{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,16]],"date-time":"2026-07-16T21:34:01Z","timestamp":1784237641965,"version":"3.55.0"},"publisher-location":"Cham","reference-count":63,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783030954048","type":"print"},{"value":"9783030954055","type":"electronic"}],"license":[{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,1,1]],"date-time":"2022-01-01T00:00:00Z","timestamp":1640995200000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2022]]},"DOI":"10.1007\/978-3-030-95405-5_28","type":"book-chapter","created":{"date-parts":[[2022,1,31]],"date-time":"2022-01-31T19:03:13Z","timestamp":1643655793000},"page":"393-407","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":9,"title":["Cybersecurity Analysis via Process Mining: A Systematic Literature Review"],"prefix":"10.1007","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9655-9228","authenticated-orcid":false,"given":"Martin","family":"Macak","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0853-2776","authenticated-orcid":false,"given":"Lukas","family":"Daubner","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Mohammadreza Fani","family":"Sani","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Barbora","family":"Buhnova","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,1,31]]},"reference":[{"issue":"12","key":"28_CR1","doi-asserted-by":"publisher","first-page":"77","DOI":"10.1109\/MC.2011.384","volume":"44","author":"W van der Aalst","year":"2011","unstructured":"van der Aalst, W.: Using process mining to bridge the gap between BI and BPM. Computer 44(12), 77\u201380 (2011)","journal-title":"Computer"},{"key":"28_CR2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-49851-4","volume-title":"Process Mining: Data Science in Action","author":"W van der Aalst","year":"2016","unstructured":"van der Aalst, W.: Process Mining: Data Science in Action, 2nd edn. Springer Publishing Company, Incorporated (2016)","edition":"2"},{"key":"28_CR3","doi-asserted-by":"publisher","first-page":"172","DOI":"10.1016\/j.cose.2017.10.010","volume":"73","author":"M Alizadeh","year":"2018","unstructured":"Alizadeh, M., Lu, X., Fahland, D., Zannone, N., van der Aalst, W.: Linking data and process perspectives for conformance analysis. Comput. Secur. 73, 172\u2013193 (2018)","journal-title":"Comput. Secur."},{"key":"28_CR4","doi-asserted-by":"publisher","first-page":"474","DOI":"10.1016\/j.cose.2017.11.021","volume":"73","author":"SC de Alvarenga","year":"2018","unstructured":"de Alvarenga, S.C., Barbon, S., Miani, R.S., Cukier, M., Zarpel\u00e3o, B.B.: Process mining and hierarchical clustering to help intrusion alert visualization. Comput. Secur. 73, 474\u2013491 (2018)","journal-title":"Comput. Secur."},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Asghar, M.R., Hu, Q., Zeadally, S.: Cybersecurity in industrial control systems: issues, technologies, and challenges. Comput. Netw. 165, 106946 (2019)","DOI":"10.1016\/j.comnet.2019.106946"},{"key":"28_CR6","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1016\/j.accinf.2018.03.004","volume":"31","author":"G Baader","year":"2018","unstructured":"Baader, G., Krcmar, H.: Reducing false positives in fraud detection: combining the red flag approach with process mining. Int. J. Acc. Inf. Syst. 31, 1\u201316 (2018)","journal-title":"Int. J. Acc. Inf. Syst."},{"key":"28_CR7","doi-asserted-by":"crossref","unstructured":"Bahrani, A., Bidgly, A.J.: Ransomware detection using process mining and classification algorithms. In: 16th International ISC Conference on Information Security and Cryptology, pp. 73\u201377 (2019)","DOI":"10.1109\/ISCISC48546.2019.8985149"},{"issue":"3","key":"28_CR8","doi-asserted-by":"publisher","first-page":"257","DOI":"10.1007\/s10207-018-0415-3","volume":"18","author":"ML Bernardi","year":"2019","unstructured":"Bernardi, M.L., Cimitile, M., Distante, D., Martinelli, F., Mercaldo, F.: Dynamic malware detection and phylogeny analysis using process mining. Int. J. Inf. Secur. 