{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,1,30]],"date-time":"2026-01-30T01:49:32Z","timestamp":1769737772867,"version":"3.49.0"},"publisher-location":"New York, NY, USA","reference-count":51,"publisher":"ACM","license":[{"start":{"date-parts":[[2015,10,16]],"date-time":"2015-10-16T00:00:00Z","timestamp":1444953600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2015,10,16]]},"DOI":"10.1145\/2808783.2808789","type":"proceedings-article","created":{"date-parts":[[2015,10,6]],"date-time":"2015-10-06T15:22:12Z","timestamp":1444144932000},"page":"29-39","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":2,"title":["Novel Insider Threat Techniques"],"prefix":"10.1145","author":[{"given":"Aniello","family":"Castiglione","sequence":"first","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Arcangelo","family":"Castiglione","sequence":"additional","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Alfredo","family":"De Santis","sequence":"additional","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Barbara","family":"Masucci","sequence":"additional","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Francesco","family":"Palmieri","sequence":"additional","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"given":"Raffaele","family":"Pizzolante","sequence":"additional","affiliation":[{"name":"University of Salerno, Fisciano, Italy"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2015,10,16]]},"reference":[{"key":"e_1_3_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1109\/INCoS.2011.129"},{"key":"e_1_3_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.1109\/BWCCA.2011.62"},{"key":"e_1_3_2_1_3_1","volume-title":"Portable RealVNC Server. Accessed","author":"Weber Andreas","year":"2015","unstructured":"Andreas Weber . Portable RealVNC Server. Accessed May 2015 . Andreas Weber. Portable RealVNC Server. Accessed May 2015."},{"key":"e_1_3_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2013.08.001"},{"key":"e_1_3_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2007.70241"},{"key":"e_1_3_2_1_6_1","volume-title":"The KeyNote trust-management system version 2","author":"Blaze M.","year":"1999","unstructured":"M. Blaze and A. D. Keromytis . The KeyNote trust-management system version 2 . 1999 . M. Blaze and A. D. Keromytis. The KeyNote trust-management system version 2. 1999."},{"key":"e_1_3_2_1_7_1","volume-title":"Default Judgment.","author":"Ingersoll Buchanan","year":"2011","unstructured":"Buchanan Ingersoll & Rooney PC. Destruction of Electronic Evidence, Discovery Misconduct Lead to$1 Million Fine , Default Judgment. June 13, 2011 . Buchanan Ingersoll & Rooney PC. Destruction of Electronic Evidence, Discovery Misconduct Lead to$1 Million Fine, Default Judgment. June 13, 2011."},{"key":"e_1_3_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/BWCCA.2011.64"},{"key":"e_1_3_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1109\/ACCESS.2013.2260817"},{"key":"e_1_3_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1109\/IMIS.2012.127"},{"key":"e_1_3_2_1_11_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"430","DOI":"10.1007\/978-3-642-32498-7_32","volume-title":"G. Quirchmayr, J. Basl, I. You","author":"Castiglione A.","year":"2012","unstructured":"A. Castiglione , G. Cattaneo , R. De Prisco , A. De Santis , and K. Yim . How to Forge a Digital Alibi on Mac OS X . In G. Quirchmayr, J. Basl, I. You , L. Xu, and E. Weippl, editors, Multidisciplinary Research and Practice for Information Systems, volume 7465 of Lecture Notes in Computer Science , pages 430 -- 444 . Springer Berlin Heidelberg , 2012 . A. Castiglione, G. Cattaneo, R. De Prisco, A. De Santis, and K. Yim. How to Forge a Digital Alibi on Mac OS X. In G. Quirchmayr, J. Basl, I. You, L. Xu, and E. Weippl, editors, Multidisciplinary Research and Practice for Information Systems, volume 7465 of Lecture Notes in Computer Science, pages 430--444. Springer Berlin Heidelberg, 2012."