{"id":"https://openalex.org/W2034200492","doi":"https://doi.org/10.1109/isi.2013.6578813","title":"Layered behavioral trace modeling for threat detection","display_name":"Layered behavioral trace modeling for threat detection","publication_year":2013,"publication_date":"2013-06-01","ids":{"openalex":"https://openalex.org/W2034200492","doi":"https://doi.org/10.1109/isi.2013.6578813","mag":"2034200492"},"language":"en","primary_location":{"id":"doi:10.1109/isi.2013.6578813","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi.2013.6578813","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2013 IEEE International Conference on Intelligence and Security Informatics","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5042882698","display_name":"Rudolph L. Mappus","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]},{"id":"https://openalex.org/I4388482740","display_name":"Georgia Tech Research Institute","ror":"https://ror.org/04qfrh333","country_code":null,"type":"facility","lineage":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]}],"countries":["US"],"is_corresponding":true,"raw_author_name":"Rudolph L. Mappus","raw_affiliation_strings":["Georgia Tech Research Institute, Atlanta, GA, USA","Georgia Tech Research Institute, Atlanta, GA, USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Georgia Tech Research Institute, Atlanta, GA, USA","institution_ids":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]},{"raw_affiliation_string":"Georgia Tech Research Institute, Atlanta, GA, USA#TAB#","institution_ids":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5052396585","display_name":"Erica Briscoe","orcid":null},"institutions":[{"id":"https://openalex.org/I130701444","display_name":"Georgia Institute of Technology","ror":"https://ror.org/01zkghx44","country_code":"US","type":"education","lineage":["https://openalex.org/I130701444"]},{"id":"https://openalex.org/I4388482740","display_name":"Georgia Tech Research Institute","ror":"https://ror.org/04qfrh333","country_code":null,"type":"facility","lineage":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Erica Briscoe","raw_affiliation_strings":["Georgia Tech Research Institute, Atlanta, GA, USA","Georgia Tech Research Institute, Atlanta, GA, USA#TAB#"],"affiliations":[{"raw_affiliation_string":"Georgia Tech Research Institute, Atlanta, GA, USA","institution_ids":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]},{"raw_affiliation_string":"Georgia Tech Research Institute, Atlanta, GA, USA#TAB#","institution_ids":["https://openalex.org/I130701444","https://openalex.org/I4388482740"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":["https://openalex.org/A5042882698"],"corresponding_institution_ids":["https://openalex.org/I130701444","https://openalex.org/I4388482740"],"apc_list":null,"apc_paid":null,"fwci":0.3624,"has_fulltext":false,"cited_by_count":1,"citation_normalized_percentile":{"value":0.64988654,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":94},"biblio":{"volume":null,"issue":null,"first_page":"173","last_page":"175"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9998999834060669,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11512","display_name":"Anomaly Detection Techniques and Applications","score":0.9998000264167786,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9922999739646912,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/insider-threat","display_name":"Insider threat","score":0.900496780872345},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.8136862516403198},{"id":"https://openalex.org/keywords/false-positive-paradox","display_name":"False positive paradox","score":0.7885874509811401},{"id":"https://openalex.org/keywords/trace","display_name":"TRACE (psycholinguistics)","score":0.5785788893699646},{"id":"https://openalex.org/keywords/identification","display_name":"Identification (biology)","score":0.5742961168289185},{"id":"https://openalex.org/keywords/behavioral-pattern","display_name":"Behavioral pattern","score":0.5499788522720337},{"id":"https://openalex.org/keywords/set","display_name":"Set (abstract data type)","score":0.5439607501029968},{"id":"https://openalex.org/keywords/insider","display_name":"Insider","score":0.49489039182662964},{"id":"https://openalex.org/keywords/intrusion-detection-system","display_name":"Intrusion detection system","score":0.44257861375808716},{"id":"https://openalex.org/keywords/behavioral-modeling","display_name":"Behavioral modeling","score":0.42844802141189575},{"id":"https://openalex.org/keywords/activity-detection","display_name":"Activity detection","score":0.4227280616760254},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.4144488573074341},{"id":"https://openalex.org/keywords/data-mining","display_name":"Data mining","score":0.37055811285972595},{"id":"https://openalex.org/keywords/artificial-intelligence","display_name":"Artificial intelligence","score":0.3312695324420929}],"concepts":[{"id":"https://openalex.org/C2776633304","wikidata":"https://www.wikidata.org/wiki/Q6038026","display_name":"Insider