<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Developing an Ontology for Individual and Organizational Sociotechnical Indicators of Insider Threat Risk</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Frank L. Greitzer</string-name>
          <email>Frank@PsyberAnalytix.com</email>
          <xref ref-type="aff" rid="aff4">4</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Muhammad Imran</string-name>
          <email>mimran4@gmu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Justin Purl</string-name>
          <email>JPurl@humrro.org</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Elise T. Axelrad</string-name>
          <email>eaxelrad@innovativedecisions.com</email>
          <xref ref-type="aff" rid="aff3">3</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Yung Mei Leong</string-name>
          <email>y.leong03@gmail.com</email>
          <xref ref-type="aff" rid="aff2">2</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>D.E. (Sunny) Becker</string-name>
          <email>sbecker@humrro.org</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Kathryn B. Laskey</string-name>
          <email>klaskey@gmu.edu</email>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Paul J. Sticha</string-name>
          <email>psticha@humrro.org</email>
          <xref ref-type="aff" rid="aff1">1</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>George Mason University</institution>
          ,
          <addr-line>Fairfax, VA</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
        <aff id="aff1">
          <label>1</label>
          <institution>Human Resources Research Organization</institution>
          ,
          <addr-line>Alexandria, VA</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
        <aff id="aff2">
          <label>2</label>
          <institution>Independent Consultant</institution>
          ,
          <addr-line>Hyattsville, MD</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
        <aff id="aff3">
          <label>3</label>
          <institution>Innovative Decisions, Inc.</institution>
          ,
          <addr-line>Vienna, VA</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
        <aff id="aff4">
          <label>4</label>
          <institution>PsyberAnalytix</institution>
          ,
          <addr-line>Richland WA</addr-line>
          ,
          <country country="US">USA</country>
        </aff>
      </contrib-group>
      <pub-date>
        <year>2016</year>
      </pub-date>
      <abstract>
        <p>-Human behavioral factors are fundamental to understanding, detecting and mitigating insider threats, but to date insufficiently represented in a formal ontology. We report on the design and development of an ontology that emphasizes individual and organizational sociotechnical factors, and incorporates technical indicators from previous work. We compare our ontology with previous research and describe use cases to demonstrate how the ontology may be applied. Our work advances current efforts toward development of a comprehensive knowledge base to support advanced reasoning for insider threat mitigation.</p>
      </abstract>
      <kwd-group>
        <kwd>insider threat</kwd>
        <kwd>sociotechnical indicators ontology</kwd>
        <kwd>domain knowledge representation</kwd>
        <kwd>SME knowledge modeling</kwd>
        <kwd>human behavioral modeling</kwd>
        <kwd>domain knowledge sharing</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>-</title>
      <p>INTRODUCTION</p>
      <p>
        Government and corporate organizations alike recognize
the serious threat posed by insiders who seek to destroy, steal
or leak confidential information, or act in ways that expose the
organization to outside attacks. A widely accepted definition of
the insider threat is “a current or former employee, contractor,
or other business partner who has or had authorized access to
an organization’s network, system, or data and who
intentionally (or unintentionally) exceeds or misuses that
access to negatively affect the confidentiality, integrity, or
availability of the organization’s information or information
systems” [
        <xref ref-type="bibr" rid="ref1">1</xref>
        ]. More generally, the insider threat may be defined
in terms of internal risks to physical and human assets as well
as organizational information. In light of recent government
initiatives, Executive Order 13587 [
        <xref ref-type="bibr" rid="ref2">2</xref>
        ], and the National Insider
Threat Policy that specifies minimum standards for establishing
an insider threat program, there is increasing acknowledgment
of the need to develop formal frameworks to represent and
analyze vast amounts of data that may be collected by insider
threat monitoring and mitigation systems. There is a notable
lack of standards within the insider threat domain to assist in
developing, describing, testing, and sharing techniques and
Research reported here was supported under IARPA contract
201616031400006. The content is solely the responsibility of the authors and does
not necessarily represent the official views of the U.S. Government.
methods for detecting and preventing insider threats [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ]. The
present research is directed toward a systematic and
comprehensive representation of concepts in the insider threat
domain that will support reasoning and threat assessment
models.
      </p>
      <p>II.</p>
    </sec>
    <sec id="sec-2">
      <title>BACKGROUND</title>
    </sec>
    <sec id="sec-3">
      <title>Research on insider threat has sought to develop models</title>
      <p>and tools to identify individuals who pose increased insider
threat risk. Most mitigation approaches focus more narrowly on
(a) detecting unauthorized user activity and anomalous activity
that may be malicious; and (b) preventing data exfiltration.
Typical approaches attempt to prevent unauthorized access
through the use of firewalls, passwords, and encryption. That
is, they are primarily based on the tools and technology used to
thwart external attacks. Unfortunately, these security measures
will not prevent authorized access by an insider.</p>
      <p>
        Because a key element of insider threat is a “trusted”
perpetrator with authorized access to organizational assets,
monitoring and analysis approaches should not only address
suspicious host/network activities (identifying so-called
technical indicators) but also seek to identify broader aspects of
human behavior, motivation, and intent that may characterize
malicious insider threats. Thus, as noted in [4], approaches
should seek to identify attack-related behaviors that include
deliberate markers, preparatory behaviors, correlated usage
patterns, and even verbal behavior and personality traits, all of
which can be pieced together to detect potential insider threats.
While a number of researchers [5-9] recommend including
behavioral indicators that may be accessible to organizations
prior to an attack, tools and methods that incorporate formal
representations of these human behavioral factors are rare
(exceptions are models described in [
        <xref ref-type="bibr" rid="ref10 ref11 ref9">10-12</xref>
        ]). The research and
operational security communities require a comprehensive
knowledge base of technical and behavioral indicators to
stimulate the development of more effective insider threat
mitigation systems. Existing ontologies include a knowledge
base for technical indicators of insider threat [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ][
        <xref ref-type="bibr" rid="ref12">13</xref>
        ] and a
human factors oriented ontology for cybersecurity risk [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]; our
work extends [
        <xref ref-type="bibr" rid="ref12">13</xref>
        ] and complements [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ] by further specifying
individual human and organizational sociotechnical factors.
      </p>
      <p>III.</p>
      <p>OBJECTIVES</p>
      <p>The objective of this research is to develop a formal
representation of our current understanding of factors
underlying insider threats, particularly relating to individual
behavioral and psychological indicators and constructs
reflecting organizational factors. The work to date complements and
extends extant insider threat ontology frameworks. First, it adds
substantial detail (depth) to existing insider threat ontology
frameworks that focus on cyber/technical constructs. Second, it
defines formal ontological representations of individual and
organizational sociotechnical constructs, which are
insufficiently represented in current ontological frameworks. The use of a
formal, standardized language (ontology) for expressing
knowledge about the insider threat domain facilitates
information sharing across the insider threat research
community and supports model development. A longer term
goal is to inform the development of ontology-based reasoning
systems and models to support insider threat detection and
mitigation. Adopting and using more comprehensive, formal
ontological representations will also facilitate the systematic
construction of scenarios that may be used in exercising and
validating insider threat detection models.</p>
      <p>IV.</p>
      <p>APPROACH</p>
    </sec>
    <sec id="sec-4">
      <title>Our approach consisted of (a) developing a hierarchical</title>
      <p>
        taxonomy for insider threat risk that can be applied generally to
all types of organizations; and (b) migrating the taxonomy into
a formal ontology for insider threat risk. Care was taken to
compare our representation with existing frameworks
(particularly the ontology developed by Carnegie Mellon
University's Computer Emergency Response Team CERT
[
        <xref ref-type="bibr" rid="ref12">13</xref>
        ]) to maximize consistency and interoperability among
formulations across the research community. Our approach to
ontology development seeks to extend the ontological
framework by incorporating probabilistic methods to express
and reason with uncertainty, i.e., this work will inform the
development of a probabilistic ontology to support reasoning
about insider threat risk.
