{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2020:5TUWCDBQHDYYWESKMX5QI5ASIX","short_pith_number":"pith:5TUWCDBQ","schema_version":"1.0","canonical_sha256":"ece9610c3038f18b124a65fb04741245d815d91f77e702af834790ddee9cd064","source":{"kind":"arxiv","id":"2008.04676","version":1},"attestation_state":"computed","paper":{"title":"ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bobby Filar, David French","submitted_at":"2020-08-11T12:59:07Z","abstract_excerpt":"It is becoming more common that adversary attacks consist of more than a standalone executable or script. Often, evidence of an attack includes conspicuous process heritage that may be ignored by traditional static machine learning models. Advanced attacker techniques, like \"living off the land\" that appear normal in isolation become more suspicious when observed in a parent-child context. The context derived from parent-child process chains can help identify and group malware families, as well as discover novel attacker techniques. Adversaries chain these techniques to achieve persistence, by"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2008.04676","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2020-08-11T12:59:07Z","cross_cats_sorted":[],"title_canon_sha256":"6aaca35ef15b79c914479b2ffe4034df998a25236051cafe61ca1471829cfd61","abstract_canon_sha256":"a1c49f70ffc24ed8fa5970a0d09f3f4cc703a82ea17f4090de4b1162dd4b3209"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T01:26:27.843817Z","signature_b64":"wR4YR+XoHUA/GjxjFRcW1BEBn+1zC8UicEdYZh/qDZWXB3iT92wpzDjaVL95ESixK+5FT4U9tUJhfa0b3HHXBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"ece9610c3038f18b124a65fb04741245d815d91f77e702af834790ddee9cd064","last_reissued_at":"2026-07-05T01:26:27.843431Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T01:26:27.843431Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"ProblemChild: Discovering Anomalous Patterns based on Parent-Child Process Relationships","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Bobby Filar, David French","submitted_at":"2020-08-11T12:59:07Z","abstract_excerpt":"It is becoming more common that adversary attacks consist of more than a standalone executable or script. Often, evidence of an attack includes conspicuous process heritage that may be ignored by traditional static machine learning models. Advanced attacker techniques, like \"living off the land\" that appear normal in isolation become more suspicious when observed in a parent-child context. The context derived from parent-child process chains can help identify and group malware families, as well as discover novel attacker techniques. Adversaries chain these techniques to achieve persistence, by"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2008.04676","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2008.04676/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2008.04676","created_at":"2026-07-05T01:26:27.843489+00:00"},{"alias_kind":"arxiv_version","alias_value":"2008.04676v1","created_at":"2026-07-05T01:26:27.843489+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2008.04676","created_at":"2026-07-05T01:26:27.843489+00:00"},{"alias_kind":"pith_short_12","alias_value":"5TUWCDBQHDYY","created_at":"2026-07-05T01:26:27.843489+00:00"},{"alias_kind":"pith_short_16","alias_value":"5TUWCDBQHDYYWESK","created_at":"2026-07-05T01:26:27.843489+00:00"},{"alias_kind":"pith_short_8","alias_value":"5TUWCDBQ","created_at":"2026-07-05T01:26:27.843489+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":1,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2412.04259","citing_title":"SCADE: Scalable Framework for Anomaly Detection in High-Performance System","ref_index":16,"is_internal_anchor":true}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX","json":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX.json","graph_json":"https://pith.science/api/pith-number/5TUWCDBQHDYYWESKMX5QI5ASIX/graph.json","events_json":"https://pith.science/api/pith-number/5TUWCDBQHDYYWESKMX5QI5ASIX/events.json","paper":"https://pith.science/paper/5TUWCDBQ"},"agent_actions":{"view_html":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX","download_json":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX.json","view_paper":"https://pith.science/paper/5TUWCDBQ","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2008.04676&json=true","fetch_graph":"https://pith.science/api/pith-number/5TUWCDBQHDYYWESKMX5QI5ASIX/graph.json","fetch_events":"https://pith.science/api/pith-number/5TUWCDBQHDYYWESKMX5QI5ASIX/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX/action/timestamp_anchor","attest_storage":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX/action/storage_attestation","attest_author":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX/action/author_attestation","sign_citation":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX/action/citation_signature","submit_replication":"https://pith.science/pith/5TUWCDBQHDYYWESKMX5QI5ASIX/action/replication_record"}},"created_at":"2026-07-05T01:26:27.843489+00:00","updated_at":"2026-07-05T01:26:27.843489+00:00"}