{"id":"W4386214371","doi":"10.1109/csr57506.2023.10224951","title":"Detecting Internal Reconnaissance Behavior Through Classification of Command Collections","year":2023,"lang":"en","type":"article","venue":"","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":0,"is_retracted":false,"has_abstract":true,"ca_institutions":"Open Text (Canada)","funders":"","keywords":"Computer science; Adversary; Task (project management); Artificial intelligence; False positive paradox; Binary classification; Latent Dirichlet allocation; Internal model; Adversarial system; Machine learning; Computer security; Control (management); Support vector machine; Topic model","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.000574321,0.0005324,0.0005491697,0.002095054,0.0003710457,0.0009331849,0.0005757267,0.0004761905,0.0005368057],"category_scores_gemma":[0.002114999,0.0001478822,0.000417423,0.001112457,0.0004406142,0.00101698,0.000694075,0.0006456698,0.0005270618],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.0005144535,"about_ca_system_score_gemma":0.000473671,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.003404759,"about_ca_topic_score_gemma":0.003650077,"domain_scores_codex":[0.999249,0.0001435434,0.00005248065,0.0001583555,0.0002543256,0.0001421479],"domain_scores_gemma":[0.9981273,0.000512968,0.0004640906,0.000307198,0.0004763765,0.0001121472],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0006047538,0.0005900297,0.1164691,0.0001701191,0.0001357292,0.0004441257,0.0007518192,0.1051739,0.06776559,0.002551769,0.004930957,0.7004122],"study_design_scores_gemma":[0.000006230299,0.0001590085,0.04320622,0.00002181684,0.00003017867,0.0003103637,0.0004143237,0.9220251,0.02963202,0.002205194,0.001947895,0.00004158279],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"empirical","genre_gemma":"empirical","genre_scores_codex":[0.691937,0.000328384,0.3010815,0.0002291281,0.000068997,0.0001050087,0.0004632228,0.002553693,0.003233087],"genre_scores_gemma":[0.9682307,0.00008748467,0.03007788,0.00002625682,0.0000183487,0.00002653263,0.0004882909,0.00003108683,0.001013353],"genre_candidate":"empirical","genre_consensus":"empirical","teacher_disagreement_score":0.003404759,"threshold_uncertainty_score":0.006769896,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.06594961193457226,"score_gpt":0.3004157106323904,"score_spread":0.2344660986978181,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}