{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,3]],"date-time":"2026-06-03T05:53:43Z","timestamp":1780466023245,"version":"3.54.1"},"publisher-location":"Cham","reference-count":37,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030369378","type":"print"},{"value":"9783030369385","type":"electronic"}],"license":[{"start":{"date-parts":[[2019,1,1]],"date-time":"2019-01-01T00:00:00Z","timestamp":1546300800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2019]]},"DOI":"10.1007\/978-3-030-36938-5_2","type":"book-chapter","created":{"date-parts":[[2019,12,9]],"date-time":"2019-12-09T19:04:11Z","timestamp":1575918251000},"page":"18-36","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":10,"title":["Unsupervised Insider Detection Through Neural Feature Learning and Model Optimisation"],"prefix":"10.1007","author":[{"given":"Liu","family":"Liu","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chao","family":"Chen","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Jun","family":"Zhang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Olivier","family":"De Vel","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yang","family":"Xiang","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2019,12,10]]},"reference":[{"key":"2_CR1","unstructured":"Abadi, M., et al.: TensorFlow: a system for large-scale machine learning. In: OSDI 2016, pp. 265\u2013283 (2016)"},{"issue":"2","key":"2_CR2","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1109\/JSYST.2016.2558507","volume":"11","author":"B B\u00f6se","year":"2017","unstructured":"B\u00f6se, B., Avasarala, B., Tirthapura, S., Chung, Y.Y., Steiner, D.: Detecting insider threats using radish: a system for real-time anomaly detection in heterogeneous data streams. IEEE Syst. J. 11(2), 471\u2013482 (2017)","journal-title":"IEEE Syst. J."},{"issue":"3","key":"2_CR3","doi-asserted-by":"publisher","first-page":"15","DOI":"10.1145\/1541880.1541882","volume":"41","author":"V Chandola","year":"2009","unstructured":"Chandola, V., Banerjee, A., Kumar, V.: Anomaly detection: a survey. ACM Comput. Surv. (CSUR) 41(3), 15 (2009)","journal-title":"ACM Comput. Surv. (CSUR)"},{"issue":"3","key":"2_CR4","doi-asserted-by":"publisher","first-page":"660","DOI":"10.1109\/TCSS.2018.2857473","volume":"5","author":"P Chattopadhyay","year":"2018","unstructured":"Chattopadhyay, P., Wang, L., Tan, Y.P.: Scenario-based insider threat detection from cyber activities. IEEE Trans. Comput. Soc. Syst. 5(3), 660\u2013675 (2018)","journal-title":"IEEE Trans. Comput. Soc. Syst."},{"key":"2_CR5","doi-asserted-by":"publisher","first-page":"987","DOI":"10.1109\/TIFS.2019.2932228","volume":"15","author":"Xiao Chen","year":"2020","unstructured":"Chen, X., et al.: Android HIV: a study of repackaging malware for evading machine-learning detection. IEEE Trans. Inf. Forensics Secur. 15(1), 987\u20131001 (2020)","journal-title":"IEEE Transactions on Information Forensics and Security"},{"key":"2_CR6","unstructured":"Chollet, F., et al.: Keras (2015). \nhttps:\/\/keras.io"},{"key":"2_CR7","unstructured":"Clearswift: clearswift insider threat index 2018 (2018). \nhttps:\/\/www.clearswift.com\/about-us\/pr\/press-releases\/cybersecurity-incidents-insider-threat-falls-uk-and-germany-post-gdpr\n\n. Accessed August 2019"},{"key":"2_CR8","unstructured":"Collins, M.: Common sense guide to mitigating insider threats. Technical report, Carnegie-Mellon University, Pittsburgh, PA, United States (2016)"},{"key":"2_CR9","doi-asserted-by":"publisher","unstructured":"Coulter, R., Han, Q.L., Pan, L., Zhang, J., Xiang, Y.: Data driven cyber security in perspective - intelligent traffic analysis. IEEE Trans. Cybern. \nhttps:\/\/doi.org\/10.1109\/TCYB.2019.2940940","DOI":"10.1109\/TCYB.2019.2940940"},{"key":"2_CR10","doi-asserted-by":"publisher","first-page":"439","DOI":"10.1016\/j.cose.2017.11.014","volume":"73","author":"R Coulter","year":"2018","unstructured":"Coulter, R., Pan, L.: Intelligent agents defending for an IoT world: a review. Comput. Secur. 