{"id":"W4294238081","doi":"10.1145/3559768","title":"APTHunter: Detecting Advanced Persistent Threats in Early Stages","year":2022,"lang":"en","type":"article","venue":"Digital Threats Research and Practice","topic":"Advanced Malware Detection Techniques","field":"Computer Science","cited_by":30,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University","funders":"","keywords":"Computer science; Provenance; Adversarial system; Graph; Compromise; Computer security; Data mining; Theoretical computer science; Artificial intelligence","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.001818046,0.001411603,0.0007290811,0.002470838,0.0006051974,0.001484077,0.001650636,0.00106766,0.001996922],"category_scores_gemma":[0.01168661,0.0006892295,0.00085626,0.000936405,0.0009659911,0.004468595,0.002551149,0.001971056,0.0009696508],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0007082394,"about_ca_system_score_gemma":0.001335009,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003344326,"about_ca_topic_score_gemma":0.004892288,"domain_scores_codex":[0.9977735,0.0003102781,0.0001481387,0.0005432539,0.00109648,0.0001284401],"domain_scores_gemma":[0.9930112,0.002854477,0.0009224641,0.002283897,0.0006685526,0.000259396],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"not_applicable","study_design_scores_codex":[0.00141742,0.00102308,0.06797296,0.001095828,0.0004292434,0.002010301,0.002373635,0.07772291,0.1163772,0.01573763,0.05449545,0.6593444],"study_design_scores_gemma":[0.0001059847,0.0004362145,0.01011776,0.000103625,0.0001304009,0.0008571199,0.0002067821,0.8169081,0.1172588,0.02255188,0.03117898,0.0001444409],"study_design_candidate":"not_applicable","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.09936485,0.0007746758,0.6456304,0.000824507,0.0002620274,0.0008669675,0.004313231,0.2439774,0.003986086],"genre_scores_gemma":[0.5187064,0.0004320993,0.4631225,0.0004857491,0.00008214382,0.0004008585,0.006647728,0.005863453,0.004258968],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.003344326,"threshold_uncertainty_score":0.009614885,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.09393009053068718,"score_gpt":0.3949436509728956,"score_spread":0.3010135604422084,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}