{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,3]],"date-time":"2025-08-03T01:11:52Z","timestamp":1754183512619,"version":"3.41.2"},"reference-count":94,"publisher":"Institute of Electronics, Information and Communications Engineers (IEICE)","issue":"8","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEICE Trans. Inf. &amp; Syst."],"published-print":{"date-parts":[[2025,8,1]]},"DOI":"10.1587\/transinf.2024dak0001","type":"journal-article","created":{"date-parts":[[2025,2,6]],"date-time":"2025-02-06T17:12:58Z","timestamp":1738861978000},"page":"917-932","source":"Crossref","is-referenced-by-count":0,"title":["VATH: A System for Extracting Relationships between Vulnerabilities and Attackers to Support Threat Hunting"],"prefix":"10.1587","volume":"E108.D","author":[{"given":"Masayuki","family":"HIRAYABU","sequence":"first","affiliation":[{"name":"Department of Electrical and Electronic Engineering, Kobe University"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yoshiaki","family":"SHIRAISHI","sequence":"additional","affiliation":[{"name":"Department of Electrical and Electronic Engineering, Kobe University"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"532","reference":[{"key":"1","unstructured":"[1] \u201ccpe:2.3:o:cisco:nx-os:11.0(1b):*:*:*:*:*:*:*,\u201d https:\/\/nvd.nist.gov\/products\/cpe\/detail\/AA15989D-7198-4AD0-98F9-08233ACA469C?namingFormat=2.3&amp;orderBy=CPEURI&amp;keyword=cpe%3A2.3%3Ao%3Acisco%3Anx-os%3A11.0%5C%281b%5C%29%3A*%3A*%3A*%3A*%3A*%3A*%3A*&amp;status=FINAL"},{"key":"2","unstructured":"[2] \u201cCVE-2021-1228,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-1228"},{"key":"3","unstructured":"[3] \u201cCWE-284,\u201d https:\/\/cwe.mitre.org\/data\/definitions\/284.html"},{"key":"4","unstructured":"[4] \u201cCAPEC-578,\u201d https:\/\/capec.mitre.org\/data\/definitions\/578.html"},{"key":"5","unstructured":"[5] \u201cG0119,\u201d https:\/\/attack.mitre.org\/versions\/v11\/groups\/G0119\/"},{"key":"6","unstructured":"[6] \u201cT1562.001,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1562\/001\/"},{"key":"7","unstructured":"[7] \u201cTA0005,\u201d https:\/\/attack.mitre.org\/versions\/v11\/tactics\/TA0005\/"},{"key":"8","unstructured":"[8] \u201cS0331,\u201d https:\/\/attack.mitre.org\/versions\/v11\/software\/S0331"},{"key":"9","unstructured":"[9] \u201cM1022,\u201d https:\/\/attack.mitre.org\/versions\/v11\/mitigations\/M1022"},{"key":"10","unstructured":"[10] \u201cDS0009,\u201d https:\/\/attack.mitre.org\/versions\/v11\/datasources\/DS0009\/"},{"key":"11","doi-asserted-by":"publisher","unstructured":"[11] K. Kanakogi, H. Washizaki, Y. Fukazawa, S. Ogata, T. Okubo, T. Kato, H. Kanuka, A. Hazeyama, and N. Yoshioka, \u201cComparative Evaluation of NLP-Based Approaches for Linking CAPEC Attack Patterns from CVE Vulnerability Information,\u201d Applied Sciences, vol.12, no.7, p.3400, Apr. 2022. 10.3390\/app12073400","DOI":"10.3390\/app12073400"},{"key":"12","doi-asserted-by":"crossref","unstructured":"[12] T. Tsutsui, Y. Shiraishi, and M. Morii, \u201cSystemization of Vulnerability Information by Ontology for Impact Analysis,\u201d 2021 IEEE 21st Int. Conf. Software Quality, Reliability and Security Companion (QRS-C), pp.1126-1134, Dec. 2021. 10.1109\/qrs-c55045.2021.00167","DOI":"10.1109\/QRS-C55045.2021.00167"},{"key":"13","unstructured":"[13] Z. Syed, A. Padia, T. Finin, L. Mathews, and A. Joshi, \u201cUCO: A Unified Cybersecurity Ontology,\u201d AAAI Workshop: Artificial Intelligence for Cyber Security, Feb. 2016."