{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,2]],"date-time":"2026-06-02T07:23:06Z","timestamp":1780384986405,"version":"3.54.1"},"reference-count":40,"publisher":"MDPI AG","issue":"9","license":[{"start":{"date-parts":[[2020,9,14]],"date-time":"2020-09-14T00:00:00Z","timestamp":1600041600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100001809","name":"the National Natural Science Foundation of China","doi-asserted-by":"publisher","award":["1672158, 61672159, 61502104, 61502105"],"award-info":[{"award-number":["1672158, 61672159, 61502104, 61502105"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"publisher"}]},{"name":"the Industry-Academy Cooperation Project","award":["2018H6010"],"award-info":[{"award-number":["2018H6010"]}]},{"name":"the Technology Guidance Project of Fujian Province","award":["2017H0015"],"award-info":[{"award-number":["2017H0015"]}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Entropy"],"abstract":"<jats:p>Attack graph modeling aims to generate attack models by investigating attack behaviors recorded in intrusion alerts raised in network security devices. Attack models can help network security administrators discover an attack strategy that intruders use to compromise the network and implement a timely response to security threats. However, the state-of-the-art algorithms for attack graph modeling are unable to obtain a high-level or global-oriented view of the attack strategy. To address the aforementioned issue, considering the similarity between attack behavior and workflow, we employ a heuristic process mining algorithm to generate the initial attack graph. Although the initial attack graphs generated by the heuristic process mining algorithm are complete, they are extremely complex for manual analysis. To improve their readability, we propose a graph segmentation algorithm to split a complex attack graph into multiple subgraphs while preserving the original structure. Furthermore, to handle massive volume alert data, we propose a distributed attack graph generation algorithm based on Hadoop MapReduce and a distributed attack graph segmentation algorithm based on Spark GraphX. Additionally, we conduct comprehensive experiments to validate the performance of the proposed algorithms. The experimental results demonstrate that the proposed algorithms achieve considerable improvement over comparative algorithms in terms of accuracy and efficiency.<\/jats:p>","DOI":"10.3390\/e22091026","type":"journal-article","created":{"date-parts":[[2020,9,13]],"date-time":"2020-09-13T22:50:20Z","timestamp":1600037420000},"page":"1026","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Distributed Attack Modeling Approach Based on Process Mining and Graph Segmentation"],"prefix":"10.3390","volume":"22","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-7408-2684","authenticated-orcid":false,"given":"Yuzhong","family":"Chen","sequence":"first","affiliation":[{"name":"Fujian Key Laboratory of Network Computing and Intelligent Information Processing, College of Mathematics and Computer Science, Fuzhou University, Fuzhou 350116, China"},{"name":"Key Laboratory of Spatial Data Mining &amp; Information Sharing, Ministry of Education, Fuzhou 350116, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Zhenyu","family":"Liu","sequence":"additional","affiliation":[{"name":"Fujian Key Laboratory of Network Computing and Intelligent Information Processing, College of Mathematics and Computer Science, Fuzhou University, Fuzhou 350116, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1683-0255","authenticated-orcid":false,"given":"Yulin","family":"Liu","sequence":"additional","affiliation":[{"name":"Key Laboratory of Information Security of Network Systems, Fuzhou University, Fuzhou 350116, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chen","family":"Dong","sequence":"additional","affiliation":[{"name":"Fujian Key Laboratory of Network Computing and Intelligent Information Processing, College of Mathematics and Computer Science, Fuzhou University, Fuzhou 350116, China"},{"name":"Key Laboratory of Information Security of Network Systems, Fuzhou University, Fuzhou 350116, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2020,9,14]]},"reference":[{"key":"ref_1","doi-asserted-by":"crossref","first-page":"419","DOI":"10.1016\/j.comcom.2008.11.012","article-title":"Intrusion detection alarms reduction using root cause analysis and clustering","volume":"32","author":"Zhang","year":"2009","journal-title":"Comput. Commun."