{"id":"W4393034384","doi":"10.1109/tnsm.2024.3378972","title":"AUTOMA: Automated Generation of Attack Hypotheses and Their Variants for Threat Hunting Using Knowledge Discovery","year":2024,"lang":"en","type":"article","venue":"IEEE Transactions on Network and Service Management","topic":"Network Security and Intrusion Detection","field":"Computer Science","cited_by":11,"is_retracted":false,"has_abstract":true,"ca_institutions":"Concordia University; Ericsson (Canada)","funders":"","keywords":"Computer science; Computer security; Data science","routes":{"ca_aff":true,"ca_fund":false,"ca_venue":false,"about_ca":false,"invisible_to_affiliation_only":false},"retraction":null,"screen":null,"direct_labels":[],"prediction":{"model_version":"metacan-v3-hybrid-931329e0061c","candidate_categories":[],"consensus_categories":[],"category_scores_codex":[0.003474142,0.002409306,0.001106434,0.00800775,0.0009629398,0.002361506,0.003113553,0.002153054,0.004484743],"category_scores_gemma":[0.01193216,0.0006407876,0.002931237,0.002482723,0.0007855409,0.003435742,0.002737896,0.001688732,0.003129538],"about_ca_system_candidate":false,"about_ca_system_consensus":false,"about_ca_system_score_codex":0.001043702,"about_ca_system_score_gemma":0.002316981,"about_ca_topic_candidate":false,"about_ca_topic_consensus":false,"about_ca_topic_score_codex":0.004145167,"about_ca_topic_score_gemma":0.008309249,"domain_scores_codex":[0.9966535,0.0009393516,0.0002406166,0.0009147031,0.001042229,0.0002096928],"domain_scores_gemma":[0.9920679,0.005260811,0.0005119083,0.001195169,0.0007381687,0.0002259494],"domain_codex":null,"domain_gemma":null,"domain_candidate":null,"domain_consensus":null,"study_design_codex":"design_other","study_design_gemma":"simulation_or_modeling","study_design_scores_codex":[0.0008171566,0.001368088,0.02847352,0.002460886,0.0007608674,0.001122844,0.0009894372,0.04381947,0.01675894,0.008469544,0.07220136,0.822758],"study_design_scores_gemma":[0.0002963663,0.0007021191,0.01146698,0.0003480807,0.0004473758,0.001213756,0.001055614,0.8723648,0.02019181,0.0303496,0.06141966,0.0001437761],"study_design_candidate":"simulation_or_modeling","study_design_consensus":null,"genre_codex":"methods","genre_gemma":"empirical","genre_scores_codex":[0.0892193,0.003906621,0.7659816,0.001975109,0.0003338863,0.002318122,0.02988858,0.09706098,0.009315738],"genre_scores_gemma":[0.1677929,0.0007417547,0.7759814,0.0005437717,0.00009023113,0.0007697858,0.05142089,0.0006801251,0.001979186],"genre_candidate":"empirical","genre_consensus":null,"teacher_disagreement_score":0.00800775,"threshold_uncertainty_score":0.01837325,"prediction_status":"machine_predicted_unvalidated"},"machine_scores":{"provisional":true,"baseline":true,"maturity_gate_passed":false,"score_opus":0.05084952304846543,"score_gpt":0.2754338352616307,"score_spread":0.2245843122131653,"validation_status":"score_only:v0-immature-baseline","note":"Baseline scores from an immature model (maturity gate not passed). Scores rank; they never assert a category."}}