},{"key":"14","doi-asserted-by":"publisher","unstructured":"[14] R. Syed, \u201cCybersecurity vulnerability management: A conceptual ontology and cyber intelligence alert system,\u201d Information &amp; Management, vol.57, no.6, p.103334, Sept. 2020. 10.1016\/j.im.2020.103334","DOI":"10.1016\/j.im.2020.103334"},{"key":"15","doi-asserted-by":"crossref","unstructured":"[15] L. Aouad and M.R. Asghar, \u201cDefender-centric Conceptual Cyber Exposure Ontology for Adaptive Cyber Risk Assessment,\u201d Proc. 17th International Joint Conference on e-Business and Telecommunications, vol.3:SECRYPT, pp.580-586, 2020. 10.5220\/0009826205800586","DOI":"10.5220\/0009826205800586"},{"key":"16","doi-asserted-by":"publisher","unstructured":"[16] A.B. Ajmal, M.A. Shah, C. Maple, M.N. Asghar, and S.U. Islam, \u201cOffensive Security: Towards Proactive Threat Hunting via Adversary Emulation,\u201d IEEE Access, vol.9, pp.126023-126033, Aug. 2021. 10.1109\/access.2021.3104260","DOI":"10.1109\/ACCESS.2021.3104260"},{"key":"17","doi-asserted-by":"crossref","unstructured":"[17] M.G. Ahmed, S. Panda, C. Xenakis, and E. Panaousis, \u201cMITRE ATT&amp;CK-driven Cyber Risk Assessment,\u201d Proc. 17th Int. Conf. Availability, Reliability and Security (ARES \u201922), no.107, pp.1-10, Aug. 2022. 10.1145\/3538969.3544420","DOI":"10.1145\/3538969.3544420"},{"key":"18","doi-asserted-by":"crossref","unstructured":"[18] A. Kuppa, L. Aouad, and N. Le-Khac, \u201cLinking CVE\u2019s to MITRE ATT&amp;CK Techniques,\u201d Proc. 16th Int. Conf. Availability, Reliability and Security (ARES \u201921), no.21, pp.1-12, Aug. 2021. 10.1145\/3465481.3465758","DOI":"10.1145\/3465481.3465758"},{"key":"19","unstructured":"[19] E. Hemberg, J. Kelly, M. Shlapentokh-Rothman, B. Reinstadler, K. Xu, N. Rutar, and U. O\u2019Reilly, \u201cBRON : Linking Attack Tactics, Techniques, and Patterns with Defensive Weakness, Vulnerabilities and Affected Platform Configurations.,\u201d arXiv:2010.00533v1, 2010."},{"key":"20","doi-asserted-by":"crossref","unstructured":"[20] Y. Merah and T. Kenaza, \u201cProactive Ontology-based Cyber Threat Intelligence Analytic,\u201d 2021 Int. Conf. Recent Advances in Mathematics and Informatics (ICRAMI), pp.1-7, Sept. 2021. 10.1109\/icrami52622.2021.9585984","DOI":"10.1109\/ICRAMI52622.2021.9585984"},{"key":"21","doi-asserted-by":"crossref","unstructured":"[21] Y. Merah and T. Kenaza, \u201cOntology-based Cyber Risk Monitoring Using Cyber Threat Intelligence,\u201d Proc. 16th Int. Conf. Availability, Reliability and Security (ARES \u201921), no.88, pp.1-8, Aug. 2021. 10.1145\/3465481.3470024","DOI":"10.1145\/3465481.3470024"},{"key":"22","doi-asserted-by":"crossref","unstructured":"[22] P. Gao, F. Shao, X. Liu, X. Xiao, H. Liu, Z. Qin, F. Xu, P. Mittal, S.R. Kulkarni, and D. Song, \u201cA System for Efficiently Hunting for Cyber Threats in Computer Systems Using Threat Intelligence,\u201d 2021 IEEE 37th Int. Conf. Data Engineering (ICDE), pp.2705-2708, Jan. 2021. 10.1109\/icde51399.2021.00309","DOI":"10.1109\/ICDE51399.2021.00309"},{"key":"23","doi-asserted-by":"crossref","unstructured":"[23] F.K. Kaiser, U. Dardik, A. Elitzur, P. Zilberman, N. Daniel, M. Wiens, F. Schultmann, Y. Elovici, and R. Puzis, \u201cAttack Hypotheses Generation Based on Threat Intelligence Knowledge Graph,\u201d IEEE Trans. Dependable and Secure Computing, vol.20, no.6, pp.4793-4809, 2023. 