener Comput Syst 61:26\u201336","journal-title":"Futur Gener Comput Syst"},{"issue":"6","key":"311_CR34","doi-asserted-by":"publisher","first-page":"1283","DOI":"10.1109\/TDSC.2018.2867595","volume":"17","author":"Y Xie","year":"2018","unstructured":"Xie Y, Feng D, Hu Y, Li Y, Sample S, Long D (2018) Pagoda: a hybrid approach to enable efficient real-time provenance based intrusion detection in big data environments. IEEE Trans Dependable Secure Comput 17(6):1283\u20131296","journal-title":"IEEE Trans Dependable Secure Comput"},{"issue":"6","key":"311_CR35","first-page":"2658","volume":"18","author":"Y Xie","year":"2019","unstructured":"Xie Y, Wu Y, Feng D, Long D (2019) P-Gaussian: provenance-based gaussian distribution for detecting intrusion behavior variants using high efficient and real time memory databases. IEEE Trans Dependable Secure Comput 18(6):2658\u20132674","journal-title":"IEEE Trans Dependable Secure Comput"},{"key":"311_CR36","doi-asserted-by":"crossref","unstructured":"Xu Z, Wu Z, Li Z, Jee K, Rhee J, Xiao X, Xu F, Wang H, Jiang G (2016) High fidelity data reduction for big data security dependency analyses. Association for Computing Machinery, pp 504\u2013516","DOI":"10.1145\/2976749.2978378"},{"key":"311_CR37","unstructured":"Yang F, Xu J, Xiong C, Li Z, Zhang K (2023) PROGRAPHER: an anomaly detection system based on provenance graph embedding. In: 32nd USENIX security symposium, pp 4355\u20134372"},{"key":"311_CR38","doi-asserted-by":"crossref","unstructured":"Zhao M, Zhai J, He Z (2010) Intrusion detection system based on support vector machine active learning and data fusion. In: International symposium on intelligence computation and applications. Springer, Berlin, pp 272\u2013279","DOI":"10.1007\/978-3-642-16493-4_28"}],"container-title":["Cybersecurity"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00311-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1186\/s42400-024-00311-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1186\/s42400-024-00311-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,1,27]],"date-time":"2025-01-27T02:03:09Z","timestamp":1737943389000},"score":1,"resource":{"primary":{"URL":"https:\/\/cybersecurity.springeropen.com\/articles\/10.1186\/s42400-024-00311-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,27]]},"references-count":38,"journal-issue":{"issue":"1","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["311"],"URL":"https:\/\/doi.org\/10.1186\/s42400-024-00311-y","relation":{},"ISSN":["2523-3246"],"issn-type":[{"value":"2523-3246","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,27]]},"assertion":[{"value":"4 March 2024","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"29 July 2024","order":2,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"27 January 2025","order":3,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}},{"order":1,"name":"Ethics","group":{"name":"EthicsHeading","label":"Declarations"}},{"value":"The authors declare that they have no competing interests.","order":2,"name":"Ethics","group":{"name":"EthicsHeading","label":"Competing interests"}}],"article-number":"6"}}