{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T05:20:24Z","timestamp":1755926424387,"version":"3.40.3"},"publisher-location":"Cham","reference-count":28,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030415785"},{"type":"electronic","value":"9783030415792"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-41579-2_20","type":"book-chapter","created":{"date-parts":[[2020,2,17]],"date-time":"2020-02-17T16:09:09Z","timestamp":1581955749000},"page":"341-356","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["AGE: Authentication Graph Embedding for Detecting Anomalous Login Activities"],"prefix":"10.1007","author":[{"given":"Renzheng","family":"Wei","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Lijun","family":"Cai","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Aimin","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Meng","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,2,18]]},"reference":[{"key":"20_CR1","unstructured":"Banjo, S.: Home depot hackers exposed 53 million email addresses. Wall Street J. (2014)"},{"key":"20_CR2","doi-asserted-by":"crossref","unstructured":"Bhattacharjee, S.D., Yuan, J., Jiaqi, Z., Tan, Y.P.: Context-aware graph-based analysis for detecting anomalous activities. In: 2017 IEEE International Conference on Multimedia and Expo (ICME), pp. 1021\u20131026. IEEE (2017)","DOI":"10.1109\/ICME.2017.8019421"},{"key":"20_CR3","doi-asserted-by":"crossref","unstructured":"Bohara, A., Noureddine, M.A., Fawaz, A., Sanders, W.H.: An unsupervised multi-detector approach for identifying malicious lateral movement. In: 2017 IEEE 36th Symposium on Reliable Distributed Systems (SRDS), pp. 224\u2013233. IEEE (2017)","DOI":"10.1109\/SRDS.2017.31"},{"key":"20_CR4","doi-asserted-by":"publisher","first-page":"93","DOI":"10.1145\/335191.335388","volume":"29","author":"MM Breunig","year":"2000","unstructured":"Breunig, M.M., Kriegel, H.P., Ng, R.T., Sander, J.: LOF: identifying density-based local outliers. ACM SIGMOD Rec. 29, 93\u2013104 (2000)","journal-title":"ACM SIGMOD Rec."},{"key":"20_CR5","doi-asserted-by":"crossref","unstructured":"Brown, A., Tuor, A., Hutchinson, B., Nichols, N.: Recurrent neural network attention mechanisms for interpretable system log anomaly detection. In: Proceedings of the First Workshop on Machine Learning for Computing Systems, p. 1. ACM (2018)","DOI":"10.1145\/3217871.3217872"},{"key":"20_CR6","unstructured":"Business insider: how the hackers broke into Sony and why it could happen to any company (2014). http:\/\/www.businessinsider.com\/how-the-hackers-broke-into-sony-2014-12"},{"issue":"1","key":"20_CR7","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1080\/19361610.2011.529413","volume":"6","author":"W Eberle","year":"2010","unstructured":"Eberle, W., Graves, J., Holder, L.: Insider threat detection using a graph-based approach. J. Appl. Secur. Res. 6(1), 32\u201381 (2010)","journal-title":"J. Appl. Secur. Res."},{"key":"20_CR8","doi-asserted-by":"crossref","unstructured":"Glasser, J., Lindauer, B.: Bridging the gap: a pragmatic approach to generating insider threat data. In: 2013 IEEE Security and Privacy Workshops, pp. 98\u2013104. IEEE (2013)","DOI":"10.1109\/SPW.2013.37"},{"key":"20_CR9","doi-asserted-by":"crossref","unstructured":"Gon\u00e7alves, D., Bota, J., Correia, M.: Big data analytics for detecting host misbehavior in large logs. In: 2015 IEEE Trustcom\/BigDataSE\/ISPA, vol. 1, pp. 238\u2013245. IEEE (2015)","DOI":"10.1109\/Trustcom.2015.380"},{"key":"20_CR10","doi-asserted-by":"crossref","unstructured":"Hagberg, A., Lemons, N., Kent, A., Neil, J.: Connected components and credential hopping in authentication graphs. In: 2014 Tenth International Conference on Signal-Image Technology and Internet-Based Systems, pp. 416\u2013423. IEEE (2014)","DOI":"10.1109\/SITIS.2014.95"},{"key":"20_CR11","unstructured":"Javed, M.: Detecting credential compromise in enterprise networks. Ph.D. thesis, UC Berkeley (2016)"},{"key":"20_CR12","unstructured":"Joyce, R.: Disrupting nation state hackers. USENIX Association, San Francisco, January 2016"},{"key":"20_CR13","doi-asserted-by":"publisher","first-page":"150","DOI":"10.1016\/j.cose.2014.09.001","volume":"48","author":"AD Kent","year":"2015","unstructured":"Kent, A.D., Liebrock, L.M., Neil, J.C.: Authentication graphs: analyzing user behavior within an enterprise network. Comput. Secur. 48, 150\u2013166 (2015)","journal-title":"Comput. Secur."