      </p>
      <sec id="sec-4-1">
        <title>A. Taxonomy Development</title>
        <p>A well-defined taxonomy provides an initial hierarchy of
domain concepts as a starting point for our insider threat
ontology. The taxonomy is based on a systematic review, analysis
and synthesis of existing research, case studies and guidelines
that have been produced by the insider threat research
community. Continually being expanded at the leaf nodes, the
current taxonomy is 6-7 levels deep. There are 262 unique
factors (leaf nodes) defined across the entire taxonomy: a total of
223 constructs defined for the individual factors and 39 for the
organizational factors. Our class structure overall contains
more than 350 constructs.</p>
        <p>
          At the highest level we distinguish individual human
factors from organizational factors. Individual human factors
reflect behaviors, attitudes, personal issues, sociocultural or
ideological factors, and various biographical factors that may
indicate increased risk. The individual level also differentiates
psychological traits from dynamic states, consistent with
findings that these two constructs are reliably distinct despite their
admitted overlap (e.g., [
          <xref ref-type="bibr" rid="ref14 ref15">15-16</xref>
          ]) and with the diverse body of
psychological research that hinges on (e.g., [
          <xref ref-type="bibr" rid="ref16 ref17 ref18">17-19</xref>
          ]) or
capitalizes on (e.g., [
          <xref ref-type="bibr" rid="ref19 ref20">20-21</xref>
          ]) that distinction. This detailed branch of
the taxonomy reflects a substantial body of work by a diverse
set of researchers and practitioners focusing on psychosocial
factors underlying insider threats (e.g., [5], [7-9], [
          <xref ref-type="bibr" rid="ref21 ref22 ref23 ref24 ref25 ref26 ref27 ref28 ref29 ref30 ref31 ref32">22-33</xref>
          ]). The
constructs that comprise this branch are listed in Table I, which
shows the main factors (or classes) in column 1 and sub-classes
(in italics) in column 2. Column 2 also includes illustrative
descriptions or instances that reflect lower-level constructs (not
exhaustive). In column 1 we also indicate a count of the total
number of constructs defined at the leaf node level for each
class, to provide a sense of the extensiveness of the taxonomy.
        </p>
        <p>
          Organizational factors focus on organizational and
management practices, policies, and work setting
characteristics that influence worker satisfaction, attitudes,
safety, or protection/vulnerabilities of assets. These factors
have received much attention by organizations that publish best
practices—indicating situations or conditions that contribute to
an increased likelihood of insider threats within an
organization. Although they may play a role in triggering
malicious or unintentional insider threats, these factors have not
generally been identified in insider threat ontologies to date.
This branch of our taxonomy was constructed by consulting the
broad and diverse literature on industrial/organizational
psychology and human error research, including [
          <xref ref-type="bibr" rid="ref33 ref34 ref35">34-36</xref>
          ] and
relevant discussion of these factors in the context of workplace
violence and insider threat (e.g., [
          <xref ref-type="bibr" rid="ref36 ref37">37-38</xref>
          ]). Table II lists classes
and sub-classes defined to date for organizational factors.
        </p>
      </sec>
      <sec id="sec-4-2">
        <title>B. Ontology Development Approach</title>
        <p>
          To date, insider threat ontology development has focused
primarily on technical factors (e.g., [
          <xref ref-type="bibr" rid="ref12">13</xref>
          ]). In contrast, our
approach is grounded in an extended problem space that
includes methods, motivation, psychology, and circumstances of
human behavior. As noted by previous authors (e.g., [
          <xref ref-type="bibr" rid="ref12">13</xref>
          ]),
behavioral aspects of insider threat can be an extraordinarily
complex domain to model. There are many overlapping
concepts (e.g., state and trait anger), many providing little meaning
in isolation (e.g., surfing the web vs. surfing the web instead of
working). Our task has been to contextualize behaviors with
related concepts (e.g., underlying motivations and personality
traits) that allow the cataloging of information pertaining to
both the insider threat incident and the insider. Through this
catalogue of information, researchers and organizations can
index cases and gain further insight into common attack vectors
driven by human behavior. Our ontology extends previous
work [
          <xref ref-type="bibr" rid="ref3">3</xref>
          ][
          <xref ref-type="bibr" rid="ref12">13</xref>
          ][
          <xref ref-type="bibr" rid="ref13">14</xref>
          ] in two ways: (a) adding more detail to the
technical indicator branch of the ontology and (b) adding
material focusing on individual behavioral and organizational
factors.
        </p>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>Our approach is to migrate our taxonomy into a formal on</title>
      <p>tology expressed in the popular OWL-DL ontology language.
OWL-DL balances expressiveness (ability to represent many
kinds of domain entities and relationships), computational
properties (conclusions are guaranteed to be computable in
finite time), and functionality for drawing inferences from
asserted facts. Enumeration of (potentially hundreds of)
Competency Questions (CQs) for our ontology serves as a
requirements specification as well as a means of testing the ontology
implementation. An example of a simple CQ is “What are the
components of class Attitude?” A more complex CQ is “What
factors are associated with the observables attendance
problems, unauthorized personal use of work computer, and
hostile? The CQs may be evaluated using SPARQL queries. Our
OWL-DL implementation will enable automated inferences
about class relationships. For example, from the assertion that
an individual belongs to class Aggressive and class
Manipulative, the reasoning engine can infer that the individual fulfills
the membership conditions of class Threat.</p>
      <p>
        Following widely recognized guidelines for ontology
development [
        <xref ref-type="bibr" rid="ref38">39</xref>
        ], we used the Methontology ontology
engineering methodology [
        <xref ref-type="bibr" rid="ref39">40</xref>
        ], which enables construction at the
conceptual level and allows for development, re-use, or
reengineering of existing ontologies. In the Specification phase
we defined the purpose of the ontology, its intended uses and
its end users. In the Conceptualization phase we structured the
domain knowledge into meaningful graphical models. In the
Formalization phase we represented our conceptual models as
a formal or semi-computable model. The Implementation phase
supports the ontology development in the Web Ontology
Language (OWL). Updates and corrections take place in the
Maintenance phase. Our development also included supporting
      </p>
      <sec id="sec-5-1">
        <title>Methontology activities of Knowledge Acquisition, Evaluation</title>
        <p>(verification and validation that the ontology represents the
domain), Integration (reuse of other available ontologies),</p>
      </sec>
      <sec id="sec-5-2">
        <title>Documentation, and Configuration management. We also</title>
        <p>adopted IDEF5 methods in conceptualization and formalization
phases to acquire knowledge and develop graphical knowledge
representation models. We implemented our taxonomy using
an off-the-shelf ontology development tool (Protégé).</p>
      </sec>
    </sec>
    <sec id="sec-6">
      <title>By default, the Protégé tool does not assume that classes are mutually exclusive. This is useful when concepts are most meaningful in combination. For example, high absenteeism, a weak indicator by itself, is made stronger in association with</title>
      <p>
        other concerning factors [
        <xref ref-type="bibr" rid="ref31">32</xref>
        ], but the risk is mitigated when
associated with documented illness, vacation or maternity
leave. As another example, relaxation of the assumption of
mutual exclusivity is especially useful when considering
various correlated psychological or personality characteristics such
as those defined in the Five Factor Model (FFM) of personality
traits [
        <xref ref-type="bibr" rid="ref40">41</xref>
        ]. There are numerous well-supported relationships
between dimensions of personality and various types of
counterproductive work behavior [
        <xref ref-type="bibr" rid="ref27">28</xref>
        ].
