{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,6,15]],"date-time":"2026-06-15T00:26:50Z","timestamp":1781483210288,"version":"3.54.1"},"reference-count":31,"publisher":"Springer Science and Business Media LLC","issue":"16","license":[{"start":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T00:00:00Z","timestamp":1646438400000},"content-version":"tdm","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"},{"start":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T00:00:00Z","timestamp":1646438400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.springer.com\/tdm"}],"content-domain":{"domain":["link.springer.com"],"crossmark-restriction":false},"short-container-title":["Multimed Tools Appl"],"published-print":{"date-parts":[[2022,7]]},"DOI":"10.1007\/s11042-022-12173-y","type":"journal-article","created":{"date-parts":[[2022,3,5]],"date-time":"2022-03-05T05:10:54Z","timestamp":1646457054000},"page":"22953-22983","update-policy":"https:\/\/doi.org\/10.1007\/springer_crossmark_policy","source":"Crossref","is-referenced-by-count":19,"title":["User behavior based Insider Threat Detection using a Multi Fuzzy Classifier"],"prefix":"10.1007","volume":"81","author":[{"ORCID":"https:\/\/orcid.org\/0000-0003-4313-4239","authenticated-orcid":false,"given":"Malvika","family":"Singh","sequence":"first","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"BM","family":"Mehtre","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"S","family":"Sangeetha","sequence":"additional","affiliation":[],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"297","published-online":{"date-parts":[[2022,3,5]]},"reference":[{"key":"12173_CR1","doi-asserted-by":"publisher","first-page":"40626","DOI":"10.1109\/ACCESS.2018.2857450","volume":"6","author":"A Almehmadi","year":"2018","unstructured":"Almehmadi A (2018) Micromovement behavior as an intention detection measurement for preventing insider threats. IEEE Access 6:40626\u201340637","journal-title":"IEEE Access"},{"key":"12173_CR2","doi-asserted-by":"crossref","unstructured":"Bin Ahmad M, Akram A, Asif M, Ur-Rehman S (2014) Using genetic algorithm to minimize false alarms in insider threats detection of information misuse in windows environment. Math Probl Eng 2014:12","DOI":"10.1155\/2014\/179109"},{"issue":"2","key":"12173_CR3","doi-asserted-by":"publisher","first-page":"471","DOI":"10.1109\/JSYST.2016.2558507","volume":"11","author":"B B\u00f6se","year":"2017","unstructured":"B\u00f6se B., Avasarala B, Tirthapura S, Chung Y-Y, Steiner D (2017) Detecting insider threats using radish: a system for real-time anomaly detection in heterogeneous data streams. IEEE Syst J 11(2):471\u2013482","journal-title":"IEEE Syst J"},{"issue":"1","key":"12173_CR4","doi-asserted-by":"publisher","first-page":"280","DOI":"10.1109\/TVCG.2015.2467196","volume":"22","author":"N Cao","year":"2015","unstructured":"Cao N, Shi C, Lin S, Lu J, Lin Y-R, Lin CY (2015) Targetvue: Visual analysis of anomalous user behaviors in online communication systems. IEEE Trans Vis Comput Graph 22(1):280\u2013289","journal-title":"IEEE Trans Vis Comput Graph"},{"key":"12173_CR5","first-page":"13","volume":"9","author":"P Chapman","year":"2000","unstructured":"Chapman P, Clinton J, Kerber R, Khabaza T, Reinartz T, Shearer C, Wirth R, et al. (2000) Crisp-dm 1.0: Step-by-step data mining guide. SPSS inc 9:13","journal-title":"SPSS inc"},{"issue":"3","key":"12173_CR6","doi-asserted-by":"publisher","first-page":"660","DOI":"10.1109\/TCSS.2018.2857473","volume":"5","author":"P Chattopadhyay","year":"2018","unstructured":"Chattopadhyay P, Wang L, Tan Y. -P. (2018) Scenario-based insider threat detection from cyber activities. IEEE Trans Comput Soc Syst 5(3):660\u2013675","journal-title":"IEEE Trans Comput Soc Syst"},{"key":"12173_CR7","unstructured":"Cmu-cert insider threat test dataset. ftp:\/\/ftp.sei.cmu.edu\/pub\/cert-data\/"},{"key":"12173_CR8","doi-asserted-by":"publisher","first-page":"20","DOI":"10.1016\/j.knosys.2018.06.001","volume":"159","author":"G Dhiman","year":"2018","unstructured":"Dhiman G, Kumar V (2018) Emperor penguin optimizer: a bio-inspired algorithm for engineering