{"id":"https://openalex.org/W2042587773","doi":"https://doi.org/10.1145/2535813.2535825","title":"Information behaving badly","display_name":"Information behaving badly","publication_year":2013,"publication_date":"2013-09-09","ids":{"openalex":"https://openalex.org/W2042587773","doi":"https://doi.org/10.1145/2535813.2535825","mag":"2042587773"},"language":"en","primary_location":{"id":"doi:10.1145/2535813.2535825","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2535813.2535825","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2013 New Security Paradigms Workshop","raw_type":"proceedings-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5017384306","display_name":"Julie Boxwell Ard","orcid":null},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Julie Boxwell Ard","raw_affiliation_strings":["University of California at Davis, Davis, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California at Davis, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5053448222","display_name":"Matt Bishop","orcid":"https://orcid.org/0000-0002-7301-7060"},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Matt Bishop","raw_affiliation_strings":["University of California at Davis, Davis, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California at Davis, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5109880287","display_name":"Carrie Gates","orcid":null},"institutions":[],"countries":[],"is_corresponding":false,"raw_author_name":"Carrie Gates","raw_affiliation_strings":["CA Labs, New York, NY, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"CA Labs, New York, NY, USA","institution_ids":[]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5077620868","display_name":"Michael Xin Sun","orcid":null},"institutions":[{"id":"https://openalex.org/I84218800","display_name":"University of California, Davis","ror":"https://ror.org/05rrcem69","country_code":"US","type":"education","lineage":["https://openalex.org/I84218800"]}],"countries":["US"],"is_corresponding":false,"raw_author_name":"Michael Xin Sun","raw_affiliation_strings":["University of California at Davis, Davis, CA, USA"],"raw_orcid":null,"affiliations":[{"raw_affiliation_string":"University of California at Davis, Davis, CA, USA","institution_ids":["https://openalex.org/I84218800"]}]}],"institutions":[],"countries_distinct_count":1,"institutions_distinct_count":4,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":1.1318,"has_fulltext":false,"cited_by_count":5,"citation_normalized_percentile":{"value":0.81114601,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":{"min":89,"max":96},"biblio":{"volume":null,"issue":null,"first_page":"107","last_page":"118"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T10400","display_name":"Network Security and Intrusion Detection","score":0.9995999932289124,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.998199999332428,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11241","display_name":"Advanced Malware Detection Techniques","score":0.9944999814033508,"subfield":{"id":"https://openalex.org/subfields/1711","display_name":"Signal Processing"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/insider-threat","display_name":"Insider threat","score":0.8882419466972351},{"id":"https://openalex.org/keywords/workflow","display_name":"Workflow","score":0.8137338161468506},{"id":"https://openalex.org/keywords/computer-science","display_name":"Computer science","score":0.6986662149429321},{"id":"https://openalex.org/keywords/insider","display_name":"Insider","score":0.6462395787239075},{"id":"https://openalex.org/keywords/action","display_name":"Action (physics)","score":0.6067685484886169},{"id":"https://openalex.org/keywords/information-flow","display_name":"Information flow","score":0.5240768790245056},{"id":"https://openalex.org/keywords/information-leakage","display_name":"Information leakage","score":0.5145377516746521},{"id":"https://openalex.org/keywords/data-science","display_name":"Data science","score":0.4112258553504944},{"id":"https://openalex.org/keywords/computer-security","display_name":"Computer security","score":0.37883245944976807},{"id":"https://openalex.org/keywords/database","display_name":"Database","score":0.15035855770111084}],"concepts":[{"id":"https://openalex.org/C2776633304","wikidata":"https://www.wikidata.org/wiki/Q6038026","display_name":"Insider threat","level":3,"score":0.8882419466972351},{"id":"https://openalex.org/C177212765","wikidata":"https://www.wikidata.org/wiki/Q627335","display_name":"Workflow","level":2,"score":0.8137338161468506},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.6986662149429321},{"id":"https://openalex.org/C2778971194","wikidata":"https://www.wikidata.org/wiki/Q1664551","display_name":"Insider","level":2,"score":0.6462395787239075},{"id":"https://openalex.org/C2780791683","wikidata":"https://www.wikidata.org/wiki/Q846785","display_name":"Action (physics)","level":2,"score":0.6067685484886169},{"id":"https://openalex.org/C2779136372","wikidata":"https://www.wikidata.org/wiki/Q10283002","display_name":"Information flow","level":2,"score":0.5240768790245056},{"id":"https://openalex.org/C2779201187","wikidata":"https://www.wikidata.org/wiki/Q2775060","display_name":"Information leakage","level":2,"score":0.5145377516746521},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.4112258553504944},{"id":"https://openalex.org/C38652104","wikidata":"https://www.wikidata.org/wiki/Q3510521","display_name":"Computer security","level":1,"score":0.37883245944976807},{"id":"https://openalex.org/C77088390","wikidata":"https://www.wikidata.org/wiki/Q8513","display_name":"Database","level":1,"score":0.15035855770111084},{"id":"https://openalex.org/C62520636","wikidata":"https://www.wikidata.org/wiki/Q944","display_name":"Quantum