{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,10,26]],"date-time":"2025-10-26T14:33:04Z","timestamp":1761489184716,"version":"3.28.0"},"reference-count":11,"publisher":"IEEE","content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":[],"published-print":{"date-parts":[[2013,5]]},"DOI":"10.1109\/spw.2013.32","type":"proceedings-article","created":{"date-parts":[[2013,7,25]],"date-time":"2013-07-25T17:07:43Z","timestamp":1374772063000},"page":"60-67","source":"Crossref","is-referenced-by-count":28,"title":["Use of Domain Knowledge to Detect Insider Threats in Computer Activities"],"prefix":"10.1109","author":[{"given":"William T.","family":"Young","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Henry G.","family":"Goldberg","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alex","family":"Memory","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"James F.","family":"Sartain","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Ted E.","family":"Senator","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"journal-title":"The CERT Guide to Insider Threats How to Detect Prevent and Respond to Information Technology Crimes","year":"2012","author":"cappelli","key":"3"},{"journal-title":"Understanding the Insider Threat Proceedings of a March 2004 Workshop","year":"2004","author":"brackney","key":"2"},{"journal-title":"SureView Proactive Endpoint Information Protection","year":"2013","key":"10"},{"year":"0","author":"jensen","key":"1"},{"journal-title":"Insider Threat Study Computer System Sabotage in Critical Infrastructure Sectors","year":"2005","author":"keeney","key":"7"},{"journal-title":"Insider Threat Study Illicit Cyber Activity in the Government Sector","year":"2008","author":"kowalski","key":"6"},{"journal-title":"Out of the Ordinary Finding Hidden Threats by Analyzing Behavior","year":"2004","author":"hollywood","key":"5"},{"key":"4","article-title":"Insider Threat Detection Using a Graph-based Approach","volume":"6","author":"eberle","year":"2011","journal-title":"Journal of Applied Security Research"},{"key":"9","doi-asserted-by":"crossref","DOI":"10.1007\/978-0-387-77322-3_5","article-title":"A Survey of Insider Attack Detection Research","author":"salem","year":"2008","journal-title":"Insider Attack and Cyber Security Beyond the Hacker"},{"key":"8","doi-asserted-by":"crossref","DOI":"10.21236\/ADA580209","author":"lee","year":"2012","journal-title":"Fast Anomaly Discovery Given Duplicates"},{"key":"11","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.37"}],"event":{"name":"2013 IEEE CS Security and Privacy Workshops (SPW2013)","start":{"date-parts":[[2013,5,23]]},"location":"San Francisco, CA","end":{"date-parts":[[2013,5,24]]}},"container-title":["2013 IEEE Security and Privacy Workshops"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx7\/6564486\/6565207\/06565230.pdf?arnumber=6565230","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2019,7,19]],"date-time":"2019-07-19T12:00:26Z","timestamp":1563537626000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6565230\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2013,5]]},"references-count":11,"URL":"https:\/\/doi.org\/10.1109\/spw.2013.32","relation":{},"subject":[],"published":{"date-parts":[[2013,5]]}}}