},{"key":"20_CR14","unstructured":"Mikolov, T., Sutskever, I., Chen, K., Corrado, G.S., Dean, J.: Distributed representations of words and phrases and their compositionality. In: Advances in Neural Information Processing Systems, pp. 3111\u20133119 (2013)"},{"key":"20_CR15","doi-asserted-by":"crossref","unstructured":"Niinuma, K., Jain, A.K.: Continuous user authentication using temporal information. In: Biometric Technology for Human Identification VII, vol. 7667, p. 76670L. International Society for Optics and Photonics (2010)","DOI":"10.1117\/12.847886"},{"key":"20_CR16","doi-asserted-by":"crossref","unstructured":"Oprea, A., Li, Z., Yen, T.F., Chin, S.H., Alrwais, S.: Detection of early-stage enterprise infection by mining large-scale log data. In: 2015 45th Annual IEEE\/IFIP International Conference on Dependable Systems and Networks, pp. 45\u201356. IEEE (2015)","DOI":"10.1109\/DSN.2015.14"},{"key":"20_CR17","doi-asserted-by":"crossref","unstructured":"Siadati, H., Memon, N.: Detecting structurally anomalous logins within enterprise networks. In: Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security, pp. 1273\u20131284. ACM (2017)","DOI":"10.1145\/3133956.3134003"},{"key":"20_CR18","unstructured":"Silver-Greenberg, J., Goldstein, M., Perlroth, N.: JPMorgan chase hack affects 76 million households. New York Times 2 (2014)"},{"key":"20_CR19","volume-title":"Continuous Authentication Using Biometrics: Data, Models, and Metrics: Data, Models, and Metrics","author":"I Traore","year":"2011","unstructured":"Traore, I.: Continuous Authentication Using Biometrics: Data, Models, and Metrics: Data, Models, and Metrics. IGI Global, Hershey (2011)"},{"key":"20_CR20","unstructured":"TrendMicro: Apt myths and challenges. https:\/\/blog.trendmicro.com\/trendlabs-security-intelligence\/infographic-apt-myths-and-challenges\/. Accessed 4 April 2012"},{"key":"20_CR21","unstructured":"Tuor, A., Kaplan, S., Hutchinson, B., Nichols, N., Robinson, S.: Deep learning for unsupervised insider threat detection in structured cybersecurity data streams. In: Workshops at the Thirty-First AAAI Conference on Artificial Intelligence (2017)"},{"key":"20_CR22","unstructured":"Tuor, A.R., Baerwolf, R., Knowles, N., Hutchinson, B., Nichols, N., Jasper, R.: Recurrent neural network language models for open vocabulary event-level cyber anomaly detection. In: Workshops at the Thirty-Second AAAI Conference on Artificial Intelligence (2018)"},{"issue":"2\u20134","key":"20_CR23","doi-asserted-by":"publisher","first-page":"147","DOI":"10.1007\/s00607-011-0155-y","volume":"93","author":"P Van Mieghem","year":"2011","unstructured":"Van Mieghem, P.: The N-intertwined SIS epidemic network model. Computing 93(2\u20134), 147\u2013169 (2011)","journal-title":"Computing"},{"key":"20_CR24","doi-asserted-by":"crossref","unstructured":"Wang, D., Cheng, H., Wang, P., Yan, J., Huang, X.: A security analysis of honeywords. In: NDSS (2018)","DOI":"10.14722\/ndss.2018.23142"},{"key":"20_CR25","unstructured":"Weiss, N.E., Miller, R.S.: The target and other financial data breaches: frequently asked questions. In: Congressional Research Service, Prepared for Members and Committees of Congress, February, vol. 4, p. 2015 (2015)"},{"key":"20_CR26","unstructured":"Wikipedia: Phishing \u2013 Wikipedia, the free encyclopedia (2019). http:\/\/en.wikipedia.org\/w\/index.php?title=Phishing&oldid=892015701. Accessed 14 April 2019"},{"issue":"1\u20133","key":"20_CR27","doi-asserted-by":"publisher","first-page":"37","DOI":"10.1016\/0169-7439(87)80084-9","volume":"2","author":"S Wold","year":"1987","unstructured":"Wold, S., Esbensen, K., Geladi, P.: Principal component analysis. Chemometr. Intell. Lab. Syst. 2(1\u20133), 37\u201352 (1987)","journal-title":"Chemometr. Intell. Lab. Syst."},{"key":"20_CR28","unstructured":"Zhang, J., et al.: Safeguarding academic accounts and resources with the university credential abuse auditing system. In: IEEE\/IFIP International Conference on Dependable Systems and Networks (DSN 2012), pp. 1\u20138. IEEE (2012)"}],"container-title":["Lecture Notes in Computer Science","Information and Communications Security"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-41579-2_20","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2020,11,26]],"date-time":"2020-11-26T20:19:10Z","timestamp":1606421950000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-030-41579-2_20"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030415785","9783030415792"],"references-count":28,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-41579-2_20","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"18 February 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ICICS","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Information and Communications Security","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Beijing","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"China","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2019","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"15 December 2019","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17 December 2019","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"21","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"icics2019","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Double-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"Easy Chair","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"199","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"47","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"0","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"24% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"8","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}