mechanics","level":1,"score":0.0},{"id":"https://openalex.org/C17744445","wikidata":"https://www.wikidata.org/wiki/Q36442","display_name":"Political science","level":0,"score":0.0},{"id":"https://openalex.org/C41895202","wikidata":"https://www.wikidata.org/wiki/Q8162","display_name":"Linguistics","level":1,"score":0.0},{"id":"https://openalex.org/C199539241","wikidata":"https://www.wikidata.org/wiki/Q7748","display_name":"Law","level":1,"score":0.0},{"id":"https://openalex.org/C121332964","wikidata":"https://www.wikidata.org/wiki/Q413","display_name":"Physics","level":0,"score":0.0},{"id":"https://openalex.org/C138885662","wikidata":"https://www.wikidata.org/wiki/Q5891","display_name":"Philosophy","level":0,"score":0.0}],"mesh":[],"locations_count":4,"locations":[{"id":"doi:10.1145/2535813.2535825","is_oa":false,"landing_page_url":"https://doi.org/10.1145/2535813.2535825","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"Proceedings of the 2013 New Security Paradigms Workshop","raw_type":"proceedings-article"},{"id":"pmh:oai:CiteSeerX.psu:10.1.1.434.6600","is_oa":false,"landing_page_url":"http://citeseerx.ist.psu.edu/viewdoc/summary?doi=10.1.1.434.6600","pdf_url":null,"source":null,"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"http://www.nspw.org/papers/2013/nspw2013-ard.pdf","raw_type":"text"},{"id":"pmh:oai:escholarship.org/ark:/13030/qt5cc455fs","is_oa":false,"landing_page_url":"https://escholarship.org/uc/item/5cc455fs","pdf_url":null,"source":{"id":"https://openalex.org/S4306400115","display_name":"eScholarship (California Digital Library)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2801248553","host_organization_name":"California Digital Library","host_organization_lineage":["https://openalex.org/I2801248553"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"","raw_type":"chapter"},{"id":"pmh:qt5cc455fs","is_oa":false,"landing_page_url":"http://www.escholarship.org/uc/item/5cc455fs","pdf_url":null,"source":{"id":"https://openalex.org/S4306400115","display_name":"eScholarship (California Digital Library)","issn_l":null,"issn":null,"is_oa":false,"is_in_doaj":false,"is_core":false,"host_organization":"https://openalex.org/I2801248553","host_organization_name":"California Digital Library","host_organization_lineage":["https://openalex.org/I2801248553"],"host_organization_lineage_names":[],"type":"repository"},"license":null,"license_id":null,"version":"submittedVersion","is_accepted":false,"is_published":false,"raw_source_name":"Ard, Julie B.; Bishop, Matt; Gates, Carrie; &amp; Sun, Michael X.(2013). Information Behaving Badly. In Proceedings of the 2013 New Security Paradigms Workshop. UC Davis: Retrieved from: http://www.escholarship.org/uc/item/5cc455fs","raw_type":"article"}],"best_oa_location":null,"sustainable_development_goals":[{"id":"https://metadata.un.org/sdg/16","score":0.7300000190734863,"display_name":"Peace, Justice and strong institutions"}],"awards":[],"funders":[],"has_content":{"grobid_xml":false,"pdf":false},"content_urls":null,"referenced_works_count":26,"referenced_works":["https://openalex.org/W132347231","https://openalex.org/W175854469","https://openalex.org/W1490658580","https://openalex.org/W1528748720","https://openalex.org/W1552694902","https://openalex.org/W1587877048","https://openalex.org/W1603920809","https://openalex.org/W1985987493","https://openalex.org/W1986294018","https://openalex.org/W2011910480","https://openalex.org/W2043978338","https://openalex.org/W2054075152","https://openalex.org/W2063423504","https://openalex.org/W2087922528","https://openalex.org/W2095772265","https://openalex.org/W2097090328","https://openalex.org/W2121717903","https://openalex.org/W2131689821","https://openalex.org/W2134937538","https://openalex.org/W2141427753","https://openalex.org/W2153437389","https://openalex.org/W2167985173","https://openalex.org/W2237291032","https://openalex.org/W2733628661","https://openalex.org/W3016356276","https://openalex.org/W4230145224"],"related_works":["https://openalex.org/W2766781562","https://openalex.org/W4205304595","https://openalex.org/W2979782961","https://openalex.org/W308359497","https://openalex.org/W1499596878","https://openalex.org/W3136170567","https://openalex.org/W2947769183","https://openalex.org/W4387194049","https://openalex.org/W2018332730","https://openalex.org/W2286217954"],"abstract_inverted_index":{"Traditionally,":[0],"insider":[1],"threat":[2],"detection":[3],"has":[4],"focused":[5],"on":[6,19],"observing":[7,54,58],"human":[8,55],"actors":[9,23],"--":[10,24],"or,":[11],"more":[12],"precisely,":[13],"computer":[14],"accounts":[15],"and":[16,80],"processes":[17],"acting":[18],"behalf":[20],"of":[21,74],"those":[22],"to":[25,57],"model":[26],"their":[27],"\"normal\"":[28],"behavior,":[29],"then":[30],"determine":[31],"if":[32,41],"they":[33],"have":[34],"performed":[35],"some":[36],"anomalous":[37],"action":[38,43],"and,":[39],"further,":[40],"that":[42,71,81],"is":[44],"malicious.":[45],"In":[46],"this":[47],"paper,":[48],"we":[49],"shift":[50],"the":[51],"paradigm":[52],"from":[53,85],"behavior":[56,60],"information":[59],"by":[61],"modeling":[62],"how":[63],"documents":[64,75],"flow":[65],"through":[66],"an":[67],"organization.":[68],"We":[69],"hypothesize":[70],"similar":[72,78],"types":[73],"will":[76],"exhibit":[77],"workflows,":[79],"a":[82],"document":[83],"deviating":[84],"its":[86],"expected":[87],"workflow":[88],"indicates":[89],"potential":[90],"data":[91],"leakage.":[92]},"counts_by_year":[{"year":2020,"cited_by_count":1},{"year":2018,"cited_by_count":1},{"year":2016,"cited_by_count":1},{"year":2014,"cited_by_count":2}],"updated_date":"2026-06-11T09:08:48.828518","created_date":"2025-10-10T00:00:00"}