18(3), 257\u2013284 (2019)","journal-title":"Int. J. Inf. Secur."},{"key":"28_CR9","doi-asserted-by":"crossref","unstructured":"Bernardi, S., Alastuey, R.P., Trillo-Lado, R.: Using process mining and model-driven engineering to enhance security of web information systems. In: IEEE European Symposium on Security and Privacy Workshops, pp. 160\u2013166 (2017)","DOI":"10.1109\/EuroSPW.2017.66"},{"key":"28_CR10","doi-asserted-by":"crossref","unstructured":"Bernardi, S., Trillo-Lado, R., Merseguer, J.: Detection of integrity attacks to smart grids using process mining and time-evolving graphs. In: 14th European Dependable Computing Conference, pp. 136\u2013139 (2018)","DOI":"10.1109\/EDCC.2018.00032"},{"key":"28_CR11","doi-asserted-by":"crossref","unstructured":"Bogar\u00edn, A., Cerezo, R., Romero, C.: A survey on educational process mining. Wiley Interdisc. Rev.: Data Mining Knowl. Disc. 8(1) (2018)","DOI":"10.1002\/widm.1230"},{"key":"28_CR12","doi-asserted-by":"publisher","unstructured":"B\u00f6hmer, K., Rinderle-Ma, S.: Multi-perspective anomaly detection in business process execution events. In: OTM Confederated International Conferences on the Move to Meaningful Internet Systems, pp. 80\u201398. Springer (2016). https:\/\/doi.org\/10.1007\/978-3-319-48472-3_5","DOI":"10.1007\/978-3-319-48472-3_5"},{"key":"28_CR13","doi-asserted-by":"crossref","unstructured":"Burattin, A., Sperduti, A., Veluscek, M.: Business models enhancement through discovery of roles. In: CIDM, pp. 103\u2013110 (2013)","DOI":"10.1109\/CIDM.2013.6597224"},{"key":"28_CR14","doi-asserted-by":"publisher","unstructured":"Burattin, A., van Zelst, S.J., Armas-Cervantes, A., van Dongen, B.F., Carmona, J.: Online conformance checking using behavioural patterns. In: Business Process Management, pp. 250\u2013267. Springer International Publishing, Cham (2018). https:\/\/doi.org\/10.1007\/978-3-319-98648-7_15","DOI":"10.1007\/978-3-319-98648-7_15"},{"key":"28_CR15","doi-asserted-by":"crossref","unstructured":"Bustos-Jim\u00e9nez, J., Saint-Pierre, C., Graves, A.: Applying process mining techniques to DNS traces analysis. In: 33rd International Conference of the Chilean Computer Science Society, pp. 12\u201316 (2014)","DOI":"10.1109\/SCCC.2014.9"},{"key":"28_CR16","doi-asserted-by":"publisher","unstructured":"Carmona, J., van Dongen, B., Solti, A., Weidlich, M.: Conformance Checking. Springer (2018). https:\/\/doi.org\/10.1007\/978-3-319-99414-7","DOI":"10.1007\/978-3-319-99414-7"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Cimino, M.G., De Francesco, N., Mercaldo, F., Santone, A., Vaglini, G.: Model checking for malicious family detection and phylogenetic analysis in mobile environment. Comput. Secur. 90, 101691 (2020)","DOI":"10.1016\/j.cose.2019.101691"},{"key":"28_CR18","doi-asserted-by":"publisher","unstructured":"Coltellese, S., Maggi, F.M., Marrella, A., Massarelli, L., Querzoni, L.: Triage of IoT attacks through process mining. In: OTM Confederated International Conferences \u201cOn the Move to Meaningful Internet Systems\u201d, pp. 326\u2013344. Springer (2019). https:\/\/doi.org\/10.1007\/978-3-030-33246-4_22","DOI":"10.1007\/978-3-030-33246-4_22"},{"key":"28_CR19","doi-asserted-by":"crossref","unstructured":"Compagna, L., dos Santos, D.R., Ponta, S.E., Ranise, S.: Aegis: automatic enforcement of security policies in workflow-driven web applications. In: Proceedings of the 7th ACM Conference on Data and Application Security and Privacy, pp. 321\u2013328. ACM (2017)","DOI":"10.1145\/3029806.3029813"},{"issue":"2","key":"28_CR20","doi-asserted-by":"publisher","first-page":"300","DOI":"10.1109\/TKDE.2016.2614680","volume":"29","author":"R Conforti","year":"2016","unstructured":"Conforti, R., La Rosa, M., ter Hofstede, A.H.: Filtering out infrequent behavior from business process event logs. IEEE Trans. Knowl. Data Eng. 29(2), 300\u2013314 (2016)","journal-title":"IEEE Trans. Knowl. Data Eng."