10.1109\/tdsc.2022.3233703","DOI":"10.1109\/TDSC.2022.3233703"},{"key":"24","doi-asserted-by":"publisher","unstructured":"[24] A. Mahboubi, K. Luong, H. Aboutorab, H.T. Bui, G. Jarrad, M. Bahutair, S. Camtepe, G. Pogrebna, E. Ahmed, B. Barry, and H. Gately, \u201cEvolving techniques in cyber threat hunting: A systematic review,\u201d Journal of Network and Computer Applications, vol.232, no.104004, 2024. 10.1016\/j.jnca.2024.104004","DOI":"10.1016\/j.jnca.2024.104004"},{"key":"25","doi-asserted-by":"publisher","unstructured":"[25] S. Homayoun, A. Dehghantanha, M. Ahmadzadeh, S. Hashemi, and R. Khayami, \u201cKnow Abnormal, Find Evil: Frequent Pattern Mining for Ransomware Threat Hunting and Intelligence,\u201d IEEE Trans. Emerging Topics in Computing, vol.8, no.2, pp.341-351, 2020. 10.1109\/tetc.2017.2756908","DOI":"10.1109\/TETC.2017.2756908"},{"key":"26","doi-asserted-by":"publisher","unstructured":"[26] A. Berady, M. Jaume, V.V.T. Tong, and G. Guette, \u201cFrom TTP to IoC: Advanced Persistent Graphs for Threat Hunting,\u201d IEEE Trans. Network and Service Management, vol.18, no.2, pp.1321-1333, 2021. 10.1109\/tnsm.2021.3056999","DOI":"10.1109\/TNSM.2021.3056999"},{"key":"27","doi-asserted-by":"crossref","unstructured":"[27] V. Mavroeidis and A. J\u00f8sang, \u201cData-Driven Threat Hunting Using Sysmon,\u201d The 2nd Int. Conf. Cryptography, Security and Privacy (ICCSP 2018), pp.82-88, 2018. 10.1145\/3199478.3199490","DOI":"10.1145\/3199478.3199490"},{"key":"28","doi-asserted-by":"crossref","unstructured":"[28] A.J.H. Neto and A.F.P. Santos, \u201cCyber Threat Hunting Through Automated Hypothesis and Multi-Criteria Decision Making,\u201d 2020 IEEE Int. Conf. Big Data (Big Data), pp.1823-1830, 2020. 10.1109\/bigdata50022.2020.9378213","DOI":"10.1109\/BigData50022.2020.9378213"},{"key":"29","unstructured":"[29] \u201cNVD,\u201d https:\/\/nvd.nist.gov\/"},{"key":"30","unstructured":"[30] \u201cCPE,\u201d https:\/\/nvd.nist.gov\/products\/cpe"},{"key":"31","unstructured":"[31] \u201cCVE,\u201d https:\/\/www.cve.org\/"},{"key":"32","unstructured":"[32] \u201cCWE,\u201d https:\/\/cwe.mitre.org\/"},{"key":"33","unstructured":"[33] \u201cCAPEC,\u201d https:\/\/capec.mitre.org\/"},{"key":"34","unstructured":"[34] \u201cMITRE ATT&amp;CK,\u201d https:\/\/attack.mitre.org\/"},{"key":"35","unstructured":"[35] \u201cNVD JSON Feeds,\u201d https:\/\/nvd.nist.gov\/vuln\/data-feeds"},{"key":"36","unstructured":"[36] \u201cATT&amp;CK STIX Data,\u201d https:\/\/github.com\/mitre-attack\/attack-stix-data"},{"key":"37","unstructured":"[37] \u201cCAPEC Downloads,\u201d https:\/\/capec.mitre.org\/data\/downloads.html"},{"key":"38","unstructured":"[38] \u201cT1078.002,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1078\/002\/"},{"key":"39","unstructured":"[39] \u201cCAPEC-560,\u201d https:\/\/capec.mitre.org\/data\/definitions\/560.html"},{"key":"40","unstructured":"[40] \u201cCWE-307,\u201d http:\/\/cwe.mitre.org\/data\/definitions\/307.html"},{"key":"41","doi-asserted-by":"crossref","unstructured":"[41] \u201cCVE-2020-12752,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-12752","DOI":"10.5465\/AMBPP.2020.12752abstract"},{"key":"42","unstructured":"[42] E.M. Hutchins, M.J. Cloppert, R.M. Amin, Ph.D., \u201cIntelligence-Driven Computer Network Defense Informed by Analysis of Adversary Campaigns and Intrusion Kill Chains,\u201d Jan. 