{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T21:18:47Z","timestamp":1776374327355,"version":"3.51.2"},"reference-count":45,"publisher":"Institute of Electrical and Electronics Engineers (IEEE)","issue":"2","license":[{"start":{"date-parts":[[2012,3,1]],"date-time":"2012-03-01T00:00:00Z","timestamp":1330560000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/ieeexplore.ieee.org\/Xplorehelp\/downloads\/license-information\/IEEE.html"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["IEEE Trans. Syst., Man, Cybern. A"],"published-print":{"date-parts":[[2012,3]]},"DOI":"10.1109\/tsmca.2011.2162500","type":"journal-article","created":{"date-parts":[[2011,9,1]],"date-time":"2011-09-01T19:57:09Z","timestamp":1314907029000},"page":"331-347","source":"Crossref","is-referenced-by-count":18,"title":["Intelligence Analyses and the Insider Threat"],"prefix":"10.1109","volume":"42","author":[{"given":"Eugene","family":"Santos","sequence":"first","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Hien","family":"Nguyen","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Fei","family":"Yu","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Keum Joo","family":"Kim","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Deqing","family":"Li","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"John T.","family":"Wilkinson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Adam","family":"Olson","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Jacob","family":"Russell","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Brittany","family":"Clark","sequence":"additional","affiliation":[],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"263","reference":[{"key":"ref39","author":"riding","year":"1998","journal-title":"Cognitive Styles and Learning Strategies Understanding Style Differences in Learning and Behaviors"},{"key":"ref38","first-page":"41","article-title":"An insider threat model for adversary simulation","volume":"2","author":"wood","year":"2000","journal-title":"Proc Res Mitigating Insider Threat Inf Syst"},{"key":"ref33","doi-asserted-by":"publisher","DOI":"10.1177\/154193120304700818"},{"key":"ref32","author":"nguyen","year":"2005","journal-title":"Capturing user intent for information"},{"key":"ref31","first-page":"27","article-title":"Impacts of user modeling on personalization of information retrieval: An evaluation with human intelligence analysts","author":"santos","year":"2005","journal-title":"Proc 4th Workshop Eval Adapt Syst Conjunction With UM"},{"key":"ref30","doi-asserted-by":"publisher","DOI":"10.1177\/154193120404800321"},{"key":"ref37","author":"heuer","year":"1999","journal-title":"Psychology of Intelligence Analysis"},{"key":"ref36","first-page":"548","article-title":"Comparison of conceptual graphs","author":"montes-y-gmez","year":"2000","journal-title":"Proc 3rd MICAI"},{"key":"ref35","author":"manning","year":"2002","journal-title":"Foundations of Statistical Natural Language Processing"},{"key":"ref34","first-page":"111","article-title":"A robust parsing algorithm for link grammars","author":"grinberg","year":"1995","journal-title":"Proc 4th Int l Workshop Parsing Technology"},{"key":"ref10","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1997.601332"},{"key":"ref40","doi-asserted-by":"publisher","DOI":"10.1037\/h0025070"},{"key":"ref11","doi-asserted-by":"publisher","DOI":"10.1109\/SMCSIA.2003.1232400"},{"key":"ref12","doi-asserted-by":"publisher","DOI":"10.1109\/IAW.2005.1495972"},{"key":"ref13","first-page":"49","article-title":"AI lessons learned from experiments in insider threat detection","author":"liu","year":"2006","journal-title":"Proc AAAI Spring Symp"},{"key":"ref14","first-page":"326","article-title":"On the detection of anomalous system call arguments","author":"kruegel","year":"2003","journal-title":"Proc ESORICS"},{"key":"ref15","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1214\/ss\/998929476","article-title":"Computer intrusion: Detecting masquerades","volume":"16","author":"schonlau","year":"2001","journal-title":"Stat Sci"},{"key":"ref16","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2002.1028903"},{"key":"ref17","first-page":"398","article-title":"Masquerade detection based on SVM and sequence-based user commands profile","author":"seo","year":"2007","journal-title":"Proc 2nd ACM Symp Inf Comput Commun