      </p>
      <sec id="sec-6-1">
        <title>B. Description of the Ontology Classes</title>
      </sec>
    </sec>
    <sec id="sec-7">
      <title>We began by formalizing the hierarchy of concepts</title>
      <p>
        provided by the taxonomy discussed in Section IV-A, and
translating the hierarchy into parent-child relationships of
classes in our ontology. Classes represent objects with similar
structure and properties Classes are arranged hierarchically;
those without further subcategories are termed leaf nodes.
Individuals in the ontology represent instances of classes.
Class relationships other than parent-child are derived from the
research literature, available material on insider threat cases,
and the experience and judgment of subject-matter experts
within the development team. As reuse of previous knowledge
models is a key advantage of ontologies and an encouraged
practice in ontology engineering, we included as much
information from previous work as possible, especially the
recent ontology developed by CERT [
        <xref ref-type="bibr" rid="ref3">3</xref>
        ][
        <xref ref-type="bibr" rid="ref12">13</xref>
        ]. In particular, the
      </p>
      <sec id="sec-7-1">
        <title>Actor, Asset, Action, Event, Temporal Thing and Information</title>
        <p>
          class structures are adopted in total. Selected classes from the
Unified Cyber Security Ontology [
          <xref ref-type="bibr" rid="ref41">42</xref>
          ] were also incorporated
into our ontology. For example the idea of “Consequence”
class is adopted by our ontology but renamed to Outcome class
since this terminology is more consistent with the insider threat
cases scenario template used by CERT. The concepts of
Vulnerability (e.g., [6]) and Catalyst/Trigger events (e.g.,
[4344]) are also formalized as classes in our ontology. To capture
the temporal information involved in insider threat cases, we
imported the Temporal Interval class from the CERT ontology.
        </p>
      </sec>
    </sec>
    <sec id="sec-8">
      <title>Figs. 1-3 show the hierarchy of classes in our ontology, as</title>
      <p>implemented in the Protégé tool. The ontology is derived from
the extensive taxonomy described in Section IV-A. Due to
space constraints we depict only selected classes with detail
restricted to the 4th level of the hierarchy. A comparison of
Tables I and II with Figs. 1-3, shows how the class hierarchy in
the ontology represents the organization of domain concepts in
the taxonomy. Fig. 1 shows how the ontology accounts for both
malicious and non-malicious (unintentional) insider threats.
Importantly, we distinguish between actions performed by
employees (as insiders) and actions performed by organizations
(which may, for example, include poor institutional policies
and/or security practices as well as inadequate or exacerbating
responses to potential threats). At the same root level we also
include classes such as Industry, Insider Threat Risk, Effect,
Location and Outcome as attributes of the organization.
Industry may account for differences in organizational rules,
regulations and policies that differ across industry sectors. The
Effect class captures information about the impact of the insider
criminal activity on the organization(s), for example the action
of injecting a virus into an enterprise network can induce a
malfunction in other workstations on the network and/or a full
network shutdown. The concept of the consequences of an
attack is captured by the Outcome class, for example the
shutdown of the network has an outcome of a halt of
organization’s operations and thousands of dollars of loss. The
Location class encapsulates geographic information about the
source of an attack. The Insider Threat Risk class captures the
threat level that would be associated with the individuals of the
Actor class based on the inference performed over the
ontology.</p>
      <p>Fig. 2 expands the Human Factor node of Fig. 1, and Fig. 3
expands the Organizational Factor node. Inspection of the
human psychosocial factors in Fig. 2 reveal classes (and
associated sub-classes) that correspond to elements of the
taxonomy. Acknowledging the Capability-Motive-Opportunity
(CMO) model (e.g., [4]), which postulates that the perpetrator
of an attack must have the capability, motive, and opportunity
to commit the attack, we include these constructs as classes in
the ontology. Full implementation of CMO constructs is
deferred for future efforts to define relationships among these
classes.</p>
    </sec>
    <sec id="sec-9">
      <title>The capability to conduct an attack is in part dependent on</title>
      <p>
        an individual’s knowledge/skills/abilities that are represented in
certain human behavioral factors (cf [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]), particularly the
Biographical Data subclass within the Life Narrative factors class.
Motive (or motivation) may be represented within the Intention
class (and its malicious or non-malicious subclasses) in Fig 1; it
is also related to psychological characteristics or
predispositions such as Static Traits, Dynamic States, and
LifeNarrative factors (e.g., financial or health problems that may
act as stressors)—which are sub-classes of the Human Factor
class (see Fig. 2)—as well as Organizational Factors (Fig. 3)
that may act as stressors or triggers that can motivate an attack.
      </p>
      <sec id="sec-9-1">
        <title>The sub-class Concerning Behavior, within the Human</title>
        <p>Factor class, contains a large set of individual actions that
includes the subcategories Job Performance, Boundary</p>
      </sec>
      <sec id="sec-9-2">
        <title>Violation, and Cyber Security Violation. These in turn are bro</title>
        <p>ken down into more granular, lower-level constructs (shown in
boxes); not shown are even lower levels of the hierarchy and
individuals representing instances of the classes.</p>
        <p>The initial structure of the ontology grew out of the detailed
taxonomic structure that we developed based on subject-matter
expertise and our analysis/synthesis of research literature and
numerous case studies. A more robust and richer representation
has been informed by exploring complex relationships among
constructs (e.g., classes, sub-classes, instances) spread across
multiple branches of the hierarchy. As a simple example, the
ontology recognizes that different types of attack are identified
from their relationships with certain aspects of the
cyber/technical exploit (e.g., exfiltration requires certain
actions performed on sensitive information, such as saving to
external media, printing, emailing, uploading to the cloud, etc.).
A more complex example may be considered in using the
CMO model (mentioned above) to reason about insider risk.
