{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,23]],"date-time":"2026-07-23T15:46:33Z","timestamp":1784821593690,"version":"3.55.0"},"publisher-location":"Boston, MA","reference-count":40,"publisher":"Springer US","isbn-type":[{"value":"9781441971326","type":"print"},{"value":"9781441971333","type":"electronic"}],"license":[{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2010,1,1]],"date-time":"2010-01-01T00:00:00Z","timestamp":1262304000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2010]]},"DOI":"10.1007\/978-1-4419-7133-3_5","type":"book-chapter","created":{"date-parts":[[2010,7,27]],"date-time":"2010-07-27T18:09:37Z","timestamp":1280254177000},"page":"85-113","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":90,"title":["Combining Traditional Cyber Security Audit Data with Psychosocial Data: Towards Predictive Modeling for Insider Threat Mitigation"],"prefix":"10.1007","author":[{"given":"Frank L.","family":"Greitzer","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Deborah A.","family":"Frincke","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2010,7,28]]},"reference":[{"key":"5_CR1","doi-asserted-by":"crossref","unstructured":"Aleman-Meza, B., Burns, P., Eavenson, M., Palaniswami, D., Sheth, A.P.: An ontological approach to the document access problem of insider threat. In: Proceedigs of the IEEE International Conference on Intelligence and Security Informatics (ISI 2005), pp. 486\u2013491 (2005)","DOI":"10.1007\/11427995_47"},{"key":"5_CR2","volume-title":"Comparing insider IT sabotage and espionage: A model-based analysis. Tech. rep","author":"S.R. Band","year":"2006","unstructured":"Band, S.R., Cappelli, D., Fischer, L.F., Moore, A.P., Shaw, E.D., Trzeciak, R.F.: Comparing insider IT sabotage and espionage: A model-based analysis. Tech. rep., Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania, U.S.A. (2006)"},{"key":"5_CR3","doi-asserted-by":"crossref","unstructured":"Barbosa, R., Silva, N., Duraes, J., Madeira, H.: Verification and validation of (real time) COTS products using fault injection techniques. In: Proceedings of the Sixth International IEEE Conference on Commercial-off-the-Shelf (COTS)-Based Software Systems (ICCBSS \u201907), pp. 233\u2013242. IEEE Computer Society, Washington, DC, USA (2007)","DOI":"10.1109\/ICCBSS.2007.45"},{"issue":"11","key":"5_CR4","doi-asserted-by":"publisher","first-page":"1237","DOI":"10.1007\/BF00412822","volume":"15","author":"W.S. Brown","year":"1996","unstructured":"Brown, W.S.: Technology, workplace privacy and personhood. Journal of Business Ethics 15(11), 1237\u20131248 (1996)","journal-title":"Journal of Business Ethics"},{"key":"5_CR5","doi-asserted-by":"crossref","unstructured":"Butts, J.W., Mills, R.F., Baldwin, R.O.: Developing an insider threat model using functional decomposition. In: Proceedings of the Third International Workshop on Mathematical Methods, Models, and Architectures for Computer Network Security (MMM-ACNS 2005), pp. 412\u2013417 (2005)","DOI":"10.1007\/11560326_32"},{"key":"5_CR6","volume-title":"Management and education of the risk of insider threat (MERIT): Mitigating the risk of sabotage to employers? information, systems, or networks. Tech. rep.","author":"D.M. Cappelli","year":"2006","unstructured":"Cappelli, D.M., Desai, A.G., Moore, A.P., Shimeall, T.J., Weaver, E.A., Willke, B.J.: Management and education of the risk of insider threat (MERIT): Mitigating the risk of sabotage to employers? information, systems, or networks. Tech. rep., Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2006)"},{"key":"5_CR7","volume-title":"Common sense guide to prevention and detection of insider threats. Tech. rep.","author":"D.M. Cappelli","year":"2009","unstructured":"Cappelli, D.M., Moore, A.P., Trzeciak, R.F., Shimeall, T.J.: Common sense guide to prevention and detection of insider threats. Tech. rep., Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2009). 3rd edition, version 301. Available at http: \/\/www.cert.org\/archive\/pdf\/CSG-V3.pdf."