Mike Just

dblp:03/3777 · DBLP profile ↗
← Back
21ranked-venue papers
6as first author
7since 2021 · last 2026
0000-0002-9669-5067ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 5 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 8 · 2 first-author · 2 since 2021Computer networks · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Clear, Actionable and Confidence-Inspiring Recommendations? Comparative Study of AI-Generated and Human-Written PT Reports
Katarína Galanská, Maria Pibilota Murumaa, Vashek Matyas, Agata Kruzikova, Mike Just, Tomás Cerný
SOUPS5
2025 IoTGeM: Generalizable models for behaviour-based IoT attack detection
Kahraman Kostas, Mike Just, Michael A. Lones
Comput. Networks2
2023 A comic-based approach to permission request communication
abstract
Text-based permission requests do little to engage and inform smartphone users. Comics have recently been used with permission requests, though only in a survey of participants' perceived reactions. In this paper we study more realistic reactions to comic-based and text-based permission requests. For our study, we invited participants to engage with a prototype version of a fictitious WebApp (PetConnect); participants were only informed of our intent to study permission requests at the end of the study. While using the app, participants were exposed to four permission request types (contact, storage, location and calendar) related to different functions of our app, using one of two styles of request (comic-based or text-based). Our results showed that participants were significantly more likely to deny the comic-based requests vs the text-based requests (47% vs 33%) and that comic-based requests were perceived to be more influential in participant decision making. Both styles of request were perceived to be equally relevant to the app, as well as equally annoying. We discuss several observations for future permission request design based on our participants' explanations of their choices.
Katie Watson, Mike Just, Tessa Berg
Comput. Secur.2
2022 Digital security in families: the sources of information relate to the active mediation of internet safety and parental internet skills
abstract
Home users of information and communication technologies are often the target of online attacks. At the same time they tend to lack the knowledge and skills to effectively protect themselves. Families with children are in a particularly difficult position since parents are responsible not only for their own digital safety, but of their children’s too. This study focuses on the sources of digital security information used by parents. The aim of this study was to determine the factors that are associated with parents’ preferences for digital security information. To achieve this aim, we conducted an online survey of 331 Czech parents and examined the patterns of sources used for digital security information using latent class analysis. This analysis identified four groups of parents: (1) those relying predominantly on the internet in general, (2) those using specialised sources (expert websites and professionals), (3) those utilising a wide spectrum of sources, including internet, television, and friends and family, and (4) those who predominantly gain information from their partners, and partially from specialists. The study also shows that the preferences of specific sources are connected to parental mediation practices and both parents’ internet skills.
Lenka Dedkova, David Smahel, Mike Just
Behav. Inf. Technol.3
2022 IoTDevID: A Behavior-Based Device Identification Method for the IoT
abstract
Device identification (DI) is one way to secure a network of Internet of Things (IoT) devices, whereby devices identified as suspicious can subsequently be isolated from a network. In this study, we present a machine-learning-based method, IoTDevID, that recognizes devices through the characteristics of their network packets. As a result of using a rigorous feature analysis and selection process, our study offers a generalizable and realistic approach to modeling device behavior, achieving high predictive accuracy across two public data sets. The model’s underlying feature set is shown to be more predictive than existing feature sets used for DI and is shown to generalize to data unseen during the feature selection process. Unlike most existing approaches to IoT DI, IoTDevID is able to detect devices using non-IP and low-energy protocols.