threat","level":3,"score":0.900496780872345},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.8136862516403198},{"id":"https://openalex.org/C64869954","wikidata":"https://www.wikidata.org/wiki/Q1859747","display_name":"False positive paradox","level":2,"score":0.7885874509811401},{"id":"https://openalex.org/C75291252","wikidata":"https://www.wikidata.org/wiki/Q1315756","display_name":"TRACE (psycholinguistics)","level":2,"score":0.5785788893699646},{"id":"https://openalex.org/C116834253","wikidata":"https://www.wikidata.org/wiki/Q2039217","display_name":"Identification (biology)","level":2,"score":0.5742961168289185},{"id":"https://openalex.org/C83804111","wikidata":"https://www.wikidata.org/wiki/Q1063558","display_name":"Behavioral pattern","level":2,"score":0.5499788522720337},{"id":"https://openalex.org/C177264268","wikidata":"https://www.wikidata.org/wiki/Q1514741","display_name":"Set (abstract data type)","level":2,"score":0.5439607501029968},{"id":"https://openalex.org/C2778971194","wikidata":"https://www.wikidata.org/wiki/Q1664551","display_name":"Insider","level":2,"score":0.49489039182662964},{"id":"https://openalex.org/C35525427","wikidata":"https://www.wikidata.org/wiki/Q745881","display_name":"Intrusion detection system","level":2,"score":0.44257861375808716},{"id":"https://openalex.org/C78639753","wikidata":"https://www.wikidata.org/wiki/Q3318160","display_name":"Behavioral modeling","level":2,"score":0.42844802141189575},{"id":"https://openalex.org/C2988656282","wikidata":"https://www.wikidata.org/wiki/Q4677630","display_name":"Activity detection","level":2,"score":0.4227280616760254},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.4144488573074341},{"id":"https://openalex.org/C124101348","wikidata":"https://www.wikidata.org/wiki/Q172491","display_name":"Data mining","level":1,"score":0.37055811285972595},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.3312695324420929},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C86803240","wikidata":"https://www.wikidata.org/wiki/Q420","display_name":"Biology","level":0,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C59822182","wikidata":"https://www.wikidata.org/wiki/Q441","display_name":"Botany","level":1,"score":0.0},{"id":"https://openalex.org/C199360897","wikidata":"https://www.wikidata.org/wiki/Q9143","display_name":"Programming language","level":1,"score":0.0},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1109/isi.2013.6578813","is_oa":false,"landing_page_url":"https://doi.org/10.1109/isi.2013.6578813","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"2013 IEEE International Conference on Intelligence and Security Informatics","raw_type":"proceedings-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7300000190734863}],"awards":[],"funders":[],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":20,"referenced_works":["https://openalex.org/W1483307070","https://openalex.org/W1967354722","https://openalex.org/W1986334900","https://openalex.org/W2054549097","https://openalex.org/W2082542916","https://openalex.org/W2098613108","https://openalex.org/W2106353924","https://openalex.org/W2119539043","https://openalex.org/W2122646361","https://openalex.org/W2124817326","https://openalex.org/W2129166692","https://openalex.org/W2144779807","https://openalex.org/W2148061324","https://openalex.org/W2148720028","https://openalex.org/W2152004686","https://openalex.org/W2155146488","https://openalex.org/W2905795134","https://openalex.org/W4246793006","https://openalex.org/W6682030849","https://openalex.org/W6757047819"],"related_works":["https://openalex.org/W2152238375","https://openalex.org/W3088948716","https://openalex.org/W432535052","https://openalex.org/W2488112254","https://openalex.org/W4210491229","https://openalex.org/W4384559558","https://openalex.org/W4285612255","https://openalex.org/W2075878881","https://openalex.org/W2013973943","https://openalex.org/W2354206928"],"abstract_inverted_index":{"A":[0],"fundamental":[1],"problem":[2,34],"in":[3],"detecting":[4],"threats":[5,51],"to":[6,44,78],"security":[7],"by":[8,35,56],"monitoring":[9],"computer":[10],"usage":[11],"is":[12],"the":[13,33,47,101],"high":[14],"number":[15],"of":[16,103,106],"false":[17],"positives":[18],"that":[19,81],"are":[20],"created":[21],"when":[22],"analyzing":[23],"a":[24,67,79,93],"large":[25],"data":[26],"set":[27],"for":[28,46,70,100],"anomalous":[29],"behavior.":[30,84,108],"We":[31,85],"address":[32],"modeling":[36],"user":[37,72],"behavior":[38],"at":[39,74],"multiple":[40,75],"scales":[41,77],"so":[42],"as":[43],"allow":[45],"identification":[48],"potential":[49],"insider":[50],"from":[52],"users'":[53,58],"logged":[54],"activity":[55,59,73],"tracking":[57],"over":[60],"time.":[61],"In":[62],"this":[63],"work,":[64],"we":[65],"apply":[66],"novel":[68],"method":[69,96],"representing":[71],"temporal":[76],"dataset":[80],"contains":[82],"malicious":[83,107],"report":[86],"our":[87],"detection":[88,95],"results":[89],"and":[90],"discuss":[91],"how":[92],"layered":[94],"may":[97],"be":[98],"advantageous":[99],"discovery":[102],"specific":[104],"types":[105]},"counts_by_year":[{"year":2013,"cited_by_count":1}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