},{"key":"5_CR8","doi-asserted-by":"crossref","unstructured":"Chinchani, R., Iyer, A., Ngo, H.Q., Upadhyaya, S.J.: Towards a theory of insider threat assessment. In: Proceedings of The International Conference on Dependable Systems and Networks (DSN 2005), pp. 108\u2013117 (2005)","DOI":"10.1109\/DSN.2005.94"},{"key":"5_CR9","unstructured":"Costa, P.C.G., Laskey, K.B., Revankar, M., Mirza, S., Alghamdi, G., Barbar, D., Shakelford, T., Wright, E.J.: DTB project: A behavioral model for detecting insider threats. In: Proceedings of the 2005 International Conference on Intelligence Analysis. The Mitre Corporation (2005)"},{"key":"5_CR10","volume-title":"Characterizing motion in video streams using supple knowledge. Tech. Rep. PNNL-16518","author":"P.J. Doucette","year":"2007","unstructured":"Doucette, P.J., Harvey, W.J., Hohimer, R.E., Martucci, L.M., Paulson, P.R., Petrie, G.M., Pike, B.A., Seedahmed, G.H.: Characterizing motion in video streams using supple knowledge. Tech. Rep. PNNL-16518, Pacific Northwest National Laboratory, Richland, Washington (2007)"},{"key":"5_CR11","volume-title":"The insider threat to information systems. State-of-the-art report. Tech. rep","author":"B. Gabrielson","year":"2008","unstructured":"Gabrielson, B., Goertzel, K.M., Hoenicke, B., Kleiner, D., Winograd, T.: The insider threat to information systems. State-of-the-art report. Tech. rep., Information Assurance Technology Analysis Center, Herndon, Virginia (2008)"},{"key":"5_CR12","volume-title":"Exploring the mind of the spy. In: Employees\u2019 Guide to Security Responsibilities","author":"M. Gelles","year":"2005","unstructured":"Gelles, M.: Exploring the mind of the spy. In: Employees\u2019 Guide to Security Responsibilities. Texas A&M University Research Foundation, College Station, Texas (2005)"},{"key":"5_CR13","unstructured":"Greitzer, F.L., Frincke, D.A., Zabriskie, M.M.: Social\/ethical issues in predictive insider threat monitoring. In: M.J. Dark (ed.) Information Assurance and Security Ethics in Complex Systems: Interdisciplinary Perspectives. IGI Global, Hershey, Pennsylvania (in press)"},{"key":"5_CR14","doi-asserted-by":"publisher","first-page":"61","DOI":"10.1109\/MSP.2008.8","volume":"6","author":"F.L. Greitzer","year":"2008","unstructured":"Greitzer, F.L., Moore, A.P., Cappelli, D.M., Andrews, D.H., Carroll, L.A., Hull, T.D.: Combating the insider cyber threat. IEEE Security and Privacy 6, 61\u201364 (2008)","journal-title":"IEEE Security and Privacy"},{"key":"5_CR15","volume-title":"Predictive modeling for insider threat mitigation. Tech. Rep. PNNL-SA-60737","author":"F.L. Greitzer","year":"2008","unstructured":"Greitzer, F.L., Paulson, P.R., Kangas, L.J., Edgar, T., Zabriskie, M.M., Franklin, L.R., Frincke, D.A.: Predictive modeling for insider threat mitigation. Tech. Rep. PNNL-SA-60737, Pacific Northwest National Laboratory, Richland, Washington (2008)"},{"key":"5_CR16","unstructured":"Infosec Research Council: Hard problem list (2005). Available from http:\/\/www. infosec - research.org\/docs_public\/2 0 05113 0- IRC-HPL-FINAL.pdf. Accessed January 11, 2010."},{"key":"5_CR17","volume-title":"Insider threat study: Computer system sabotage in critical infrastructure sectors. Tech. rep.","author":"M. Keeney","year":"2005","unstructured":"Keeney, M., Kowalski, E., Cappelli, D.M., Moore, A.P., Shimeall, T.J., Rogers, S.: Insider threat study: Computer system sabotage in critical infrastructure sectors. Tech. rep., U.S. Secret Service and CERT Coordination Center, Washington, D.C., Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2005). Available from http:\/\/ www.secretservice.gov\/ntac\/its%5Freport%5F050516.pdf. Accessed August 14, 2009"},{"key":"5_CR18","volume-title":"Technological, social, and economic trends that are increasing u.s. vulnerability to insider espionage. Tech. Rep. 05-10","author":"L.A. Kramer","year":"2005","unstructured":"Kramer, L.A., Jr., R.J.H., Crawford, K.S.: Technological, social, and economic trends that are increasing u.s. vulnerability to insider espionage. Tech. Rep. 05-10, Personnel Security Research Center (PERSEREC), Monterey, California (2005)"},{"key":"5_CR19","volume-title":"Behavioral Consultation in Personnel Security","author":"J.L. Krofcheck","year":"2005","unstructured":"Krofcheck, J.L., Gelles, M.G.: Behavioral Consultation in Personnel Security: Training and Reference Manual for