},{"key":"e_1_3_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-03964-5_6"},{"key":"e_1_3_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/NBiS.2014.106"},{"key":"e_1_3_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.jss.2006.07.006"},{"key":"e_1_3_2_1_15_1","unstructured":"CERT. Insider Threat Center. Accessed May 2015.  CERT. Insider Threat Center. Accessed May 2015."},{"key":"e_1_3_2_1_16_1","volume-title":"Ubiquitous Computing, and Dependable Applications, 4(4):1--19","author":"Claycomb W.","year":"2013","unstructured":"W. Claycomb and C. Huth . A method for characterizing sociotechnical events related to insider threat sabotage. Journal of Wireless Mobile Networks , Ubiquitous Computing, and Dependable Applications, 4(4):1--19 , 2013 . W. Claycomb and C. Huth. A method for characterizing sociotechnical events related to insider threat sabotage. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 4(4):1--19, 2013."},{"key":"e_1_3_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC.2012.113"},{"key":"e_1_3_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1002\/sec.362"},{"key":"e_1_3_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCSim.2013.6641428"},{"key":"e_1_3_2_1_20_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"359","DOI":"10.1007\/978-3-642-23300-5_28","volume-title":"Automated Construction of a False Digital Alibi","author":"Santis A. De","year":"2011","unstructured":"A. De Santis , A. Castiglione , G. Cattaneo , G. De Maio , and M. Ianulardo . Automated Construction of a False Digital Alibi . In A. M. Tjoa, G. Quirchmayr, I. You, and L. Xu, editors, MURPBES, volume 6908 of Lecture Notes in Computer Science , pages 359 -- 373 . Springer , 2011 . A. De Santis, A. Castiglione, G. Cattaneo, G. De Maio, and M. Ianulardo. Automated Construction of a False Digital Alibi. In A. M. Tjoa, G. Quirchmayr, I. You, and L. Xu, editors, MURPBES, volume 6908 of Lecture Notes in Computer Science, pages 359--373. Springer, 2011."},{"key":"e_1_3_2_1_21_1","doi-asserted-by":"publisher","DOI":"10.1109\/35.312844"},{"key":"e_1_3_2_1_22_1","volume-title":"forensics community. Forensics Wiki. Accessed","author":"D.","year":"2015","unstructured":"D. forensics community. Forensics Wiki. Accessed May 2015 . D. forensics community. Forensics Wiki. Accessed May 2015."},{"key":"e_1_3_2_1_23_1","series-title":"Lecture Notes in Computer Science","doi-asserted-by":"crossref","first-page":"361","DOI":"10.1007\/978-3-642-40588-4_25","volume-title":"A denial of service attack to GSM networks via attach procedure","author":"Gobbo N.","year":"2013","unstructured":"N. Gobbo , A. Merlo , and M. Migliardi . A denial of service attack to GSM networks via attach procedure . In A. Cuzzocrea, C. Kittl, D. E. Simos, E. R. Weippl, L. Xu, A. Cuzzocrea, C. Kittl, D. E. Simos, E. R. Weippl, and L. Xu, editors, Security Engineering and Intelligence Informatics - CD-ARES 2013 Workshops : MoCrySEn and SeCIHD, Regensburg, Germany, September 2--6, 2013. Proceedings, volume 8128 of Lecture Notes in Computer Science , pages 361 -- 376 . Springer , 2013. N. Gobbo, A. Merlo, and M. Migliardi. A denial of service attack to GSM networks via attach procedure. In A. Cuzzocrea, C. Kittl, D. E. Simos, E. R. Weippl, L. Xu, A. Cuzzocrea, C. Kittl, D. E. Simos, E. R. Weippl, and L. Xu, editors, Security Engineering and Intelligence Informatics - CD-ARES 2013 Workshops: MoCrySEn and SeCIHD, Regensburg, Germany, September 2--6, 2013. Proceedings, volume 8128 of Lecture Notes in Computer Science, pages 361--376. Springer, 2013."