<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Using Semantic Lifting for improving Process Mining: a Data Loss Prevention System case study</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Antonia Azzini</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Chiara Braghin</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Ernesto Damiani</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Francesco Zavatarelli</string-name>
          <email>francesco.zavatarellig@unimi.it</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>Dipartimento di Informatica Universita degli Studi di Milano</institution>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <fpage>62</fpage>
      <lpage>73</lpage>
      <abstract>
        <p>Process mining is a process management technique to extract knowledge from the event logs recorded by an information system. We show how applying an appropriate semantic lifting to the event and work ow log may help to discover the process that is actually being executed. In particular, we show how it is possible to extract not only knowledge about the structure of the process, but also to verify if some non-functional properties, such as security properties, hold during the process execution.</p>
      </abstract>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>Introduction</title>
      <p>Business Process Intelligence (BPI) is a research area that is quickly gaining
interest and importance: it refers to the application of various measurement and
analysis techniques both at design and at run-time in the area of business process
management. In practice, BPI stands for an integrated set of tools for
managing process execution quality by o ering several features such as monitoring,
analysis, discovery, control, optimization and prediction.</p>
      <p>In particular, process mining is a process management technique to extract
knowledge from the event logs recorded by an information system. It is often
used for discovering processes if there is no a priori model, or for conformance
analysis in case there is an a priori model that is compared with the event log
in order to nd out if there are discrepancies between the log and the model.</p>
      <p>In this work, we focus our attention on process mining techniques based on
the computation of frequencies among event dependencies to reconstruct the
work ow of concurrent systems. In particular, we show how applying an
appropriate semantic lifting to the event and work ow log may help to discover the
process that is actually being executed. In the Web scenario, the term semantic
lifting refers to the process of associating content items with suitable semantic
objects as metadata to turn unstructured content items into semantic
knowledge resources. In our case, the semantic lifting procedure corresponds to all the
transformations of low-level systems logs carried out in order to achieve a
conceptual description of business process instances, without knowing the business
process a priori.</p>
      <p>To illustrate our proposal, we present a case study based on a data loss
prevention scenario aiming to preventing the loss of critical information in
companies. In order to describe our running example, we use a lightweight data
representation model designed to support real time monitoring of business
processes based on a shared vocabulary de ned using open standard representations
(RDF). We believe that the usage of RDF as modeling language allows
independence and extremely exible interoperability between applications.</p>
      <p>The contributions of this paper are:
{ an example on how semantic lifting may help to improve the discovering
process during process mining;
{ a de nition of a Data Loss Prevention System in RDF, modeling a multi-level
security policy based on the organizational boundaries (internal vs external
actors and resources);
{ an example on how, using semantic lifting in combination with standard
process mining techniques during the discovery phase, it is possible to extract
not only knowledge about the structure of the process, but also to verify if
some non-functional properties, such as security properties, hold during the
process execution.</p>
      <p>This work is organized as follows. In Section 2, we introduce the semantic
lifting approach and describe how it has been used so far; in Section 3, we give
a short overview of the Resource Description Framework (RDF). Section 4 is
the core of the paper, where we present the Data Loss scenario and we give
some examples on how semantic lifting helps improving the investigation on the
process. Section 5 concludes the paper.
2</p>
    </sec>
    <sec id="sec-2">
      <title>Semantic Lifting: State of the Art</title>
      <p>
        In the Web scenario, the term semantic lifting refers to the process of associating
content items with suitable semantic objects as metadata to turn unstructured
content items into semantic knowledge resources. As discussed in [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ], by semantic
lifting we refer to all the transformations of low-level systems logs carried out in
order to achieve a conceptual description of business process instances. Typically,
this procedure is implicitly done by converting data from the data storages of an
information system to an event log format suitable for process monitoring [
        <xref ref-type="bibr" rid="ref5">5</xref>
        ].
We believe that this problem is orthogonal to the abstraction problem in process
mining, dealing with di erent levels of abstraction when comparing events with
modeled business activities [
        <xref ref-type="bibr" rid="ref4">4</xref>
        ]: our goal is to see how associating some semantics
to an event from the log it is possible to extract better knowledge about some
properties of the overall process, not to see which is the mapping between events
and business activities/tasks.
