Research Article

Distance Measurement Methods for Improved Insider Threat Detection

Table 5

Full evaluation results.

UsernameScenarioAnswer filenameDLJaccardCosineHMM

AAM06581r4.2-1-AAM0658.csvFalse424242
AJR09321r4.2-1-AJR0932.csv37363636
BDV01681r4.2-1-BDV0168.csvFalse30False31
BIH07451r4.2-1-BIH0745.csvFalseFalseFalseFalse
BLS06781r4.2-1-BLS0678.csvFalseFalseFalseFalse
BTL02261r4.2-1-BTL0226.csvFalse40False40
CAH09361r4.2-1-CAH0936.csvFalse32FalseFalse
DCH08431r4.2-1-DCH0843.csv57FalseFalseFalse
EHB08241r4.2-1-EHB0824.csv30292929
EHD05841r4.2-1-EHD0584.csv40393939
FMG05271r4.2-1-FMG0527.csvFalseFalseFalse53
FTM04061r4.2-1-FTM0406.csvFalse474747
GHL04601r4.2-1-GHL0460.csv45FalseFalseFalse
HJB07421r4.2-1-HJB0742.csvFalse46False46
JMB03081r4.2-1-JMB0308.csvFalse282828
JRG02071r4.2-1-JRG0207.csvFalse555555
KLH05961r4.2-1-KLH0596.csv59FalseFalseFalse
KPC00731r4.2-1-KPC0073.csvFalse272727
LJR05231r4.2-1-LJR0523.csvFalse303030
LQC04791r4.2-1-LQC0479.csvFalse37False37
MAR09551r4.2-1-MAR0955.csvFalseFalseFalseFalse
MAS00251r4.2-1-MAS0025.csvFalseFalseFalse39
MCF06001r4.2-1-MCF0600.csv38383838
MYD09781r4.2-1-MYD0978.csv51FalseFalseFalse
PPF04351r4.2-1-PPF0435.csvFalseFalse58False
RAB05891r4.2-1-RAB0589.csv37FalseFalseFalse
RGG00641r4.2-1-RGG0064.csvFalse424242
RKD06041r4.2-1-RKD0604.csvFalseFalseFalseFalse
TAP05511r4.2-1-TAP0551.csvFalse42False42
WDD03661r4.2-1-WDD0366.csvFalse60FalseFalse
AAF05352r4.2-2-AAF0535.csvFalseFalse3332
ABC01742r4.2-2-ABC0174.csvFalseFalse5049
AKR00572r4.2-2-AKR0057.csvFalseFalseFalse46
CCL00682r4.2-2-CCL0068.csv60False5758
CEJ01092r4.2-2-CEJ0109.csvFalseFalse6464
CQW06522r4.2-2-CQW0652.csvFalseFalse64False
DIB02852r4.2-2-DIB0285.csvFalseFalse3736
DRR01622r4.2-2-DRR0162.csv48False5050
EDB07142r4.2-2-EDB0714.csv47False4648
EGD01322r4.2-2-EGD0132.csv37False3737
FSC06012r4.2-2-FSC0601.csvFalseFalseFalse62
HBO04132r4.2-2-HBO0413.csvFalseFalse6363
HXL09682r4.2-2-HXL0968.csv40False3541
IJM07762r4.2-2-IJM0776.csv32FalseFalse33
IKR04012r4.2-2-IKR0401.csvFalseFalse5657
IUB05652r4.2-2-IUB0565.csv47False4646
JJM02032r4.2-2-JJM0203.csvFalseFalse4040
KRL05012r4.2-2-KRL0501.csv51FalseFalse53
LCC08192r4.2-2-LCC0819.csv28False3030
MDH05802r4.2-2-MDH0580.csv58FalseFalse59
MOS00472r4.2-2-MOS0047.csvFalseFalseFalseFalse
NWT00982r4.2-2-NWT0098.csvFalseFalse6564
PNL03012r4.2-2-PNL0301.csv31FalseFalse30
PSF01332r4.2-2-PSF0133.csv31False3137
RAR07252r4.2-2-RAR0725.csv28FalseFalse31
RHL09922r4.2-2-RHL0992.csv36False3234
RMW05422r4.2-2-RMW0542.csv3327False30
TNM09612r4.2-2-TNM0961.csvFalseFalse4948
VSS01542r4.2-2-VSS0154.csvFalseFalseFalse43
XHW04982r4.2-2-XHW0498.csv36False3337
BBS00393r4.2-3-BBS0039.csvFalse32FalseFalse
BSS03693r4.2-3-BSS0369.csvFalseFalseFalseFalse
CCA00463r4.2-3-CCA0046.csvFalseFalseFalseFalse
CSC02173r4.2-3-CSC0217.csv23232323
GTD02193r4.2-3-GTD0219.csvFalseFalseFalseFalse
JGT02213r4.2-3-JGT0221.csv2828False28
JLM03643r4.2-3-JLM0364.csvFalse69FalseFalse
JTM02233r4.2-3-JTM0223.csvFalse29FalseFalse
MPM02203r4.2-3-MPM0220.csvFalseFalseFalseFalse
MSO02223r4.2-3-MSO0222.csvFalse49FalseFalse

This table gives the full results of evaluation against all 70 insiders against each of the three distance measurement techniques described in this paper. An entry of “False” indicates that the technique failed to detect the correct week in which insider threat occurred while a numerical value denotes the week in which the highest measurement value was detected for an attack.