},{"key":"28_CR21","doi-asserted-by":"crossref","unstructured":"Cook, J.E., Wolf, A.L.: Automating process discovery through event-data analysis. In: Proceedings of the 17th International Conference on Software Engineering, pp. 73\u201382. ACM (1995)","DOI":"10.1145\/225014.225021"},{"key":"28_CR22","doi-asserted-by":"crossref","unstructured":"Elkoumy, G., et al.: Privacy and confidentiality in process mining-threats and research challenges. arXiv preprint arXiv:2106.00388 (2021)","DOI":"10.1145\/3468877"},{"key":"28_CR23","doi-asserted-by":"publisher","first-page":"220","DOI":"10.1016\/j.is.2013.12.007","volume":"47","author":"D Fahland","year":"2015","unstructured":"Fahland, D., van der Aalst, W.M.: Model repair-aligning process models to reality. Inform. Syst. 47, 220\u2013243 (2015)","journal-title":"Inform. Syst."},{"key":"28_CR24","doi-asserted-by":"publisher","unstructured":"Sani, M.F., van Zelst, S.J., van der Aalst, W.M.: Applying sequence mining for outlier detection in process mining. In: OTM Confederated International Conferences \u201cOn the Move to Meaningful Internet Systems\u201d, pp. 98\u2013116. Springer (2018). https:\/\/doi.org\/10.1007\/978-3-030-02671-4_6","DOI":"10.1007\/978-3-030-02671-4_6"},{"key":"28_CR25","doi-asserted-by":"publisher","unstructured":"Fazzinga, B., Folino, F., Furfaro, F., Pontieri, L.: Combining model-and example-driven classification to detect security breaches in activity-unaware logs. In: On the Move to Meaningful Internet Systems. OTM 2018 Conferences, pp. 173\u2013190. Springer (2018). https:\/\/doi.org\/10.1007\/978-3-030-02671-4_10","DOI":"10.1007\/978-3-030-02671-4_10"},{"key":"28_CR26","doi-asserted-by":"crossref","unstructured":"Fazzinga, B., Folino, F., Furfaro, F., Pontieri, L.: An ensemble-based approach to the security-oriented classification of low-level log traces. Expert Syst. Appl. 153, 113386 (2020)","DOI":"10.1016\/j.eswa.2020.113386"},{"key":"28_CR27","doi-asserted-by":"crossref","unstructured":"Genga., L., Zannone., N.: Towards a systematic process-aware behavioral analysis for security. In: Proceedings of the 15th International Joint Conference on e-Business and Telecommunications - Volume 1: BASS, pp. 460\u2013469. INSTICC, SciTePress (2018)","DOI":"10.5220\/0006944606260635"},{"issue":"5","key":"28_CR28","doi-asserted-by":"publisher","first-page":"94","DOI":"10.1109\/MS.2014.20","volume":"31","author":"M van Genuchten","year":"2014","unstructured":"van Genuchten, M., Mans, R., Reijers, H., Wismeijer, D.: Is your upgrade worth it? process mining can tell. IEEE software 31(5), 94\u2013100 (2014)","journal-title":"IEEE software"},{"key":"28_CR29","unstructured":"Geyer-Klingeberg, J., Nakladal, J., Baldauf, F., Veit, F.: Process mining and robotic process automation: a perfect match. In: Proceedings of the Dissertation Award, Demonstration, and Industrial Track at BPM 2018, pp. 124\u2013131 (2018)"},{"issue":"1","key":"28_CR30","doi-asserted-by":"publisher","first-page":"67","DOI":"10.1007\/s00766-018-00308-3","volume":"25","author":"M Ghasemi","year":"2020","unstructured":"Ghasemi, M., Amyot, D.: From event logs to goals: a systematic literature review of goal-oriented process mining. Requirements Eng. 25(1), 67\u201393 (2020)","journal-title":"Requirements Eng."