2011. https:\/\/www.lockheedmartin.com\/content\/dam\/lockheed-martin\/rms\/documents\/cyber\/LM-White-Paper-Intel-Driven-Defense.pdf"},{"key":"43","unstructured":"[43] \u201cT1584.004,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1584\/004"},{"key":"44","unstructured":"[44] \u201cT1486,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1486"},{"key":"45","unstructured":"[45] \u201cT1489,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1489"},{"key":"46","unstructured":"[46] \u201cCVE-2020-24433,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-24433"},{"key":"47","unstructured":"[47] \u201cWhat is DoppelPaymer Ransomware?,\u201d https:\/\/www.blackpanda.com\/jp\/blog\/what-is-doppelpaymer-ransomware"},{"key":"48","unstructured":"[48] \u201cFlask,\u201d https:\/\/flask.palletsprojects.com\/en\/3.0.x\/changes\/#version-2-1-2"},{"key":"49","unstructured":"[49] \u201cjinja2,\u201d https:\/\/jinja.palletsprojects.com\/en\/3.1.x\/changes\/#version-3-1-2"},{"key":"50","unstructured":"[50] \u201cvis.js Network,\u201d https:\/\/visjs.org\/"},{"key":"51","unstructured":"[51] \u201cD3.js,\u201d https:\/\/d3js.org\/"},{"key":"52","unstructured":"[52] \u201cOwlready2,\u201d http:\/\/www.lesfleursdunormal.fr\/static\/informatique\/owlready\/index_en.html"},{"key":"53","unstructured":"[53] \u201cSQLite,\u201d https:\/\/www.sqlite.org\/"},{"key":"54","unstructured":"[54] \u201cCVE-2020-15906,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-15906"},{"key":"55","unstructured":"[55] \u201cCAPEC-49,\u201d https:\/\/capec.mitre.org\/data\/definitions\/49.html"},{"key":"56","unstructured":"[56] \u201cT1110,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1110\/"},{"key":"57","unstructured":"[57] \u201cG0087,\u201d https:\/\/attack.mitre.org\/versions\/v11\/groups\/G0087\/"},{"key":"58","unstructured":"[58] \u201cIranian Backed APT Group APT39: Chafer,\u201d https:\/\/www.infinitumit.com.tr\/en\/iran-supported-apt-group-apt39-chafer\/"},{"key":"59","unstructured":"[59] \u201cCVE-2020-4574,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-4574"},{"key":"60","unstructured":"[60] \u201cTA0006,\u201d https:\/\/attack.mitre.org\/versions\/v11\/tactics\/TA0006\/"},{"key":"61","unstructured":"[61] \u201cCVE-2021-32739,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-32739"},{"key":"62","unstructured":"[62] \u201cT1115,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1115\/"},{"key":"63","unstructured":"[63] \u201cChafer used Remexi malware to spy on Iran-based foreign diplomatic entities,\u201d https:\/\/securelist.com\/chafer-used-remeximalware\/89538\/"},{"key":"64","unstructured":"[64] \u201cCVE-2020-10876,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-10876"},{"key":"65","unstructured":"[65] \u201cT1197,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1197\/"},{"key":"66","unstructured":"[66] \u201cT1033,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1033\/"},{"key":"67","unstructured":"[67] \u201cCVE-2021-43939,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-43939"},{"key":"68","unstructured":"[68] \u201cCWE-285,\u201d https:\/\/cwe.mitre.org\/data\/definitions\/285.html"},{"key":"69","unstructured":"[69] \u201cCAPEC-647,\u201d https:\/\/capec.mitre.org\/data\/definitions\/647.html"},{"key":"70","unstructured":"[70] \u201cT1012,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1012\/"},{"key":"71","unstructured":"[71] \u201cG0032,\u201d https:\/\/attack.mitre.org\/versions\/v11\/groups\/G0032\/"},{"key":"72","unstructured":"[72] \u201cLazarus targets defense industry with ThreatNeedle,\u201d https:\/\/securelist.com\/lazarus-threatneedle\/100803\/"},{"key":"73","unstructured":"[73] \u201cT1083,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1083\/"},{"key":"74","unstructured":"[74] \u201cCVE-2021-27453,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-27453"},{"key":"75","unstructured":"[75] \u201cCWE-288,\u201d