},{"key":"e_1_3_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2008.8"},{"key":"e_1_3_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.clsr.2013.05.014"},{"key":"e_1_3_2_1_26_1","volume-title":"Java Remote Desktop (jrDesktop). Accessed","year":"2015","unstructured":"jrDesktop. Java Remote Desktop (jrDesktop). Accessed May 2015 . jrDesktop. Java Remote Desktop (jrDesktop). Accessed May 2015."},{"key":"e_1_3_2_1_27_1","doi-asserted-by":"crossref","unstructured":"M. Kandias K. Galbogini L. Mitrou and D. Gritzalis. Insiders trapped in the mirror reveal themselves in social media. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 7873 LNCS:220--235 2013.  M. Kandias K. Galbogini L. Mitrou and D. Gritzalis. Insiders trapped in the mirror reveal themselves in social media. Lecture Notes in Computer Science (including subseries Lecture Notes in Artificial Intelligence and Lecture Notes in Bioinformatics) 7873 LNCS:220--235 2013.","DOI":"10.1007\/978-3-642-38631-2_17"},{"key":"e_1_3_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2013.10.005"},{"key":"e_1_3_2_1_29_1","volume-title":"Ubiquitous Computing, and Dependable Applications, 4(4):20--37","author":"Legg P.","year":"2013","unstructured":"P. Legg , N. Moffat , J. Nurse , J. Happa , I. Agrafiotis , M. Goldsmith , and S. Creese . Towards a conceptual model and reasoning structure for insider threat detection. Journal of Wireless Mobile Networks , Ubiquitous Computing, and Dependable Applications, 4(4):20--37 , 2013 . P. Legg, N. Moffat, J. Nurse, J. Happa, I. Agrafiotis, M. Goldsmith, and S. Creese. Towards a conceptual model and reasoning structure for insider threat detection. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 4(4):20--37, 2013."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/2517840.2517868"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1109\/HPCSim.2014.6903732"},{"key":"e_1_3_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2014.2315198"},{"key":"e_1_3_2_1_33_1","volume-title":"Resources and Tools for IT Professionals | TechNet. Accessed","year":"2015","unstructured":"Microsoft. Resources and Tools for IT Professionals | TechNet. Accessed May 2015 . Microsoft. Resources and Tools for IT Professionals | TechNet. Accessed May 2015."},{"key":"e_1_3_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.5555\/2595805.2595811"},{"key":"e_1_3_2_1_35_1","doi-asserted-by":"publisher","DOI":"10.1145\/2493190.2493223"},{"key":"e_1_3_2_1_36_1","unstructured":"Nuclear Winter Crew. Bandook. Accessed May 2015.  Nuclear Winter Crew. Bandook. Accessed May 2015."},{"key":"e_1_3_2_1_37_1","unstructured":"opengear. Ip-kvm 1001. Accessed May 2015.  opengear. Ip-kvm 1001. Accessed May 2015."},{"key":"e_1_3_2_1_38_1","volume-title":"Department of Justice. Computer Records and the Federal Rules of Evidence","author":"Kerr Orin S.","year":"2001","unstructured":"Orin S. Kerr , U. S. Department of Justice. Computer Records and the Federal Rules of Evidence . March 2001 . Orin S. Kerr, U.S. Department of Justice. Computer Records and the Federal Rules of Evidence. March 2001."},{"key":"e_1_3_2_1_39_1","unstructured":"S. Padrepietro. DEFT Linux - Computer Forensics Live CD Accessed May 2015.  S. Padrepietro. DEFT Linux - Computer Forensics Live CD Accessed May 2015."},{"key":"e_1_3_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/2414456.2414511"},{"key":"e_1_3_2_1_41_1","unstructured":"PRO Group. Prorat. Accessed May 2015.  PRO Group. Prorat. Accessed May 2015."