problems. Knowl-Based Syst 159:20\u201350","journal-title":"Knowl-Based Syst"},{"key":"12173_CR9","unstructured":"Gurucul - insider threat survey report. https:\/\/gurucul.com\/2020-insider-threat-survey-report\/"},{"key":"12173_CR10","doi-asserted-by":"crossref","unstructured":"Iranmanesh SM, Mohammadi M, Akbari A, Nassersharif B (2011) Improving detection rate in intrusion detection systems using fcm clustering to select meaningful landmarks in incremental landmark isomap algorithm. In: International Conference on Theoretical and Mathematical Foundations of Computer Science, pp. 46\u201353 Springer","DOI":"10.1007\/978-3-642-24999-0_7"},{"key":"12173_CR11","doi-asserted-by":"crossref","unstructured":"Izquierdo S, Izquierdo LR (2017) Mamdani fuzzy systems for modelling and simulation: A critical assessment, Available at SSRN 2900827","DOI":"10.2139\/ssrn.2900827"},{"key":"12173_CR12","volume-title":"Cyber defense and situational awareness, vol 62","author":"A Kott","year":"2015","unstructured":"Kott A, Wang C, Erbacher RF (2015) Cyber defense and situational awareness, vol 62. Springer, New York"},{"issue":"3","key":"12173_CR13","doi-asserted-by":"publisher","first-page":"377","DOI":"10.1109\/TPAMI.2006.56","volume":"28","author":"MH Law","year":"2006","unstructured":"Law MH, Jain AK (2006) Incremental nonlinear dimensionality reduction by manifold learning. IEEE transactions on pattern analysis and machine intelligence 28(3):377\u2013391","journal-title":"IEEE transactions on pattern analysis and machine intelligence"},{"key":"12173_CR14","doi-asserted-by":"crossref","unstructured":"Le DC, Khanchi S, Zincir-Heywood AN, Heywood MI (2018) Benchmarking evolutionary computation approaches to insider threat detection. In: Proceedings of the Genetic and Evolutionary Computation Conference. pp 1286\u20131293","DOI":"10.1145\/3205455.3205612"},{"issue":"1","key":"12173_CR15","doi-asserted-by":"publisher","first-page":"49","DOI":"10.1177\/1548512917715342","volume":"15","author":"NO Leslie","year":"2018","unstructured":"Leslie NO, Harang RE, Knachel LP, Kott A (2018) Statistical models for the number of successful cyber intrusions. The Journal of Defense Modeling and Simulation 15(1):49\u201363","journal-title":"The Journal of Defense Modeling and Simulation"},{"key":"12173_CR16","doi-asserted-by":"crossref","unstructured":"Liu L, De Vel O, Chen C, Zhang J, Xiang Y (2018) Anomaly-based insider threat detection using deep autoencoders. In: 2018 IEEE International Conference on Data Mining Workshops (ICDMW), pp. 39\u201348, IEEE","DOI":"10.1109\/ICDMW.2018.00014"},{"key":"12173_CR17","doi-asserted-by":"crossref","unstructured":"Lo O, Buchanan WJ, Griffiths P, Macfarlane R (2018) Distance measurement methods for improved insider threat detection. Secur Commun Netw 2018","DOI":"10.1155\/2018\/5906368"},{"key":"12173_CR18","doi-asserted-by":"crossref","unstructured":"Lu J, Wong RK (2019) Insider threat detection with long short-term memory. In: proceedings of the Australasian Computer Science Week Multiconference, pp. 1\u201310","DOI":"10.1145\/3290688.3290692"},{"key":"12173_CR19","unstructured":"May C, et al. (2017) Insight into insiders: a survey of insider threat taxonomies, analysis, modeling and countermeasures"},{"key":"12173_CR20","doi-asserted-by":"crossref","unstructured":"Meng F, Lou F, Fu Y, Tian Z (2018) Deep learning based attribute classification insider threat detection for data security. In: 2018 IEEE Third International Conference on Data Science in Cyberspace (DSC), pp. 576\u2013581 IEEE","DOI":"10.1109\/DSC.2018.00092"},{"key":"12173_CR21","unstructured":"Ramos J, et al. (2003) Using tf-idf to determine word relevance in document queries. In: proceedings of the first instructional conference on machine learning, 242, pp. 133\u2013142, Piscataway, NJ"},{"key":"12173_CR22","doi-asserted-by":"crossref","unstructured":"Sen S (2015) A survey of intrusion detection systems using evolutionary computation. In: Bio-inspired computation in telecommunications, pp. 73\u201394, Elsevier","DOI":"10.1016\/B978-0-12-801538-4.00004-5"},{"issue":"4","key":"12173_CR23","first-page":"13","volume":"5","author":"C