{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,6,4]],"date-time":"2025-06-04T02:24:54Z","timestamp":1749003894995,"version":"3.40.3"},"publisher-location":"Cham","reference-count":23,"publisher":"Springer International Publishing","isbn-type":[{"type":"print","value":"9783319112114"},{"type":"electronic","value":"9783319112121"}],"license":[{"start":{"date-parts":[[2014,1,1]],"date-time":"2014-01-01T00:00:00Z","timestamp":1388534400000},"content-version":"tdm","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2014]]},"DOI":"10.1007\/978-3-319-11212-1_22","type":"book-chapter","created":{"date-parts":[[2014,8,14]],"date-time":"2014-08-14T16:36:45Z","timestamp":1408034205000},"page":"383-400","source":"Crossref","is-referenced-by-count":19,"title":["Detecting Insider Information Theft Using Features from File Access Logs"],"prefix":"10.1007","author":[{"given":"Christopher","family":"Gates","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ninghui","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Zenglin","family":"Xu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Suresh N.","family":"Chari","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ian","family":"Molloy","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Youngja","family":"Park","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","reference":[{"issue":"2","key":"22_CR1","doi-asserted-by":"publisher","first-page":"38","DOI":"10.1109\/2.485845","volume":"29","author":"R.S. Sandhu","year":"1996","unstructured":"Sandhu, R.S., Coyne, E.J., Feinstein, H.L., Youman, C.E.: Role-based access control models. IEEE Computer\u00a029(2), 38\u201347 (1996)","journal-title":"IEEE Computer"},{"key":"22_CR2","doi-asserted-by":"crossref","unstructured":"Bell, D.E., LaPadula, L.J.: Secure computer systems: Unified exposition and Multics interpretation. Technical Report ESD-TR-75-306, Mitre Corporation (March 1976)","DOI":"10.21236\/ADA023588"},{"key":"22_CR3","unstructured":"Park, J., Sandhu, R.: Originator control in usage control. In: Proceedings of the Third International Workshop on Policies for Distributed Systems and Networks 2002 (2002)"},{"key":"22_CR4","unstructured":"Horizontal integration: Broader access models for realizing information dominance, JASON Report JSR-04-132 (2004)"},{"key":"22_CR5","doi-asserted-by":"crossref","unstructured":"Salem, M., Hershkop, S., Stolfo, S.: A Survey of Insider Attack Detection Research. In: Insider Attack and Cyber Security, pp. 69\u201390 (2008)","DOI":"10.1007\/978-0-387-77322-3_5"},{"key":"22_CR6","doi-asserted-by":"crossref","unstructured":"Chen, Y., Malin, B.: Detection of anomalous insiders in collaborative environments via relational analysis of access logs. CODASPY 2011: Proceedings of the First ACM Conference on Data and Application Security and Privacy (February 2011)","DOI":"10.1145\/1943513.1943524"},{"issue":"2","key":"22_CR7","doi-asserted-by":"publisher","first-page":"222","DOI":"10.1109\/TSE.1987.232894","volume":"SE-13","author":"D.E. Denning","year":"1987","unstructured":"Denning, D.E.: An Intrusion-Detection Model. IEEE Transactions on Software Engineering\u00a0SE-13(2), 222\u2013232 (1987)","journal-title":"IEEE Transactions on Software Engineering"},{"key":"22_CR8","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"36","DOI":"10.1007\/3-540-36084-0_3","volume-title":"Recent Advances in Intrusion Detection","author":"F. Apap","year":"2002","unstructured":"Apap, F., Honig, A., Hershkop, S., Eskin, E., Stolfo, S.J.: Detecting malicious software by monitoring anomalous windows registry accesses. In: Wespi, A., Vigna, G., Deri, L. (eds.) RAID 2002. LNCS, vol.\u00a02516, p. 36. Springer, Heidelberg (2002)"},{"key":"22_CR9","doi-asserted-by":"crossref","unstructured":"Senator, T.E., Goldberg, H.G., Memory, A., Young, W.T., Rees, B., Pierce, R., Huang, D., Reardon, M., Bader, D.A., Chow, E., Essa, I., Jones, J., Bettadapura, V., Chau, D.H., Green, O., Kaya, O., Zakrzewska, A., Briscoe, E., Mappus, R.I.L., McColl, R., Weiss, L., Dietterich, T.G., Fern, A., Wong, W.K., Das, S., Emmott, A., Irvine, J., Lee, J.Y., Koutra, D., Faloutsos, C., Corkill, D., Friedland, L., Gentzel, A., Jensen, D.: Detecting insider threats in a real corporate database of computer usage activity. In: KDD 2013: Proceedings of the 19th ACM SIGKDD International Conference on Knowledge Discovery and Data Mining, ACM Request Permissions (August 2013)","DOI":"10.1145\/2487575.2488213"},{"key":"22_CR10","series-title":"Lecture Notes in Artificial Intelligence","doi-asserted-by":"publisher","first-page":"14","DOI":"10.1007\/11425274_2","volume-title":"Foundations of Intelligent Systems","author":"S.J. Stolfo","year":"2005","unstructured":"Stolfo, S.J., Hershkop, S., Bui, L.H., Ferster, R., Wang, K.: Anomaly detection in computer security and an application to file system accesses. In: Hacid, M.