{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,22]],"date-time":"2026-04-22T18:59:43Z","timestamp":1776884383035,"version":"3.51.2"},"publisher-location":"Cham","reference-count":19,"publisher":"Springer International Publishing","isbn-type":[{"value":"9783319942674","type":"print"},{"value":"9783319942681","type":"electronic"}],"license":[{"start":{"date-parts":[[2018,1,1]],"date-time":"2018-01-01T00:00:00Z","timestamp":1514764800000},"content-version":"unspecified","delay-in-days":0,"URL":"http:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2018]]},"DOI":"10.1007\/978-3-319-94268-1_28","type":"book-chapter","created":{"date-parts":[[2018,6,12]],"date-time":"2018-06-12T12:49:21Z","timestamp":1528807761000},"page":"333-344","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":18,"title":["A Hybrid Model Based on Multi-dimensional Features for Insider Threat Detection"],"prefix":"10.1007","author":[{"given":"Bin","family":"Lv","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Yan","family":"Wang","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Qiujian","family":"Lv","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Dan","family":"Lu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"297","published-online":{"date-parts":[[2018,6,13]]},"reference":[{"key":"28_CR1","doi-asserted-by":"crossref","unstructured":"Gavai, G., et al.: Detecting insider threat from enterprise social and online activity data. In: ACM CCS International Workshop on Managing Insider Security Threats, pp. 13\u201320. ACM (2015)","DOI":"10.1145\/2808783.2808784"},{"key":"28_CR2","unstructured":"By the numbers: cyber attack costs compared (2016). http:\/\/www.csoonline.com\/article\/3074826\/security\/bythe-numbers-cyber-attack-costs-compared.html . Accessed 31 May 2016"},{"key":"28_CR3","volume-title":"The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud)","author":"D Cappelli","year":"2012","unstructured":"Cappelli, D., Moore, A., Trzeciak, R.: The CERT Guide to Insider Threats: How to Prevent, Detect, and Respond to Information Technology Crimes (Theft, Sabotage, Fraud). Addison-Wesley Professional, Boston (2012)"},{"key":"28_CR4","doi-asserted-by":"crossref","unstructured":"Young, W.T., et al.: Use of domain knowledge to detect insider threats in computer activities (2013)","DOI":"10.1109\/SPW.2013.32"},{"key":"28_CR5","doi-asserted-by":"crossref","unstructured":"Rashid, T., Agrafiotis, I., Nurse, J.R.C.: A new take on detecting insider threats: exploring the use of hidden Markov models. In: International Workshop, pp. 47\u201356 (2016)","DOI":"10.1145\/2995959.2995964"},{"issue":"3","key":"28_CR6","first-page":"575","volume":"31","author":"H Eldardiry","year":"2014","unstructured":"Eldardiry, H., Sricharan, K., Liu, J., et al.: Multi-source fusion for anomaly detection: using across-domain and across-time peer-group consistency checks. Comput. Inform. 31(3), 575\u2013606 (2014)","journal-title":"Comput. Inform."},{"key":"28_CR7","volume-title":"Operations Research: Applications and Algorithms","author":"WL Winston","year":"1994","unstructured":"Winston, W.L.: Operations Research: Applications and Algorithms. Duxbury Press, Belmont (1994)"},{"issue":"4","key":"28_CR8","doi-asserted-by":"publisher","first-page":"183","DOI":"10.1080\/19393555.2011.654318","volume":"21","author":"S Zeadally","year":"2012","unstructured":"Zeadally, S., et al.: Detecting insider threats: solutions and trends. Inf. Secur. J. Glob. Perspect. 21(4), 183\u2013192 (2012)","journal-title":"Inf. Secur. J. Glob. Perspect."