By incorporating knowledge of relationships among detected
behaviors, individual behavioral factors, and organizational
factors, the ontology allows reasoning about the risk associated
with detected behaviors in the context of possible motives,
capabilities, and opportunity. Relationships and gaps (missing
elements in classes) were further identified by exercising the
knowledge base using known or fictitious use cases.</p>
      </sec>
      <sec id="sec-9-3">
        <title>C. Use Case and Application</title>
        <p>Use cases help to verify the comprehensiveness of the
knowledge representation and to identify missing or ill-defined
classes and relationships. In this section, we demonstrate the
application of the ontology to use cases that include human
behavioral factors and organization factors as well as
cyber/technical indicators. In the scenarios described, we use
[brackets] to identify significant indicators with actions
described in the scenario.</p>
      </sec>
    </sec>
    <sec id="sec-10">
      <title>Use Case #1 (see small text box) describes a simple cyber</title>
      <p>related insider threat incident. Use Case #2 (see large text box),
which entirely subsumes the contextual and technical
information regarding the insider threat incident described in the
first use case, injects additional human behavioral factors.</p>
      <p>Use Case #1
John [PERSON: Insider X] is a long-time system administrator [LIFE
NARRATIVE: PERS HISTORY] [CAPABILITY] with access to sensitive
and classified information [OPPORTUNITY] in a company that performs
government-sponsored R&amp;D [ORGANIZATION: VICTIM
ORGANIZATION].</p>
      <p>John uses his personal web-based email account from his work computer to
communicate with prospective employers [DIGITAL ACTION: EMAIL
ACTION]. Then he uses his administrative privileges to access some sensitive
intellectual property information [BUSINESS INFORMATION:
INTELLECTUAL PROPERTY] that will be of interest to a competitor. John
saves these files to his computer [COMPUTER ASSET: WORK PC] and
copies the files to a thumb drive [CONCERNING BEHAVIOR:
TECH/CYBER VIOLATION–DIGITAL ACTION/COPY ACTION]
[PHYSICAL ASSET: USB DRIVE], which he then sneaks out of the office
with the intention of using the information to leverage a job offer with a
competitor [THEFT EVENT: DATA THEFT]. Subsequently John resigns
and accepts a job offer from a competitor.</p>
      <p>It is evident that Use Case #1 lacks substantial contextual
information described in Use Case #2 regarding possible
contributing or mitigating factors, relevant personal
predispositions, or concerning behaviors that may be associated
with this individual’s insider threat risk. Fig. 4 is a concept map
depicting Use Case #2, showing all the behavioral and
technical concepts and their associated relations. The dashed</p>
      <p>Use Case #2
John [PERSON: Insider X] is a long-time system administrator [LIFE NARRATIVE: PERS HISTORY] [CAPABILITY] with access to sensitive and
classified information [OPPORTUNITY] in a company that performs government-sponsored R&amp;D [ORGANIZATION: VICTIM ORGANIZATION]. The
following input was recorded in his personnel file: (1) One colleague states that John discounts the opinions of colleagues and he becomes hostile when
colleagues discuss and critique his ideas [STATIC TRAIT: TEMPERAMENT: RESISTS CRITICISM] [DYNAMIC STATE: AFFECT—HOSTILE]. (2)
A different colleague states that John seeks to control all aspects of a project and often insists on dominating the conversation about project tasks and approach
[STATIC TRAIT: OTHER PERSONALITY DIMENSIONS—AUTHORITARIANISM]. (3) His manager corroborates these inputs and adds that John
tends to become argumentative and irritated, and defensively cites his superior knowledge of industry best practices when others criticize his rigid protocols
[DYNAMIC STATE: AFFECT–HOSTILE] [STATIC TRAIT: TEMPERAMENT—BIG EGO]. Staff development/performance review assessment
includes criticism by colleagues that portions of his protocols are idiosyncratic with weak rationale, and that his rigid protocols have impacted company projects
[CONCERNING BEHAVIORS: JOB PERF—NEGATIVE PERF EVALUATION].</p>
      <p>John was passed over for a promotion to manage a new, prestigious project [LIFE NARRATIVE: PERS HISTORY: EMPLOYMENT–PASSED OVER
FOR PROMOTION]. He files a complaint with HR claiming unfair treatment and his manager, compelled to meet with him, comes away with the impression
that John still harbors resentment over not being promoted. John’s most recent evaluation cited a decline in performance [CONCERNING BEHAVIORS:
JOB PERF—NEGATIVE PERF EVALUATION]; since being denied the promotion his attitude has been increasingly disgruntled [DYNAMIC STATE:
ATTITUDE—DISGRUNTLEMENT]; and that there were multiple complaints from coworkers about frequent tardiness [CONCERNING BEHAVIORS:
BOUNDARY VIOLATION—ATTENDANCE]. The attendance problem led to a formal, written warning [CONCERNING BEHAVIORS: BOUNDARY
VIOLATION–POLICY VIOLATION]. After getting the warning, John talks to his manager and loses his cool—storming out of the office [DYNAMIC
STATE: AFFECT–HOSTILE]. A colleague hears John’s outburst and tells the manager about John’s recent marital separation to provide some context to
Johns behavior [LIFE NARRATIVE: PERS HISTORY—MAJOR LIFE EVENTS/RECENT CHANGE IN MARITAL STATUS (MARITAL
SEPARATION)]. The incident prompts the manager to contact the company Security Office. The Security Office checks the local court records to learn that
three weeks ago, John was arrested for allegedly driving under the influence (his first contact with the criminal justice system) [LIFE NARRATIVE:
CRIMINAL RECORD—DUI].</p>
      <p>Faced with these job and personal stressors, John begins to seek work with a competitor. John contacts a competitor to see if they are interested in him and in
proprietary information he can provide. To avoid being noticed, John carries out email dialogue with the competitor by logging into his personal Yahoo web
mail account from his work computer [CONCERNING BEHAVIORS: JOB PERFORMANCE—CYBERLOAFING]. Next, John carries out the insider
threat attack and resigns, as described in second paragraph of Use Case #1.
box in Fig. 4 represents Use Case #1 (due to space limitations,
not all details are shown). In a real scenario, detecting
concerning behaviors or other factors may require multiple
factors to meet threshold requirements for alerts—these are not
described or represented here due to space constraints. Events
depicted in the use case scenarios are numbered
chronologically. Shown in the lower right side of the figure is a timeline
(spanning several months for illustrative purposes) suggesting
that monitoring of sociotechnical factors may help achieve
proactive mitigation goals (getting “left of the boom”).</p>
      <p>VI.</p>
      <p>COMPARISON WITH RELATED WORK</p>
      <p>
        The focus of our effort is to express and represent
individual and organizational sociotechnical factors in an ontological
characterization of insider threat risk (e.g., [
        <xref ref-type="bibr" rid="ref12 ref13">13-14</xref>
        ]). Our
ontology provides a more robust, richer description of not only the
nature of the attack but also possible contributing factors that
more fully describe the insider threat to the organization. CERT
[
        <xref ref-type="bibr" rid="ref12">13</xref>
        ] began with a database of insider threat case descriptions.
      </p>
      <p>
        The information framework underlying this database informed
the vocabulary in the ontology. Namely, organizations grant
access to persons that perpetrate events that harm the
organization. Persons and Organizations are the actors in the
CERT ontology, and their actions culminate in events (i.e.,
insider threat incidents). Instead of a focus on events, our
ontology focuses on the insider. Our taxonomy and ontology are
based on theories and models of insider threat in the literature
that incorporate human behavioral as well as technical
indicators of threat (e.g., [
        <xref ref-type="bibr" rid="ref10 ref11 ref9">10-12</xref>
        ]). While the current CERT ontology
only describes technical/cyber events, our ontology also
includes non-technical or sociotechnical constructs that reflect
actions and psychosocial indicators of persons of interest. As a
specific example, consider the class Concerning Behaviors. A
concerning behavior such as “Leaving a classified security
container unlocked and unattended” can be described using two
concepts in the CERT ontology: an Asset (e.g., Classified file)
and an Action (e.g., Unlock). However, this may not be the
focal event, or a precipitating event, in a case description, and
there may be other related contributing factors. For example, a
previous condition (e.g., organizational reduction in
force/layoffs) or individual predispositions (e.g., personality
traits, personal stress) may lead to actions that reflect a lack of
diligence or motivation in an actor who later commits an act of
insider threat (these contributing factors are in part identified in
the cybersecurity human factors ontology (HUFO) by [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]. The
CERT ontology, in particular, does not connect these
behavioral constructs to technical/cyber actions that comprise
the actual exploit.
