{"id":"https://openalex.org/W4414343920","doi":"https://doi.org/10.1145/3763792","title":"Evaluating Honeyfile Realism and Enticement Metrics","display_name":"Evaluating Honeyfile Realism and Enticement Metrics","publication_year":2025,"publication_date":"2025-09-18","ids":{"openalex":"https://openalex.org/W4414343920","doi":"https://doi.org/10.1145/3763792"},"language":"en","primary_location":{"id":"doi:10.1145/3763792","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3763792","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"},"type":"article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5079306410","display_name":"Roelien C. Timmer","orcid":"https://orcid.org/0009-0009-4621-3363"},"institutions":[{"id":"https://openalex.org/I1292875679","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07","country_code":"AU","type":"government","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]},{"id":"https://openalex.org/I4210087931","display_name":"Institute for Security Studies","ror":"https://ror.org/004zjze34","country_code":"KE","type":"nonprofit","lineage":["https://openalex.org/I4210087931","https://openalex.org/I4210093398"]},{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU","KE"],"is_corresponding":true,"raw_author_name":"Roelien Timmer","raw_affiliation_strings":["CSIRO Data61","Cyber Security CRC","University of New South Wales","Cyber Security CRC, Sydney Australia","CSIRO Data61, Sydney, Australia","University of New South Wales, Sydney, Australia"],"raw_orcid":"https://orcid.org/0009-0009-4621-3363","affiliations":[{"raw_affiliation_string":"CSIRO Data61","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I1292875679"]},{"raw_affiliation_string":"Cyber Security CRC","institution_ids":[]},{"raw_affiliation_string":"University of New South Wales","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"Cyber Security CRC, Sydney Australia","institution_ids":["https://openalex.org/I4210087931"]},{"raw_affiliation_string":"CSIRO Data61, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I1292875679"]},{"raw_affiliation_string":"University of New South Wales, Sydney, Australia","institution_ids":["https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034185104","display_name":"David Liebowitz","orcid":"https://orcid.org/0009-0003-0561-7931"},"institutions":[{"id":"https://openalex.org/I188329596","display_name":"University of Canberra","ror":"https://ror.org/04s1nv328","country_code":"AU","type":"education","lineage":["https://openalex.org/I188329596"]},{"id":"https://openalex.org/I2803011651","display_name":"PEN American Center","ror":"https://ror.org/00686bx53","country_code":"US","type":"nonprofit","lineage":["https://openalex.org/I2803011651"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU","US"],"is_corresponding":false,"raw_author_name":"David Liebowitz","raw_affiliation_strings":["Penten","University of New South Wales","University of New South Wales, Sydney Australia","Penten, Canberra Australia"],"raw_orcid":"https://orcid.org/0009-0003-0561-7931","affiliations":[{"raw_affiliation_string":"Penten","institution_ids":["https://openalex.org/I2803011651"]},{"raw_affiliation_string":"University of New South Wales","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"University of New South Wales, Sydney Australia","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"Penten, Canberra Australia","institution_ids":["https://openalex.org/I188329596"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5082256444","display_name":"\u202aSurya Nepal\u202c","orcid":"https://orcid.org/0000-0002-3289-6599"},"institutions":[{"id":"https://openalex.org/I1292875679","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07","country_code":"AU","type":"government","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I4210087931","display_name":"Institute for Security Studies","ror":"https://ror.org/004zjze34","country_code":"KE","type":"nonprofit","lineage":["https://openalex.org/I4210087931","https://openalex.org/I4210093398"]},{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU","KE"],"is_corresponding":false,"raw_author_name":"Surya Nepal","raw_affiliation_strings":["CSIRO Data61","Cyber Security CRC","CSIRO Data61, Sydney Australia","Cyber Security CRC, Sydney Australia"],"raw_orcid":"https://orcid.org/0000-0002-3289-6599","affiliations":[{"raw_affiliation_string":"CSIRO Data61","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I1292875679"]},{"raw_affiliation_string":"Cyber Security CRC","institution_ids":[]},{"raw_affiliation_string":"CSIRO Data61, Sydney Australia","institution_ids":["https://openalex.org/I42894916"]},{"raw_affiliation_string":"Cyber Security CRC, Sydney Australia","institution_ids":["https://openalex.org/I4210087931"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5059077090","display_name":"Salil S. Kanhere","orcid":"https://orcid.org/0000-0002-1835-3475"},"institutions":[{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]},{"id":"https://openalex.org/I4210087931","display_name":"Institute