{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T16:51:00Z","timestamp":1784998260351,"version":"3.55.0"},"reference-count":30,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2020,8,31]],"date-time":"2020-08-31T00:00:00Z","timestamp":1598832000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Natural Science Foundation of China","doi-asserted-by":"crossref","award":["U1636215, 61871140, 61872100 and 61572153"],"award-info":[{"award-number":["U1636215, 61871140, 61872100 and 61572153"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Guangdong Province Key Research and Development Plan","award":["2019B010137004"],"award-info":[{"award-number":["2019B010137004"]}]},{"name":"National Key Research and Development Plan","award":["2018YFB0803504"],"award-info":[{"award-number":["2018YFB0803504"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM\/IMS Trans. Data Sci."],"published-print":{"date-parts":[[2020,8,31]]},"abstract":"<jats:p>Recently, the urban network infrastructure has undergone a rapid expansion that is increasingly generating a large quantity of data and transforming our cities into smart cities. However, serious security problems arise with this development with more and more smart devices collecting private information under smart city scenario. In this article, we investigate the task of detecting insiders\u2019 anomalous behaviors to prevent urban big data leakage. Specifically, we characterize a user's daily activities from four perspectives and use several deep learning algorithms (long short-term memory (LSTM) and convolutional LSTM (convLSTM)) to calculate deviations between realistic actions and normalcy of daily behaviors and use multilayer perceptron (MLP) to identify abnormal behaviors according to those deviations. To evaluate the proposed multimodel-based system (MBS), we conducted experiments on the CERT (United States Computer Emergency Readiness Team) dataset. The experimental results show that our proposed MBS has a remarkable ability to learn the normal pattern of users\u2019 daily activities and detect anomalous behaviors.<\/jats:p>","DOI":"10.1145\/3374749","type":"journal-article","created":{"date-parts":[[2020,7,7]],"date-time":"2020-07-07T08:37:20Z","timestamp":1594111040000},"page":"1-19","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":34,"title":["User and Entity Behavior Analysis under Urban Big Data"],"prefix":"10.1145","volume":"1","author":[{"given":"Zhihong","family":"Tian","sequence":"first","affiliation":[{"name":"Cyberspace Institute of Advanced Technology, GuangZhou University, GuangZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Chaochao","family":"Luo","sequence":"additional","affiliation":[{"name":"Venustech established Active Defense Laboratory, Beijing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Hui","family":"Lu","sequence":"additional","affiliation":[{"name":"Cyberspace Institute of Advanced Technology, GuangZhou University, GuangZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Shen","family":"Su","sequence":"additional","affiliation":[{"name":"Cyberspace Institute of Advanced Technology, GuangZhou University, GuangZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Yanbin","family":"Sun","sequence":"additional","affiliation":[{"name":"Cyberspace Institute of Advanced Technology, GuangZhou University, GuangZhou, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Man","family":"Zhang","sequence":"additional","affiliation":[{"name":"Peng Cheng Laboratory, Shenzhen, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2020,9,25]]},"reference":[{"key":"e_1_2_1_1_1","volume-title":"Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 33--44)","author":"Hashem Y.","unstructured":"Y. Hashem, H. Takabi, R. Dantu, and R. Nielsen. 2017, October. A multi-modal neuro-physiological study of malicious insider threats. In Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 33--44). ACM."},{"key":"e_1_2_1_2_1","volume-title":"Proceedings of the ASE Big Data 8 Social Informatics 2015 (p. 28)","author":"Tang B.","unstructured":"B. Tang, Z. Chen, G. Hefferman, T. Wei, H. He, and Q. Yang. 2015, October. A hierarchical distributed fog computing architecture for big data analysis in smart cities. In Proceedings of the ASE Big Data 8 Social Informatics 2015 (p. 28). ACM."},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1109\/TII.2019.2907754"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1186\/s13174-015-0041-5"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/TVT.2019.2910217"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2014.2306328"},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2018.12.054"},{"key":"e_1_2_1_8_1","doi-asserted-by":"crossref","unstructured":"H. Schaffers N. Komninos M. Pallot B. Trousse M. Nilsson and A. Oliveira. 2011 May. Smart cities and the future internet: Towards cooperation frameworks for open innovation. In The Future Internet Assembly (pp. 431--446). Springer Berlin.","DOI":"10.1007\/978-3-642-20898-0_31"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","unstructured":"J. Qiu L. Du D. Zhang S. Su and Z. Tian. 2019. Nei-TTE: Intelligent traffic time estimation based on fine-grained time derivation of road segments for smart city. IEEE Transactions on Industrial Informatics. 2019. DOI:10.1109\/TII.2019.2943906","DOI":"10.1109\/TII.2019.2943906"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.future.2013.01.010"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1109\/MIC.2009.143"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2018.2846624"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks 8 Network Function Virtualization (pp. 29--32)","author":"Pan J.","unstructured":"J. Pan and Z. Yang. 2018, March. Cybersecurity challenges and opportunities in the new edge computing+ IoT world. In Proceedings of the 2018 ACM International Workshop on Security in Software Defined Networks 8 Network Function Virtualization (pp. 29--32). ACM."