      </p>
      <p>At a basic level, the Factor class, which contains much of
the vocabulary in our ontology, can be placed alongside Assets
in the CERT ontology. Both are non-temporal classes that a
person can possess (i.e., Things). We integrated the two
ontologies and eliminated duplications. All CERT ontology classes
were incorporated in this way. There are, however, stark
differences between the extent and scope of the CERT ontology and
our ontology. The CERT ontology contains a standardized and
well-defined vocabulary for describing the actions of insider
threats. It contains 31 actions (e.g., Copy), along with six
action modifiers (e.g., Suspicious), organized under four major
classes to describe digital, financial, and job-related insider
threat behavior. These actions can be taken on 26 assets (e.g.,
USB drive) in three major categories (i.e., Physical, Financial,
and Digital) and/or 16 types of information (e.g., Password)
organized in seven major categories (i.e., National Security,
Technology, Financial, Medical, Classified, Business, and
Uniquely Identifiable). Eleven focal events are also captured as
classes in the ontology (e.g., Theft), for a total of 125
constructs within their class structure. In contrast to the CERT
ontology, our framework is broader and deeper. In addition to
containing these constructs, our ontology represents a
knowledge base that is six to seven layers deep, comprising a
total of over 350 constructs. In sum, we have greatly expanded
the CERT ontology by adding classes representing human
behavioral and organizational factors of insider threat.</p>
      <p>
        While not specifically addressing insider threat, the
cybersecurity HUFO presented by [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ], which focuses on trust, is
similar to and largely compatible with our ontology; it defines
roughly 48 human factors classes that address characteristics
such as motivation, integrity, rationality, benevolence,
personality, ideology, ethics, and risk posture, as well as knowledge,
skills and abilities. In comparison, our ontology probes several
levels deeper than the HUFO ontology. Further work is
planned to integrate relevant features of these ontologies.
      </p>
      <p>VII.</p>
      <p>CONCLUSIONS AND FUTURE WORK</p>
      <p>Our work addresses two major challenges. First, due to the
large number of concepts and their complex interrelationships,
the insider threat domain is cumbersome to model. Second,
there is a need to establish a common terminology and shared
understanding of the complex insider threat domain. We used
an exhaustive approach that incorporates into our taxonomy
most of the concepts we have encountered in the insider threat
literature. We then developed a mapping that transforms the
taxonomy into an ontology, and added relationships to the
ontology to produce a formal representation of concepts and
their interrelationships. By synthesizing the contributions of a
diverse set of experts, we developed a knowledge
representation that more fully characterizes insider threat indicators—
from the perspective of human behavior as well as
cyber/technical indicators—and that can be made available in a
shareable knowledge base to facilitate reuse and collaboration.</p>
      <p>Beyond its immediate use in providing a common,
shareable knowledge base of insider threat problem space constructs,
the present research will help to advance efforts to model and
mitigate insider threats. Informed by extant research on human
and organizational factors associated with insider threats, the
constructs and indicators represented in the present ontology
can be used to develop models to assess individual risk and
organizational vulnerability, as well as to inform operational
risk management practices. In addition, by specifying a more
comprehensive knowledge base, our ontology facilitates the
generation of diverse scenarios for use in red teaming and
testing of more holistic insider threat models. Finally, the
knowledge base provided here may have further operational
impact by informing the structure of data to be captured by
enterprises for effective insider threat monitoring and analysis.</p>
      <p>A brief discussion of some limitations of the research
reported here may be useful in interpreting progress to date as
well as motivating future work. First, our choice to define a
taxonomy as a foundation for the ontology meant that the initial
structure only specified hierarchical parent-child relationships
among constructs. Other relationships were then defined as part
of the process of transforming the taxonomy into an ontology.</p>
      <p>
        Because our primary interest (and recognized need in modeling
insider threats) was to incorporate sociotechnical factors that
have been suggested in research literature, there was also an
inherent limitation in the ability to specify robust axioms that
reflect more complex relationships among constructs.
Ultimately this more complete specification will be required to support
inferences about classes and individuals. There is a tradeoff
between implementing the asserted classes and individuals
versus the inferred constructs. While some of the classes in our
ontology are defined by certain inference rules and axioms
(e.g., the class Capability categorizes instances based on
specified rules), much more work is needed to more fully specify
relationships that will ultimately be required to support
inferences about insider threat risks. A second limitation is that,
while the current ontology has captured salient constructs in the
literature, there are certainly more constructs that can and
should be added to the ontology. Research should continue the
process of encapsulating the entirety of constructs related to
insider threat. We are continually populating the individual and
organizational classes of ontology with relevant instances
(informed by use cases); we plan to further develop the
Capabilities and Opportunities classes and associated relationships,
building upon recent related work [
        <xref ref-type="bibr" rid="ref13">14</xref>
        ]. Future research should
also focus on addressing the need to represent temporal
relationships among constructs.
      </p>
      <p>
        We use the present forum and others to share these results
with the research community. We also plan to extend our
ontology into a probabilistic ontology by incorporating
information about uncertainty in the insider threat domain. The
resulting probabilistic ontology will support reasoning under
uncertainty [
        <xref ref-type="bibr" rid="ref44">45</xref>
        ]. Probabilistic ontologies combine semantically
rich representations that support interoperability and automated
reasoning with mathematically well-founded uncertainty
management. Advancing research and development of
probabilistic ontologies for insider threats will facilitate modeling
and tool development. Our ontology provides a rich foundation
for logical and probabilistic inferences necessary for protection
against insider attacks.
      </p>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>D. M.</given-names>
            <surname>Cappelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Moore</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R. F.</given-names>
            <surname>Trzeciak</surname>
          </string-name>
          ,
          <article-title>The CERT guide to insider threats: How to prevent, detect, and respond to information technology crimes (theft, sabotage</article-title>
          , fraud).
          <source>Addison-Wesley</source>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>The</given-names>
            <surname>White House. Executive Order</surname>
          </string-name>
          13587
          <article-title>-Structural Reforms to Improve the Security of Classified Networks and the Responsible Sharing and Safeguarding of Classified Information</article-title>
          ,
          <year>October 2011</year>
          . http://www.whitehouse.gov/the-press-office/
          <year>2011</year>
          /10/07/executiveorder-structural
          <article-title>-reforms-improve-security-classified-networks-</article-title>
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Costa</surname>
          </string-name>
          , M. Collins,
          <string-name>
            <given-names>J. S.</given-names>
            <surname>Perl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. M.</given-names>
            <surname>Albrethsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.G.</given-names>
            <surname>Silowash</surname>
          </string-name>
          , and
          <string-name>
            <surname>D. Spooner.</surname>
          </string-name>
          (
          <year>2014</year>
          ).
          <article-title>An Ontology for Insider Threat Indicators</article-title>
          . In K. B.
          <string-name>
            <surname>Laskey</surname>
            ,
            <given-names>I.</given-names>
          </string-name>
          <string-name>
            <surname>Emmons and P C.G. Costa</surname>
          </string-name>
          (Eds.),
          <source>Proceedings of the Ninth Conference on Semantic Technologies for Intelligence</source>
          , Defense, and
          <string-name>
            <surname>Security</surname>
          </string-name>
          (STIDS
          <year>2014</year>
          ),
          <year>2014</year>
          ,
          <fpage>48</fpage>
          -
          <lpage>53</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          <string-name>
            <given-names>E. E.</given-names>
            <surname>Schultz</surname>
          </string-name>
          , “
          <article-title>A framework for understanding and predicting insider attacks</article-title>
          .
          <source>” Computers &amp; Security</source>
          ,
          <year>2002</year>
          , vol.