},{"key":"ref_2","first-page":"1","article-title":"Intelligent Alert Clustering Model for Network Intrusion Analysis","volume":"1","author":"Siraj","year":"2009","journal-title":"Int. J. Adv. Soft Comput. Appl."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Bopche, G.S., and Mehtre, B.M. (2014, January 24\u201327). Attack Graph Generation. Visualization and Analysis: Issues and Challenges. Proceedings of the International Symposium on Security in Computing & Communication (SSCC 2014), Delhi, India.","DOI":"10.1007\/978-3-662-44966-0_37"},{"key":"ref_4","doi-asserted-by":"crossref","unstructured":"Van der Aalst, W. (2011). Process Mining: Discovery Conformance and Enhancement of Business Processes, Springer.","DOI":"10.1007\/978-3-642-19345-3"},{"key":"ref_5","doi-asserted-by":"crossref","first-page":"237","DOI":"10.1016\/S0169-023X(03)00066-1","article-title":"Workflow Mining: A Survey of Issues and Approaches","volume":"47","author":"Herbst","year":"2003","journal-title":"Data Knowl. Eng."},{"key":"ref_6","doi-asserted-by":"crossref","first-page":"713","DOI":"10.1016\/j.is.2006.05.003","article-title":"Business Process Mining: An Industrial Application","volume":"32","author":"Reijers","year":"2007","journal-title":"Inf. Syst."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"238","DOI":"10.1007\/978-981-10-5780-9_22","article-title":"Process Mining in Intrusion Detection\u2014The Need of Current Digital World","volume":"712","author":"Mishra","year":"2017","journal-title":"Adv. Inform. Comput. Res."},{"key":"ref_8","doi-asserted-by":"crossref","unstructured":"Phillips, C., and Swiler, L.P. (1998, January 22\u201325). A Graph-based System for Network-vulnerability Analysis. Proceedings of the 1998 Workshop on New Security Paradigms, Charlottsville, VA, USA.","DOI":"10.1145\/310889.310919"},{"key":"ref_9","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cosrev.2014.07.001","article-title":"DAG-based attack and defense modeling: Don\u2019t miss the forest for the attack trees","volume":"13\u201314","author":"Kordy","year":"2014","journal-title":"Comput. Sci. Rev."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"1","DOI":"10.1016\/j.cose.2014.12.003","article-title":"Intrusion alert prioritisation and attack detection using post-correlation analysis","volume":"50","author":"Shittu","year":"2015","journal-title":"Comput. Secur."},{"key":"ref_11","unstructured":"Za, C., Ane, O.R., Goebel, R.G., Hand, D.P., Keim, D.P., and NG, R.P. (2002). Proceedings of the Eighth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, Edmonton, AB, Canada, 23\u201326 July 2002, Association for Computing Machinery."},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Zong, B., Wu, Y., Song, J., Singh, A.K., Cam, H., Han, J., and Yan, X. (2014, January 24\u201327). Towards scalable critical alert mining. Proceedings of the 20th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, New York, NY, USA.","DOI":"10.1145\/2623330.2623729"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Loreti, D., Chesani, F., Ciampolini, A., and Mello, P. (2017). Distributed Compliance Monitoring of Business Processes over MapReduce Architectures. Future Gener. Comput. Syst., 104\u2013118.","DOI":"10.1016\/j.future.2017.12.043"},{"key":"ref_14","doi-asserted-by":"crossref","first-page":"104","DOI":"10.1016\/j.future.2017.12.043","article-title":"A distributed approach to compliance monitoring of business process event streams","volume":"82","author":"Loreti","year":"2018","journal-title":"Future Gener. Comput. Syst."