      </p>
      <p>
        So far, the term semantic lifting has been used in the context of model-driven
software development. In [
        <xref ref-type="bibr" rid="ref9">9</xref>
        ], the authors proposed a technique for designing
and implementing tool components which can semantically lift model di erences
arising among the tools. In particular, they used the term semantic lifting of
di erences to refer to the transformation of low-level changes to all the more
conceptual descriptions of model modi cations.
      </p>
      <p>
        The literature [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] reports how the Business Process Management (BPM)
usually operates at two main distinct levels, corresponding, respectively, to a
management level, supporting business organizations in optimizing their
operational processes, and a technology level, supporting IT users in process modeling
and execution.
      </p>
      <p>
        In these two levels, experts operate without a systematic interaction and
cooperation, causing the well known problem of Business/IT alignment. In fact,
one key problem is the alignment of di erent tools and methods used by the
two communities (business and IT experts). In order to reduce the gap between
these two levels, De Nicola and colleagues refer in [
        <xref ref-type="bibr" rid="ref11">11</xref>
        ] to semantic
technologies as an useful approach at supporting business process design, reengineering
and maintenance of the business process, by highlighting some advantages
related to the semantic lifting. The rst one regards the support that the semantic
lifting can give to business process design by a semantic alignment of a
business process respect to a reference ontology. The semantic alignment can be
achieved by performing consistency checking through the use of a reasoning
engine. Then, the reengineering of a business process (BP) can be improved by
providing suggestions to experts during the design phase of a BP, for example in
nding alternative elements with semantic search and similarity reasoning over
the business ontology. The authors also indicate, as another advantage, the
possibility to support a BP maintenance by automatically checking the alignment
between one of more business processes against the business ontology when the
latter is modi ed. This can provide strong bene ts since, for instance, a change
in the company organization, could a ect many business processes that need to
be manually checked.
3
      </p>
    </sec>
    <sec id="sec-3">
      <title>RDF to model Business Processes</title>
      <p>
        Generally speaking, the Resource Description Framework (RDF) [
        <xref ref-type="bibr" rid="ref7">7</xref>
        ] corresponds
to a standard vocabulary de nition, which is at the basis of the Semantic Web
vision, and it is composed by three elements: concepts, relations between concepts
and attributes of concepts. These elements are modeled as a labelled oriented
graph [
        <xref ref-type="bibr" rid="ref6">6</xref>
        ], de ned by a set of triples &lt; s; p; o &gt; where s is subject, p is predicate
and o is object, combined as shown in Figure 1.
      </p>
      <p>New information is inserted into an RDF graph by adding new triples to the
set. It is therefore easy to understand why such a representation can provide big
bene ts for real time business process analysis: data can be appended `on the
y' to the existing one, and it will become part of the graph, available for any
analytical application, without the need for recon guration or any other data
preparation steps.</p>
      <p>
        RDF standard vocabularies allow external applications to query data through
SPARQL query language [
        <xref ref-type="bibr" rid="ref12">12</xref>
        ]. SPARQL is a standard query language for RDF
graphs based on conjunctive queries on triple patterns, identifying paths in the
RDF graph. Thus, queries can be seen as graph views. SPARQL is supported
by most of the triples stores available.
      </p>
      <p>Moreover, RDF provides a basic set of semantics that is used to de ne
concepts, sub-concepts, relations, attributes, and can be extended easily with any
domain-speci c information. For this reason, it is an extremely generic data
representation model that can be used in any domain.</p>
      <p>
        In [
        <xref ref-type="bibr" rid="ref10">10</xref>
        ], the authors present a framework based on RDF for business
process monitoring and analysis. They de ne an RDF model to represent a generic
business process that can be easily extended in order to describe any speci c
business process by only extending the RDF vocabulary and adding new triples
to the triple store. The model is used as a reference by both monitoring
applications (i.e., applications producing the data to be analyzed) and analyzing
tools. On one side, a process monitor creates and maintains the extension of the
generic business process vocabulary either at start time, if the process is known
a priori, or at runtime while capturing process execution data, if the process
is not known. Process execution data is then saved as triples with respect to
the extended model. On the other side, the analyzing tools may send SPARQL
queries to the continuously updated process execution RDF graph.
      </p>
      <p>Figure 2 shows the conceptual model of a generic business process, seen as
a sequence of di erent tasks, each having a start/end time and possibly having
zero or more sub-tasks. We will use this model to describe our running example.