Shearer","year":"2000","unstructured":"Shearer C (2000) The crisp-dm model: the new blueprint for data mining. J data warehous 5(4):13\u201322","journal-title":"J data warehous"},{"key":"12173_CR24","doi-asserted-by":"crossref","unstructured":"Singh M, Mehtre B, Sangeetha S (2019) User behavior profiling using ensemble approach for insider threat detection. In: 2019 IEEE 5th International Conference on Identity, Security, and Behavior Analysis (ISBA), pp. 1\u20138, IEEE","DOI":"10.1109\/ISBA.2019.8778466"},{"key":"12173_CR25","doi-asserted-by":"crossref","unstructured":"Singh M, Mehtre B, Sangeetha S (2020) Insider threat detection based on user behaviour analysis. In: International Conference on Machine Learning, Image Processing, Network Security and Data Sciences, pp. 559\u2013574, Springer","DOI":"10.1007\/978-981-15-6318-8_45"},{"key":"12173_CR26","doi-asserted-by":"crossref","unstructured":"Willett P (2006) The porter stemming algorithm: then and now, Program","DOI":"10.1108\/00330330610681295"},{"key":"12173_CR27","doi-asserted-by":"publisher","first-page":"35365","DOI":"10.1109\/ACCESS.2018.2836950","volume":"6","author":"Y Xin","year":"2018","unstructured":"Xin Y, Kong L, Liu Z, Chen Y, Li Y, Zhu H, Gao M, Hou H, Wang C (2018) Machine learning and deep learning methods for cybersecurity. IEEE Access 6:35365\u201335381","journal-title":"IEEE Access"},{"key":"12173_CR28","doi-asserted-by":"crossref","unstructured":"Yamin MM, Katt B, Sattar K, Ahmad MB (2019) Implementation of insider threat detection system using honeypot based sensors and threat analytics. In: Future of Information and Communication Conference, pp. 801\u2013829, Springer Insiderthreatdetectionwithdeepneuralnetwork(2018)","DOI":"10.1007\/978-3-030-12385-7_56"},{"issue":"8","key":"12173_CR29","first-page":"860","volume":"51","author":"A Zaytsev","year":"2017","unstructured":"ZaytsevA,MalyukA(2017)Identifyingapotentialinsiderusingclassification models.AutomControlComputSci 51(8):860\u2013866","journal-title":"AutomControlComputSci"},{"issue":"8","key":"12173_CR30","first-page":"1666","volume":"10","author":"Z Zhan","year":"2015","unstructured":"ZhanZ,XuM,XuS(2015)Predictingcyberattackrateswithextremevalues. IEEETransactionsonInformationForensicsandSecurity 10(8):1666\u20131677","journal-title":"IEEETransactionsonInformationForensicsandSecurity"},{"key":"12173_CR31","unstructured":"ZhengK-m,QianX,ZhouY,JiaL-j(2009)Intrusiondetectionusingisomap andsupportvectormachine.In: 2009InternationalConferenceonArtificialIntelligence andComputationalIntelligence,3,pp.235\u2013239IEEE"}],"container-title":["Multimedia Tools and Applications"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-12173-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/article\/10.1007\/s11042-022-12173-y\/fulltext.html","content-type":"text\/html","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/link.springer.com\/content\/pdf\/10.1007\/s11042-022-12173-y.pdf","content-type":"application\/pdf","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2022,6,22]],"date-time":"2022-06-22T07:38:05Z","timestamp":1655883485000},"score":1,"resource":{"primary":{"URL":"https:\/\/link.springer.com\/10.1007\/s11042-022-12173-y"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,3,5]]},"references-count":31,"journal-issue":{"issue":"16","published-print":{"date-parts":[[2022,7]]}},"alternative-id":["12173"],"URL":"https:\/\/doi.org\/10.1007\/s11042-022-12173-y","relation":{},"ISSN":["1380-7501","1573-7721"],"issn-type":[{"value":"1380-7501","type":"print"},{"value":"1573-7721","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,3,5]]},"assertion":[{"value":"30 March 2020","order":1,"name":"received","label":"Received","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"28 September 2021","order":2,"name":"revised","label":"Revised","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"7 January 2022","order":3,"name":"accepted","label":"Accepted","group":{"name":"ArticleHistory","label":"Article History"}},{"value":"5 March 2022","order":4,"name":"first_online","label":"First Online","group":{"name":"ArticleHistory","label":"Article History"}}]}}