https:\/\/cwe.mitre.org\/data\/definitions\/288.html"},{"key":"76","unstructured":"[76] \u201cCAPEC-127,\u201d https:\/\/capec.mitre.org\/data\/definitions\/127.html"},{"key":"77","unstructured":"[77] \u201cTA0007,\u201d https:\/\/attack.mitre.org\/versions\/v11\/tactics\/TA0007\/"},{"key":"78","unstructured":"[78] \u201cCommonly Known Tools Used by Lazarus,\u201d https:\/\/blogs.jpcert.or.jp\/en\/2021\/01\/Lazarus_tools.html"},{"key":"79","unstructured":"[79] \u201cCVE-2020-25716,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-25716"},{"key":"80","unstructured":"[80] \u201cT1557.001,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1557\/001\/"},{"key":"81","unstructured":"[81] \u201cT1534,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1534\/"},{"key":"82","unstructured":"[82] \u201cCVE-2021-38453,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2021-38453"},{"key":"83","unstructured":"[83] \u201cCWE-15,\u201d https:\/\/cwe.mitre.org\/data\/definitions\/15.html"},{"key":"84","unstructured":"[84] \u201cCAPEC-270,\u201d https:\/\/capec.mitre.org\/data\/definitions\/270.html"},{"key":"85","unstructured":"[85] \u201cT1547.001,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1547\/001\/"},{"key":"86","unstructured":"[86] \u201cG0046,\u201d https:\/\/attack.mitre.org\/versions\/v11\/groups\/G0046\/"},{"key":"87","unstructured":"[87] \u201cAdversary Carbon Spider,\u201d https:\/\/prod.adversary.crowdstrike.cloud.jam3.net\/ja-JP\/adversary\/carbon-spider\/"},{"key":"88","unstructured":"[88] \u201cCVE-2020-29591,\u201d https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2020-29591"},{"key":"89","unstructured":"[89] \u201cCWE-521,\u201d https:\/\/cwe.mitre.org\/data\/definitions\/521.html"},{"key":"90","unstructured":"[90] \u201cCAPEC-509,\u201d https:\/\/capec.mitre.org\/data\/definitions\/509.html"},{"key":"91","unstructured":"[91] \u201cT1558.003,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1558\/003\/"},{"key":"92","doi-asserted-by":"publisher","unstructured":"[92] D. Demers and H. Lee, \u201cKerberoasting: Case Studies of an Attack on a Cryptographic Authentication Technology,\u201d International Journal of Cybersecurity Intelligence and Cybercrime, vol.5, no.2, pp.25-39, Nov. 2022. 10.52306\/2578-3289.1136","DOI":"10.52306\/2578-3289.1136"},{"key":"93","unstructured":"[93] \u201cT1078,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1078\/"},{"key":"94","unstructured":"[94] \u201cT1497.002,\u201d https:\/\/attack.mitre.org\/versions\/v11\/techniques\/T1497\/002\/"}],"container-title":["IEICE Transactions on Information and Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/8\/E108.D_2024DAK0001\/_pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,2]],"date-time":"2025-08-02T03:28:40Z","timestamp":1754105320000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.jstage.jst.go.jp\/article\/transinf\/E108.D\/8\/E108.D_2024DAK0001\/_article"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,8,1]]},"references-count":94,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2025]]}},"URL":"https:\/\/doi.org\/10.1587\/transinf.2024dak0001","relation":{},"ISSN":["0916-8532","1745-1361"],"issn-type":[{"type":"print","value":"0916-8532"},{"type":"electronic","value":"1745-1361"}],"subject":[],"published":{"date-parts":[[2025,8,1]]},"article-number":"2024DAK0001"}}