{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,6]],"date-time":"2026-01-06T13:09:23Z","timestamp":1767704963399,"version":"3.40.3"},"publisher-location":"Cham","reference-count":32,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783030503086"},{"type":"electronic","value":"9783030503093"}],"license":[{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"},{"start":{"date-parts":[[2020,1,1]],"date-time":"2020-01-01T00:00:00Z","timestamp":1577836800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springernature.com\/gp\/researchers\/text-and-data-mining"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2020]]},"DOI":"10.1007\/978-3-030-50309-3_42","type":"book-chapter","created":{"date-parts":[[2020,7,9]],"date-time":"2020-07-09T23:21:31Z","timestamp":1594336891000},"page":"619-636","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":5,"title":["Understanding Insider Threat Attacks Using Natural Language Processing: Automatically Mapping Organic Narrative Reports to Existing Insider Threat Frameworks"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-4472-8955","authenticated-orcid":false,"given":"Katie","family":"Paxton-Fear","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-0660-8776","authenticated-orcid":false,"given":"Duncan","family":"Hodges","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1502-5721","authenticated-orcid":false,"given":"Oliver","family":"Buckley","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2020,7,10]]},"reference":[{"issue":"7","key":"42_CR1","doi-asserted-by":"publisher","first-page":"9","DOI":"10.1016\/S1361-3723(15)30066-X","volume":"2015","author":"I Agrafiotis","year":"2015","unstructured":"Agrafiotis, I., Nurse, J.R., Buckley, O., Legg, P., Creese, S., Goldsmith, M.: Identifying attack patterns for insider threat detection. Comput. Fraud Secur. 2015(7), 9\u201317 (2015). https:\/\/doi.org\/10.1016\/S1361-3723(15)30066-X","journal-title":"Comput. Fraud Secur."},{"key":"42_CR2","series-title":"Lecture Notes in Computer Science (Lecture Notes in Artificial Intelligence)","doi-asserted-by":"publisher","first-page":"391","DOI":"10.1007\/978-3-642-13657-3_43","volume-title":"Advances in Knowledge Discovery and Data Mining","author":"R Arun","year":"2010","unstructured":"Arun, R., Suresh, V., Veni Madhavan, C.E., Narasimha Murthy, M.N.: On finding the natural number of topics with latent dirichlet allocation: some observations. In: Zaki, M.J., Yu, J.X., Ravindran, B., Pudi, V. (eds.) PAKDD 2010. LNCS (LNAI), vol. 6118, pp. 391\u2013402. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-13657-3_43"},{"issue":"Jan","key":"42_CR3","first-page":"993","volume":"3","author":"DM Blei","year":"2003","unstructured":"Blei, D.M., Ng, A.Y., Jordan, M.I.: Latent dirichlet allocation. J. Mach. Learn. Res. 3(Jan), 993\u20131022 (2003)","journal-title":"J. Mach. Learn. Res."},{"key":"42_CR4","doi-asserted-by":"crossref","unstructured":"Brown, C.R., Watkins, A., Greitzer, F.L.: Predicting insider threat risks through linguistic analysis of electronic communication. In: 2013 46th Hawaii International Conference on System Sciences, pp. 1849\u20131858 (2013). https:\/\/doi.org\/10\/gdrb3z","DOI":"10.1109\/HICSS.2013.453"},{"key":"42_CR5","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"412","DOI":"10.1007\/11560326_32","volume-title":"Computer Network Security","author":"JW Butts","year":"2005","unstructured":"Butts, J.W., Mills, R.F., Baldwin, R.O.: Developing an insider threat model using functional decomposition. In: Gorodetsky, V., Kotenko, I., Skormin, V. (eds.) MMM-ACNS 2005. LNCS, vol. 3685, pp. 412\u2013417. Springer, Heidelberg (2005). https:\/\/doi.org\/10.1007\/11560326_32"},{"key":"42_CR6","volume-title":"The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud)","author":"D Cappelli","year":"2012","unstructured":"Cappelli, D., Moore, A., Trzeciak, R.: The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud). Addison-Wesley Professional, Boston (2012)"},{"key":"42_CR7","doi-asserted-by":"publisher","first-page":"45","DOI":"10.1007\/978-1-4419-7133-3_3","volume-title":"Insider Threats in Cyber Security","author":"L Coles-Kemp","year":"2010","unstructured":"Coles-Kemp, L., Theoharidou, M.: Insider threat and information security management. In: Probst, C.W., Hunker, J., Gollmann, D., Bishop, M. (eds.) Insider Threats in Cyber Security, pp. 45\u201371. Springer, Boston (2010). https:\/\/doi.org\/10.1007\/978-1-4419-7133-3_3"},{"issue":"1","key":"42_CR8","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1080\/19361610.2011.529413","volume":"6","author":"W Eberle","year":"2010","unstructured":"Eberle, W., Graves, J., Holder, L.: Insider threat detection using a graph-based approach. J. Appl. Secur. Res. 6(1), 32\u201381 (2010). https:\/\/doi.org\/10.1080\/19361610.2011.529413","journal-title":"J. Appl. Secur. Res."},{"key":"42_CR9","doi-asserted-by":"publisher","unstructured":"Elmrabit, N., Yang, S.H., Yang, L.: Insider threats in information security categories and approaches. In: 2015 21st International Conference on Automation and Computing (ICAC), pp. 1\u20136 (2015). https:\/\/doi.org\/10.1109\/IConAC.2015.7313979","DOI":"10.1109\/IConAC.2015.7313979"},{"key":"42_CR10","doi-asserted-by":"crossref","unstructured":"Forte, L.: Insider Threat Report 2019. Insider Threat Report 2019, Red Goat Cyber Security (2019)","DOI":"10.1016\/S1353-4858(19)30068-6"},{"key":"42_CR11","doi-asserted-by":"publisher","unstructured":"Gavai, G., Sricharan, K., Gunning, D., Hanley, J., Singhal, M., Rolleston, R.: Supervised and unsupervised methods to detect insider threat from enterprise social and online activity data. J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl. (JoWUA) 6(4) (2015). https:\/\/doi.org\/10.1145\/2808783.2808784","DOI":"10.1145\/2808783.2808784"},{"issue":"1","key":"42_CR12","doi-asserted-by":"publisher","first-page":"106","DOI":"10.2979\/eservicej.9.1.106","volume":"9","author":"FL Greitzer","year":"2013","unstructured":"Greitzer, F.L., Kangas, L.J., Noonan, C.F., Brown, C.R., Ferryman, T.: Psychosocial modeling of insider threat risk based on behavioral and word use analysis. e-Serv. J. 9(1), 106 (2013). https:\/\/doi.org\/10\/gdrb4d","journal-title":"e-Serv. J."},{"key":"42_CR13","doi-asserted-by":"publisher","unstructured":"Greitzer, F.L., et al.: Unintentional insider threat: contributing factors, observables, and mitigation strategies. In: 2014 47th Hawaii International Conference on System Sciences, pp. 2025\u20132034, January 2014. https:\/\/doi.org\/10.1109\/HICSS.2014.256","DOI":"10.1109\/HICSS.2014.256"},{"issue":"2","key":"42_CR14","doi-asserted-by":"publisher","first-page":"25","DOI":"10.5038\/1944-0472.4.2.2","volume":"4","author":"FL Greitzer","year":"2011","unstructured":"Greitzer, F.L., Hohimer, R.E.: Modeling human behavior to anticipate insider attacks. J. Strateg. Secur. 4(2), 25\u201348 (2011). http:\/\/www.jstor.org\/stable\/26463925","journal-title":"J. Strateg. Secur."},{"issue":"Suppl. 1","key":"42_CR15","doi-asserted-by":"publisher","first-page":"5228","DOI":"10.1073\/pnas.0307752101","volume":"101","author":"TL Griffiths","year":"2004","unstructured":"Griffiths, T.L., Steyvers, M.: Finding scientific topics. Proc. Natl. Acad. Sci. 101(Suppl. 1), 5228\u20135235 (2004)","journal-title":"Proc. Natl. Acad. Sci."