},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Weijters, A.J.M.M., and Ribeiro, J.T.S. (2011, January 11\u201315). Flexible Heuristics Miner (FHM). Proceedings of the 2011 IEEE Symposium on Computational Intelligence and Data Mining (CIDM), Paris, France.","DOI":"10.1109\/CIDM.2011.5949453"},{"key":"ref_16","doi-asserted-by":"crossref","first-page":"474","DOI":"10.1016\/j.cose.2017.11.021","article-title":"Process mining and hierarchical clustering to help intrusion alert visualization","volume":"73","author":"Barbon","year":"2018","journal-title":"Comput. Secur."},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"169","DOI":"10.1016\/j.cose.2005.09.004","article-title":"Real-time analysis of intrusion detection alerts via correlation","volume":"25","author":"Lee","year":"2006","journal-title":"Comput. Secur."},{"key":"ref_18","doi-asserted-by":"crossref","unstructured":"Ning, P., and Xu, D. (2003, January 27\u201331). Learning attack strategies from intrusion alerts. Proceedings of the 10th ACM Conference on Computer and Communications Security, Washington, DC, USA.","DOI":"10.1145\/948109.948137"},{"key":"ref_19","doi-asserted-by":"crossref","unstructured":"Vigo, R., Nielson, F., and Nielson, H.R. (2014, January 19\u201322). Automated Generation of Attack Trees. Proceedings of the IEEE Computer Security Foundations Symposium, Vienna, Austria.","DOI":"10.1109\/CSF.2014.31"},{"key":"ref_20","doi-asserted-by":"crossref","first-page":"31","DOI":"10.4204\/EPTCS.148.3","article-title":"Towards automating the construction & maintenance of attack trees: A feasibility study","volume":"148","author":"Paul","year":"2014","journal-title":"Electron. Proc. Theor. Comput. Sci."},{"key":"ref_21","unstructured":"Birkholz, H., Edelkamp, S., Junge, F., and Sohr, K. (2010, January 11\u201312). Efficient automated generation of attack trees from vulnerability databases. Proceedings of the Working Notes for the 2010 AAAI Workshop on Intelligent Security (SecArt), Atlanta, GA, USA."},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"2221","DOI":"10.1016\/j.comnet.2011.03.005","article-title":"A hybrid model for correlating alerts of known and unknown attack scenarios and updating attack graphs","volume":"55","author":"Ahmadinejad","year":"2011","journal-title":"Comput. Netw."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"176","DOI":"10.1016\/j.cose.2013.03.005","article-title":"Enhancing IDS performance through comprehensive alert post-processing","volume":"37","author":"Spathoulas","year":"2013","journal-title":"Comput. Secur."},{"key":"ref_24","doi-asserted-by":"crossref","first-page":"153","DOI":"10.1016\/j.cose.2008.11.010","article-title":"An incremental frequent structure mining framework for real-time alert correlation","volume":"28","author":"Sadoddin","year":"2009","journal-title":"Comput. Secur."},{"key":"ref_25","doi-asserted-by":"crossref","unstructured":"Lagzian, S., Amiri, F., Enayati, A.R., and Gharaee, H. (2012, January 6\u20138). Frequent item set mining-based alert correlation for extracting multi-stage attack scenarios. Proceedings of the Sixth International Symposium on Telecommunications, Tehran, Iran.","DOI":"10.1109\/ISTEL.2012.6483134"},{"key":"ref_26","first-page":"122","article-title":"Discovering attackers past behavior to generate online hyper-alerts","volume":"10","author":"Kawakani","year":"2017","journal-title":"ISys-Rev. Bras. Sist. Informa\u00e7\u00e3o"},{"key":"ref_27","unstructured":"De Alvarenga, S.C., Zarpel\u00e3o, B.B., Barbon, S., Miani, R.S., and Cukier, M. (2015, January 21\u201326). Discovering attack strategies using process mining. Proceedings of the Eleventh Advanced International Conference on Telecommunications (AICT 2015), Brussels, Belgium."},{"key":"ref_28","unstructured":"Lempitsky, V., Kohli, P., Rother, C., and Sharp, T. (October, January 29). Image Segmentation with A Bounding Box Prior. Proceedings of the IEEE International Conference on Computer Vision, Kyoto, Japan."