Personnel Security Professionals. Yarrow Associates, Fairfax, Virginia (2005)"},{"key":"5_CR20","unstructured":"Lane, F.S.I.: The Naked Employee: How Technology is Compromising Workplace Privacy. American Management Association (AMACOM) (2003)"},{"issue":"1","key":"5_CR21","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1016\/S0167-4048(02)00109-8","volume":"21","author":"G.B. Magklaras","year":"2002","unstructured":"Magklaras, G.B., Furnell, S.M.: Insider threat prediction tool: Evaluating the probability of it misuse. Computers & Security 21(1), 62\u201373 (2002)","journal-title":"Computers & Security"},{"issue":"5","key":"5_CR22","doi-asserted-by":"publisher","first-page":"371","DOI":"10.1016\/j.cose.2004.10.003","volume":"24","author":"G.B. Magklaras","year":"2005","unstructured":"Magklaras, G.B., Furnell, S.M.: A preliminary model of end user sophistication for insider threat prediction in it systems. Computers & Security 24(5), 371\u2013380 (2005)","journal-title":"Computers & Security"},{"key":"5_CR23","unstructured":"Maybury, M., Chase, P., Cheikes, B., Brackney, D., Matzner, S., Hetherington, T., Wood, B., Sibley, C., Marin, J., Longstaff, T., Spitzner, L., Haile, J., Copeland, J., Lewandowski, S.: Analysis and detection of malicious insiders. In: Proceedings of the 2005 International Conference on Intelligence Analysis. The MITRE Corporation (2005)"},{"issue":"3","key":"5_CR24","doi-asserted-by":"publisher","first-page":"709","DOI":"10.2307\/258792","volume":"20","author":"R.C. Mayer","year":"1995","unstructured":"Mayer, R.C., Davis, J.H., Schoorman, F.D.: An integrative model of organizational trust. Academy of Management Review 20(3), 709\u2013734 (1995)","journal-title":"Academy of Management Review"},{"key":"5_CR25","doi-asserted-by":"crossref","DOI":"10.21236\/ADA482452","volume-title":"The \"big picture\" of insider it sabotage across u.s. critical infrastructures. Tech. rep","author":"A.P. Moore","year":"2008","unstructured":"Moore, A.P., Cappelli, D.M., Trzeciak, R.F.: The \"big picture\" of insider it sabotage across u.s. critical infrastructures. Tech. rep., Software Engineering Institute, Carnegie Mellon University, Pittsburgh, Pennsylvania (2008)"},{"key":"5_CR26","first-page":"5","volume-title":"The Description Logic Handbook: Theory, Implementation, and Applications","author":"D. Nardi","year":"2003","unstructured":"Nardi, D., Brachman, R.J.: An introduction to description logics. In: F. Baader, D. Calvanese, D.L. McGuinness, D. Nardi, P.F. Patel-Schnieder (eds.) The Description Logic Handbook: Theory, Implementation, and Applications, pp. 5\u201344. Cambridge University Press, Cambridge, United Kingdom (2003)"},{"key":"5_CR27","volume-title":"Fighting Computer Crime: A New Framework for Protecting Information","author":"D.B. Parker","year":"1998","unstructured":"Parker, D.B.: Fighting Computer Crime: A New Framework for Protecting Information. John Wiley & Sons, New York (1998)"},{"key":"5_CR28","volume-title":"Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference","author":"J. Pearl","year":"1988","unstructured":"Pearl, J.: Probabilistic Reasoning in Intelligent Systems: Networks of Plausible Inference. Morgan Kaufmann, San Francisco, California (1988)"},{"issue":"1","key":"5_CR29","doi-asserted-by":"publisher","first-page":"3","DOI":"10.1023\/A:1006133732667","volume":"22","author":"R.S Rosenberg","year":"1999","unstructured":"Rosenberg, R.S.: The workplace on the verge of the 21st century. Journal of Business Ethics 22(1), 3\u201314 (1999)","journal-title":"Journal of Business Ethics"},{"issue":"6","key":"5_CR30","doi-asserted-by":"publisher","first-page":"526","DOI":"10.1016\/S0167-4048(02)01009-X","volume":"21","author":"E.E. Schultz","year":"2002","unstructured":"Schultz, E.E.: A framework for understanding and predicting insider attacks. Computers & Security 21(6), 526\u2013531 (2002)","journal-title":"Computers & Security"},{"key":"5_CR31","volume-title":"Ten tales of betrayal: The threat to corporate infrastructure by information technology insiders analysis and observations. Tech. rep","author":"E.D. Shaw","year":"2005","unstructured":"Shaw, E.D., Fischer, L.F.: Ten tales of betrayal: The threat to corporate infrastructure by information technology insiders analysis and observations. Tech. rep., Personnel Security Research Center (PERSEREC), Monterey, California (2005). Available from http: \/\/handle.dtic.mil\/100.2\/ADA4 412 93. Accessed August 14, 2009."