},{"issue":"6245","key":"42_CR16","doi-asserted-by":"publisher","first-page":"261","DOI":"10.1126\/science.aaa8685","volume":"349","author":"J Hirschberg","year":"2015","unstructured":"Hirschberg, J., Manning, C.D.: Advances in natural language processing. Science 349(6245), 261\u2013266 (2015). https:\/\/doi.org\/10\/f7kfrk","journal-title":"Science"},{"key":"42_CR17","doi-asserted-by":"publisher","unstructured":"Ho, S.M., Hancock, J.T., Booth, C., Burmester, M., Liu, X., Timmarajus, S.S.: Demystifying insider threat: language-action cues in group dynamics. In: Proceedings of the Annual Hawaii International Conference on System Sciences, vol. 2016-March, pp. 2729\u20132738 (2016). https:\/\/doi.org\/10.1109\/HICSS.2016.343","DOI":"10.1109\/HICSS.2016.343"},{"issue":"1","key":"42_CR18","doi-asserted-by":"publisher","first-page":"89","DOI":"10.1080\/21670811.2015.1093271","volume":"4","author":"C Jacobi","year":"2016","unstructured":"Jacobi, C., van Atteveldt, W., Welbers, K.: Quantitative analysis of large amounts of journalistic texts using topic modelling. Digit. Journal. 4(1), 89\u2013106 (2016). https:\/\/doi.org\/10\/f3s2sg","journal-title":"Digit. Journal."},{"issue":"3","key":"42_CR19","doi-asserted-by":"publisher","first-page":"231","DOI":"10.1057\/ejis.2015.15","volume":"25","author":"AC Johnston","year":"2016","unstructured":"Johnston, A.C., Warkentin, M., McBride, M., Carter, L.: Dispositional and situational factors: influences on information security policy violations. Eur. J. Inf. Syst. 25(3), 231\u2013251 (2016). https:\/\/doi.org\/10.1057\/ejis.2015.15","journal-title":"Eur. J. Inf. Syst."},{"key":"42_CR20","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"26","DOI":"10.1007\/978-3-642-15152-1_3","volume-title":"Trust, Privacy and Security in Digital Business","author":"M Kandias","year":"2010","unstructured":"Kandias, M., Mylonas, A., Virvilis, N., Theoharidou, M., Gritzalis, D.: An insider threat prediction model. In: Katsikas, S., Lopez, J., Soriano, M. (eds.) TrustBus 2010. LNCS, vol. 6264, pp. 26\u201337. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15152-1_3"},{"key":"42_CR21","unstructured":"Lo, R.T.W., He, B., Ounis, I.: Automatically building a stopword list for an information retrieval system. In: Journal on Digital Information Management: Special Issue on the 5th Dutch-Belgian Information Retrieval Workshop (DIR), vol. 5, pp. 17\u201324 (2005)"},{"key":"42_CR22","doi-asserted-by":"publisher","unstructured":"Maasberg, M., Warren, J., Beebe, N.L.: The dark side of the insider: detecting the insider threat through examination of dark triad personality traits. In: 2015 48th Hawaii International Conference on System Sciences, pp. 3518\u20133526, January 2015. https:\/\/doi.org\/10.1109\/HICSS.2015.423","DOI":"10.1109\/HICSS.2015.423"},{"issue":"1","key":"42_CR23","doi-asserted-by":"publisher","first-page":"62","DOI":"10.1016\/S0167-4048(02)00109-8","volume":"21","author":"G Magklaras","year":"2001","unstructured":"Magklaras, G., Furnell, S.: Insider threat prediction tool: evaluating the probability of it misuse. Comput. Secur. 21(1), 62\u201373 (2001). https:\/\/doi.org\/10.1016\/S0167-4048(02)00109-8. http:\/\/www.sciencedirect.com\/science\/article\/pii\/S0167404802001098","journal-title":"Comput. Secur."