4</p>
    </sec>
    <sec id="sec-4">
      <title>Case study: a Data Loss Prevention System</title>
      <p>Data loss is an error condition in information systems in which information is
destroyed by failures or neglect in storage, transmission, or processing. Consider
for example some di erent companies belonging to the same manufacturing
supply chain and sharing business process critical data by using a le sharing server
in order to access to the data. This scenario could expose the critical data to
malicious users if access control is not implemented correctly. Indeed, an access
control to such a server should be carried out by a security model, based on
speci c rules considering, for example, the user authentication for le sharing,
security policies de nition for users that have access rights to some con
dential data, data checking before sending them to external companies that do not
belong to the manufacturing supply chain considered, usage of authorized
channels for data delivery, like company's e-mail, and so on. In order to prevent
any kind of data loss, systems usually develop an intellectual ownership defense,
also called data-loss model, tracking any action operated on a document. The
process is able to highlight some security-related information, such as the
economical value assigned to the outgoing intellectual ownership, or the number of
`con dential' data sent around, possibly to external destinations.</p>
      <p>Protecting the con dentiality of information stored in a computer system, or
transmitted over a public network is a relevant problem in computer security,
called information leakage. The approach of information ow analysis involves
performing a static analysis of the program with the aim of proving that there
will not be leaks of sensitive information. The starting point in secure information
ow analysis is the classi cation of program variables into di erent security levels
(i.e., de ning a multi-level security policy). In the simplest case, two levels are
used: public (or low, L) and secret (or high, H). There is an information ow
from object x to object y whenever the information stored in x is transferred to,
or used to derive information transferred to, object y. The main purpose is to
prevent leak of sensitive information from an high variable to a lower one.</p>
      <p>In our case study, we will consider the two security levels generated by the
organizational boundaries (internal/external).
4.1</p>
      <sec id="sec-4-1">
        <title>An RDF Model of the Data Loss case study</title>
        <p>
          Our RDF model representation of the Data Loss case study is based on the
lightweight RDF data model for business processes analysis carried out in [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ]
and brie y described in Section 3. As previously pointed out, the model does
not contain any data, but it only provides a generic schema that the process
monitoring applications extend and instantiate. The Data Loss RDF model is
then de ned as an extension of the general schema and is depicted in Figure 3:
it consists of the conceptual model of Figure 2 extended with domain speci c
concepts taken from the Data loss problem scenario. In particular, in our
running example, we assume that the les shared between the companies in the
same manufacturing chain are CAD les, thus the business process is named
`pCAD:CAD Process'.
        </p>
        <p>The main task is `pCAD:UseFile', which creates a data le (`pCAD:File'),
that can be used by a project manager (`pCAD:Employee'), which is an employee
of one of the companies. All the concepts labeled `dLoss' are the one which
specify the security model to prevent Data Loss. The subclass called `dLOSS:File'
is assigned several attributes: the security level (`dLoss:Con dentialFile'), and
the economic value (`dLOSS:economicValue'), in order to be able to check
information leakage or to compute the economical loss of the outgoing intellectual
ownership. The destination of an operation on a le (`dLOSS:Destination') has
three main attributes: `dLOSS:InternalNetwork', `dLOSS:ValueNetworkActor'
and `dLOSS:ExternalActor', the last specifying if the le has been shared with
a user within the organizational boundaries or not.</p>
        <p>
          As reported in Section 3, the usage of a framework based on an RDF triple
store like [
          <xref ref-type="bibr" rid="ref10">10</xref>
          ] is speci cally designed for integrating multiple source and
supporting fast and continuous execution of SPARQL queries favouring the join between
the execution processes and the monitoring.
4.2
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>Semantic Lifting for Mining a Data Loss Process</title>
        <p>
          In this section, we show how an appropriate semantic lifting may help during
the process mining phase. Process mining is the technique of distilling a
structured process description from a set of real executions. To the sake of discussion,
we limit our example to process mining algorithms that are based on detecting
ordering relations among events to characterize a work ow execution log [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ]. In
particular, they build dependency/frequencies tables that are used to compare
single executions in order to induce a reference model, or to verify the satis
ability of speci c conditions on the order of executions of events. We assume
that the reader is familiar with the following de nitions that are common in this
scenario [
          <xref ref-type="bibr" rid="ref2">2</xref>
          ].
