{"id":"https://openalex.org/W2376065778","doi":"https://doi.org/10.1142/s0218194016500169","title":"Knowledge-Driven User Behavior Pattern Discovery for System Security Enhancement","display_name":"Knowledge-Driven User Behavior Pattern Discovery for System Security Enhancement","publication_year":2016,"publication_date":"2016-04-01","ids":{"openalex":"https://openalex.org/W2376065778","doi":"https://doi.org/10.1142/s0218194016500169","mag":"2376065778"},"language":"en","primary_location":{"id":"doi:10.1142/s0218194016500169","is_oa":false,"landing_page_url":"https://doi.org/10.1142/s0218194016500169","pdf_url":null,"source":{"id":"https://openalex.org/S131442419","display_name":"International Journal of Software Engineering and Knowledge Engineering","issn_l":"0218-1940","issn":["0218-1940","1793-6403"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319815","host_organization_name":"World Scientific","host_organization_lineage":["https://openalex.org/P4310319815"],"host_organization_lineage_names":["World Scientific"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Journal of Software Engineering and Knowledge Engineering","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5101534785","display_name":"Weina Ma","orcid":"https://orcid.org/0000-0001-7864-0081"},"institutions":[{"id":"https://openalex.org/I39470171","display_name":"University of Ontario Institute of Technology","ror":"https://ror.org/016zre027","country_code":"CA","type":"education","lineage":["https://openalex.org/I39470171"]}],"countries":["CA"],"is_corresponding":true,"raw_author_name":"Weina Ma","raw_affiliation_strings":["Department of Electrical, Computer, and Software Engineering, University of Ontario Institute of Technology, Oshawa, Ontario L1H 7K4, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Electrical, Computer, and Software Engineering, University of Ontario Institute of Technology, Oshawa, Ontario L1H 7K4, Canada","institution_ids":["https://openalex.org/I39470171"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5055220196","display_name":"Kamran Sartipi","orcid":"https://orcid.org/0000-0002-3588-5991"},"institutions":[{"id":"https://openalex.org/I39470171","display_name":"University of Ontario Institute of Technology","ror":"https://ror.org/016zre027","country_code":"CA","type":"education","lineage":["https://openalex.org/I39470171"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Kamran Sartipi","raw_affiliation_strings":["Department of Electrical, Computer, and Software Engineering, University of Ontario Institute of Technology, Oshawa, Ontario L1H 7K4, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Electrical, Computer, and Software Engineering, University of Ontario Institute of Technology, Oshawa, Ontario L1H 7K4, Canada","institution_ids":["https://openalex.org/I39470171"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5068562764","display_name":"Duane Bender","orcid":"https://orcid.org/0000-0001-6923-2844"},"institutions":[{"id":"https://openalex.org/I184578258","display_name":"Mohawk College","ror":"https://ror.org/03embeq77","country_code":"CA","type":"education","lineage":["https://openalex.org/I184578258"]}],"countries":["CA"],"is_corresponding":false,"raw_author_name":"Duane Bender","raw_affiliation_strings":["Department of Electrical and Computer Engineering Technology, Mohawk College, Hamilton, Ontario L8N 3T2, Canada"],"affiliations":[{"raw_affiliation_string":"Department of Electrical and Computer Engineering Technology, Mohawk College, Hamilton, Ontario L8N 3T2, Canada","institution_ids":["https://openalex.org/I184578258"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":3,"corresponding_author_ids":["https://openalex.org/A5101534785"],"corresponding_institution_ids":["https://openalex.org/I39470171"],"apc_list":null,"apc_paid":null,"fwci":1.9904,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.89216654,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":97},"biblio":{"volume":"26","issue":"03","first_page":"379","last_page":"404"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10538","display_name":"Data Mining Algorithms and Applications","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10538","display_name":"Data Mining Algorithms and Applications","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T12761","display_name":"Data Stream Mining Techniques","score":0.9940000176429749,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10799","display_name":"Data Visualization and Analytics","score":0.9912999868392944,"subfield":{"id":"https://openalex.org/subfields/1707","display_name":"Computer Vision and Pattern Recognition"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.7950685620307922},{"id":"https://openalex.org/keywords/insider-threat","display_name":"Insider threat","score":0.7594404220581055},{"id":"https://openalex.org/keywords/insider","display_name":"Insider","score":0.6115865707397461},{"id":"https://openalex.org/keywords/process","display_name":"Process (computing)","score":0.5479859113693237},{"id":"https://openalex.org/keywords/domain","display_name":"Domain (mathematical analysis)","score":0.5352998375892639},{"id":"https://openalex.org/keywords/audit","display_name":"Audit","score":0.5250948667526245},{"id":"https://openalex.org/keywords/system-administrator","display_name":"System administrator","score":0.434002548456192},{"id":"https://openalex.org/keywords/domain-knowledge","display_name":"Domain knowledge","score":0.4228220582008362},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.385293573141098},{"id":"https://openalex.org/keywords/software-engineering","display_name":"Software engineering","score":0.2332177460193634}],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.7950685620307922},{"id":"https://openalex.org/C2776633304","wikidata":"https://www.wikidata.org/wiki/Q6038026","display_name":"Insider