{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T14:14:38Z","timestamp":1781532878118,"version":"3.54.5"},"reference-count":62,"publisher":"MDPI AG","issue":"5","license":[{"start":{"date-parts":[[2026,5,18]],"date-time":"2026-05-18T00:00:00Z","timestamp":1779062400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"crossref","award":["RS-2025-25411243"],"award-info":[{"award-number":["RS-2025-25411243"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100003725","name":"National Research Foundation of Korea","doi-asserted-by":"crossref","award":["RS-2025-25398603"],"award-info":[{"award-number":["RS-2025-25398603"]}],"id":[{"id":"10.13039\/501100003725","id-type":"DOI","asserted-by":"crossref"}]},{"award":["RS-2025-25411243"],"award-info":[{"award-number":["RS-2025-25411243"]}],"id":[{"id":"https:\/\/ror.org\/013aysd81","id-type":"ROR","asserted-by":"publisher"}]},{"award":["RS-2025-25398603"],"award-info":[{"award-number":["RS-2025-25398603"]}],"id":[{"id":"https:\/\/ror.org\/013aysd81","id-type":"ROR","asserted-by":"publisher"}]},{"name":"Ministry or Trade Industry & Energy","award":["RS-2025-02317769"],"award-info":[{"award-number":["RS-2025-02317769"]}]},{"award":["RS-2025-02317769"],"award-info":[{"award-number":["RS-2025-02317769"]}],"id":[{"id":"https:\/\/ror.org\/008nkqk13","id-type":"ROR","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100002642","name":"Korea University","doi-asserted-by":"crossref","id":[{"id":"10.13039\/501100002642","id-type":"DOI","asserted-by":"crossref"}]},{"id":[{"id":"https:\/\/ror.org\/047dqcg40","id-type":"ROR","asserted-by":"publisher"}]}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["Systems"],"abstract":"<jats:p>The contemporary cyber-threat landscape is becoming increasingly diverse and complex, creating a persistent gap between situational awareness and operational response. This study presents a framework designed to bridge this gap by transforming up-to-date cyber-threat intelligence (CTI) into standardized knowledge structures and actionable defense measures. First, the proposed framework integrates the threat data collected from OpenCTI and normalizes them based on the MITRE ATT&amp;CK tactics and techniques matrix. It then leverages a large language model to automatically generate diverse threat scenarios based on the analyzed intelligence. Each scenario is organized as a tactic sequence, and individual techniques are mapped to MITRE D3FEND defensive categories based on official ATT&amp;CK\u2013D3FEND relationships and structured contextual interpretation. Finally, the framework produces outputs in the form of a Defense Description that includes the corresponding technique IDs, recommended defense strategies, supporting rationales, and prerequisites. An evaluation using several recent cases demonstrates that the proposed framework effectively connects current threat intelligence with practical defense strategies. In summary, the proposed framework strengthens proactive cyber defense by directly linking structured attack flows to actionable context-aware defensive techniques. In addition, this framework provides a structured pipeline that systematizes and automates steps conventionally performed manually, thereby reducing repetitive analyst effort.<\/jats:p>","DOI":"10.3390\/systems14050575","type":"journal-article","created":{"date-parts":[[2026,5,20]],"date-time":"2026-05-20T15:45:34Z","timestamp":1779291934000},"page":"575","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":0,"title":["Proactive Cyber Defense: A Real-Time CTI Framework with ATT&amp;CK\u2013D3FEND Mapping"],"prefix":"10.3390","volume":"14","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-4069-7293","authenticated-orcid":false,"given":"Rino","family":"Jo","sequence":"first","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-7555-8115","authenticated-orcid":false,"given":"Han-Bin","family":"Lee","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-3594-9023","authenticated-orcid":false,"given":"Jihun","family":"Han","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0009-0006-0107-9197","authenticated-orcid":false,"given":"Woong-Kyo","family":"Jung","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun-Yong","family":"Lee","sequence":"additional","affiliation":[{"name":"AI