{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,18]],"date-time":"2026-07-18T18:36:29Z","timestamp":1784399789580,"version":"3.55.0"},"publisher-location":"Cham","reference-count":14,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030008277","type":"print"},{"value":"9783030008284","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-030-00828-4_43","type":"book-chapter","created":{"date-parts":[[2018,9,25]],"date-time":"2018-09-25T17:19:35Z","timestamp":1537895975000},"page":"421-429","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":20,"title":["An Insider Threat Detection Method Based on User Behavior Analysis"],"prefix":"10.1007","author":[{"given":"Wei","family":"Jiang","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yuan","family":"Tian","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Weixin","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Wenmao","family":"Liu","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2018,9,26]]},"reference":[{"key":"43_CR1","unstructured":"Pannell, G., Ashman, H.: Anomaly detection over user profiles for intrusion detection. University of South Australia (2012)"},{"issue":"2","key":"43_CR2","first-page":"319","volume":"26","author":"L Xuan","year":"2009","unstructured":"Xuan, L., Zhang, F., Ye, L.: User behavior mining algorithm design based on NetFlow. Comput. Appl. Res. 26(2), 319\u2013321 (2009)","journal-title":"Comput. Appl. Res."},{"issue":"3","key":"43_CR3","first-page":"325","volume":"25","author":"Y Lian","year":"2002","unstructured":"Lian, Y., Dai, Y., Wang, H.: User behavior anomaly detection based on pattern mining. J. Comput. Sci. 25(3), 325\u2013330 (2002)","journal-title":"J. Comput. Sci."},{"issue":"7","key":"43_CR4","first-page":"168","volume":"25","author":"L Wang","year":"2004","unstructured":"Wang, L., An, N., Wu, X., Fang, D.: Behavior pattern mining in intrusion detection system. J. Commun. 25(7), 168\u2013175 (2004)","journal-title":"J. Commun."},{"issue":"3","key":"43_CR5","doi-asserted-by":"publisher","first-page":"919","DOI":"10.1016\/j.eswa.2013.08.022","volume":"41","author":"JB Camina","year":"2014","unstructured":"Camina, J.B., Hernandez-Gracidas, C., Monroy, R., Trejo, L.: The windows-users and-intruder simulations logs dataset (WUIL): an experimental framework for masquerade detection mechanisms. Expert Syst. Appl. 41(3), 919\u2013930 (2014)","journal-title":"Expert Syst. Appl."},{"key":"43_CR6","doi-asserted-by":"crossref","unstructured":"Gamachchi, A., Boztas, S.: Insider threat detection through attributed graph clustering. In: Trustcom\/BigDataSE\/ICESS, pp. 112\u2013119 (2017)","DOI":"10.1109\/Trustcom\/BigDataSE\/ICESS.2017.227"},{"key":"43_CR7","doi-asserted-by":"crossref","unstructured":"Kandias, M., Stavrou, V., Bozovic, N., Mitrou, L., Gritzalis, D.: Can we trust this user? predicting insider\u2019s attitude via youtube usage profiling. In: 2013 IEEE 10th International Conference on Ubiquitous Intelligence and Computing and 10th International Conference on Autonomic and Trusted Computing (UIC\/ATC), pp. 347\u2013354. IEEE (2013)","DOI":"10.1109\/UIC-ATC.2013.12"},{"issue":"6","key":"43_CR8","doi-asserted-by":"publisher","first-page":"22","DOI":"10.1109\/MSP.2009.109","volume":"7","author":"BM Bowen","year":"2009","unstructured":"Bowen, B.M., Ben Salem, M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Designing host and network sensors to mitigate the insider threat. IEEE Secur. Priv. 7(6), 22\u201329 (2009)","journal-title":"IEEE Secur. Priv."},{"key":"43_CR9","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/978-3-540-74320-0_8","volume-title":"Recent Advances in Intrusion Detection","author":"MA Maloof","year":"2007","unstructured":"Maloof, M.A., Stephens, G.D.: elicit: A system for detecting insiders who violate need-to-know. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 146\u2013166. Springer, Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-74320-0_8"},{"issue":"1","key":"43_CR10","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1080\/19361610.2011.529413","volume":"6","author":"W Eberle","year":"2010","unstructured":"Eberle, W., Graves, J., Holder, L.: Insider threat detection using a graph-based approach. J. Appl. Secur. Res. 6(1), 32\u201381 (2010)","journal-title":"J. Appl. Secur. Res."},{"key":"43_CR11","doi-asserted-by":"crossref","unstructured":"Myers, J., Grimaila, M.R., Mills, R.F.: Towards insider threat detection using web server logs. In: Proceedings of the 5th Annual Workshop on Cyber Security and Information Intelligence Research: Cyber Security and Information Intelligence Challenges and Strategies, pp. 54:1\u201354:4. ACM, New York (2009)","DOI":"10.1145\/1558607.1558670"},{"key":"43_CR12","doi-asserted-by":"crossref","unstructured":"Eldardiry, H., Bart, E., Liu, J., Hanley, J., Price, B., Brdiczka, O.: Multi-domain information fusion for insider threat detection. In: 2013 IEEE on Security and Privacy Workshops (SPW) (2013)","DOI":"10.1109\/SPW.2013.14"},{"key":"43_CR13","doi-asserted-by":"crossref","unstructured":"Andropov, S., Guirik, A., Budko, M.: Network: Anomaly detection using artificial neural networks. Open Innovations Association, pp. 26\u201331 (2017)","DOI":"10.23919\/FRUCT.2017.8071288"},{"key":"43_CR14","doi-asserted-by":"crossref","unstructured":"Rashid, T., Agrafiotis, I., Nurse, J.R.C.: A new take on detecting insider threats: exploring the use of hidden Markov models. In: International Workshop on Managing Insider Security Threats, pp. 47\u201356 (2016)","DOI":"10.1145\/2995959.2995964"}],"container-title":["IFIP Advances in Information and Communication Technology","Intelligent Information Processing IX"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-00828-4_43","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,10,10]],"date-time":"2022-10-10T00:07:42Z","timestamp":1665360462000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-00828-4_43"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783030008277","9783030008284"],"references-count":14,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-00828-4_43","relation":{},"ISSN":["1868-4238","1868-422X"],"issn-type":[{"value":"1868-4238","type":"print"},{"value":"1868-422X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]},"assertion":[{"value":"26 September 2018","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"IIP","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Intelligent Information Processing","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Nanning","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2018","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 October 2018","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22 October 2018","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"10","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"iip2018","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/www.intsci.ac.cn\/iip2018\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}