Kahraman Kostas, Mike Just, Michael A. Lones
IEEE Internet Things J.2
2021 Anomaly Detection for Insider Threats: An Objective Comparison of Machine Learning Models and Ensembles
Filip Wieslaw Bartoszewski, Mike Just, Michael A. Lones, Oleksii Mandrychenko
SEC2
2021 A review of amplification-based distributed denial of service attacks and their mitigation
Salih Ismail, Hani Ragab Hassen, Mike Just, Hind Zantout
Comput. Secur.3
2018 Experimental large-scale review of attractors for detection of potentially unwanted applications
Vlasta Stavova, Lenka Dedkova, Vashek Matyas, Mike Just, David Smahel, Martin Ukrop
Comput. Secur.4
2017 Keeping Children Safe Online: Understanding the Concerns of Carers of Children with Autism
Mike Just, Tessa Berg
INTERACT (3)1
2016 Investigating Time Series Visualisations to Improve the User Experience
abstract
Research on graphical perception of time series visualisations has focused on visual representation, and not on interaction. Even for visual representation, there has been limited study of the impact on users of visual encodings and the strengths and weaknesses of Cartesian and Polar coordinate systems. In order to address this research gap, we performed a comprehensive graphical perception study that measured the effectiveness of time series visualisations with different interactions, visual encodings and coordinate systems for several tasks. Our results show that, while positional and colour visual encodings were better for most tasks, area visual encoding performed better for data comparison. Most importantly, we identified that introducing interactivity within time series visualisations considerably enhances the user experience, without any loss of efficiency or accuracy. We believe that our findings can greatly improve the development of visual analytics tools using time series visualisations in a variety of domains.
Muhammad Adnan 0001, Mike Just, Lynne Baillie
CHI2
2016 Codes v. People: A Comparative Usability Study of Two Password Recovery Mechanisms
Vlasta Stavova, Vashek Matyas, Mike Just
WISTP3
2015 Why aren't Users Using Protection? Investigating the Usability of Smartphone Locking
abstract
One of the main reasons why smartphone users do not adopt screen locking mechanisms is due to the inefficiency of entering a PIN/pattern each time they use their phone. To address this problem we designed a context-sensitive screen locking application which asked participants to enter a PIN/pattern only when necessary, and evaluated its impact on efficiency and satisfaction. Both groups of participants, who prior to the study either locked or did not lock their phone, adopted our application and felt that unlocking their phone only when necessary was more efficient, did not annoy them and offered a reasonable level of security. Participants responded positively to the option of choosing when a PIN/pattern is required in different contexts. Therefore, we recommend that designers of smartphone locking mechanisms should consider ceding a reasonable level of control over security settings to users to increase adoption and convenience, while keeping smartphones reasonably secure.
Nicholas Micallef, Mike Just, Lynne Baillie, Martin Halvey, Hilmi Günes Kayacik
MobileHCI2
2015 Sensor use and usefulness: Trade-offs for data-driven authentication on mobile devices
abstract
Modern mobile devices come with an array of sensors that support many interesting applications. However, sensors have different sampling costs (e.g., battery drain) and benefits (e.g., accuracy) under different circumstances. In this work we investigate the trade-off between the cost of using a sensor and the benefit gained from its use, with application to data-driven authentication on mobile devices. Current authentication practice, where user behaviour is first learned from the sensor data and then used to detect anomalies, typically assumes a fixed sampling rate and does not consider the battery consumption and usefulness of sensors. In this work we study how battery consumption and sensor effectiveness (e.g., for detecting attacks) vary when using different sensors and different sensor sampling rates. We use data from both controlled lab studies, as well as field trials, for our experiments. We also propose an adaptive sampling technique that adjusts the sampling rate based on an expected device vigilance level. Our results show that it is possible to reduce the battery consumption tenfold without significantly impacting the detection of attacks.
Nicholas Micallef, Hilmi Günes Kayacik, Mike Just, Lynne Baillie, David Aspinall 0001
PerCom3
2015 Investigating the work practices of network security professionals
abstract
Purpose – The purpose of this paper is to investigate the work practices of network security professionals and to propose a new and robust work practices model of these professionals. Design/methodology/approach – The proposed work practices model is composed by combining the findings of ten notable empirical studies performed so far this century. The proposed model was then validated by an online survey of 125 network security professionals with a wide demographic spread. Findings – The empirical data collected from the survey of network security professionals strongly validate the proposed work practices model. The results also highlight interesting trends for different groups of network security professionals, with respect to performing different security-related activities. Research limitations/implications – Further studies could investigate more closely the links and dependencies between the different activities of the proposed work practices model and tools used by network security professionals to perform these activities. Practical implications – A robust work practices model of network security professionals could hugely assist tool developers in designing usable tools for network security management. Originality/value – This paper proposes a new work practices model of network security professionals, which is built by consolidating existing empirical evidence and validated by conducting a survey of network security professionals. The findings enhance the understanding of tool developers about the day-to-day activities of network security professionals, consequently assisting developers in designing better tools for network security management.