Cyber Security (Undergraduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Tae-Young","family":"Kang","sequence":"additional","affiliation":[{"name":"AI Cyber Security (Undergraduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1494-9503","authenticated-orcid":false,"given":"Youngsoo","family":"Kim","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2009-4580","authenticated-orcid":false,"given":"Byung Il","family":"Kwak","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-1692-3788","authenticated-orcid":false,"given":"Mee Lan","family":"Han","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jungmin","family":"Kang","sequence":"additional","affiliation":[{"name":"Cyber Security (Graduate), Korea University, 2511 Sejong-ro, Sejong-si 30019, Republic of Korea"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2026,5,18]]},"reference":[{"key":"ref_1","unstructured":"American Hospital Association (2026, April 20). Change Healthcare Cyberattack Underscores Urgent Need to Strengthen Cyber Preparedness for Individual Health Care Organizations and as a Field. Available online: https:\/\/www.aha.org\/change-healthcare-cyberattack-underscores-urgent-need-strengthen-cyber-preparedness-individual-health-care-organizations-and."},{"key":"ref_2","unstructured":"Hong Kong Information Services Department (2026, February 12). LCQ9: Combating Frauds Involving Deepfake, Available online: https:\/\/www.info.gov.hk\/gia\/general\/202406\/26\/P2024062600192.htm."},{"key":"ref_3","doi-asserted-by":"crossref","unstructured":"Su, C., Wang, J., Wang, X., and Li, Z. (2026). Robustness Analysis of Clustered Mine Cyber-Physical System Considering Node Overload and Underload under Cascading Failure. Proc. Inst. Mech. Eng. Part O J. Risk Reliab.","DOI":"10.1177\/1748006X261433734"},{"key":"ref_4","unstructured":"Insurance Business America (2025, September 02). Supply Chain Cyber Attacks Surge Over 400%, Expected to Continue Rising. Available online: https:\/\/www.insurancebusinessmag.com\/us\/news\/cyber\/supply-chain-cyber-attacks-surge-over-400-expected-to-continue-rising--cowbell-report-525369.aspx."},{"key":"ref_5","unstructured":"Fortinet FortiGuard Labs (2025, September 02). Key Findings from the 2H 2023 Threat Landscape Report. Available online: https:\/\/www.fortinet.com\/blog\/threat-research\/key-findings-2h-2023-fortiguard-labs-threat-report."},{"key":"ref_6","unstructured":"CI-ISAC (Australia) (2025, September 02). Threat Intelligence Is Essential for Good Cyber Security. Available online: https:\/\/ci-isac.org.au\/threat-intelligence-is-essential-for-good-cyber-security."},{"key":"ref_7","doi-asserted-by":"crossref","first-page":"1603","DOI":"10.1007\/s10207-024-00812-4","article-title":"From sinking to saving: MITRE ATT&CK and D3FEND frameworks for maritime cybersecurity","volume":"23","author":"Yousaf","year":"2024","journal-title":"Int. J. Inf. Secur."},{"key":"ref_8","doi-asserted-by":"crossref","first-page":"249","DOI":"10.1007\/s10207-022-00638-y","article-title":"Cyber risk management for autonomous passenger ships using threat-informed defense-in-depth","volume":"22","author":"Amro","year":"2023","journal-title":"Int. J. Inf. Secur."},{"key":"ref_9","unstructured":"Jiang, Y., Meng, Q., Shang, F., Oo, N., Minh, L.T.H., Lim, H.W., and Sikdar, B. (2025). MITRE ATT&CK Applications in Cybersecurity and The Way Forward. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","unstructured":"Yu, Z., and Miao, Q. (2025, January 21\u201323). Cybersecurity Survivability Testing Technology Based on ATT&CK and D3FEND. Proceedings of the 2025 2nd International Conference on Generative Artificial Intelligence and Information Security (GAIIS \u201925), New York, NY, USA.","DOI":"10.1145\/3728725.3728768"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Alam, M.T., Bhusal, D., Park, Y., and Rastogi, N. (2023, January 16\u201318). Looking beyond IoCs: Automatically extracting attack patterns from external CTI. Proceedings of the 26th International Symposium on Research in Attacks, Intrusions and Defenses (RAID), Hong Kong, China.","DOI":"10.1145\/3607199.3607208"},{"key":"ref_12","doi-asserted-by":"crossref","unstructured":"Ampel, B., Vahedi, T., Samtani, S., and Chen, H. (2023). Mapping exploit code on paste sites to the MITRE ATT&CK