},{"key":"28_CR9","doi-asserted-by":"crossref","unstructured":"Gamachchi, A., Sun, L., Boztas, S.: A graph based framework for malicious insider threat detection. In: Hawaii International Conference on System Sciences (2017)","DOI":"10.24251\/HICSS.2017.319"},{"issue":"4","key":"28_CR10","first-page":"20","volume":"4","author":"PA Legg","year":"2013","unstructured":"Legg, P.A., et al.: Towards a conceptual model and reasoning structure for insider threat detection. J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl. 4(4), 20\u201337 (2013)","journal-title":"J. Wirel. Mob. Netw. Ubiquit. Comput. Dependable Appl."},{"key":"28_CR11","doi-asserted-by":"crossref","unstructured":"Bishop, M., et al.: Insider threat detection by process analysis. In: Proceedings of IEEE SPW, pp. 251\u2013264 (2014)","DOI":"10.1109\/SPW.2014.40"},{"key":"28_CR12","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"publisher","first-page":"382","DOI":"10.1007\/978-3-642-15512-3_20","volume-title":"Recent Advances in Intrusion Detection","author":"S Mathew","year":"2010","unstructured":"Mathew, S., Petropoulos, M., Ngo, H.Q., Upadhyaya, S.: A data-centric approach to insider attack detection in database systems. In: Jha, S., Sommer, R., Kreibich, C. (eds.) RAID 2010. LNCS, vol. 6307, pp. 382\u2013401. Springer, Heidelberg (2010). https:\/\/doi.org\/10.1007\/978-3-642-15512-3_20"},{"issue":"1","key":"28_CR13","doi-asserted-by":"publisher","first-page":"32","DOI":"10.1080\/19361610.2011.529413","volume":"6","author":"W Eberle","year":"2010","unstructured":"Eberle, W., Graves, J., Holder, L.: Insider threat detection using a graph-based approach. J. Appl. Secur. Res. 6(1), 32\u201381 (2010)","journal-title":"J. Appl. Secur. Res."},{"key":"28_CR14","doi-asserted-by":"crossref","unstructured":"Eldardiry, H., et al.: Multi-domain information fusion for insider threat detection. In: Proceedings of IEEE SPW, pp. 45\u201351, May 2013","DOI":"10.1109\/SPW.2013.14"},{"issue":"2","key":"28_CR15","doi-asserted-by":"publisher","first-page":"503","DOI":"10.1109\/JSYST.2015.2438442","volume":"11","author":"PA Legg","year":"2017","unstructured":"Legg, P.A., Buckley, O., Goldsmith, M., et al.: Automated insider threat detection system using user and role-based profile assessment. IEEE Syst. J. 11(2), 503\u2013512 (2017)","journal-title":"IEEE Syst. J."},{"key":"28_CR16","doi-asserted-by":"publisher","DOI":"10.1002\/0470013192.bsa501","volume-title":"Principal Component Analysis","author":"I Jolliffe","year":"2005","unstructured":"Jolliffe, I.: Principal Component Analysis. Wiley, Hoboken (2005)"},{"key":"28_CR17","doi-asserted-by":"crossref","unstructured":"Liu, F.T., Ting, K.M., Zhou, Z.H.: Isolation forest. In: 2008 Eighth IEEE International Conference on Data Mining, pp. 413\u2013422, December 2008","DOI":"10.1109\/ICDM.2008.17"},{"key":"28_CR18","unstructured":"Ye, N.: A Markov chain model of temporal behavior for anomaly detection, pp. 171\u2013174 (2000)"},{"issue":"3","key":"28_CR19","doi-asserted-by":"publisher","first-page":"168","DOI":"10.1504\/IJSN.2017.084391","volume":"12","author":"LL Ko","year":"2017","unstructured":"Ko, L.L., et al.: Insider threat detection and its future directions. Int. J. Secur. Netw. 12(3), 168 (2017)","journal-title":"Int. J. Secur. Netw."}],"container-title":["Lecture Notes in Computer Science","Wireless Algorithms, Systems, and Applications"],"original-title":[],"link":[{"URL":"http:\/\/link.springer.com\/content\/pdf\/10.1007\/978-3-319-94268-1_28","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,7,5]],"date-time":"2025-07-05T02:51:11Z","timestamp":1751683871000},"score":1,"resource":{"primary":{"URL":"http:\/\/link.springer.com\/10.1007\/978-3-319-94268-1_28"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2018]]},"ISBN":["9783319942674","9783319942681"],"references-count":19,"URL":"https:\/\/doi.org\/10.1007\/978-3-319-94268-1_28","relation":{},"ISSN":["0302-9743","1611-3349"],"issn-type":[{"value":"0302-9743","type":"print"},{"value":"1611-3349","type":"electronic"}],"subject":[],"published":{"date-parts":[[2018]]}}}