Muhammad Adnan 0001, Mike Just, Lynne Baillie, Hilmi Günes Kayacik
Inf. Comput. Secur.2
2014 An ID and Address Protection Unit for NoC based Communication Architectures
abstract
Security is becoming the primary concern in today's embedded systems. Network-on-Chip (NoC) based communication architectures have emerged as an alternative to shared bus mechanism in Multiprocessor System-on-Chip (MPSoC) devices, and the increasing number and functionality of processing cores has made such systems vulnerable to security attacks. In this paper an id and address verification (IAV) security module is presented, which is embedded in each router at the communication level. IAV verifies the identity and address range to be accessed by incoming and outgoing data packets in a NoC-based many-core shared memory architecture. Our IAV architecture is implemented on a FPGA device for functional verification and evaluated in terms of its area and power consumption overhead. For FPGA-based systems, the IAV module can be reconfigured at run-time through partial reconfiguration. In addition, a cycle-accurate simulation is carried out to analyse the performance overhead for different network configurations. The proposed IAV module has reduced area and power consumption overhead when compared with similar existing solutions.
Ahmed Saeed 0003, Ali Ahmadinia, Mike Just, Christophe Bobda
SIN3
2013 Stop questioning me!: towards optimizing user involvement during data collection on mobile devices
abstract
Current methods of behavioral data collection from mobile devices either require significant involvement from participants to verify the 'ground truth' of the data, or approximations that involve post-experiment comparisons to seed data. In this paper we argue that user involvement can be gracefully reduced by performing more intelligent seed comparisons. We aim to reduce the participant involvement to the 'most interesting' temporal slots, both during the experiment and in post-experiment verification. We carried out a 2 week study with 4 users, consisting of an initial opportunistic gathering of mobile sensor data. Our findings suggest that by using such a method we can significantly reduce user involvement.
Nicholas Micallef, Mike Just, Lynne Baillie, Hilmi Günes Kayacik
Mobile HCI2
2009 Personal choice and challenge questions: a security and usability assessment
abstract
Challenge questions are an increasingly important part of mainstream authentication solutions, yet there are few published studies concerning their usability or security. This paper reports on an experimental investigation into user-chosen questions. We collected questions from a large cohort of students, in a way that encouraged participants to give realistic data. The questions allow us to consider possible modes of attack and to judge the relative effort needed to crack a question, according to an innovative model of the knowledge of the attacker. Using this model, we found that many participants were likely to have chosen questions with low entropy answers, yet they believed that their challenge questions would resist attacks from a stranger. Though by asking multiple questions, we are able to show a marked improvement in security for most users. In a second stage of our experiment, we applied existing metrics to measure the usability of the questions and answers. Despite having youthful memories and choosing their own questions, users made errors more frequently than desirable.
Mike Just, David Aspinall 0001
SOUPS1
1999 Addressing the Problem of Undetected Signature Key Compromise
Mike Just, Paul C. van Oorschot
NDSS1
1998 Some Timestamping Protocol Failures
Mike Just
NDSS1
1996 Authenticated Multi-Party Key Agreement
Mike Just, Serge Vaudenay
ASIACRYPT1
1994 On Key Distribution via True Broadcasting
abstract
We consider true broadcast systems for the secure communication of session keys. These schemes provide for parallel rather than serial construction of broadcast messages, while avoiding selective broadcasting. We begin by introducing a conceptual framework for true broadcasting and illustrate its design with a secure key broadcast scheme based on probabilistic encryption. The framework provides for a system requiring user anonymity, as a result of the absence of addressing for the broadcast message. We also illustrate how Shamir's threshold scheme can be altered to allow for parallel broadcasting. We then present a formal model and use information theoretic techniques to establish a lower bound on the size of the broadcast message for a class of true broadcast schemes. Finally, we improve upon the aforementioned threshold scheme such that it achieves the lower bound.
Mike Just, Evangelos Kranakis, Danny Krizanc, Paul C. van Oorschot
CCS1