Security"},{"key":"ref18","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2003.1209911"},{"key":"ref19","author":"greenberg","year":"1988","journal-title":"Using Unix Collected Traces of 168 Users"},{"key":"ref28","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-77322-3_2"},{"key":"ref4","doi-asserted-by":"crossref","first-page":"151","DOI":"10.3233\/JCS-980109","article-title":"Intrusion detection using sequences of system calls","volume":"6","author":"hofmeyr","year":"1998","journal-title":"J Comput Security"},{"key":"ref27","doi-asserted-by":"crossref","first-page":"201","DOI":"10.1007\/978-3-540-25952-7_15","article-title":"Composite role-based monitoring (CRBM) for countering insider threats","author":"park","year":"2004","journal-title":"1st NSF\/NIJ Symp Intell Security Informatics"},{"key":"ref3","doi-asserted-by":"crossref","first-page":"69","DOI":"10.1007\/978-0-387-77322-3_5","author":"salem","year":"2008","journal-title":"Insider Attack and Cyber Security"},{"key":"ref6","doi-asserted-by":"publisher","DOI":"10.1109\/SECPRI.1996.502675"},{"key":"ref29","first-page":"4","article-title":"Insiders and insider threats&#x2014;An overview of definitions and mitigation techniques","volume":"2","author":"hunker","year":"2011","journal-title":"J Wireless Mobile Netw Ubiquitous Comput Dependable Appl"},{"key":"ref5","first-page":"118","article-title":"Learning classifiers for misuse detection using a bag of system calls representation","author":"kang","year":"2005","journal-title":"Proc 6th Annu IEEE SMC IAW"},{"key":"ref8","first-page":"21","article-title":"Understanding precision in host based intrusion detection","author":"sharif","year":"2007","journal-title":"Proc RAID Int Symp"},{"key":"ref7","first-page":"1","article-title":"Exploiting execution context for the detection of anomalous system calls","author":"mutz","year":"2007","journal-title":"Proc RAID Int Symp"},{"key":"ref2","doi-asserted-by":"publisher","DOI":"10.1109\/WIIAT.2008.376"},{"key":"ref9","doi-asserted-by":"publisher","DOI":"10.1109\/65.283931"},{"key":"ref1","author":"riding","year":"2000","journal-title":"Cognitive Styles"},{"key":"ref20","first-page":"1","author":"kirkpatrick","year":"2009","journal-title":"An architecture for contextual insider threat detection"},{"key":"ref45","doi-asserted-by":"publisher","DOI":"10.1016\/j.lindif.2009.06.003"},{"key":"ref22","first-page":"304","article-title":"Security policies to mitigate insider threat in the document control domain","author":"suranjan","year":"2004","journal-title":"Proc Comput Security Appl Conf"},{"key":"ref21","first-page":"31","article-title":"Display-only file server: A solution against information theft due to insider attack","author":"yang","year":"2004","journal-title":"Proc ACM Workshop Digital Rights Management"},{"key":"ref42","doi-asserted-by":"publisher","DOI":"10.3102\/00346543047001001"},{"key":"ref24","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-25952-7_41"},{"key":"ref41","doi-asserted-by":"publisher","DOI":"10.1111\/j.2044-8279.1976.tb02305.x"},{"key":"ref23","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-74320-0_8"},{"key":"ref44","doi-asserted-by":"publisher","DOI":"10.1037\/0021-9010.61.5.622"},{"key":"ref26","doi-asserted-by":"publisher","DOI":"10.1007\/978-0-387-71613-8_19"},{"key":"ref43","author":"hudson","year":"1966","journal-title":"Contrary Imaginations A Psychological Study of the English Schoolboy"},{"key":"ref25","doi-asserted-by":"crossref","first-page":"492","DOI":"10.1007\/978-3-540-25952-7_40","article-title":"Semantic analysis for monitoring insider threats","author":"symonenko","year":"2004","journal-title":"1st NSF\/NIJ Symp Intell Security Informatics"}],"container-title":["IEEE Transactions on Systems, Man, and Cybernetics - Part A: Systems and Humans"],"original-title":[],"link":[{"URL":"http:\/\/xplorestaging.ieee.org\/ielx5\/3468\/6151939\/06006537.pdf?arnumber=6006537","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2021,10,10]],"date-time":"2021-10-10T23:47:48Z","timestamp":1633909668000},"score":1,"resource":{"primary":{"URL":"http:\/\/ieeexplore.ieee.org\/document\/6006537\/"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2012,3]]},"references-count":45,"journal-issue":{"issue":"2"},"URL":"https:\/\/doi.org\/10.1109\/tsmca.2011.2162500","relation":{},"ISSN":["1083-4427","1558-2426"],"issn-type":[{"value":"1083-4427","type":"print"},{"value":"1558-2426","type":"electronic"}],"subject":[],"published":{"date-parts":[[2012,3]]}}}