        </p>
        <p>Work ow trace. Let E = fe1; e2; ; eng be a set of events, then t 2 E
is a work ow (execution) trace.</p>
        <p>Work ow log. Let E = fe1; e2; ; eng be a set of events, then W E is
a work ow log.</p>
        <p>Successor. Let W be a work ow log over E and a; b 2 E be two events,
then b is a successor of a (notation a W b) if and only if there is a trace t 2 W
such that t = fe1; e2; ; eng with ei a and ei+1 b. Similarly, we use the
notation a nW b to express that event b is successor of event a by n steps (i.e.,
ei a and ei+k b, with 1 &lt; k n).</p>
        <p>
          Notice that the successor relationship is rich enough to reveal many
workow properties since we can construct dependency/frequency tables that allow
to verify the relations that constraint a set of log traces. However, in order to
better characterize the signi cance of dependency between events, other
measures, based on information theory, are adopted in the literature, such as for
instance the J-Measure proposed by Smyth and Goodman [
          <xref ref-type="bibr" rid="ref13">13</xref>
          ], able to quantify
the information content of a rule.
        </p>
        <p>Table 1 shows a fragment of a work ow log possibly generated by a data loss
prevention system tracking in-use actions based on the RDF model described
in the previous section. The system reports all the events that generated a new
status of a speci c document. In particular, we assume that for each event it is
speci ed: (i) the type of event (Create, Update, Share, Remove); (ii) the user
performing the action on the le expressed by the email address; (iii) the
timestamp spotlighting the end point (a system user, in our case) that achieved the
control on the document at the end of the event which allow us to
chronologically order the events; and (iv) the estimated value of the le (in the range:
Low, Medium, High).</p>
        <p>
          Following the approach in [
          <xref ref-type="bibr" rid="ref14">14</xref>
          ], we construct the dependency/frequency (D/F)
table from the data log illustrated in Table 1. More in detail, the information
contained in Table 2, are:
{ the overall frequency of event a (notation #a);
{ the frequency of event a followed by event Create (C for short);
{ the frequency of event a followed by event Update (U for short) by 1, 2 and
3 steps;
{ the frequency of event a followed by event Share (S for short) by 1, 2 and 3
steps.
High
Medium
Medium
        </p>
        <p>Using this table we can observe that the following patterns hold in W :
Create W U pdate or Create W Share, that is, a le is always created before
being updated or shared.</p>
        <p>Since a `data-loss model' is typically aimed at detecting anomalous
behaviors, the expected behavior in the form of unwanted behaviors (black-listing)
or wanted behavior (white-listing) needs to be de ned. This can be done by
identifying behavioral patterns over the sequences of events that are normally
registered in the work ow logs. We may, for instance, be interested in mining
expected behavior for documents shared within and outside the boundaries of
the organization. Still focusing our attention on the Share events which might
cause unwanted information ows, we might be interested to see which are the
users that most frequently share the documents with other users either inside or
outside the boundaries. To this aim, a semantic lifting procedure can be applied
to the log data for remodeling the representation of the process and allowing
additional investigations.</p>
        <p>
          A rst semantic lifting can be done by applying the Data Loss model
described in the previous section to our log, in order to distinguish among events
where les are shared internally or externally to the organization. In our example,
the lifting can be done by exploiting two data transformations rules expressed
according to Equation 1. Data are then mapped to the model using standard
techniques for mapping RDF data [
          <xref ref-type="bibr" rid="ref8">8</xref>
          ].
        </p>
        <p>U serk [A</p>
        <p>Z0
[A</p>
        <p>Z0</p>
        <p>9 : ] + @staf f + : [A
! dLOSS : Internal
9 : ] + @inc + : [A
! dLOSS : External</p>
        <p>Z] f2; 4g
Z] f2; 4g
(1)</p>
        <p>After applying the semantic lifting to the log, we are able to build and ll
Table 3, where a Share event is rewritten as `Share Internal' when the Share event is
performed by an Internal user, otherwise the event is rewritten as a `Share
External' event. In this new dependences/frequencies among events, we observe that
a new pattern holds: ShareInternal W ShareInternal W ShareExternal.