framework: A multi-label transformer approach. Proceedings of the 2023 IEEE International Conference on Intelligence and Security Informatics (ISI), IEEE.","DOI":"10.1109\/ISI58743.2023.10297272"},{"key":"ref_13","doi-asserted-by":"crossref","unstructured":"Joy, A., Chandane, M., Nagare, Y., and Kazi, F. (2025). Threat Intelligence Extraction Framework (TIEF) for TTP Extraction. J. Cybersecur. Priv., 5.","DOI":"10.3390\/jcp5030063"},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Liu, J., and Zhan, J. (2023). Constructing Knowledge Graph from Cyber Threat Intelligence Using Large Language Model. Proceedings of the 2023 IEEE International Conference on Big Data (BigData), IEEE.","DOI":"10.1109\/BigData59044.2023.10386611"},{"key":"ref_15","doi-asserted-by":"crossref","first-page":"6345","DOI":"10.1109\/TDSC.2025.3584826","article-title":"CRUcialG: Reconstruct Integrated Attack Scenario Graphs by Cyber Threat Intelligence Reports","volume":"22","author":"Cheng","year":"2025","journal-title":"IEEE Trans. Dependable Secur. Comput."},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Akbar, K.A., Halim, S.M., Hu, Y., Singhal, A., Khan, L., and Thuraisingham, B. (2022, January 18\u201320). Knowledge mining in cybersecurity: From attack to defense. Proceedings of the IFIP Annual Conference on Data and Applications Security and Privacy, Cham, Switzerland.","DOI":"10.1007\/978-3-031-10684-2_7"},{"key":"ref_17","doi-asserted-by":"crossref","first-page":"146150","DOI":"10.1109\/ACCESS.2025.3597850","article-title":"LLM-Based Automated Generation and Tri-Modal Representation of Cyber Attack Scenario","volume":"13","author":"Roh","year":"2025","journal-title":"IEEE Access"},{"key":"ref_18","unstructured":"Shah, S., and Khoda Parast, F. (2024). AI-Driven Cyber Threat Intelligence Automation. arXiv."},{"key":"ref_19","unstructured":"Liu, X., Liang, J., Yan, Q., Ye, M., Jia, J., and Xi, Z. (2025). Cyber Defense Reinvented: Large Language Models as Threat Intelligence Copilots. arXiv."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Afenu, D.S., Asiri, M., and Saxena, N. (2024). Industrial Control Systems Security Validation Based on MITRE Adversarial Tactics, Techniques, and Common Knowledge Framework. Electronics, 13.","DOI":"10.3390\/electronics13050917"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Sekonya, N., and Sithungu, S. (2023). An Analysis of Critical Cybersecurity Controls for Industrial Control Systems. Proceedings of the 22nd European Conference on Cyber Warfare and Security (ECCWS), University of Johannesburg, Academic Conferences International Limited.","DOI":"10.34190\/eccws.22.1.1157"},{"key":"ref_22","unstructured":"Roy, S., Panaousis, E., Noakes, C., Laszka, A., Panda, S., and Loukas, G. (2023). Sok: The MITRE ATT&CK framework in research and practice. arXiv."},{"key":"ref_23","unstructured":"MITRE (2025, September 02). Updates\u2014October 2022 (ATT&CK v12) Release Notes. Available online: https:\/\/attack.mitre.org\/resources\/updates\/updates-october-2022\/."},{"key":"ref_24","unstructured":"MITRE D3FEND (2025, September 13). Model Tactic (d3f:Model). Available online: https:\/\/d3fend.mitre.org\/tactic\/d3f:Model\/."},{"key":"ref_25","unstructured":"OpenCTI (2025, September 02). OpenCTI Documentation. Available online: https:\/\/docs.opencti.io\/latest\/."},{"key":"ref_26","unstructured":"OpenCTI (2025, September 02). OpenCTI Connectors. Available online: https:\/\/docs.opencti.io\/latest\/deployment\/connectors\/."},{"key":"ref_27","unstructured":"OASIS Open (2025, December 31). STIX Version 2.1. Available online: https:\/\/docs.oasis-open.org\/cti\/stix\/v2.1\/os\/stix-v2.1-os.html."},{"key":"ref_28","unstructured":"RabbitMQ (2025, September 13). RabbitMQ Documentation. Available online: https:\/\/www.rabbitmq.com\/."},{"key":"ref_29","unstructured":"Elastic (2025, September 13). Elasticsearch Documentation. Available online: https:\/\/www.elastic.co\/docs\/reference\/elasticsearch."},{"key":"ref_30","unstructured":"Redis (2025, September 13). Redis Documentation. Available online: https:\/\/redis.io\/docs\/latest\/."},{"key":"ref_31","unstructured":"MinIO (2025, September 13). MinIO (Object Storage) Documentation. Available online: https:\/\/github.com\/minio\/minio."