          <volume>21</volume>
          ,
          <fpage>526</fpage>
          -
          <lpage>531</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          <string-name>
            <given-names>E. D.</given-names>
            <surname>Shaw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J. M.</given-names>
            <surname>Post</surname>
          </string-name>
          , and
          <string-name>
            <surname>K. G.</surname>
          </string-name>
          <article-title>Ruby, “Inside the mind of the insider</article-title>
          .
          <source>” Security Management</source>
          ,
          <year>1999</year>
          , vol
          <volume>43</volume>
          (
          <issue>12</issue>
          ),
          <fpage>34</fpage>
          -
          <lpage>42</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          <string-name>
            <given-names>P.</given-names>
            <surname>Moore</surname>
          </string-name>
          .
          <article-title>Insider threat study: illicit cyber activity in the banking and financial sector</article-title>
          . Carnegie-Mellon University. Software Engineering Institute. CMU/SEI-2004
          <source>-TR-021</source>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          <string-name>
            <given-names>S. R.</given-names>
            <surname>Band</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. M.</given-names>
            <surname>Cappelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Fischer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Moore</surname>
          </string-name>
          ,
          <string-name>
            <given-names>E. D.</given-names>
            <surname>Shaw</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R. F.</given-names>
            <surname>Trzeciak</surname>
          </string-name>
          .
          <article-title>Comparing insider IT sabotage and espionage: a modelbased analysis</article-title>
          . Carnegie-Mellon University. Software Engineering Institute. CERT Coordination Center. CMU/SEI-2006
          <source>-TR-026</source>
          ,
          <year>2006</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          <string-name>
            <surname>Ferryman</surname>
          </string-name>
          .
          <article-title>Psychosocial modeling of insider threat risk based on behavioral and word use analysis</article-title>
          .
          <source>e-Service Journal</source>
          ,
          <year>2013</year>
          ,
          <volume>9</volume>
          (
          <issue>1</issue>
          ),
          <fpage>106</fpage>
          -
          <lpage>138</lpage>
          . http://www.jstor.org/stable/10.2979/eservicej.9.1.106
          <string-name>
            <given-names>M.</given-names>
            <surname>Maasberg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Warren</surname>
          </string-name>
          , and
          <string-name>
            <given-names>N. L.</given-names>
            <surname>Beebe</surname>
          </string-name>
          .
          <article-title>The dark side of the insider: Detecting the insider threat through examination of dark triad personality traits</article-title>
          .
          <source>IEEE. 48th Hawaii International Conference on System Sciences</source>
          ,
          <year>2015</year>
          ,
          <fpage>3518</fpage>
          -
          <lpage>3526</lpage>
          . DOI 10.1109/HICSS.
          <year>2015</year>
          .423
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          and
          <string-name>
            <given-names>R. E.</given-names>
            <surname>Hohimer</surname>
          </string-name>
          .
          <article-title>"Modeling Human Behavior to Anticipate Insider Attacks."</article-title>
          <source>Journal of Strategic Security</source>
          ,
          <year>2011</year>
          ,
          <volume>4</volume>
          (
          <issue>2</issue>
          ):
          <fpage>25</fpage>
          -
          <lpage>48</lpage>
          . http://scholarcommons.usf.edu/jss/vol4/iss2/
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>R. E.</given-names>
            <surname>Hohimer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. F.</given-names>
            <surname>Noonan</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J. D.</given-names>
            <surname>Strasburg</surname>
          </string-name>
          .
          <article-title>"CHAMPION: Intelligent Hierarchical Reasoning Agents for Enhanced Decision Support." In Semantic Technology for Intelligence, Defense, and</article-title>
          <string-name>
            <surname>Security (STIDS</surname>
          </string-name>
          <year>2011</year>
          ).
          <year>2011</year>
          ,
          <fpage>36</fpage>
          -
          <lpage>43</lpage>
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>E. T.</given-names>
            <surname>Axelrad</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. J.</given-names>
            <surname>Sticha</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Brdiczka</surname>
          </string-name>
          , and
          <string-name>
            <given-names>J.</given-names>
            <surname>Shen</surname>
          </string-name>
          , “
          <article-title>A Bayesian network model for predicting insider threats</article-title>
          .
          <source>” IEEE SPW Workshop on Research for Insider Threat (WRIT)</source>
          , San Francisco, CA,
          <year>2013</year>
          ,
          <fpage>82</fpage>
          -
          <lpage>89</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Costa</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. J.</given-names>
            <surname>Albrethsen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Collins</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. J.</given-names>
            <surname>Perl</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. J.</given-names>
            <surname>Silowash</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Spooner</surname>
          </string-name>
          .
          <article-title>An Insider Threat Indicator Ontology</article-title>
          .
          <source>TECHNICAL REPORT CMU/SEI-2016-TR-007</source>
          . Pittsburgh, PA: SEI,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>A.</given-names>
            <surname>Oltramari</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. H.</given-names>
            <surname>Henshel</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Cains</surname>
          </string-name>
          , and
          <string-name>
            <given-names>B.</given-names>
            <surname>Hoffman</surname>
          </string-name>
          . “
          <article-title>Towards a human factors ontology for cyber security</article-title>
          .”
          <source>In Semantic Technology for Intelligence</source>
          , Defense, and
          <string-name>
            <surname>Security</surname>
          </string-name>
          (STIDS
          <year>2015</year>
          ).
          <year>2015</year>
          ,
          <fpage>26</fpage>
          -
          <lpage>33</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [15]
          <string-name>
            <given-names>W. E.</given-names>
            <surname>Chaplin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O. P.</given-names>
            <surname>John</surname>
          </string-name>
          , and
          <string-name>
            <given-names>L. R.</given-names>
            <surname>Goldberg</surname>
          </string-name>
          . “
          <article-title>Conceptions of states and traits: Dimensional attributes with ideals as prototypes</article-title>
          .
          <source>” Journal of Personality and Social Psychology</source>
          ,
          <year>1988</year>
          ,
          <volume>54</volume>
          (
          <issue>4</issue>
          ),
          <fpage>541</fpage>
          -
          <lpage>557</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>R.</given-names>
            <surname>Steyer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Mayer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C.</given-names>
            <surname>Geiser</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Cole</surname>
          </string-name>
          .
          <article-title>"A theory of states and traits-</article-title>
          <source>Revised." Annual Review of Clinical Psychology</source>
          ,
          <year>2015</year>
          ,
          <volume>11</volume>
          ,
          <fpage>71</fpage>
          -
          <lpage>98</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>S. C.</given-names>
            <surname>Roesch</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. A.</given-names>
            <surname>Aldridge</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. N.</given-names>
            <surname>Stocking</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F.</given-names>
            <surname>Villodas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>Q.</given-names>
            <surname>Leung</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. E.</given-names>
            <surname>Bartley</surname>
          </string-name>
          , and
          <string-name>
            <given-names>L. J.</given-names>
            <surname>Black</surname>
          </string-name>
          . “
          <article-title>Multilevel factor analysis and structural equation modeling of daily diary coping data: Modeling trait and state variation</article-title>
          .
