{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T20:49:55Z","timestamp":1774558195761,"version":"3.50.1"},"reference-count":61,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","license":[{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-029"},{"start":{"date-parts":[[2026,1,1]],"date-time":"2026-01-01T00:00:00Z","timestamp":1767225600000},"content-version":"stm-asf","delay-in-days":0,"URL":"https:\/\/doi.org\/10.15223\/policy-037"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans.Inform.Forensic Secur."],"published-print":{"date-parts":[[2026]]},"DOI":"10.1109\/tifs.2026.3675443","type":"journal-article","created":{"date-parts":[[2026,3,18]],"date-time":"2026-03-18T19:37:50Z","timestamp":1773862670000},"page":"3153-3168","source":"Crossref","is-referenced-by-count":0,"title":["Mitigating Insider-Facilitated Advanced Persistent Threat: A Three-Player Differential Game Approach"],"prefix":"10.1109","volume":"21","author":[{"ORCID":"https:\/\/orcid.org\/0009-0006-5184-5849","authenticated-orcid":false,"given":"Yang","family":"Qin","sequence":"first","affiliation":[{"name":"School of Big Data and Software Engineering, Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-9229-5787","authenticated-orcid":false,"given":"Lu-Xing","family":"Yang","sequence":"additional","affiliation":[{"name":"Deakin Cyber Research and Innovation Center, School of Information Technology, Deakin University, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-3273-1233","authenticated-orcid":false,"given":"Xiaofan","family":"Yang","sequence":"additional","affiliation":[{"name":"School of Big Data and Software Engineering, Chongqing University, Chongqing, China"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-1583-641X","authenticated-orcid":false,"given":"Gang","family":"Li","sequence":"additional","affiliation":[{"name":"Deakin Cyber Research and Innovation Center, School of Information Technology, Deakin University, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6143-6850","authenticated-orcid":false,"given":"Robin","family":"Doss","sequence":"additional","affiliation":[{"name":"Deakin Cyber Research and Innovation Center, School of Information Technology, Deakin University, Melbourne, VIC, Australia"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref1","volume-title":"Advanced Persistent Threat: Understanding the Danger and How to Protect Your Organization","author":"Cole","year":"2012"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1145\/3303771"},{"key":"ref3","volume-title":"2024 Insider Threat Report","year":"2024"},{"key":"ref4","doi-asserted-by":"publisher","DOI":"10.1109\/INFOCOM.2015.7218444"},{"key":"ref5","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2011.67"},{"key":"ref6","volume-title":"The CERT Guide To Insider Threats: How to Prevent, Detect, and Respond To Information Technology Crimes","author":"Cappelli","year":"2012"},{"key":"ref7","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2024.3353929"},{"key":"ref8","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3135639"},{"key":"ref9","first-page":"3313","article-title":"Unveiling the hunter-gatherers: Exploring threat hunting practices and challenges in cyber defense","volume-title":"Proc. 33rd USENIX Secur. Symp.","author":"Badva"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3299519"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1631\/FITEE.1800573"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/MCOM.001.2300224"},{"key":"ref13","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3396390"},{"key":"ref14","doi-asserted-by":"publisher","DOI":"10.1109\/msec.2024.3492132"},{"key":"ref15","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2024.3378972"},{"key":"ref16","volume-title":"Technical Requirements for the ArcSight Platform","year":"2021"},{"key":"ref17","first-page":"2783","article-title":"99% false positives: A qualitative study of SOC analysts\u2019 perspectives on security alarms","volume-title":"Proc. 31st USENIX Secur. Symp.","author":"Alahmadi"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-44374-4"},{"key":"ref19","doi-asserted-by":"publisher","DOI":"10.1007\/s11432-022-3777-y"},{"key":"ref20","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104190"},{"key":"ref21","doi-asserted-by":"publisher","DOI":"10.1007\/s13235-022-00428-0"},{"key":"ref22","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2020.3029898"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1142\/S2301385024410152"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2024.3397196"},{"key":"ref25","doi-asserted-by":"publisher","DOI":"10.1007\/s00145-012-9134-5"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-12601-2_10"},{"key":"ref27","doi-asserted-by":"publisher","DOI":"10.1109\/JSAC.2017.2659418"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1109\/TCSS.2024.3443174"},{"key":"ref29","doi-asserted-by":"publisher","DOI":"10.1016\/j.iot.2025.101522"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1109\/MILCOM.2015.7357413"},{"key":"ref31","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2021.3065504"},{"key":"ref32","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3284564"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2017.2734904"},{"key":"ref34","doi-asserted-by":"publisher","DOI":"10.1109\/TNET.2019.2912847"},{"key":"ref35","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2018.2885251"},{"key":"ref36","doi-asserted-by":"publisher","DOI":"10.1109\/TNSE.2020.3040247"},{"key":"ref37","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2024.104003"},{"key":"ref38","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2023.3318954"},{"key":"ref39","volume-title":"CrowdStrike 2025 Global Threat Report","year":"2025"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1016\/S1361-3723(15)30066-X"},{"key":"ref41","first-page":"113","article-title":"Intelligence-driven computer network defense informed by analysis of adversary campaigns and intrusion kill chains","author":"Hutchins","year":"2011","journal-title":"Leading Issues in Information Warfare and Security Research"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2020.2971484"},{"key":"ref43","doi-asserted-by":"publisher","DOI":"10.1109\/TIFS.2025.3541890"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1145\/581271.581274"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1007\/s10796-010-9265-x"},{"key":"ref46","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejor.2021.03.025"},{"key":"ref47","volume-title":"Numerical Solution of Ordinary Differential Equations","author":"Atkinson","year":"2011"},{"key":"ref48","doi-asserted-by":"publisher","DOI":"10.1007\/s10589-011-9454-7"},{"key":"ref49","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-05078-1"},{"key":"ref50","doi-asserted-by":"publisher","DOI":"10.1145\/3510548.3519368"},{"key":"ref51","doi-asserted-by":"publisher","DOI":"10.1257\/jep.27.1.173"},{"key":"ref52","volume-title":"VAST Challenge Dataset","year":"2013"},{"key":"ref53","doi-asserted-by":"publisher","DOI":"10.1145\/3450569.3463573"},{"key":"ref54","volume-title":"A Realistic Cyber Defense Dataset"},{"key":"ref55","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2019.03.024"},{"key":"ref56","doi-asserted-by":"publisher","DOI":"10.1016\/j.ejor.2011.12.035"},{"key":"ref57","doi-asserted-by":"publisher","DOI":"10.1109\/COMST.2023.3273282"},{"key":"ref58","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2021.3130944"},{"key":"ref59","doi-asserted-by":"publisher","DOI":"10.1109\/TNSM.2021.3056999"},{"key":"ref60","doi-asserted-by":"publisher","DOI":"10.1098\/rstb.2021.0495"},{"key":"ref61","doi-asserted-by":"publisher","DOI":"10.1016\/j.cosrev.2020.100343"}],"container-title":["IEEE Transactions on Information Forensics and Security"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx8\/10206\/11313711\/11442692.pdf?arnumber=11442692","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,3,26]],"date-time":"2026-03-26T19:49:07Z","timestamp":1774554547000},"score":1,"resource":{"primary":{"URL":"https:\/\/ieeexplore.ieee.org\/document\/11442692\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026]]},"references-count":61,"URL":"https:\/\/doi.org\/10.1109\/tifs.2026.3675443","relation":{},"ISSN":["1556-6013","1556-6021"],"issn-type":[{"value":"1556-6013","type":"print"},{"value":"1556-6021","type":"electronic"}],"subject":[],"published":{"date-parts":[[2026]]}}}