{"record_type":"pith_number_record","schema_url":"https://pith.science/schemas/pith-number/v1.json","pith_number":"pith:2023:T23I2PVNZZFQDZLFTSP3BSI6NX","short_pith_number":"pith:T23I2PVN","schema_version":"1.0","canonical_sha256":"9eb68d3eadce4b01e5659c9fb0c91e6deb748cf721688d3a17e6cc0a5b4f3d94","source":{"kind":"arxiv","id":"2311.02331","version":1},"attestation_state":"computed","paper":{"title":"NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ding Li, Fei Shao, Feng Dong, Haoyu Wang, Jiedong Chen, Shaofei Li, Xiangqun Chen, Xusheng Xiao, Yao Guo","submitted_at":"2023-11-04T05:36:59Z","abstract_excerpt":"Advanced Persistent Threats (APT) attacks have plagued modern enterprises, causing significant financial losses. To counter these attacks, researchers propose techniques that capture the complex and stealthy scenarios of APT attacks by using provenance graphs to model system entities and their dependencies. Particularly, to accelerate attack detection and reduce financial losses, online provenance-based detection systems that detect and investigate APT attacks under the constraints of timeliness and limited resources are in dire need. Unfortunately, existing online systems usually sacrifice de"},"verification_status":{"content_addressed":true,"pith_receipt":true,"author_attested":false,"weak_author_claims":0,"strong_author_claims":0,"externally_anchored":false,"storage_verified":false,"citation_signatures":0,"replication_records":0,"graph_snapshot":true,"references_resolved":false,"formal_links_present":false},"canonical_record":{"source":{"id":"2311.02331","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.CR","submitted_at":"2023-11-04T05:36:59Z","cross_cats_sorted":[],"title_canon_sha256":"5fab98fd83b243bdeea3287d282f3fd912176877b9006c4bde0b00eee8690501","abstract_canon_sha256":"7489c79a0a47fbc1e986045904e7f14d9a41df9f65354084c18058ac01c02ffb"},"schema_version":"1.0"},"receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-05T07:09:09.849199Z","signature_b64":"D/ymUM3VfWYbzjS8A4cejiUtRLlZTMTDs3Dg44TK3MWvS5OR/ehzXY9OCyDvsM6uCQ4ztIXEYDqKpA2aRwGnBw==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"9eb68d3eadce4b01e5659c9fb0c91e6deb748cf721688d3a17e6cc0a5b4f3d94","last_reissued_at":"2026-07-05T07:09:09.848800Z","signature_status":"signed_v1","first_computed_at":"2026-07-05T07:09:09.848800Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"graph_snapshot":{"paper":{"title":"NODLINK: An Online System for Fine-Grained APT Attack Detection and Investigation","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.CR","authors_text":"Ding Li, Fei Shao, Feng Dong, Haoyu Wang, Jiedong Chen, Shaofei Li, Xiangqun Chen, Xusheng Xiao, Yao Guo","submitted_at":"2023-11-04T05:36:59Z","abstract_excerpt":"Advanced Persistent Threats (APT) attacks have plagued modern enterprises, causing significant financial losses. To counter these attacks, researchers propose techniques that capture the complex and stealthy scenarios of APT attacks by using provenance graphs to model system entities and their dependencies. Particularly, to accelerate attack detection and reduce financial losses, online provenance-based detection systems that detect and investigate APT attacks under the constraints of timeliness and limited resources are in dire need. Unfortunately, existing online systems usually sacrifice de"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"2311.02331","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/2311.02331/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"aliases":[{"alias_kind":"arxiv","alias_value":"2311.02331","created_at":"2026-07-05T07:09:09.848856+00:00"},{"alias_kind":"arxiv_version","alias_value":"2311.02331v1","created_at":"2026-07-05T07:09:09.848856+00:00"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.2311.02331","created_at":"2026-07-05T07:09:09.848856+00:00"},{"alias_kind":"pith_short_12","alias_value":"T23I2PVNZZFQ","created_at":"2026-07-05T07:09:09.848856+00:00"},{"alias_kind":"pith_short_16","alias_value":"T23I2PVNZZFQDZLF","created_at":"2026-07-05T07:09:09.848856+00:00"},{"alias_kind":"pith_short_8","alias_value":"T23I2PVN","created_at":"2026-07-05T07:09:09.848856+00:00"}],"events":[],"event_summary":{},"paper_claims":[],"inbound_citations":{"count":3,"internal_anchor_count":1,"sample":[{"citing_arxiv_id":"2607.05989","citing_title":"ProvICS: A Provenance-based Intrusion Detection for Industrial Control Systems","ref_index":2,"is_internal_anchor":true},{"citing_arxiv_id":"2605.29269","citing_title":"HunterAgent: Neuro-Symbolic Attack Trace Reconstruction under Anti-Forensics","ref_index":26,"is_internal_anchor":false},{"citing_arxiv_id":"2506.06226","citing_title":"No Data? No Problem: Synthesizing Security Graphs for Better Intrusion Detection","ref_index":37,"is_internal_anchor":false}]},"formal_canon":{"evidence_count":0,"sample":[],"anchors":[]},"links":{"html":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX","json":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX.json","graph_json":"https://pith.science/api/pith-number/T23I2PVNZZFQDZLFTSP3BSI6NX/graph.json","events_json":"https://pith.science/api/pith-number/T23I2PVNZZFQDZLFTSP3BSI6NX/events.json","paper":"https://pith.science/paper/T23I2PVN"},"agent_actions":{"view_html":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX","download_json":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX.json","view_paper":"https://pith.science/paper/T23I2PVN","resolve_alias":"https://pith.science/api/pith-number/resolve?arxiv=2311.02331&json=true","fetch_graph":"https://pith.science/api/pith-number/T23I2PVNZZFQDZLFTSP3BSI6NX/graph.json","fetch_events":"https://pith.science/api/pith-number/T23I2PVNZZFQDZLFTSP3BSI6NX/events.json","actions":{"anchor_timestamp":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX/action/timestamp_anchor","attest_storage":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX/action/storage_attestation","attest_author":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX/action/author_attestation","sign_citation":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX/action/citation_signature","submit_replication":"https://pith.science/pith/T23I2PVNZZFQDZLFTSP3BSI6NX/action/replication_record"}},"created_at":"2026-07-05T07:09:09.848856+00:00","updated_at":"2026-07-05T07:09:09.848856+00:00"}