},{"key":"ref_32","unstructured":"FIRST (2025, September 02). Common Vulnerability Scoring System (CVSS). Available online: https:\/\/www.first.org\/cvss\/."},{"key":"ref_33","unstructured":"FIRST (2025, September 02). Exploit Prediction Scoring System (EPSS). Available online: https:\/\/www.first.org\/epss\/."},{"key":"ref_34","unstructured":"Adams, M. (2025, September 02). AttackGen. GitHub Repository. Available online: https:\/\/github.com\/mrwadams\/attackgen."},{"key":"ref_35","unstructured":"B\u00fcchel, M., Paladini, T., Longari, S., Carminati, M., Zanero, S., Binyamini, H., Engelberg, G., Klein, D., Guizzardi, G., and Caselli, M. (2025, January 13). SoK: Automated TTP Extraction from CTI Reports\u2014Are We There Yet?. Proceedings of the 34th USENIX Security Symposium (USENIX Security 2025), Seattle, WA, USA."},{"key":"ref_36","doi-asserted-by":"crossref","unstructured":"Shimizu, N., and Hashimoto, M. (2025). Vulnerability Management Chaining: An Integrated Framework for Efficient Cybersecurity Risk Prioritization. arXiv.","DOI":"10.1109\/ACCESS.2026.3665768"},{"key":"ref_37","unstructured":"Kaloroumakis, P.E., and Smith, M.J. (2025, September 13). Toward a Knowledge Graph of Cybersecurity Countermeasures. Technical Report, The MITRE Corporation, 2021. Available online: https:\/\/d3fend.mitre.org\/resources\/."},{"key":"ref_38","doi-asserted-by":"crossref","unstructured":"Ouyang, S., Zhang, J., Harman, M., and Wang, M. (2025). An Empirical Study of the Non-Determinism of ChatGPT in Code Generation. ACM Trans. Softw. Eng. Methodol., 34.","DOI":"10.1145\/3697010"},{"key":"ref_39","doi-asserted-by":"crossref","unstructured":"Deutsch, D., Dror, R., and Roth, D. (2022). On the Limitations of Reference-Free Evaluations of Generated Text. arXiv.","DOI":"10.18653\/v1\/2022.emnlp-main.753"},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Caglayan, O., Madhyastha, P., and Specia, L. (2020, January 8\u201313). Curious Case of Language Generation Evaluation Metrics: A Cautionary Tale. Proceedings of the 28th International Conference on Computational Linguistics, Online.","DOI":"10.18653\/v1\/2020.coling-main.210"},{"key":"ref_41","doi-asserted-by":"crossref","unstructured":"Laskar, M.T.R., Alqahtani, S., Bari, M.S., Rahman, M., and Khan, M.A.M. (2024, January 12\u201316). A Systematic Survey and Critical Review on Evaluating Large Language Models: Challenges, Limitations, and Recommendations. Proceedings of the 2024 Conference on Empirical Methods in Natural Language Processing, Miami, FL, USA.","DOI":"10.18653\/v1\/2024.emnlp-main.764"},{"key":"ref_42","doi-asserted-by":"crossref","unstructured":"Reimers, N., and Gurevych, I. (2019). Sentence-BERT: Sentence Embeddings Using Siamese BERT-Networks. arXiv.","DOI":"10.18653\/v1\/D19-1410"},{"key":"ref_43","doi-asserted-by":"crossref","unstructured":"Hadifar, A., Sterckx, L., Demeester, T., and Develder, C. (2019, January 2). A Self-Training Approach for Short Text Clustering. Proceedings of the 4th Workshop on Representation Learning for NLP (RepL4NLP-2019), Florence, Italy.","DOI":"10.18653\/v1\/W19-4322"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Zhang, Z., Fang, M., Chen, L., and Namazi-Rad, M.R. (2022, January 10\u201315). Is Neural Topic Modelling Better than Clustering? An Empirical Study on Clustering with Contextual Embeddings for Topics. Proceedings of the 2022 Conference of the North American Chapter of the Association for Computational Linguistics: Human Language Technologies, Online.","DOI":"10.18653\/v1\/2022.naacl-main.285"},{"key":"ref_45","first-page":"2187","article-title":"An integrated clustering and BERT framework for improved topic modeling","volume":"15","author":"George","year":"2023","journal-title":"Int. J. Inf. Technol."},{"key":"ref_46","doi-asserted-by":"crossref","first-page":"1249","DOI":"10.1109\/TVCG.2016.2640960","article-title":"Visualizing High-Dimensional Data: Advances in the Past Decade","volume":"23","author":"Liu","year":"2017","journal-title":"IEEE Trans. Vis. Comput. Graph."},{"key":"ref_47","doi-asserted-by":"crossref","unstructured":"McInnes, L., Healy, J., and Melville, J. (2018). UMAP: Uniform Manifold Approximation and Projection for Dimension Reduction. arXiv.","DOI":"10.21105\/joss.00861"},{"key":"ref_48","first-page":"3221","article-title":"Accelerating t-SNE using tree-based algorithms","volume":"15","year":"2014","journal-title":"J. Mach. Learn. Res."