},{"key":"ref_29","doi-asserted-by":"crossref","first-page":"159","DOI":"10.1142\/S021812669200012X","article-title":"Simulated annealing and tabu search algorithms for multiway graph partition","volume":"2","author":"Tao","year":"1992","journal-title":"J. Circuits Syst. Comput."},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Farshbaf, M., and Feizi-Derakhshi, M.R. (2009, January 11\u201316). Multi-objective Optimization of Graph Partitioning Using Genetic Algorithms. Proceedings of the International Conference on Advanced Engineering Computing & Applications in Sciences, Sliema, Malta.","DOI":"10.1109\/ADVCOMP.2009.8"},{"key":"ref_31","doi-asserted-by":"crossref","first-page":"321","DOI":"10.1109\/TEVC.2002.802452","article-title":"Data mining with an ant colony optimization algorithm","volume":"6","author":"Parpinelli","year":"2002","journal-title":"IEEE Trans. Evol. Comput."},{"key":"ref_32","doi-asserted-by":"crossref","first-page":"1341","DOI":"10.1016\/j.eswa.2007.01.002","article-title":"A hybrid cooperative\u2013comprehensive learning based PSO algorithm for image segmentation using multilevel thresholding","volume":"34","author":"Maitra","year":"2008","journal-title":"Expert Syst. Appl."},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"056114","DOI":"10.1103\/PhysRevE.80.056114","article-title":"Spectral properties of networks with community structure","volume":"80","author":"Chauhan","year":"2009","journal-title":"Phys. Rev. E"},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"P10012","DOI":"10.1088\/1742-5468\/2004\/10\/P10012","article-title":"Detecting network communities: A new systematic and efficient algorithm","volume":"2004","author":"Donetti","year":"2004","journal-title":"J. Stat. Mech. Theory Exp."},{"key":"ref_35","doi-asserted-by":"crossref","first-page":"P10020","DOI":"10.1088\/1742-5468\/2010\/10\/P10020","article-title":"Spectral methods for the detection of network community structure: A comparative analysis","volume":"2010","author":"Shen","year":"2010","journal-title":"J. Stat. Mech. Theory Exp."},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"291","DOI":"10.1002\/j.1538-7305.1970.tb01770.x","article-title":"An Efficient Heuristic Procedure for Partitioning Graphs","volume":"49","author":"Kernighan","year":"1970","journal-title":"Bell Syst. Tech. J."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1007\/BF02614373","article-title":"A branch-and-cut algorithm for the equicut problem","volume":"78","author":"Brunetta","year":"1997","journal-title":"Math. Program."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"177","DOI":"10.1287\/ijoc.12.3.177.12637","article-title":"Solving Graph Bisection Problems with Semidefinite Programming","volume":"12","author":"Karisch","year":"2000","journal-title":"INFORMS J. Comput."},{"key":"ref_39","first-page":"1","article-title":"Process mining with the heuristics miner-algorithm","volume":"166","author":"Weijters","year":"2006","journal-title":"Tech. Univ. Eindh."},{"key":"ref_40","doi-asserted-by":"crossref","first-page":"1128","DOI":"10.1109\/TKDE.2004.47","article-title":"Workflow mining: Discovering process models from event logs","volume":"16","author":"Weijters","year":"2004","journal-title":"IEEE Trans. Knowl. Data Eng."}],"container-title":["Entropy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/9\/1026\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,10,11]],"date-time":"2025-10-11T10:09:39Z","timestamp":1760177379000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/1099-4300\/22\/9\/1026"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,9,14]]},"references-count":40,"journal-issue":{"issue":"9","published-online":{"date-parts":[[2020,9]]}},"alternative-id":["e22091026"],"URL":"https:\/\/doi.org\/10.3390\/e22091026","relation":{},"ISSN":["1099-4300"],"issn-type":[{"value":"1099-4300","type":"electronic"}],"subject":[],"published":{"date-parts":[[2020,9,14]]}}}