<?xml version="1.0" encoding="UTF-8"?>
<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Publishing DTD v1.4 20241031//EN"
        "https://jats.nlm.nih.gov/publishing/1.4/JATS-journalpublishing1-4.dtd">
<article  article-type="other"        dtd-version="1.4">
            <front>

                <journal-meta>
                                                                <journal-id>jscai</journal-id>
            <journal-title-group>
                                                                                    <journal-title>Journal of Soft Computing and Artificial Intelligence</journal-title>
            </journal-title-group>
                            <issn pub-type="ppub">2717-8226</issn>
                                                                                                        <publisher>
                    <publisher-name>Mahmut DİRİK</publisher-name>
                </publisher>
                    </journal-meta>
                <article-meta>
                                        <article-id pub-id-type="doi">10.55195/jscai.1213782</article-id>
                                                                <article-categories>
                                            <subj-group  xml:lang="en">
                                                            <subject>Artificial Intelligence</subject>
                                                            <subject>Computer Software</subject>
                                                    </subj-group>
                                            <subj-group  xml:lang="tr">
                                                            <subject>Yapay Zeka</subject>
                                                            <subject>Bilgisayar Yazılımı</subject>
                                                    </subj-group>
                                    </article-categories>
                                                                                                                                                        <title-group>
                                                                                                                                                            <article-title>A User and Entity Behavior Analysis for SIEM Systems: Preprocessing of The Computer Emergency and Response Team Dataset</article-title>
                                                                                                    </title-group>
            
                                                    <contrib-group content-type="authors">
                                                                        <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0000-0001-8276-2030</contrib-id>
                                                                <name>
                                    <surname>Görmez</surname>
                                    <given-names>Yasin</given-names>
                                </name>
                                                                    <aff>SİVAS CUMHURİYET ÜNİVERSİTESİ</aff>
                                                            </contrib>
                                                    <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0000-0003-3286-5159</contrib-id>
                                                                <name>
                                    <surname>Arslan</surname>
                                    <given-names>Halil</given-names>
                                </name>
                                                                    <aff>SİVAS CUMHURİYET ÜNİVERSİTESİ</aff>
                                                            </contrib>
                                                    <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0000-0001-6176-7545</contrib-id>
                                                                <name>
                                    <surname>Işık</surname>
                                    <given-names>Yunus Emre</given-names>
                                </name>
                                                                    <aff>SİVAS CUMHURİYET ÜNİVERSİTESİ</aff>
                                                            </contrib>
                                                    <contrib contrib-type="author">
                                                                    <contrib-id contrib-id-type="orcid">
                                        https://orcid.org/0000-0003-3745-7015</contrib-id>
                                                                <name>
                                    <surname>Dadaş</surname>
                                    <given-names>İbrahim Ethem</given-names>
                                </name>
                                                                    <aff>Detaysoft</aff>
                                                            </contrib>
                                                                                </contrib-group>
                        
                                        <pub-date pub-type="pub" iso-8601-date="20230625">
                    <day>06</day>
                    <month>25</month>
                    <year>2023</year>
                </pub-date>
                                        <volume>4</volume>
                                        <issue>1</issue>
                                        <fpage>1</fpage>
                                        <lpage>6</lpage>
                        
                        <history>
                                    <date date-type="received" iso-8601-date="20221202">
                        <day>12</day>
                        <month>02</month>
                        <year>2022</year>
                    </date>
                                                    <date date-type="accepted" iso-8601-date="20230308">
                        <day>03</day>
                        <month>08</month>
                        <year>2023</year>
                    </date>
                            </history>
                                        <permissions>
                    <copyright-statement>Copyright © 2020, Journal of Soft Computing and Artificial Intelligence</copyright-statement>
                    <copyright-year>2020</copyright-year>
                    <copyright-holder>Journal of Soft Computing and Artificial Intelligence</copyright-holder>
                </permissions>
            
                                                                                                                        <abstract><p>A lot of work has been done to prevent attacks from external sources and a great deal of success has been achieved. However, studies to detect internal attacks aren’t sufficient today. One of the most important studies for the detection of insider attacks is User and Entity Behavior Analysis (UEBA). In this letter, UEBA studies in the literature were reviewed and The Computer Emergency and Response Team Dataset was analyzed (CERT). For this purpose, preprocessing and feature extraction steps were applied on CERT datasets. Several log files combined with respect to user and for each user the number of activities in the specified time interval were obtained. The python code of these preprocessing and feature extraction steps were shared as open source in GitHub platform. In the final phase, future analysis was described and UEBA system planned to be designed was explained.</p></abstract>
                                                            
            
                                                                                        <kwd-group>
                                                    <kwd>User and Entity Behavior Analysis 
Preprocessing
Classification 
CERT 
Security Information and Event Management</kwd>
                                                    <kwd>  Preprocessing</kwd>
                                                    <kwd>  Classification</kwd>
                                                    <kwd>  CERT</kwd>
                                                    <kwd>  Security Information and Event Management</kwd>
                                            </kwd-group>
                            
                                                                                                                                                <funding-group specific-use="FundRef">
                    <award-group>
                                                    <funding-source>
                                <named-content content-type="funder_name">Detaysoft</named-content>
                            </funding-source>
                                                                    </award-group>
                </funding-group>
                                </article-meta>
    </front>
    <back>
                            </back>
    </article>