Informally, we can interpret this pattern in the execution traces as the identi
cation of an expected behavior about document sharing: before a document is
shared externally to the organization it has to pass some (typically two) internal
steps.</p>
        <p>Another semantic lifting can be done by grouping together all the Share log
events performed by the same user. Please notice that, as described in detail in
Section 3, RDF allows to easily aggregate data by considering their shared
properties. Moreover, SPARQL queries allow us to manipulate data to view them
in the appropriate structural order, by de ning, for example, events that are
grouped and aggregated by di erent attributes. Table 4 reports the
frequencies of these events, referring to an event Share with userV@staff.org as SV,
Share with userA@staff.org as SA, and so on.</p>
        <p>
          We can observe that the table is sparse, therefore few patterns can be proved
to hold in W . In our example, for instance, we can derive that in only one case
SA 2W SM , meaning that User userA@staff.org shares a document before
the same document is shared by User userM@staff.org. We can also derive
that User userM@staff.org is always the last to share the document, possibly
meaning that he is at the bottom of the organization hierarchy or that he is an
untrusted user (thing that is supported by the fact that it is an external user).
Given the low frequency of both cases, the two conclusions we drew are not
particularly relevant since they are not supported by a large number of traces.
The sparsity of the table is typical of so called `spaghetti-like processes', i.e.,
unstructured processes where recurrent event sequences are not so easily de ned
[
          <xref ref-type="bibr" rid="ref1">1</xref>
          ]. In this case, a semantic lifting procedure could be applied to the log data
for remodeling the representation of the process and implementing additional
investigations.
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Conclusion</title>
      <p>In this paper we showed how standard process mining techniques can be
combined with semantic lifting procedures on the work ow logs in order to discover
more precise work ow models from event-based data. Moreover, we highlighted
the bene ts using RDF as a modeling formalism by using it in our case study.
This is just a rst step to show the feasibility and the advantages of the
approach. As a future work we plan to study how to automatize the process by
exploiting the usage of RDF as a modeling language.</p>
    </sec>
    <sec id="sec-6">
      <title>Acknowledgment</title>
      <p>This work was partly funded by the Italian Ministry of Economic Development
under the Industria 2015 contract - KITE.IT project.</p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          1.
          <string-name>
            <surname>Van der Aalst</surname>
            ,
            <given-names>W.M.P.</given-names>
          </string-name>
          :
          <article-title>Process mining: Discovering and improving spaghetti and lasagna processes</article-title>
          .
          <source>Keynote Lecture, IEEE Symposium Series on Computational Intelligence (SSCI</source>
          <year>2011</year>
          )
          <article-title>/IEEE Symposium on Computational Intelligence and Data Mining (CIDM</article-title>
          <year>2011</year>
          ) (
          <year>April 2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          2.
          <string-name>
            <surname>Van der Aalst</surname>
          </string-name>
          , W.M.P.,
          <string-name>
            <surname>van Dongen</surname>
            ,
            <given-names>B.F.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Herbst</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Maruster</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Schimm</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Weijters</surname>
            ,
            <given-names>A.J.M.M.:</given-names>
          </string-name>
          <article-title>Work ow mining: a survey of issues and approaches</article-title>
          .
          <source>Data Knowl. Eng</source>
          .
          <volume>47</volume>
          (
          <issue>2</issue>
          ),
          <volume>237</volume>
          {267 (Nov
          <year>2003</year>
          ), http://dx.doi.org/10.1016/
          <fpage>S0169</fpage>
          - 023X(
          <issue>03</issue>
          )
          <fpage>00066</fpage>
          -
          <lpage>1</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          3.
          <string-name>
            <surname>Azzini</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Ceravolo</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Consistent process mining over big data triple stores</article-title>
          .
          <source>In: Proceedings of the IEEE International Conference on Big Data</source>
          . p. to appear. IEEE Publisher, June 27-July 2,
          <year>2013</year>
          , Santa Clara Marriott, CA, USA (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          4.
          <string-name>
            <surname>Baier</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mendling</surname>
          </string-name>
          , J.:
          <article-title>Bridging abstraction layers in process mining by automated matching of events and activities</article-title>
          . In: Daniel,
          <string-name>
            <given-names>F.</given-names>
            ,
            <surname>Wang</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            ,
            <surname>Weber</surname>
          </string-name>
          ,
          <string-name>
            <surname>B</surname>
          </string-name>
          . (eds.)
