Research Article

Distance Measurement Methods for Improved Insider Threat Detection

Table 1

CERT r4.2 file description.

FilenameDescription

device.csvConnection and disconnection of removable devices (e.g., USB hard drive) is described in this file.

email.csvContains logs of user emails.

file.csvFile access activity is provided in this file.

logon.csvRelates to user activity based on logging on and logging off on computing devices.

psychometric.csvProvides personality and job satisfaction variables for each of the 1000 simulated users.

LDAPThis folder contains a set of LDAP files which describe the ontology of each simulated user (their role, email, department, supervisor, etc.).