},{"key":"e_1_3_2_1_42_1","volume-title":"Ubiquitous Computing, and Dependable Applications, 4(4):38--48","author":"Probst C.","year":"2013","unstructured":"C. Probst and R. Hansen . Reachability-based impact as a measure for insiderness. Journal of Wireless Mobile Networks , Ubiquitous Computing, and Dependable Applications, 4(4):38--48 , 2013 . C. Probst and R. Hansen. Reachability-based impact as a measure for insiderness. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 4(4):38--48, 2013."},{"key":"e_1_3_2_1_43_1","volume-title":"Trusted computer system evaluation criteria","author":"Qiu L.","year":"1985","unstructured":"L. Qiu , Y. Zhang , F. Wang , M. Kyung , and H. R. Mahajan . Trusted computer system evaluation criteria . In National Computer Security Center . Citeseer, 1985 . L. Qiu, Y. Zhang, F. Wang, M. Kyung, and H. R. Mahajan. Trusted computer system evaluation criteria. In National Computer Security Center. Citeseer, 1985."},{"key":"e_1_3_2_1_44_1","volume-title":"Ubiquitous Computing, and Dependable Applications, 3(1--2):99--119","author":"Sasaki T.","year":"2012","unstructured":"T. Sasaki . A framework for detecting insider threats using psychological triggers. Journal of Wireless Mobile Networks , Ubiquitous Computing, and Dependable Applications, 3(1--2):99--119 , 2012 . T. Sasaki. A framework for detecting insider threats using psychological triggers. Journal of Wireless Mobile Networks, Ubiquitous Computing, and Dependable Applications, 3(1--2):99--119, 2012."},{"key":"e_1_3_2_1_45_1","doi-asserted-by":"publisher","DOI":"10.1016\/S0167-4048(02)01009-X"},{"key":"e_1_3_2_1_46_1","doi-asserted-by":"publisher","DOI":"10.1109\/SERE.2012.40"},{"key":"e_1_3_2_1_47_1","volume-title":"Operating System Concepts","author":"Silberschatz A.","year":"2008","unstructured":"A. Silberschatz , P. B. Galvin , and G. Gagne . Operating System Concepts . Wiley Publishing , 8 th edition, 2008 . A. Silberschatz, P. B. Galvin, and G. Gagne. Operating System Concepts. Wiley Publishing, 8th edition, 2008.","edition":"8"},{"key":"e_1_3_2_1_48_1","volume-title":"Remote Access & Online Meetings. Accessed","author":"Free Remote Control TeamViewer","year":"2015","unstructured":"TeamViewer GmbH. TeamViewer - Free Remote Control , Remote Access & Online Meetings. Accessed April 2015 . TeamViewer GmbH. TeamViewer - Free Remote Control, Remote Access & Online Meetings. Accessed April 2015."},{"key":"e_1_3_2_1_49_1","doi-asserted-by":"publisher","DOI":"10.1145\/2594502"},{"key":"e_1_3_2_1_50_1","volume-title":"2015 Vormetric Insider Threat Report. Accessed","author":"Security Vormetric Data","year":"2015","unstructured":"Vormetric Data Security . 2015 Vormetric Insider Threat Report. Accessed June 2015 . Vormetric Data Security. 2015 Vormetric Insider Threat Report. Accessed June 2015."},{"key":"e_1_3_2_1_51_1","doi-asserted-by":"publisher","DOI":"10.1109\/SPW.2013.32"}],"event":{"name":"CCS'15: The 22nd ACM Conference on Computer and Communications Security","location":"Denver Colorado USA","acronym":"CCS'15","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"]},"container-title":["Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808783.2808789","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2808783.2808789","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T05:48:14Z","timestamp":1750225694000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2808783.2808789"}},"subtitle":["Automation and Generation of Ad Hoc Digital Evidence"],"short-title":[],"issued":{"date-parts":[[2015,10,16]]},"references-count":51,"alternative-id":["10.1145\/2808783.2808789","10.1145\/2808783"],"URL":"https:\/\/doi.org\/10.1145\/2808783.2808789","relation":{},"subject":[],"published":{"date-parts":[[2015,10,16]]},"assertion":[{"value":"2015-10-16","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}