          <source>Business Process Management, Lecture Notes in Computer Science</source>
          , vol.
          <volume>8094</volume>
          , pp.
          <volume>17</volume>
          {
          <fpage>32</fpage>
          . Springer Berlin Heidelberg (
          <year>2013</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          5.
          <string-name>
            <surname>Buijs</surname>
          </string-name>
          , J.:
          <article-title>Mapping data sources to xes in a generic way, master's thesis (</article-title>
          <year>2010</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          6.
          <string-name>
            <surname>Carroll</surname>
            ,
            <given-names>J.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Bizer</surname>
            ,
            <given-names>C.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Hayes</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Stickler</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          :
          <article-title>Named graphs</article-title>
          .
          <source>Journal of Web Semantics</source>
          <volume>3</volume>
          (
          <issue>3</issue>
          ) (
          <year>2005</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          7.
          <string-name>
            <surname>Hayes</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McBride</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          :
          <article-title>Resource description framework (rdf) (</article-title>
          <year>2004</year>
          ), http://www.w3.org/
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          8.
          <string-name>
            <surname>Hert</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Reif</surname>
            ,
            <given-names>G.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Gall</surname>
          </string-name>
          , H.C.
          <article-title>: A comparison of rdb-to-rdf mapping languages</article-title>
          .
          <source>In: Proceedings of the 7th International Conference on Semantic Systems</source>
          . pp.
          <volume>25</volume>
          {
          <fpage>32</fpage>
          . I-Semantics '
          <fpage>11</fpage>
          ,
          <string-name>
            <surname>ACM</surname>
          </string-name>
          , New York, NY, USA (
          <year>2011</year>
          ), http://doi.acm.
          <source>org/10</source>
          .1145/2063518.2063522
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          9.
          <string-name>
            <surname>Kehrer</surname>
            ,
            <given-names>T.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Kelter</surname>
            ,
            <given-names>U.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Taentzer</surname>
          </string-name>
          , G.:
          <article-title>A rule-based approach to the semantic lifting of model di erences in the context of model versioning</article-title>
          .
          <source>In: Automated Software Engineering (ASE)</source>
          ,
          <year>2011</year>
          26th IEEE/ACM International Conference on. pp.
          <volume>163</volume>
          {
          <issue>172</issue>
          (
          <year>2011</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          10.
          <string-name>
            <surname>Leida</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Majeed</surname>
            ,
            <given-names>B.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Colombo</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Chu</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Lightweight rdf data model for business processes analysis</article-title>
          .
          <source>Data-Driven Process Discovery and Analysis</source>
          ,
          <source>Series: Lecture Notes in Business Information Processing</source>
          <volume>116</volume>
          (
          <year>2012</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          11.
          <string-name>
            <surname>Nicola</surname>
            ,
            <given-names>A.D.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Mascio</surname>
          </string-name>
          , T.D.,
          <string-name>
            <surname>Lezoche</surname>
            ,
            <given-names>M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Tagliano</surname>
            ,
            <given-names>F.</given-names>
          </string-name>
          :
          <article-title>Semantic lifting of business process models</article-title>
          .
          <source>2012 IEEE 16th International Enterprise Distributed Object Computing Conference Workshops</source>
          <volume>0</volume>
          ,
          <issue>120</issue>
          {
          <fpage>126</fpage>
          (
          <year>2008</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          12.
          <string-name>
            <surname>Prudhommeaux</surname>
            ,
            <given-names>E.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Seaborne</surname>
            ,
            <given-names>A.</given-names>
          </string-name>
          :
          <article-title>Sparql query language for rdf (</article-title>
          <year>2008</year>
          ), http://www.w3.org/
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          13.
          <string-name>
            <surname>Smyth</surname>
            ,
            <given-names>P.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Goodman</surname>
            ,
            <given-names>R.M.:</given-names>
          </string-name>
          <article-title>Rule induction using information theory</article-title>
          .
          <source>Knowledge discovery in databases 1991</source>
          (
          <year>1991</year>
          )
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          14.
          <string-name>
            <surname>Van Der Aalst</surname>
            , W., Van Hee,
            <given-names>K.</given-names>
          </string-name>
          :
          <article-title>Work ow management: models, methods, and systems</article-title>
          . MIT press (
          <year>2004</year>
          )
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>