73, 439\u2013458 (2018)","journal-title":"Comput. Secur."},{"key":"2_CR11","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"304","DOI":"10.1007\/978-3-030-30619-9_22","volume-title":"Machine Learning for Cyber Security","author":"R Coulter","year":"2019","unstructured":"Coulter, R., Pan, L., Zhang, J., Xiang, Y.: A visualization-based analysis on classifying Android malware. In: Chen, X., Huang, X., Zhang, J. (eds.) ML4CS 2019. LNCS, vol. 11806, pp. 304\u2013319. Springer, Cham (2019). \nhttps:\/\/doi.org\/10.1007\/978-3-030-30619-9_22"},{"issue":"1","key":"2_CR12","doi-asserted-by":"publisher","first-page":"143","DOI":"10.1145\/963770.963776","volume":"22","author":"M Deshpande","year":"2004","unstructured":"Deshpande, M., Karypis, G.: Item-based top-n recommendation algorithms. ACM Trans. Inf. Syst. (TOIS) 22(1), 143\u2013177 (2004)","journal-title":"ACM Trans. Inf. Syst. (TOIS)"},{"key":"2_CR13","doi-asserted-by":"crossref","unstructured":"Gao, X., Ichise, R.: Adjusting word embeddings by deep neural networks. In: ICAART (2), pp. 398\u2013406 (2017)","DOI":"10.5220\/0006120003980406"},{"key":"2_CR14","doi-asserted-by":"crossref","unstructured":"Glasser, J., Lindauer, B.: Bridging the gap: a pragmatic approach to generating insider threat data. In: 2013 IEEE Security and Privacy Workshops, pp. 98\u2013104. IEEE (2013)","DOI":"10.1109\/SPW.2013.37"},{"key":"2_CR15","volume-title":"Deep Learning","author":"I Goodfellow","year":"2016","unstructured":"Goodfellow, I., Bengio, Y., Courville, A., Bengio, Y.: Deep Learning, vol. 1. MIT Press, Cambridge (2016)"},{"key":"2_CR16","doi-asserted-by":"crossref","unstructured":"Haidar, D., Gaber, M.M.: Adaptive one-class ensemble-based anomaly detection: an application to insider threats. In: 2018 International Joint Conference on Neural Networks (IJCNN), pp. 1\u20139. IEEE (2018)","DOI":"10.1109\/IJCNN.2018.8489107"},{"key":"2_CR17","doi-asserted-by":"crossref","unstructured":"Hanley, M., Montelibano, J.: Insider threat control: using centralized logging to detect data exfiltration near insider termination. Technical report, Software Engineering Institute, Carnegie-Mellon University, Pittsburgh, PA (2011)","DOI":"10.21236\/ADA610463"},{"issue":"1","key":"2_CR18","doi-asserted-by":"publisher","first-page":"465","DOI":"10.1109\/COMST.2016.2615098","volume":"19","author":"J Jiang","year":"2017","unstructured":"Jiang, J., Wen, S., Yu, S., Xiang, Y., Zhou, W.: Identifying propagation sources in networks: state-of-the-art and comparative studies. IEEE Commun. Surv. Tutor. 19(1), 465\u2013481 (2017)","journal-title":"IEEE Commun. Surv. Tutor."},{"issue":"3\u20134","key":"2_CR19","doi-asserted-by":"publisher","first-page":"237","DOI":"10.1007\/s007780050006","volume":"8","author":"EM Knorr","year":"2000","unstructured":"Knorr, E.M., Ng, R.T., Tucakov, V.: Distance-based outliers: algorithms and applications. VLDB J.-Int. J. Very Large Data Bases 8(3\u20134), 237\u2013253 (2000)","journal-title":"VLDB J.