},{"key":"5_CR32","volume-title":"Nonparametric Statistics for the Behavioral Sciences","author":"S. Siegel","year":"1956","unstructured":"Siegel, S.: Nonparametric Statistics for the Behavioral Sciences. McGraw-Hill, New York (1956)"},{"issue":"3","key":"5_CR33","doi-asserted-by":"publisher","first-page":"173","DOI":"10.1007\/s10672-005-6940-z","volume":"17","author":"F. Tabak","year":"2005","unstructured":"Tabak, F., Smith, W.P.: Privacy and electronic monitoring in the workplace: A model of managerial cognition and relational trust development. Employee Responsibilities and Rights Journal 17(3), 173\u2013189 (2005)","journal-title":"Employee Responsibilities and Rights Journal"},{"key":"5_CR34","unstructured":"US-CERT\/CERT Coordination Center: 2004 e-crime watch survey\u2014summary of findings. Tech. rep., U.S. Secret Service and CERT Coordination Center, Washington, D.C. Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2004). Available from http:\/\/www.cert.org\/archive\/pdf\/ecrimesurvey05.pdf. Accessed January 11, 2010."},{"key":"5_CR35","unstructured":"US-CERT\/CERT Coordination Center: 2005 e-crime watch survey\u2014survey results. Tech. rep., U.S. Secret Service and CERT Coordination Center, Washington, D.C. Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2005). Available from http:\/\/ www.cert.org\/archive\/pdf\/ecrimesurvey06.pdf. Accessed January 11, 2010."},{"key":"5_CR36","volume-title":"Coordination Center: 2006 e-crime watch survey\u2014complete survey results. Tech. rep","author":"US-CERT\/CERT","year":"2006","unstructured":"US-CERT\/CERT Coordination Center: 2006 e-crime watch survey\u2014complete survey results. Tech. rep., U.S. Secret Service and CERT Coordination Center, Washington, D.C. Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2006). Available from http:\/\/www.cert.org\/archive\/pdf\/ecrimesurvey0 6.pdf. Accessed January 11, 2010."},{"key":"5_CR37","volume-title":"Coordination Center: 2007 e-crime watch survey\u2014complete survey results. Tech. rep","author":"US-CERT\/CERT","year":"2007","unstructured":"US-CERT\/CERT Coordination Center: 2007 e-crime watch survey\u2014complete survey results. Tech. rep., U.S. Secret Service and CERT Coordination Center, Washington, D.C. Carnegie Mellon Software Engineering Institute, Pittsburgh, Pennsylvania (2007). Available from http:\/\/www.cert.org\/archive\/pdf\/ecrimesurvey07.pdf. Accessed January 11, 2010."},{"key":"5_CR38","unstructured":"U.S. Department of Defense Office of the Inspector General (DoD): DoD management of information assurance efforts to protect automated information systems. Tech. Rep. 97-049, U.S. Department of Defense, Washington, D.C. (1997)"},{"key":"5_CR39","unstructured":"Wood, B.: An insider threat model for adversary simulation. In: Proceedings of the Research on Mitigating the Insider Threat on Information Systems. Arlington, Virginia (2000)"},{"issue":"3","key":"5_CR40","doi-asserted-by":"publisher","first-page":"338","DOI":"10.1016\/S0019-9958(65)90241-X","volume":"8","author":"L.A. Zadeh","year":"1965","unstructured":"Zadeh, L.A.: Fuzzy sets. Information Control 8(3), 338\u2013353 (1965)","journal-title":"Information Control"}],"container-title":["Advances in Information Security","Insider Threats in Cyber Security"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-1-4419-7133-3_5","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,2,23]],"date-time":"2025-02-23T12:17:59Z","timestamp":1740313079000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-1-4419-7133-3_5"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2010]]},"ISBN":["9781441971326","9781441971333"],"references-count":40,"URL":"https:\/\/doi.org\/10.1007\/978-1-4419-7133-3_5","relation":{},"ISSN":["1568-2633"],"issn-type":[{"value":"1568-2633","type":"print"}],"subject":[],"published":{"date-parts":[[2010]]},"assertion":[{"value":"28 July 2010","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}}]}}