-S., Murray, N.V., Ra\u015b, Z.W., Tsumoto, S. (eds.) ISMIS 2005. LNCS (LNAI), vol.\u00a03488, pp. 14\u201328. Springer, Heidelberg (2005)"},{"key":"22_CR11","doi-asserted-by":"crossref","unstructured":"Cheng, P.C., Rohatgi, P., Keser, C., Karger, P.A., Wagner, G.M., Reninger, A.S.: Fuzzy MLS: An Experiment on Quantified Risk-Adaptive Access Control. In: IEEE Symposium on Security and Privacy (2007)","DOI":"10.1109\/SP.2007.21"},{"key":"22_CR12","unstructured":"Javitz, H.S., Valdes, A.: The SRI IDES Statistical Anomaly Detector. Research in Security and Privacy (1991)"},{"issue":"23-24","key":"22_CR13","doi-asserted-by":"publisher","first-page":"2435","DOI":"10.1016\/S1389-1286(99)00112-7","volume":"31","author":"V. Paxson","year":"1999","unstructured":"Paxson, V.: Bro: A System for Detecting Network Intruders in Real-Time. Computer Networks\u00a031(23-24), 2435\u20132463 (1999)","journal-title":"Computer Networks"},{"key":"22_CR14","doi-asserted-by":"crossref","unstructured":"Sommer, R., Paxson, V.: Outside the closed world: On using machine learning for network intrusion detection. In: 2010 IEEE Symposium on Security and Privacy (SP), pp. 305\u2013316 (2010)","DOI":"10.1109\/SP.2010.25"},{"key":"22_CR15","doi-asserted-by":"crossref","unstructured":"Mahoney, M.V., Chan, P.K.: Learning nonstationary models of normal network traffic for detecting novel attacks. In: KDD 2002: Proceedings of the Eighth ACM SIGKDD International Conference on Knowledge Discovery and Data Mining. ACM Request Permissions (July 2002)","DOI":"10.1145\/775047.775102"},{"key":"22_CR16","unstructured":"Lee, W., Xiang, D.: Information-theoretic measures for anomaly detection. In: Proceedings of the 2001 IEEE Symposium on Security and Privacy, S&P 2001, pp. 130\u2013143 (2001)"},{"key":"22_CR17","doi-asserted-by":"crossref","unstructured":"Lakhina, A., Crovella, M., Diot, C., Lakhina, A., Crovella, M., Diot, C.: Mining anomalies using traffic feature distributions, vol.\u00a035. ACM (October 2005)","DOI":"10.1145\/1090191.1080118"},{"key":"22_CR18","doi-asserted-by":"crossref","unstructured":"Mathur, S., Coskun, B., Balakrishnan, S.: Detecting hidden enemy lines in IP address space. In: NSPW 2013: Proceedings of the 2013 Workshop on New Security Paradigms Workshop (December 2013)","DOI":"10.1145\/2535813.2535816"},{"key":"22_CR19","doi-asserted-by":"crossref","unstructured":"Jamshed, M.A., Lee, J., Moon, S., Yun, I., Kim, D., Lee, S., Yi, Y., Park, K.: Kargus: a highly-scalable software-based intrusion detection system. In: CCS 2012: Proceedings of the 2012 ACM Conference on Computer and Communications Security. ACM Request Permissions (October 2012)","DOI":"10.1145\/2382196.2382232"},{"key":"22_CR20","doi-asserted-by":"crossref","unstructured":"Huang, L., Wong, K.: Anomaly Detection by Monitoring Filesystem Activities. In: 2011 IEEE 19th International Conference on Program Comprehension (ICPC), pp. 221\u2013222. IEEE (January 2011)","DOI":"10.1109\/ICPC.2011.23"},{"key":"22_CR21","unstructured":"Bonwick, J.: Zfs end-to-end data integrity (December 2005)"},{"key":"22_CR22","series-title":"LNICST","doi-asserted-by":"publisher","first-page":"51","DOI":"10.1007\/978-3-642-05284-2_4","volume-title":"Security and Privacy in Communication Networks","author":"B.M. Bowen","year":"2009","unstructured":"Bowen, B.M., Hershkop, S., Keromytis, A.D., Stolfo, S.J.: Baiting inside attackers using decoy documents. In: Chen, Y., Dimitriou, T.D., Zhou, J. (eds.) SecureComm 2009. LNICST, vol.\u00a019, pp. 51\u201370. Springer, Heidelberg (2009)"},{"key":"22_CR23","unstructured":"Glovin, D., Harper, C.: Goldman trading-code investment put at risk by theft (2009)"}],"container-title":["Lecture Notes in Computer Science","Computer Security - ESORICS 2014"],"original-title":[],"language":"en","link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-11212-1_22","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,9,22]],"date-time":"2019-09-22T20:04:22Z","timestamp":1569182662000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-11212-1_22"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2014]]},"ISBN":["9783319112114","9783319112121"],"references-count":23,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-11212-1_22","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"type":"print","value":"0302-9743"},{"type":"electronic","value":"1611-3349"}],"subject":[],"published":{"date-parts":[[2014]]}}}