},{"key":"28_CR31","doi-asserted-by":"crossref","unstructured":"Hluch\u00fd, L., Habala, O.: Enhancing mobile device security with process mining. In: IEEE 14th International Symposium on Intelligent Systems and Informatics, pp. 181\u2013184 (2016)","DOI":"10.1109\/SISY.2016.7601493"},{"key":"28_CR32","doi-asserted-by":"crossref","unstructured":"Huda, S., Ahmad, T., Sarno, R., Santoso, H.A.: Identification of process-based fraud patterns in credit application. In: 2nd International Conference on Information and Communication Technology, pp. 84\u201389 (2014)","DOI":"10.1109\/ICoICT.2014.6914045"},{"key":"28_CR33","doi-asserted-by":"crossref","unstructured":"Jaisook, P., Premchaiswadi, W.: Time performance analysis of medical treatment processes by using disco. In: 13th International Conference on ICT and Knowledge Engineering (ICT & Knowledge Engineering 2015), pp. 110\u2013115. IEEE (2015)","DOI":"10.1109\/ICTKE.2015.7368480"},{"key":"28_CR34","unstructured":"Kelemen, R.: Systematic review on process mining and security. In: Central and Eastern European e\u2014Dem and e\u2014Gov Days 2017 (2017)"},{"key":"28_CR35","unstructured":"Kitchenham, B., Charters, S.: Guidelines for performing systematic literature reviews in software engineering (2007)"},{"key":"28_CR36","doi-asserted-by":"publisher","unstructured":"Lamma, E., Mello, P., Montali, M., Riguzzi, F., Storari, S.: Inducing declarative logic-based models from labeled traces. In: Business Process Management. pp. 344\u2013359. Springer, Berlin Heidelberg (2007). https:\/\/doi.org\/10.1007\/978-3-540-75183-0_25","DOI":"10.1007\/978-3-540-75183-0_25"},{"key":"28_CR37","doi-asserted-by":"crossref","unstructured":"Leander, B., Causevic, A., Hansson, H.: Cybersecurity challenges in large industrial IoT systems. In: 24th IEEE International Conference on Emerging Technologies and Factory Automation, pp. 1035\u20131042 (2019)","DOI":"10.1109\/ETFA.2019.8869162"},{"key":"28_CR38","doi-asserted-by":"publisher","unstructured":"Leemans, S.J.J., Fahland, D., van der Aalst, W.M.P.: Discovering block-structured process models from event logs containing infrequent behaviour. In: Business Process Management Workshops, pp. 66\u201378. Springer International Publishing (2014). https:\/\/doi.org\/10.1007\/978-3-319-06257-0_6","DOI":"10.1007\/978-3-319-06257-0_6"},{"issue":"3","key":"28_CR39","doi-asserted-by":"publisher","first-page":"273","DOI":"10.1016\/j.infsof.2013.12.004","volume":"56","author":"M Leitner","year":"2014","unstructured":"Leitner, M., Rinderle-Ma, S.: A systematic review on security in process-aware information systems - constitution, challenges, and future directions. Inf. Softw. Technol. 56(3), 273\u2013293 (2014)","journal-title":"Inf. Softw. Technol."},{"key":"28_CR40","doi-asserted-by":"crossref","unstructured":"Li, C., Ge, J., Li, Z., Huang, L., Yang, H., Luo, B.: Monitoring interactions across multi business processes with token carried data. IEEE Trans. Serv. Comput. 1 (2018)","DOI":"10.1109\/TSC.2016.2645690"},{"issue":"2","key":"28_CR41","doi-asserted-by":"publisher","first-page":"1397","DOI":"10.1109\/COMST.2018.2800740","volume":"20","author":"L Liu","year":"2018","unstructured":"Liu, L., De Vel, O., Han, Q., Zhang, J., Xiang, Y.: Detecting and preventing cyber insider threats: a survey. IEEE Commun. Surv. Tutorials 20(2), 1397\u20131417 (2018)","journal-title":"IEEE Commun. Surv. Tutorials"},{"key":"28_CR42","doi-asserted-by":"crossref","unstructured":"Macak, M., Kruzelova, D., Chren, S., Buhnova, B.: Using process mining for git log analysis of projects in a software development course. Educ. Inf. Technol. 