for Security Studies","ror":"https://ror.org/004zjze34","country_code":"KE","type":"nonprofit","lineage":["https://openalex.org/I4210087931","https://openalex.org/I4210093398"]}],"countries":["AU","KE"],"is_corresponding":false,"raw_author_name":"Salil Kanhere","raw_affiliation_strings":["Cyber Security CRC","University of New South Wales","University of New South Wales, Sydney, Australia","Cyber Security CRC, Sydney Australia"],"raw_orcid":"https://orcid.org/0000-0002-1835-3475","affiliations":[{"raw_affiliation_string":"Cyber Security CRC","institution_ids":[]},{"raw_affiliation_string":"University of New South Wales","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"University of New South Wales, Sydney, Australia","institution_ids":["https://openalex.org/I31746571"]},{"raw_affiliation_string":"Cyber Security CRC, Sydney Australia","institution_ids":["https://openalex.org/I4210087931"]}]}],"institutions":[],"countries_distinct_count":3,"institutions_distinct_count":4,"corresponding_author_ids":["https://openalex.org/A5079306410"],"corresponding_institution_ids":["https://openalex.org/I1292875679","https://openalex.org/I31746571","https://openalex.org/I4210087931","https://openalex.org/I42894916"],"apc_list":null,"apc_paid":null,"fwci":0.0,"has_fulltext":false,"cited_by_count":0,"citation_normalized_percentile":{"value":0.36098412,"is_in_top_1_percent":false,"is_in_top_10_percent":false},"cited_by_percentile_year":null,"biblio":{"volume":"28","issue":"4","first_page":"1","last_page":"34"},"is_retracted":false,"is_paratext":false,"is_xpac":false,"primary_topic":{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9939000010490417,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T12519","display_name":"Cybercrime and Law Enforcement Studies","score":0.9939000010490417,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T11644","display_name":"Spam and Phishing Detection","score":0.9933000206947327,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10734","display_name":"Information and Cyber Security","score":0.9927999973297119,"subfield":{"id":"https://openalex.org/subfields/1710","display_name":"Information Systems"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[{"id":"https://openalex.org/keywords/cohesion","display_name":"Cohesion (chemistry)","score":0.7050999999046326},{"id":"https://openalex.org/keywords/realism","display_name":"Realism","score":0.6107000112533569},{"id":"https://openalex.org/keywords/coherence","display_name":"Coherence (philosophical gambling strategy)","score":0.5134999752044678},{"id":"https://openalex.org/keywords/perception","display_name":"Perception","score":0.5105999708175659},{"id":"https://openalex.org/keywords/similarity","display_name":"Similarity (geometry)","score":0.4422000050544739},{"id":"https://openalex.org/keywords/matching","display_name":"Matching (statistics)","score":0.420199990272522}],"concepts":[{"id":"https://openalex.org/C104054115","wikidata":"https://www.wikidata.org/wiki/Q216828","display_name":"Cohesion (chemistry)","level":2,"score":0.7050999999046326},{"id":"https://openalex.org/C543847140","wikidata":"https://www.wikidata.org/wiki/Q2642826","display_name":"Realism","level":2,"score":0.6107000112533569},{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.5785999894142151},{"id":"https://openalex.org/C2781181686","wikidata":"https://www.wikidata.org/wiki/Q4226068","display_name":"Coherence (philosophical gambling strategy)","level":2,"score":0.5134999752044678},{"id":"https://openalex.org/C26760741","wikidata":"https://www.wikidata.org/wiki/Q160402","display_name":"Perception","level":2,"score":0.5105999708175659},{"id":"https://openalex.org/C103278499","wikidata":"https://www.wikidata.org/wiki/Q254465","display_name":"Similarity (geometry)","level":3,"score":0.4422000050544739},{"id":"https://openalex.org/C154945302","wikidata":"https://www.wikidata.org/wiki/Q11660","display_name":"Artificial intelligence","level":1,"score":0.42910000681877136},{"id":"https://openalex.org/C165064840","wikidata":"https://www.wikidata.org/wiki/Q1321061","display_name":"Matching (statistics)","level":2,"score":0.420199990272522},{"id":"https://openalex.org/C48145219","wikidata":"https://www.wikidata.org/wiki/Q1335365","display_name":"Security token","level":2,"score":0.38839998841285706},{"id":"https://openalex.org/C2780009758","wikidata":"https://www.wikidata.org/wiki/Q6804172","display_name":"Measure (data warehouse)","level":2,"score":0.3531999886035919},{"id":"https://openalex.org/C77805123","wikidata":"https://www.wikidata.org/wiki/Q161272","display_name":"Social psychology","level":1,"score":0.3091000020503998},{"id":"https://openalex.org/C15744967","wikidata":"https://www.wikidata.org/wiki/Q9418","display_name":"Psychology","level":0,"score":0.30799999833106995},{"id":"https://openalex.org/C168072608","wikidata":"https://www.wikidata.org/wiki/Q10860201","display_name":"Direct and indirect