},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.comcom.2007.04.009"},{"key":"e_1_2_1_15_1","volume-title":"Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1095--1108)","author":"Han Y.","unstructured":"Y. Han, S. Etigowni, H. Liu, S. Zonouz, and A. Petropulu. 2017, 2020, October. Watch me, but don't touch me! Contactless control flow monitoring via electromagnetic emanations. In Proceedings of the 2017 ACM SIGSAC Conference on Computer and Communications Security (pp. 1095--1108). ACM."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ins.2019.04.011"},{"key":"e_1_2_1_17_1","volume-title":"2018 IEEE Security and Privacy Workshops (SPW) (pp. 29--35)","author":"Doshi R.","unstructured":"R. Doshi, N. Apthorpe, and N. Feamster. 2018, May. Machine learning DDoS detection for consumer Internet of Things devices. In 2018 IEEE Security and Privacy Workshops (SPW) (pp. 29--35). IEEE."},{"key":"e_1_2_1_18_1","first-page":"4","article-title":"Aug. Security in wireless sensor networks","volume":"15","author":"Du X.","year":"2008","unstructured":"X. Du and H. H. Chen. 2008, Aug. Security in wireless sensor networks, IEEE Wireless Communications Magazine, 15, 4 (Aug. 2008), pp. 60--66","journal-title":"IEEE Wireless Communications Magazine"},{"key":"e_1_2_1_19_1","unstructured":"The CERT Insider Threat Center. 2016. Common sense guide to mitigating insider threats fifth edition CERT SRI Carnegie Mellon University Tech. Rep. CMU\/SEI-2015-TR-010 2016."},{"key":"e_1_2_1_20_1","unstructured":"National Cybersecurity and Communications Integration Center. 2014. Combating the insider threat The Us Department of homeland security Tech. Rep. 2014."},{"key":"e_1_2_1_21_1","volume-title":"Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats (pp. 75--78)","author":"Kul G.","unstructured":"G. Kul and S. Upadhyaya. 2015, October. A preliminary cyber ontology for insider threats in the financial sector. In Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats (pp. 75--78). ACM."},{"key":"e_1_2_1_22_1","volume-title":"Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats (pp. 105--108)","author":"Agrafiotis I.","unstructured":"I. Agrafiotis, A. Erola, M. Goldsmith, and S. Creese. 2016, October. A tripwire grammar for insider threat detection. In Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats (pp. 105--108). ACM."},{"key":"e_1_2_1_23_1","volume-title":"Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats (pp. 47--56)","author":"Rashid T.","unstructured":"T. Rashid, I. Agrafiotis, and J. R. Nurse. 2016, October. A new take on detecting insider threats: exploring the use of hidden markov models. In Proceedings of the 8th ACM CCS International Workshop on Managing Insider Security Threats (pp. 47--56). ACM."},{"key":"e_1_2_1_24_1","volume-title":"2018 IEEE Security and Privacy Workshops (SPW) (pp. 270--275)","author":"Le D. C.","unstructured":"D. C. Le and A. N. Zincir-Heywood. 2018, May. Evaluating insider threat detection workflow using supervised and unsupervised learning. In 2018 IEEE Security and Privacy Workshops (SPW) (pp. 270--275). IEEE."},{"key":"e_1_2_1_25_1","volume-title":"Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 33--44)","author":"Hashem Y.","unstructured":"Y. Hashem, H. Takabi, R. Dantu, and R. Nielsen. 2017, October. A multi-modal neuro-physiological study of malicious insider threats. In Proceedings of the 2017 International Workshop on Managing Insider Security Threats (pp. 33--44). ACM."},{"key":"e_1_2_1_26_1","volume-title":"Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats (pp. 71--74)","author":"Hashem Y.","unstructured":"Y. Hashem, H. Takabi, M. GhasemiGol, and R. Dantu. 2015, October. Towards insider threat detection using psychophysiological signals. In Proceedings of the 7th ACM CCS International Workshop on Managing Insider Security Threats (pp. 71--74). ACM."},{"key":"e_1_2_1_27_1","doi-asserted-by":"crossref","unstructured":"S. Hochreiter and J. Schmidhuber. 1997. Long short-term memory[J]. Neural Computation 9(8) (1997) 1735--1780.","DOI":"10.1162\/neco.1997.9.8.1735"},{"key":"e_1_2_1_28_1","unstructured":"S. H. I. Xingjian Z. Chen H. Wang D. Y. Yeung W. K. Wong and W. C. Woo. 2015. Convolutional LSTM network: A machine learning approach for precipitation nowcasting. In Advances in Neural Information Processing Systems (pp. 802--810)."},{"key":"e_1_2_1_29_1","unstructured":"https:\/\/resources.sei.cmu.edu\/library\/asset-view.cfm?assetid=508099."},{"key":"e_1_2_1_30_1","volume-title":"2013 IEEE Security and Privacy Workshops (pp. 98--104)","author":"Glasser J.","unstructured":"J. Glasser and B. Lindauer. 2013, May. Bridging the gap: A pragmatic approach to generating insider threat data. In 2013 IEEE Security and Privacy Workshops (pp. 98--104). IEEE."}],"container-title":["ACM\/IMS Transactions on Data Science"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3374749","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3374749","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,4,16]],"date-time":"2026-04-16T13:57:38Z","timestamp":1776347858000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3374749"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2020,8,31]]},"references-count":30,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2020,8,31]]}},"alternative-id":["10.1145\/3374749"],"URL":"https:\/\/doi.org\/10.1145\/3374749","relation":{},"ISSN":["2691-1922"],"issn-type":[{"value":"2691-1922","type":"print"}],"subject":[],"published":{"date-parts":[[2020,8,31]]},"assertion":[{"value":"2019-06-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2019-11-01","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2020-09-25","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}