{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2019:RCGL6GODLF5FAGZJTQF6I5QHWG","short_pith_number":"pith:RCGL6GOD","schema_version":"1.0","canonical_sha256":"888cbf19c3597a501b299c0be47607b19bbeb55973013e77dfa5e3d589367b64","source":{"kind":"arxiv","id":"1906.06940","version":4},"attestation_state":"computed","paper":{"title":"A baseline for unsupervised advanced persistent threat detection in system-level provenance","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Alec Theriault, Ghita Berrada, Himan Mookherjee, James Cheney, Ryan Wright, Sidahmed Benabderrahmane, William Maxwell","submitted_at":"2019-06-17T10:49:28Z","abstract_excerpt":"Advanced persistent threats (APT) are stealthy, sophisticated, and unpredictable cyberattacks that can steal intellectual property, damage critical infrastructure, or cause millions of dollars in damage. Detecting APTs by monitoring system-level activity is difficult because manually inspecting the high volume of normal system activity is overwhelming for security analysts. We evaluate the effectiveness of unsupervised batch and streaming anomaly detection algorithms over multiple gigabytes of provenance traces recorded on four different operating systems to determine whether they can detect r"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"1906.06940","kind":"arxiv","version":4},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2019-06-17T10:49:28Z","cross_cats_sorted":[],"title_canon_sha256":"c8070790bdcd0f0563231e8034cee319511a4a805f1625b6c1b9e51019043525","abstract_canon_sha256":"77beb9a96e27a73acd1ec9f43468a57cdce5b0e34b8a3c2c8dd895d616f066c1"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T00:45:51.415572Z","signature_b64":"ONxe6fSN40U4JjMltFaXMdNHEM7EP5KioXT3AZ9IN1usUKAIC2docj13I+3SbLkczmGzVt94nea1PsnLfx0qCw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"888cbf19c3597a501b299c0be47607b19bbeb55973013e77dfa5e3d589367b64","last_reissued_at":"2026-07-05T00:45:51.415091Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T00:45:51.415091Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"A baseline for unsupervised advanced persistent threat detection in system-level provenance","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Alec Theriault, Ghita Berrada, Himan Mookherjee, James Cheney, Ryan Wright, Sidahmed Benabderrahmane, William Maxwell","submitted_at":"2019-06-17T10:49:28Z","abstract_excerpt":"Advanced persistent threats (APT) are stealthy, sophisticated, and unpredictable cyberattacks that can steal intellectual property, damage critical infrastructure, or cause millions of dollars in damage. Detecting APTs by monitoring system-level activity is difficult because manually inspecting the high volume of normal system activity is overwhelming for security analysts. We evaluate the effectiveness of unsupervised batch and streaming anomaly detection algorithms over multiple gigabytes of provenance traces recorded on four different operating systems to determine whether they can detect r"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1906.06940","kind":"arxiv","version":4},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1906.06940/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"1906.06940","created_at":"2026-07-05T00:45:51.415149+00:00"},{"alias_kind":"arxiv_version","alias_value":"1906.06940v4","created_at":"2026-07-05T00:45:51.415149+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1906.06940","created_at":"2026-07-05T00:45:51.415149+00:00"},{"alias_kind":"pith_short_12","alias_value":"RCGL6GODLF5F","created_at":"2026-07-05T00:45:51.415149+00:00"},{"alias_kind":"pith_short_16","alias_value":"RCGL6GODLF5FAGZJ","created_at":"2026-07-05T00:45:51.415149+00:00"},{"alias_kind":"pith_short_8","alias_value":"RCGL6GOD","created_at":"2026-07-05T00:45:51.415149+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":0,"internal_anchor_count":0,"sample":[]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG","json":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG.json","graph_json":"https://pith.science/api/pith-number/RCGL6GODLF5FAGZJTQF6I5QHWG/graph.json","events_json":"https://pith.science/api/pith-number/RCGL6GODLF5FAGZJTQF6I5QHWG/events.json","paper":"https://pith.science/paper/RCGL6GOD"},"agent_actions":{"view_html":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG","download_json":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG.json","view_paper":"https://pith.science/paper/RCGL6GOD","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=1906.06940&json=true","fetch_graph":"https://pith.science/api/pith-number/RCGL6GODLF5FAGZJTQF6I5QHWG/graph.json","fetch_events":"https://pith.science/api/pith-number/RCGL6GODLF5FAGZJTQF6I5QHWG/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG/action/timestamp_anchor","attest_storage":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG/action/storage_attestation","attest_author":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG/action/author_attestation","sign_citation":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG/action/citation_signature","submit_replication":"https://pith.science/pith/RCGL6GODLF5FAGZJTQF6I5QHWG/action/replication_record"}},"created_at":"2026-07-05T00:45:51.415149+00:00","updated_at":"2026-07-05T00:45:51.415149+00:00"}