threat","level":3,"score":0.7594404220581055},{"id":"https://openalex.org/C2778971194","wikidata":"https://www.wikidata.org/wiki/Q1664551","display_name":"Insider","level":2,"score":0.6115865707397461},{"id":"https://openalex.org/C98045186","wikidata":"https://www.wikidata.org/wiki/Q205663","display_name":"Process (computing)","level":2,"score":0.5479859113693237},{"id":"https://openalex.org/C36503486","wikidata":"https://www.wikidata.org/wiki/Q11235244","display_name":"Domain (mathematical analysis)","level":2,"score":0.5352998375892639},{"id":"https://openalex.org/C199521495","wikidata":"https://www.wikidata.org/wiki/Q181487","display_name":"Audit","level":2,"score":0.5250948667526245},{"id":"https://openalex.org/C2780814629","wikidata":"https://www.wikidata.org/wiki/Q327353","display_name":"System administrator","level":2,"score":0.434002548456192},{"id":"https://openalex.org/C207685749","wikidata":"https://www.wikidata.org/wiki/Q2088941","display_name":"Domain knowledge","level":2,"score":0.4228220582008362},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.385293573141098},{"id":"https://openalex.org/C115903868","wikidata":"https://www.wikidata.org/wiki/Q80993","display_name":"Software engineering","level":1,"score":0.2332177460193634},{"id":"https://openalex.org/C187736073","wikidata":"https://www.wikidata.org/wiki/Q2920921","display_name":"Management","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C162324750","wikidata":"https://www.wikidata.org/wiki/Q8134","display_name":"Economics","level":0,"score":0.0},{"id":"https://openalex.org/C111919701","wikidata":"https://www.wikidata.org/wiki/Q9135","display_name":"Operating system","level":1,"score":0.0},{"id":"https://openalex.org/C134306372","wikidata":"https://www.wikidata.org/wiki/Q7754","display_name":"Mathematical analysis","level":1,"score":0.0},{"id":"https://openalex.org/C33923547","wikidata":"https://www.wikidata.org/wiki/Q395","display_name":"Mathematics","level":0,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1142/s0218194016500169","is_oa":false,"landing_page_url":"https://doi.org/10.1142/s0218194016500169","pdf_url":null,"source":{"id":"https://openalex.org/S131442419","display_name":"International Journal of Software Engineering and Knowledge Engineering","issn_l":"0218-1940","issn":["0218-1940","1793-6403"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319815","host_organization_name":"World Scientific","host_organization_lineage":["https://openalex.org/P4310319815"],"host_organization_lineage_names":["World Scientific"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"International Journal of Software Engineering and Knowledge Engineering","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[{"display_name":"Peace, Justice and strong institutions","id":"https://metadata.un.org/sdg/16","score":0.7099999785423279}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":14,"referenced_works":["https://openalex.org/W110264556","https://openalex.org/W1557127976","https://openalex.org/W1921112198","https://openalex.org/W1964241047","https://openalex.org/W1974037989","https://openalex.org/W2096017373","https://openalex.org/W2105162149","https://openalex.org/W2110893883","https://openalex.org/W2139422684","https://openalex.org/W2151829113","https://openalex.org/W2158454296","https://openalex.org/W2998574808","https://openalex.org/W3207440052","https://openalex.org/W4253585025"],"related_works":["https://openalex.org/W2766781562","https://openalex.org/W4205304595","https://openalex.org/W2979782961","https://openalex.org/W308359497","https://openalex.org/W1499596878","https://openalex.org/W3136170567","https://openalex.org/W2947769183","https://openalex.org/W2018332730","https://openalex.org/W4387194049","https://openalex.org/W223792481"],"abstract_inverted_index":{"Insider":[0],"threads":[1],"posed":[2],"by":[3,39,109],"authorized":[4,19],"users":[5,20],"have":[6],"caused":[7],"significant":[8],"security":[9,95],"and":[10,28,47,103,116,119],"privacy":[11],"risks":[12],"to":[13,69,92,123,136,146],"IT":[14],"systems.":[15],"The":[16],"behavior":[17,78,107],"of":[18,42,50,59,88,101],"in":[21,33],"using":[22],"system":[23,43,67,75,84,117],"services":[24],"must":[25],"be":[26],"monitored":[27],"controlled.":[29],"However,":[30],"the":[31,40,45,74,83,93,99,127,138,148],"administrators":[32,68,85],"large":[34],"distributed":[35,142],"systems":[36,63,145],"are":[37,86],"overwhelmed":[38],"number":[41],"users,":[44],"complexity":[46],"changing":[48],"nature":[49],"user":[51],"activities.":[52],"This":[53],"paper":[54],"presents":[55],"a":[56],"new":[57],"generation":[58],"intelligent":[60],"decision":[61],"support":[62],"that":[64],"effectively":[65],"assist":[66],"get":[70],"deep":[71],"insight":[72],"into":[73],"users\u2019":[76],"dynamic":[77,90],"patterns.":[79],"With":[80],"these":[81],"patterns,":[82],"capable":[87],"constructing":[89],"refinement":[91],"existing":[94],"policies.":[96],"We":[97],"explore":[98],"method":[100],"interactively":[102],"incrementally":[104],"extracting":[105],"user\u2019s":[106],"patterns":[108],"combining":[110],"data":[111],"mining":[112],"techniques":[113],"with":[114],"domain":[115],"knowledge,":[118],"applying":[120],"such":[121],"knowledge":[122],"provide":[124],"recommendations":[125],"throughout":[126],"whole":[128],"process.":[129],"A":[130],"prototype":[131],"tool":[132],"has":[133],"been":[134],"developed":[135],"analyze":[137],"audit":[139],"logs":[140],"from":[141],"medical":[143],"imaging":[144],"validate":[147],"proposed":[149],"approach.":[150]},"counts_by_year":[{"year":2025,"cited_by_count":1},{"year":2022,"cited_by_count":1},{"year":2018,"cited_by_count":3}],"updated_date":"2025-11-06T03:46:38.306776","created_date":"2025-10-10T00:00:00"}