-Int. J. Very Large Data Bases"},{"issue":"2","key":"2_CR20","first-page":"80","volume":"5","author":"B Lindauer","year":"2014","unstructured":"Lindauer, B., Glasser, J., Rosen, M., Wallnau, K.C., ExactData, L.: Generating test data for insider threat detectors. JoWUA 5(2), 80\u201394 (2014)","journal-title":"JoWUA"},{"key":"2_CR21","unstructured":"Liu, A., Martin, C., Hetherington, T., Matzner, S.: A comparison of system call feature representations for insider threat detection. In: Proceedings from the Sixth Annual IEEE SMC Information Assurance Workshop, pp. 340\u2013347. IEEE (2005)"},{"key":"2_CR22","unstructured":"Liu, A., Martin, C.E., Hetherington, T., Matzner, S.: AI lessons learned from experiments in insider threat detection. In: AAAI Spring Symposium: What Went Wrong and Why: Lessons from AI Research and Applications, pp. 49\u201355 (2006)"},{"key":"2_CR23","doi-asserted-by":"crossref","unstructured":"Liu, L., Chen, C., Zhang, J., De Vel, O., Xiang, Y.: Insider threat identification using the simultaneous neural learning of multi-source logs. In: Submitted to IEEE Access (2019)","DOI":"10.1109\/ACCESS.2019.2957055"},{"key":"2_CR24","doi-asserted-by":"crossref","unstructured":"Liu, L., De Vel, O., Chen, C., Zhang, J., Xiang, Y.: Anomaly-based insider threat detection using deep autoencoders. In: 2018 IEEE International Conference on Data Mining Workshops (ICDMW), pp. 39\u201348. IEEE (2018)","DOI":"10.1109\/ICDMW.2018.00014"},{"issue":"2","key":"2_CR25","doi-asserted-by":"publisher","first-page":"1397","DOI":"10.1109\/COMST.2018.2800740","volume":"20","author":"L Liu","year":"2018","unstructured":"Liu, L., De Vel, O., Han, Q.L., Zhang, J., Xiang, Y.: Detecting and preventing cyber insider threats: a survey. IEEE Commun. Surv. Tutor. 20(2), 1397\u20131417 (2018)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"2_CR26","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"146","DOI":"10.1007\/978-3-540-74320-0_8","volume-title":"Recent Advances in Intrusion Detection","author":"MA Maloof","year":"2007","unstructured":"Maloof, M.A., Stephens, G.D.: elicit: a system for detecting insiders who violate need-to-know. In: Kruegel, C., Lippmann, R., Clark, A. (eds.) RAID 2007. LNCS, vol. 4637, pp. 146\u2013166. Springer, Heidelberg (2007). \nhttps:\/\/doi.org\/10.1007\/978-3-540-74320-0_8"},{"key":"2_CR27","unstructured":"Mikolov, T., Sutskever, I., Chen, K., Corrado, G.S., Dean, J.: Distributed representations of words and phrases and their compositionality. In: Advances in Neural Information Processing Systems, pp. 3111\u20133119 (2013)"},{"key":"2_CR28","unstructured":"Nguyen, N., Reiher, P., Kuenning, G.H.: Detecting insider threats by monitoring system call activity. In: 2003 IEEE Systems, Man and Cybernetics Society Information Assurance Workshop, pp. 45\u201352. IEEE (2003)"},{"key":"2_CR29","unstructured":"\u0158eh\u016f\u0159ek, R., Sojka, P.: Software framework for topic modelling with large corpora. In: Proceedings of the LREC 2010 Workshop on New Challenges for NLP Frameworks, pp. 45\u201350. ELRA, Valletta, May 2010"},{"issue":"2","key":"2_CR30","doi-asserted-by":"publisher","first-page":"1744","DOI":"10.1109\/COMST.2018.2885561","volume":"21","author":"N Sun","year":"2019","unstructured":"Sun, N., Zhang, J., Rimba, P., Gao, S., Zhang, L.Y., Xiang, Y.: Data-driven cybersecurity incident prediction: a survey. IEEE Commun. Surv. Tutor. 21(2), 1744\u20131772 (2019)","journal-title":"IEEE Commun. Surv. Tutor."