realism","level":3,"score":0.30140000581741333},{"id":"https://openalex.org/C2522767166","wikidata":"https://www.wikidata.org/wiki/Q2374463","display_name":"Data science","level":1,"score":0.2797999978065491},{"id":"https://openalex.org/C111472728","wikidata":"https://www.wikidata.org/wiki/Q9471","display_name":"Epistemology","level":1,"score":0.2662000060081482},{"id":"https://openalex.org/C129671850","wikidata":"https://www.wikidata.org/wiki/Q210501","display_name":"Introspection","level":2,"score":0.2612000107765198}],"mesh":[],"locations_count":1,"locations":[{"id":"doi:10.1145/3763792","is_oa":false,"landing_page_url":"https://doi.org/10.1145/3763792","pdf_url":null,"source":{"id":"https://openalex.org/S4210174050","display_name":"ACM Transactions on Privacy and Security","issn_l":"2471-2566","issn":["2471-2566","2471-2574"],"is_oa":false,"is_in_doaj":false,"is_core":true,"host_organization":"https://openalex.org/P4310319798","host_organization_name":"Association for Computing Machinery","host_organization_lineage":["https://openalex.org/P4310319798"],"host_organization_lineage_names":["Association for Computing Machinery"],"type":"journal"},"license":null,"license_id":null,"version":"publishedVersion","is_accepted":true,"is_published":true,"raw_source_name":"ACM Transactions on Privacy and Security","raw_type":"journal-article"}],"best_oa_location":null,"sustainable_development_goals":[],"awards":[],"funders":[{"id":"https://openalex.org/F4320320386","display_name":"Commonwealth Scientific and Industrial Research Organisation","ror":"https://ror.org/03qn8fb07"},{"id":"https://openalex.org/F4320320965","display_name":"University of New South Wales","ror":"https://ror.org/03r8z3t63"}],"has_content":{"pdf":false,"grobid_xml":false},"content_urls":null,"referenced_works_count":21,"referenced_works":["https://openalex.org/W214995755","https://openalex.org/W1700658463","https://openalex.org/W1971950880","https://openalex.org/W1993091451","https://openalex.org/W2050411378","https://openalex.org/W2062293785","https://openalex.org/W2126163604","https://openalex.org/W2509254371","https://openalex.org/W2599674900","https://openalex.org/W2600441078","https://openalex.org/W2884962025","https://openalex.org/W2912342920","https://openalex.org/W2951080837","https://openalex.org/W3098034923","https://openalex.org/W3128875015","https://openalex.org/W3175044419","https://openalex.org/W3189604664","https://openalex.org/W4231510805","https://openalex.org/W4238846128","https://openalex.org/W4367046362","https://openalex.org/W4391902753"],"related_works":[],"abstract_inverted_index":{"Deceptive":[0],"files,":[1],"often":[2],"called":[3],"honeyfiles,":[4],"have":[5,98],"become":[6],"an":[7],"established":[8],"tool":[9],"in":[10,14,146],"cyber":[11],"security.":[12],"Advances":[13],"machine":[15],"learning":[16],"(ML)":[17],"models":[18],"for":[19,53,95,118,127,177,190,202],"content":[20],"generation":[21],"now":[22],"allow":[23],"the":[24,65,69,80,86,91,101,137,161,178,185,191,203],"synthesis":[25],"of":[26,51,71,82,139,165],"deceptive":[27,83],"material":[28],"automatically":[29],"and":[30,43,60,109,120,122,163,197,200,207],"at":[31],"scale.":[32],"Metrics":[33],"to":[34,41,67,85,136,143,159],"quantify":[35],"honeyfile":[36,92,166],"attributes":[37,97],"are":[38,56,58],"thus":[39],"essential":[40],"creating":[42],"evaluating":[44],"effective":[45],"deceptions.":[46],"The":[47,172],"two":[48],"critical":[49],"aspects":[50],"honeyfiles":[52],"which":[54],"metrics":[55,94,135],"useful":[57],"enticement":[59,164,179,187],"realism":[61,162,204],".":[62],"Enticement":[63],"is":[64,182],"ability":[66],"attract":[68],"attention":[70],"intruders":[72],"or":[73],"users":[74,141],"with":[75,184,213],"malicious":[76],"intent.":[77],"Realism":[78],"measures":[79],"similarity":[81],"artefacts":[84],"objects":[87],"they":[88],"mimic.":[89],"In":[90,129],"literature,":[93],"these":[96,134],"been":[99],"proposed:":[100],"Common":[102],"Token":[103],"Count":[104],"(CTC)":[105],"[":[106,114,124],"1":[107],"],":[108],"Topic":[110],"Semantic":[111],"Matching":[112],"(TSM)":[113],"2":[115],"]":[116,126],"scores":[117],"enticement,":[119],"coherence":[121],"cohesion":[123,206],"3":[125],"realism.":[128,215],"this":[130],"study,":[131],"we":[132,194],"compare":[133],"perceptions":[138],"human":[140],"exposed":[142],"text":[144,167],"samples":[145],"a":[147,153],"simulated":[148],"data":[149],"breach":[150],"scenario":[151],"on":[152],"crowd-sourcing":[154],"platform.":[155],"We":[156],"recruited":[157],"participants":[158],"judge":[160],"generated":[168],"using":[169],"several":[170],"techniques.":[171],"main":[173],"findings":[174],"are:":[175],"(i)":[176],"metrics,":[180,205],"TSM":[181],"aligned":[183],"perceived":[186,214],"(p-value&lt;0.001),":[188],"while":[189],"CTC":[192],"score,":[193],"find":[195],"inconsistent":[196],"inconclusive":[198],"results,":[199],"(ii)":[201],"coherence,":[208],"do":[209],"not":[210],"consistently":[211],"align":[212]},"counts_by_year":[],"updated_date":"2025-11-20T23:13:51.555489","created_date":"2025-10-10T00:00:00"}