},{"key":"42_CR24","volume-title":"Foundations of Statistical Natural Language Processing","author":"CD Manning","year":"1999","unstructured":"Manning, C.D., Manning, C.D., Sch\u00fctze, H.: Foundations of Statistical Natural Language Processing. MIT Press, Cambridge (1999)"},{"key":"42_CR25","doi-asserted-by":"publisher","unstructured":"Meng, F., Lou, F., Fu, Y., Tian, Z.: Deep learning based attribute classification insider threat detection for data security. In: 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC), pp. 576\u2013581, June 2018. https:\/\/doi.org\/10.1109\/DSC.2018.00092","DOI":"10.1109\/DSC.2018.00092"},{"issue":"2","key":"42_CR26","doi-asserted-by":"publisher","first-page":"175","DOI":"10.1037\/1089-2680.2.2.175","volume":"2","author":"RS Nickerson","year":"1998","unstructured":"Nickerson, R.S.: Confirmation bias: a ubiquitous phenomenon in many guises. Rev. General Psychol. 2(2), 175\u2013220 (1998). https:\/\/doi.org\/10.1037\/1089-2680.2.2.175","journal-title":"Rev. General Psychol."},{"key":"42_CR27","doi-asserted-by":"publisher","unstructured":"Nurse, J.R.C., et al.: Understanding insider threat: a framework for characterising attacks. In: 2014 IEEE Security and Privacy Workshops, pp. 214\u2013228, May 2014. https:\/\/doi.org\/10.1109\/SPW.2014.38","DOI":"10.1109\/SPW.2014.38"},{"key":"42_CR28","unstructured":"Paxton-Fear, K., Hodges, D., Buckley, O.: Corpus expansion using topic modelling: creating a library of insider threat attacks. Hum.-Centric Comput. Inf. Syst. (in review)"},{"key":"42_CR29","unstructured":"Riedl, M., Biemann, C.: Topictiling: a text segmentation algorithm based on LDA. In: Proceedings of ACL 2012 Student Research Workshop, pp. 37\u201342. Association for Computational Linguistics (2012)"},{"key":"42_CR30","doi-asserted-by":"publisher","DOI":"10.1007\/978-94-017-2388-6_4","volume-title":"Natural Language Information Retrieval","author":"AF Smeaton","year":"1999","unstructured":"Smeaton, A.F.: Using NLP or NLP resources for information retrieval tasks. In: Strzalkowski, T. (ed.) Natural Language Information Retrieval. Springer, Dordrecht (1999). https:\/\/doi.org\/10.1007\/978-94-017-2388-6_4"},{"key":"42_CR31","unstructured":"Trilla, A.: Natural language processing techniques in text-to-speech synthesis and automatic speech recognition. Departament de Tecnologies Media, pp. 1\u20135 (2009)"},{"key":"42_CR32","doi-asserted-by":"crossref","unstructured":"Verizon: 2019 data breach investigations report. https:\/\/enterprise.verizon.com\/en-gb\/resources\/reports\/dbir\/","DOI":"10.1016\/S1361-3723(19)30060-0"}],"container-title":["Lecture Notes in Computer Science","HCI for Cybersecurity, Privacy and Trust"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-50309-3_42","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2024,7,10]],"date-time":"2024-07-10T00:38:44Z","timestamp":1720571924000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-50309-3_42"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020]]},"ISBN":["9783030503086","9783030503093"],"references-count":32,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-50309-3_42","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2020]]},"assertion":[{"value":"10 July 2020","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"HCII","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Human-Computer Interaction","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Copenhagen","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Denmark","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2020","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"19 July 2020","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"24 July 2020","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"22","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"hcii2020","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/2020.hci.international\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"This content has been made available to all.","name":"free","label":"Free to read"}]}}