},{"key":"2_CR31","unstructured":"Ted, E., et al.: Detecting insider threats in a real corporate database of computer usage activity. In: Proceedings of the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1393\u20131401. ACM (2013)"},{"key":"2_CR32","unstructured":"Tuor, A., Kaplan, S., Hutchinson, B., Nichols, N., Robinson, S.: Deep learning for unsupervised insider threat detection in structured cybersecurity data streams. In: Workshops at the Thirty-First AAAI Conference on Artificial Intelligence (2017)"},{"issue":"3","key":"2_CR33","doi-asserted-by":"publisher","first-page":"640","DOI":"10.1109\/TC.2013.2295802","volume":"64","author":"S Wen","year":"2015","unstructured":"Wen, S., Haghighi, M.S., Chen, C., Xiang, Y., Zhou, W., Jia, W.: A sword with two edges: propagation studies on both positive and negative information in online social networks. IEEE Trans. Comput. 64(3), 640\u2013653 (2015)","journal-title":"IEEE Trans. Comput."},{"key":"2_CR34","doi-asserted-by":"publisher","first-page":"265","DOI":"10.1016\/j.cose.2017.11.013","volume":"76","author":"T Wu","year":"2018","unstructured":"Wu, T., Wen, S., Xiang, Y., Zhou, W.: Twitter spam detection: survey of new approaches and comparative study. Comput. Secur. 76, 265\u2013284 (2018)","journal-title":"Comput. Secur."},{"key":"2_CR35","doi-asserted-by":"crossref","unstructured":"Yen, T.F., et al.: Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks. In: Proceedings of the 29th Annual Computer Security Applications Conference, pp. 199\u2013208. ACM (2013)","DOI":"10.1145\/2523649.2523670"},{"key":"2_CR36","doi-asserted-by":"crossref","unstructured":"Young, W.T., Goldberg, H.G., Memory, A., Sartain, J.F., Senator, T.E.: Use of domain knowledge to detect insider threats in computer activities. In: Security and Privacy Workshops (SPW), pp. 60\u201367. IEEE (2013)","DOI":"10.1109\/SPW.2013.32"},{"issue":"1","key":"2_CR37","doi-asserted-by":"publisher","first-page":"104","DOI":"10.1109\/TPDS.2012.98","volume":"24","author":"J Zhang","year":"2013","unstructured":"Zhang, J., Xiang, Y., Wang, Y., Zhou, W., Xiang, Y., Guan, Y.: Network traffic classification using correlation information. IEEE Trans. Parallel Distrib. Syst. 24(1), 104\u2013117 (2013)","journal-title":"IEEE Trans. Parallel Distrib. Syst."}],"container-title":["Lecture Notes in Computer Science","Network and System Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-36938-5_2","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,12,9]],"date-time":"2019-12-09T19:04:44Z","timestamp":1575918284000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-36938-5_2"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2019]]},"ISBN":["9783030369378","9783030369385"],"references-count":37,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-36938-5_2","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2019]]},"assertion":[{"value":"10 December 2019","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"NSS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Network and System Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sapporo","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Japan","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"18 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"13","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"nss2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/nsclab.org\/nss2019\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"EasyChair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"89","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"36","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"40% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"2.8","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"7","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Yes","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}