1\u201331 (2021)","DOI":"10.1007\/s10639-021-10564-6"},{"key":"28_CR43","doi-asserted-by":"crossref","unstructured":"Macak, M., Kruzikova, A., Daubner, L., Buhnova, B.: Simulation games platform for unintentional perpetrator attack vector identification. In: Proceedings of the IEEE\/ACM 42nd International Conference on Software Engineering Workshops, pp. 222\u2013229 (2020)","DOI":"10.1145\/3387940.3391475"},{"key":"28_CR44","doi-asserted-by":"crossref","unstructured":"Macak, M., Vanat, I., Merjavy, M., Jevocin, T., Buhnova, B.: Towards process mining utilization in insider threat detection from audit logs. In: 7th International Conference on Social Networks Analysis, Management and Security, pp. 1\u20136 (2020)","DOI":"10.1109\/SNAMS52053.2020.9336573"},{"key":"28_CR45","doi-asserted-by":"crossref","unstructured":"Mardani, S., Shahriari, H.R.: A new method for occupational fraud detection in process aware information systems. In: 10th International ISC Conference on Information Security and Cryptology, pp. 1\u20135 (2013)","DOI":"10.1109\/ISCISC.2013.6767348"},{"key":"28_CR46","doi-asserted-by":"publisher","unstructured":"Myers, D., Radke, K., Suriadi, S., Foo, E.: Process discovery for industrial control system cyber attack detection. In: ICT Systems Security and Privacy Protection, pp. 61\u201375. Springer International Publishing, Cham (2017). https:\/\/doi.org\/10.1007\/978-3-319-58469-0_5","DOI":"10.1007\/978-3-319-58469-0_5"},{"key":"28_CR47","doi-asserted-by":"publisher","first-page":"103","DOI":"10.1016\/j.cose.2018.06.002","volume":"78","author":"D Myers","year":"2018","unstructured":"Myers, D., Suriadi, S., Radke, K., Foo, E.: Anomaly detection for industrial control systems using process mining. Comput. Secur. 78, 103\u2013125 (2018)","journal-title":"Comput. Secur."},{"key":"28_CR48","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-40172-6","volume-title":"Process Mining in Action: Principles","author":"L Reinkemeyer","year":"2020","unstructured":"Reinkemeyer, L.: Process Mining in Action: Principles. Use Cases and Outlook, Springer Nature (2020)"},{"key":"28_CR49","doi-asserted-by":"publisher","first-page":"224","DOI":"10.1016\/j.jbi.2016.04.007","volume":"61","author":"E Rojas","year":"2016","unstructured":"Rojas, E., Munoz-Gama, J., Sepulveda, M., Capurro, D.: Process mining in healthcare: a literature review. J. Biomed. Inform. 61, 224\u2013236 (2016)","journal-title":"J. Biomed. Inform."},{"key":"28_CR50","doi-asserted-by":"publisher","first-page":"54","DOI":"10.1016\/j.sysarc.2018.12.002","volume":"97","author":"NS Rosa","year":"2019","unstructured":"Rosa, N.S., Campos, G.M., Cavalcanti, D.J.: Lightweight formalisation of adaptive middleware. J. Syst. Archit. 97, 54\u201364 (2019)","journal-title":"J. Syst. Archit."},{"issue":"1","key":"28_CR51","doi-asserted-by":"publisher","first-page":"64","DOI":"10.1016\/j.is.2007.07.001","volume":"33","author":"A Rozinat","year":"2008","unstructured":"Rozinat, A., van der Aalst, W.M.: Conformance checking of processes based on monitoring real behavior. Inf. Syst. 33(1), 64\u201395 (2008)","journal-title":"Inf. Syst."},{"key":"28_CR52","doi-asserted-by":"publisher","first-page":"393","DOI":"10.3844\/jcssp.2014.393.402","volume":"10","author":"M Sahlabadi","year":"2014","unstructured":"Sahlabadi, M., Muniyandi, R., Shukur, Z.: Detecting abnormal behavior in social network websites by using a process mining technique. J. Comput. Sci. 10, 393\u2013402 (2014)","journal-title":"J. Comput. Sci."