          <source>Multivariate Behavioral Research</source>
          ,
          <year>2010</year>
          ,
          <volume>45</volume>
          (
          <issue>5</issue>
          ),
          <fpage>767</fpage>
          -
          <lpage>789</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [18]
          <string-name>
            <surname>L. Van Gelder</surname>
          </string-name>
          and
          <string-name>
            <surname>R. E</surname>
          </string-name>
          . De Vries. “
          <article-title>Traits and states at work: Lure, risk and personality as predictors of occupational crime</article-title>
          .” Psychology, Crime &amp; Law,
          <year>2016</year>
          ,
          <volume>22</volume>
          (
          <issue>7</issue>
          ),
          <fpage>701</fpage>
          -
          <lpage>720</lpage>
          . DOI 10.1080/1068316X.
          <year>2016</year>
          . 1174863
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [19]
          <string-name>
            <given-names>D. F.</given-names>
            <surname>Gro</surname>
          </string-name>
          ̈s,
          <string-name>
            <given-names>L. J.</given-names>
            <surname>Simms</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. M. Antony</surname>
            , and
            <given-names>R. E. McCabe.</given-names>
          </string-name>
          “
          <article-title>Psychometric properties of the State-Trait Inventory for Cognitive and Somatic Anxiety (STICSA): Comparison to the State-Trait Anxiety Inventory (STAI)</article-title>
          .
          <source>” Psychological Assessment</source>
          .
          <year>2007</year>
          ,
          <volume>19</volume>
          (
          <issue>4</issue>
          ),
          <fpage>369</fpage>
          -
          <lpage>381</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [20]
          <string-name>
            <given-names>K. S.</given-names>
            <surname>Douglas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. D.</given-names>
            <surname>Hart</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. D.</given-names>
            <surname>Webster</surname>
          </string-name>
          , and
          <string-name>
            <given-names>H.</given-names>
            <surname>Belfrage</surname>
          </string-name>
          . HCR-20V3:
          <article-title>Assessing risk of violence - User guide</article-title>
          .
          <year>2013</year>
          . Burnaby, Canada: Mental Health, Law, and Policy Institute, Simon Fraser University.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [21]
          <string-name>
            <given-names>J. R.</given-names>
            <surname>Meloy</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. G.</given-names>
            <surname>White</surname>
          </string-name>
          , and
          <string-name>
            <given-names>S.</given-names>
            <surname>Hart</surname>
          </string-name>
          . “
          <article-title>Workplace assessment of targeted violence risk: The development and reliability of the WAVR21”</article-title>
          .
          <source>Journal of Forensic Sciences</source>
          ,
          <year>2013</year>
          ,
          <volume>58</volume>
          (
          <issue>5</issue>
          ),
          <fpage>1353</fpage>
          -
          <lpage>1358</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [22]
          <string-name>
            <given-names>E. D.</given-names>
            <surname>Shaw</surname>
          </string-name>
          and
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Fischer</surname>
          </string-name>
          .
          <article-title>Ten Tales of Betrayal: The Threat to Corporate Infrastructures by Information Technology Insiders</article-title>
          .
          <article-title>Report 1-Overview</article-title>
          and
          <string-name>
            <given-names>General</given-names>
            <surname>Observations</surname>
          </string-name>
          .
          <source>Technical Report 05-04</source>
          ,
          <year>April 2005</year>
          . Monterey, CA: Defense Personnel Security Research Center.
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [23]
          <string-name>
            <given-names>M.</given-names>
            <surname>Gelles</surname>
          </string-name>
          ,
          <string-name>
            <surname>M. Exploring</surname>
          </string-name>
          <article-title>the mind of the spy</article-title>
          . In Online Employees' Guide to Security
          <source>Responsibilities: Treason 101</source>
          .
          <year>2005</year>
          .
          <string-name>
            <surname>Retrieved from Texas</surname>
            <given-names>A</given-names>
          </string-name>
          &amp;M University Research Foundation website: http://www.dss.mil/search-dir/training/csg/security/Treason/Mind.htm
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [24]
          <string-name>
            <given-names>J. L.</given-names>
            <surname>Krofcheck</surname>
          </string-name>
          and
          <string-name>
            <given-names>M. G.</given-names>
            <surname>Gelles</surname>
          </string-name>
          .
          <article-title>Behavioral Consultation in Personnel Security: Training and Reference Manual for Personnel Security Professionals</article-title>
          . Yarrow and Associates,
          <year>2005</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [25]
          <string-name>
            <given-names>D.</given-names>
            <surname>Bulling</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Scalora</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R</given-names>
            <surname>Borum</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J</given-names>
            <surname>Panuzio</surname>
          </string-name>
          , and
          <string-name>
            <given-names>A</given-names>
            <surname>Donica</surname>
          </string-name>
          .
          <article-title>Behavioral science guidelines for assessing insider threats</article-title>
          .
          <source>Publications of the University of Nebraska Public Policy Center. Paper 37</source>
          .
          <year>2008</year>
          . http://digitalcommons.unl.edu/publicpolicypublications/37
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [26]
          <string-name>
            <given-names>D. B.</given-names>
            <surname>Parker</surname>
          </string-name>
          .
          <article-title>Fighting computer crime: A new framework for protecting information</article-title>
          . New York, NY: John Wiley &amp; Sons, Inc.,
          <year>1998</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [27]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. P.</given-names>
            <surname>Moore</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. M.</given-names>
            <surname>Cappelli</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. H.</given-names>
            <surname>Andrews</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. A.</given-names>
            <surname>Carroll</surname>
          </string-name>
          , and
          <string-name>
            <given-names>T. D.</given-names>
            <surname>Hull</surname>
          </string-name>
          .
          <article-title>Combating the insider threat</article-title>
          . (
          <year>2008</year>
          ).
          <source>IEEE Security &amp; Privacy, January/February</source>
          <year>2008</year>
          ,
          <fpage>61</fpage>
          -
          <lpage>64</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [28]
          <string-name>
            <given-names>E. D.</given-names>
            <surname>Shaw</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Fischer</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A. E.</given-names>
            <surname>Rose</surname>
          </string-name>
          .
          <article-title>Insider risk evaluation and audit (No</article-title>
          . TR-
          <volume>09</volume>
          -02). Monterey, CA: Defense Personnel Security Research Center,
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [29]
          <string-name>
            <given-names>B.</given-names>
            <surname>Zadeh</surname>
          </string-name>
          and
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          . “
          <article-title>Motivation and Capability Modeling for Threat Anticipation.” OSD Human Social Culture Behavior (HSCB) Modeling Program Conference</article-title>
          . Chantilly, VA,
          <fpage>5</fpage>
          -
          <lpage>7</lpage>
          August
          <year>2009</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [30]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          and
          <string-name>
            <given-names>D. A.</given-names>
            <surname>Frincke</surname>
          </string-name>
          . D.A. “
          <article-title>Combining traditional cyber security audit data with psychosocial data: towards predictive modeling for insider threat,” in Insider Threats in Cyber Security</article-title>
          . vol.
          <volume>49</volume>
          ,
          <string-name>
            <given-names>C. W.</given-names>
            <surname>Probst</surname>
          </string-name>
          , et al., Eds.,
          <string-name>
            <surname>Springer</surname>
            <given-names>US</given-names>
          </string-name>
          ,
          <year>2010</year>
          ,
          <fpage>85</fpage>
          -
          <lpage>114</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [31]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. J.</given-names>
            <surname>Kangas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. F.</given-names>
            <surname>Noonan</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Dalton</surname>
          </string-name>
          .
          <article-title>Identifying atrisk employees: A behavioral model for predicting potential insider threats</article-title>
          .
          <source>PNNL-19665</source>
          , Richland, WA: Pacific NW National Laboratory,
          <year>2010</year>
          . http://www.pnl.gov/main/publications/external/technical_reports/PNNL19665.pdf.
