Detecting Insider Threats Through Language Change

Taylor, Paul John orcid iconORCID: 0000-0002-9999-8397, Dando, Coral J, Ormerod, Thomas C, Ball, Linden orcid iconORCID: 0000-0002-5099-0124, Jenkins, Marisa C and Sandham, Alexandra (2013) Detecting Insider Threats Through Language Change. Law and Human Behavior, 37 (4). pp. 267-275.

Full text not available from this repository.

Official URL: http://dx.doi.org/10.1037/lhb0000032

Abstract

The act of conducting an insider attack carries with it cognitive and social challenges that may affect an offender’s day-to-day work behavior. We test this hypothesis by examining the language used in e-mails that were sent as part of a 6-hr workplace simulation. The simulation involved participants (N = 54) examining databases and exchanging information as part of a four-stage organized crime investigation. After the first stage, 25% of the participants were covertly incentivized to act as an “insider” by providing information to a provocateur. Analysis of the language used in participants’ e-mails found that insiders became more self-focused, showed greater negative affect, and showed more cognitive processing compared to their coworkers. At the interpersonal level, insiders showed significantly more deterioration in the degree to which their language mimicked other team members over time. Our findings demonstrate how language may provide an indirect way of identifying employees who are undertaking an insider attack.


Repository Staff Only: item control page