},{"key":"28_CR53","doi-asserted-by":"publisher","unstructured":"Salnitri, M., Alizadeh, M., Giovanella, D., Zannone, N., Giorgini, P.: From security-by-design to the identification of security-critical deviations in process executions. In: International Conference on Advanced Information Systems Engineering, pp. 218\u2013234. Springer (2018). https:\/\/doi.org\/10.1007\/978-3-319-92901-9_19","DOI":"10.1007\/978-3-319-92901-9_19"},{"key":"28_CR54","doi-asserted-by":"crossref","unstructured":"dos Santos Garcia, C., Meincheim, A., Junior, E.R.F., Dallagassa, M.R., Sato, D.M.V., Carvalho, D.R., et al.: Process mining techniques and applications - a systematic mapping study. Expert Syst. Appl. 133, 260\u2013295 (2019)","DOI":"10.1016\/j.eswa.2019.05.003"},{"key":"28_CR55","doi-asserted-by":"crossref","unstructured":"Senator, T.E., Goldberg, H.G., Memory, A., Young, W.T., Rees, B., Pierce, R., et al.: Detecting insider threats in a real corporate database of computer usage activity. In: Proceedings of the 19th ACM\/SIGKDD International Conference on Knowledge Discovery and Data Mining, pp. 1393\u20131401 (2013)","DOI":"10.1145\/2487575.2488213"},{"key":"28_CR56","doi-asserted-by":"crossref","unstructured":"Talamo, M., Povilionis, A., Arcieri, F., Schunck, C.H.: Providing online operational support for distributed, security sensitive electronic business processes. In: International Carnahan Conference on Security Technology, pp. 49\u201354 (2015)","DOI":"10.1109\/CCST.2015.7389656"},{"issue":"1","key":"28_CR57","doi-asserted-by":"publisher","first-page":"1","DOI":"10.1007\/s10664-019-09738-1","volume":"25","author":"A Viticchi\u00e9","year":"2020","unstructured":"Viticchi\u00e9, A., Regano, L., Basile, C., Torchiano, M., Ceccato, M., Tonella, P.: Empirical assessment of the effort needed to attack programs protected with client\/server code splitting. Empirical Softw. Eng. 25(1), 1\u201348 (2020)","journal-title":"Empirical Softw. Eng."},{"key":"28_CR58","first-page":"376","volume":"247","author":"R Williams","year":"2018","unstructured":"Williams, R., Rojas, E., Peek, N., Johnson, O.A.: Process mining in primary care: a literature review. Stud. Health Technol. Inform. 247, 376\u2013380 (2018)","journal-title":"Stud. Health Technol. Inform."},{"key":"28_CR59","doi-asserted-by":"crossref","unstructured":"Yen, T.F., et al.: Beehive: large-scale log analysis for detecting suspicious activity in enterprise networks. In: Proceedings of the 29th Annual Computer Security Applications Conference, pp. 199\u2013208. ACM (2013)","DOI":"10.1145\/2523649.2523670"},{"key":"28_CR60","doi-asserted-by":"crossref","unstructured":"Young, W.T., Goldberg, H.G., Memory, A., Sartain, J.F., Senator, T.E.: Use of domain knowledge to detect insider threats in computer activities. In: 2013 IEEE Security and Privacy Workshops, pp. 60\u201367 (2013)","DOI":"10.1109\/SPW.2013.32"},{"issue":"2","key":"28_CR61","doi-asserted-by":"publisher","first-page":"407","DOI":"10.1007\/s10115-017-1060-2","volume":"54","author":"SJ van Zelst","year":"2018","unstructured":"van Zelst, S.J., van Dongen, B.F., van der Aalst, W.M.: Event stream-based process discovery using abstract representations. Knowl. Inf. Syst. 54(2), 407\u2013435 (2018)","journal-title":"Knowl. Inf. Syst."},{"key":"28_CR62","doi-asserted-by":"publisher","first-page":"80","DOI":"10.1016\/j.eswa.2018.05.030","volume":"110","author":"P Zerbino","year":"2018","unstructured":"Zerbino, P., Aloini, D., Dulmin, R., Mininno, V.: Process-mining-enabled audit of information systems: methodology and an application. Expert Syst. Appl. 110, 80\u201392 (2018)","journal-title":"Expert Syst. Appl."