},{"key":"ref_49","doi-asserted-by":"crossref","first-page":"243","DOI":"10.1016\/j.patcog.2012.07.021","article-title":"An extensive comparative study of cluster validity indices","volume":"46","author":"Arbelaitz","year":"2013","journal-title":"Pattern Recognit."},{"key":"ref_50","doi-asserted-by":"crossref","first-page":"53","DOI":"10.1016\/0377-0427(87)90125-7","article-title":"Silhouettes: A graphical aid to the interpretation and validation of cluster analysis","volume":"20","author":"Rousseeuw","year":"1987","journal-title":"J. Comput. Appl. Math."},{"key":"ref_51","doi-asserted-by":"crossref","unstructured":"Shahapure, K.R., and Nicholas, C. (2020). Cluster Quality Analysis Using Silhouette Score. Proceedings of the 2020 IEEE 7th International Conference on Data Science and Advanced Analytics (DSAA), IEEE.","DOI":"10.1109\/DSAA49011.2020.00096"},{"key":"ref_52","doi-asserted-by":"crossref","unstructured":"Shutaywi, M., and Nezamoddini-Kachouie, N. (2021). Silhouette Analysis for Performance Evaluation in Machine Learning with Applications to Clustering. Entropy, 23.","DOI":"10.3390\/e23060759"},{"key":"ref_53","doi-asserted-by":"crossref","first-page":"855","DOI":"10.1007\/s10115-022-01776-4","article-title":"New cosine similarity and distance measures for Fermatean fuzzy sets and TOPSIS approach","volume":"65","year":"2023","journal-title":"Knowl. Inf. Syst."},{"key":"ref_54","doi-asserted-by":"crossref","unstructured":"Schubert, E. (2021). A triangle inequality for cosine similarity. Proceedings of the Similarity Search and Applications, Springer. Lecture Notes in Computer Science.","DOI":"10.1007\/978-3-030-89657-7_3"},{"key":"ref_55","doi-asserted-by":"crossref","unstructured":"Wang, J., and Dong, Y. (2020). Measurement of Text Similarity: A Survey. Information, 11.","DOI":"10.3390\/info11090421"},{"key":"ref_56","doi-asserted-by":"crossref","unstructured":"Han, S., Zhao, C., Meng, W., and Li, C. (2015, January 8\u201312). Cosine similarity based fingerprinting algorithm in WLAN indoor positioning against device diversity. Proceedings of the 2015 IEEE International Conference on Communications (ICC), London, UK.","DOI":"10.1109\/ICC.2015.7248735"},{"key":"ref_57","unstructured":"Artetxe, M., and Schwenk, H. (August, January 28). Margin-based Parallel Corpus Mining with Multilingual Sentence Embeddings. Proceedings of the 57th Annual Meeting of the Association for Computational Linguistics, Florence, Italy."},{"key":"ref_58","unstructured":"SK Telecom (2025, December 12). Response Measures for the SK Telecom USIM Hacking Incident. Available online: https:\/\/skt-hack.wisoft.io\/response."},{"key":"ref_59","unstructured":"MITRE (2026, January 02). MITRE ATLAS\u2122. Available online: https:\/\/atlas.mitre.org\/."},{"key":"ref_60","unstructured":"MITRE ATT&CK (2026, January 11). C0034: 2022 Ukraine Attacks on Power Grid. Campaign ID C0034. Available online: https:\/\/attack.mitre.org\/campaigns\/C0034\/."},{"key":"ref_61","unstructured":"CISA (2026, January 12). Countering Chinese State-Sponsored Actors Compromise of U.S. Telecommunications Infrastructure. Cybersecurity Advisory AA25-239A, Available online: https:\/\/www.cisa.gov\/news-events\/cybersecurity-advisories\/aa25-239a."},{"key":"ref_62","unstructured":"Sekoia.io (2026, January 12). ViciousTrap\u2014Infiltrate, Control, Lure: Turning Edge Devices into Honeypots en Masse. Available online: https:\/\/blog.sekoia.io\/vicioustrap-infiltrate-control-lure-turning-edge-devices-into-honeypots-en-masse\/."}],"container-title":["Systems"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2079-8954\/14\/5\/575\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,21]],"date-time":"2026-05-21T04:19:56Z","timestamp":1779337196000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2079-8954\/14\/5\/575"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,5,18]]},"references-count":62,"journal-issue":{"issue":"5","published-online":{"date-parts":[[2026,5]]}},"alternative-id":["systems14050575"],"URL":"https:\/\/doi.org\/10.3390\/systems14050575","relation":{},"ISSN":["2079-8954"],"issn-type":[{"value":"2079-8954","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026,5,18]]}}}