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [32]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. J.</given-names>
            <surname>Kangas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>C. F.</given-names>
            <surname>Noonan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Dalton</surname>
          </string-name>
          , and
          <string-name>
            <given-names>R. E. Hohimer.</given-names>
            “
            <surname>Identifying</surname>
          </string-name>
          at
          <article-title>-risk employees: a behavioral model for predicting potential insider threats</article-title>
          .
          <source>” Hawaii International Conference on System Sciences. Maui, HI, Jan 4-7</source>
          ,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [33]
          <string-name>
            <given-names>Software</given-names>
            <surname>Engineering</surname>
          </string-name>
          <article-title>Institute (SEI)</article-title>
          .
          <article-title>Analytic approaches to detect insider threats</article-title>
          .
          <source>White Paper, SEI, December</source>
          <volume>9</volume>
          ,
          <year>2015</year>
          . http://resources.sei.cmu.edu/asset_files/WhitePaper/2015_019_
          <fpage>001</fpage>
          _
          <fpage>451069</fpage>
          .pdf
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [34]
          <string-name>
            <given-names>S.</given-names>
            <surname>Dekker</surname>
          </string-name>
          .
          <article-title>The field guide to human error investigations</article-title>
          . Burlington, VT: Ashgate,
          <year>2002</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [35]
          <string-name>
            <given-names>D. J.</given-names>
            <surname>Pond</surname>
          </string-name>
          and
          <string-name>
            <given-names>K. R.</given-names>
            <surname>Leifheit</surname>
          </string-name>
          . “
          <article-title>End of an error</article-title>
          .
          <source>” Security Management</source>
          ,
          <year>2003</year>
          ,
          <volume>47</volume>
          (
          <issue>5</issue>
          ).
          <fpage>113</fpage>
          -
          <lpage>117</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [36]
          <string-name>
            <given-names>D. J.</given-names>
            <surname>Pond</surname>
          </string-name>
          and
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          . “
          <article-title>Error-based accidents and security incidents in nuclear materials management</article-title>
          .
          <source>” Institute of Nuclear Materials Management 46th Annual Meeting</source>
          , Phoenix, AZ,
          <year>2005</year>
          . http://www.osti.gov/scitech/biblio/966022
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>R.</given-names>
            <surname>Baron</surname>
          </string-name>
          and
          <string-name>
            <given-names>J.</given-names>
            <surname>Neuman</surname>
          </string-name>
          .
          <article-title>Workplace violence and workplace aggression: Evidence on their relative frequency and potential causes</article-title>
          .
          <source>Aggressive Behavior</source>
          ,
          <year>1996</year>
          , vol.
          <volume>22</volume>
          , no.
          <issue>3</issue>
          ,
          <fpage>161</fpage>
          -
          <lpage>173</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Greitzer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Strozer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Cohen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Bergey</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Cowley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Moore</surname>
          </string-name>
          , and
          <string-name>
            <given-names>D.</given-names>
            <surname>Mundie</surname>
          </string-name>
          . “
          <article-title>Unintentional insider threat: contributing factors, observables, and mitigation strategies</article-title>
          .
          <source>” 47th Hawaii International Conference on Systems Sciences (HICSS-47)</source>
          , Big Island, Hawaii,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>N. F.</given-names>
            <surname>Noy</surname>
          </string-name>
          and
          <string-name>
            <given-names>D. L.</given-names>
            <surname>McGuinness</surname>
          </string-name>
          .
          <article-title>Ontology Development 101: A Guide to Creating Your First Ontology. (SMI-2001-0880 (also available as</article-title>
          <source>KSL Technical Report KSL-01-05)</source>
          )
          <fpage>2001</fpage>
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [40]
          <string-name>
            <given-names>M.</given-names>
            <surname>Fernández-López</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Gómez-Pérez</surname>
          </string-name>
          .
          <article-title>Overview and analysis of methodologies for building ontologies</article-title>
          .
          <source>The Knowledge Engineering Review</source>
          ,
          <year>2002</year>
          ,
          <volume>17</volume>
          (
          <issue>2</issue>
          ),
          <fpage>129</fpage>
          -
          <lpage>156</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [41]
          <string-name>
            <given-names>L. R.</given-names>
            <surname>Goldberg</surname>
          </string-name>
          ,
          <article-title>"The structure of phenotypic personality traits</article-title>
          .
          <source>" American Psychologist</source>
          ,
          <year>1993</year>
          , vol.
          <volume>48</volume>
          ,
          <fpage>26</fpage>
          -
          <lpage>34</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref41">
        <mixed-citation>
          [42]
          <string-name>
            <given-names>Z.</given-names>
            <surname>Syed.</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Padia</surname>
          </string-name>
          .,
          <string-name>
            <given-names>T.</given-names>
            <surname>Finin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Mathews</surname>
          </string-name>
          ,
          <article-title>and</article-title>
          <string-name>
            <given-names>A.</given-names>
            <surname>Joshi. UCO: A Unified Cybersecurity</surname>
          </string-name>
          <article-title>Ontology (Tech</article-title>
          .). Baltimore,
          <string-name>
            <surname>MD</surname>
          </string-name>
          ,
          <year>2016</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref42">
        <mixed-citation>
          [43]
          <string-name>
            <surname>Claycomb</surname>
            ,
            <given-names>W. R.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Huth</surname>
            ,
            <given-names>C. L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Flynn</surname>
            ,
            <given-names>L.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>McIntire</surname>
            ,
            <given-names>D. M.</given-names>
          </string-name>
          ,
          <string-name>
            <surname>Lewellen</surname>
            ,
            <given-names>T. B.</given-names>
          </string-name>
          , &amp;
          <string-name>
            <surname>Center</surname>
            ,
            <given-names>C. I. T.</given-names>
          </string-name>
          (
          <year>2012</year>
          ).
          <article-title>Chronological Examination of Insider Threat Sabotage: Preliminary Observations</article-title>
          .
          <source>JoWUA</source>
          ,
          <volume>3</volume>
          (
          <issue>4</issue>
          ),
          <fpage>4</fpage>
          -
          <lpage>20</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref43">
        <mixed-citation>
          [44]
          <string-name>
            <given-names>J. R. C.</given-names>
            <surname>Nurse</surname>
          </string-name>
          ,
          <string-name>
            <given-names>O.</given-names>
            <surname>Buckley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.A.</given-names>
            <surname>Legg</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Goldsmith</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Creese</surname>
          </string-name>
          ,
          <string-name>
            <given-names>G. R. T.</given-names>
            <surname>Wright</surname>
          </string-name>
          , and
          <string-name>
            <given-names>M.</given-names>
            <surname>Whitty</surname>
          </string-name>
          .
          <article-title>Understanding Insider Threat: A Framework for Characterising Attacks</article-title>
          ,
          <year>2014</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref44">
        <mixed-citation>
          [45]
          <string-name>
            <given-names>R. N.</given-names>
            <surname>Carvalho</surname>
          </string-name>
          ,
          <string-name>
            <surname>K. B. Laskey</surname>
            , and
            <given-names>P. C.</given-names>
          </string-name>
          <string-name>
            <surname>Costa</surname>
          </string-name>
          . “
          <article-title>Uncertainty modeling process for semantic technology</article-title>
          .
          <source>” PeerJ Computer Science</source>
          ,
          <year>2016</year>
          ,
          <volume>2</volume>
          :e77 https://doi.org/10.7717/peerj-cs.
          <fpage>77</fpage>
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>