},{"key":"28_CR63","doi-asserted-by":"crossref","unstructured":"Zhou, X., Jin, Y., Zhang, H., Li, S., Huang, X.: A map of threats to validity of systematic literature reviews in software engineering. In: 23rd Asia-Pacific Software Engineering Conference, pp. 153\u2013160 (2016)","DOI":"10.1109\/APSEC.2016.031"}],"container-title":["Lecture Notes in Computer Science","Advanced Data Mining and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-030-95405-5_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2023,1,25]],"date-time":"2023-01-25T09:57:35Z","timestamp":1674640655000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/978-3-030-95405-5_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022]]},"ISBN":["9783030954048","9783030954055"],"references-count":63,"URL":"https:\/\/doi.org\/10.1007\/978-3-030-95405-5_28","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022]]},"assertion":[{"value":"31 January 2022","order":1,"name":"first_online","label":"First Online","group":{"name":"ChapterHistory","label":"Chapter History"}},{"value":"ADMA","order":1,"name":"conference_acronym","label":"Conference Acronym","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"International Conference on Advanced Data Mining and Applications","order":2,"name":"conference_name","label":"Conference Name","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Sydney, NSW","order":3,"name":"conference_city","label":"Conference City","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Australia","order":4,"name":"conference_country","label":"Conference Country","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2022","order":5,"name":"conference_year","label":"Conference Year","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"2 February 2022","order":7,"name":"conference_start_date","label":"Conference Start Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"4 February 2022","order":8,"name":"conference_end_date","label":"Conference End Date","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"17","order":9,"name":"conference_number","label":"Conference Number","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"adma2021","order":10,"name":"conference_id","label":"Conference ID","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"http:\/\/adma2021.net\/","order":11,"name":"conference_url","label":"Conference URL","group":{"name":"ConferenceInfo","label":"Conference Information"}},{"value":"Single-blind","order":1,"name":"type","label":"Type","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"CMT3","order":2,"name":"conference_management_system","label":"Conference Management System","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"116","order":3,"name":"number_of_submissions_sent_for_review","label":"Number of Submissions Sent for Review","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"26","order":4,"name":"number_of_full_papers_accepted","label":"Number of Full Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"35","order":5,"name":"number_of_short_papers_accepted","label":"Number of Short Papers Accepted","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"22% - The value is computed by the equation \"Number of Full Papers Accepted \/ Number of Submissions Sent for Review * 100\" and then rounded to a whole number.","order":6,"name":"acceptance_rate_of_full_papers","label":"Acceptance Rate of Full Papers","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"5","order":7,"name":"average_number_of_reviews_per_paper","label":"Average Number of Reviews per Paper","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"3","order":8,"name":"average_number_of_papers_per_reviewer","label":"Average Number of Papers per Reviewer","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}},{"value":"No","order":9,"name":"external_reviewers_involved","label":"External Reviewers Involved","group":{"name":"ConfEventPeerReviewInformation","label":"Peer Review Information (provided by the conference organizers)"}}]}}