Matthew Edwards 0001

dblp:08/9599-1 · also Matthew John Edwards · DBLP profile ↗
← Back
14ranked-venue papers
2as first author
7since 2021 · last 2024
0000-0001-8099-0646ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 1 first-author · 3 since 2021Artificial intelligence and machine learning · 4 · 1 first-author · 3 since 2021Databases, data management, data science and information retrieval · 4 · 1 first-author · 3 since 2021Applied, interdisciplinary, general and emerging computing · 3 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1 · 1 since 2021
YearPublicationVenuePosition
2024 Leading the Mastodon Herd: Analysing the Traits of Influential Leaders on a Decentralised Social Media Platform
abstract
With the development and growing use of social media platforms in the last two decades, platform architectures have driven how we notice, consume and share information. Whilst centralised social networks and the use of recommendation algorithms are a prominently used architecture, in recent years an alternative and novel framework has emerged aiming to offer users a non-commercial decentralised platform to distribute content. Run by users of the platform, Mastodon offers many of the benefits of traditional centralised approaches, however, with the absence of recommendation algorithms there is risk that these architectures could instead promote echo-chambers and the growth of disinformation. With this in mind, we collect a new large Mastodon dataset, consisting of three million connections between over a hundred thousand users. Modelling content using 68 conversational features, and measuring influence using twelve different metrics, we analyse the most common topics being discussed between influential users, the conversational features present in influential content, and the relationships between influence measurements. Our analysis finds a strong correlation between influence and negative traits at every network resolution, with positive and neutral traits in some cases being negatively correlated with influence. Our analysis also shows that influential users have a strong relationship with social/political commentary.
Luke Gassmann, Ryan McConville, Matthew Edwards 0001
IEEE Big Data3
2023 Analysing The Activities Of Far-Right Extremists On The Parler Social Network
abstract
A significant gap remains in our understanding of the types of users who utilise online extremist platforms, as well as how their activity on these platforms influences the radicalisation of others and the dissemination of extremist content online. Our research addresses this gap by focusing on the Parler social network, one of the largest social media platforms used by the extreme far-right, boasting a reported 15 million total users as of January 2022. We present an exploration of the Parler social network, specifically reviewing the roles of users in the network and the types of activity and content shared on the platform. Our methodology provides a novel examination of Parler using tools that have previously been tested to understand other extremist groups.
James Stevenson, Matthew Edwards 0001, Awais Rashid
ASONAM2
2023 Active Countermeasures for Email Fraud
abstract
As a major component of online crime, email-based fraud is a threat that causes substantial economic losses every year. To counteract these scammers, volunteers called scam-baiters play the roles of victims, reply to scammers, and try to waste their time and attention with long and unproductive conversations. To curb email fraud and magnify the effectiveness of scam-baiting, we developed and deployed an expandable scam-baiting mailserver that can conduct scam-baiting activities automatically. We implemented three reply strategies using three different models and conducted a one-month-long experiment during which we elicited 150 messages from 130 different scammers. We compare the performance of each strategy at attracting and holding the attention of scammers, finding tradeoffs between human-written and automatically-generated response strategies. We also demonstrate that scammers can be engaged concurrently by multiple servers deploying these strategies in a second experiment, which used two server instances to contact 92 different scammers over 12 days. We release both our platform and a dataset containing conversations between our automatic scam-baiters and real human scammers, to support future work in preventing online fraud.
Fuzhou Wang, Matthew Edwards 0001
EuroS&P3
2023 Temporal Constraints in Online Dating Fraud Classification
abstract
A number of automated systems attempt to combat online fraud through the application of classifiers created using machine learning techniques. However, online fraud is a moving target, and cybercriminals alter their strategies over time, causing a gradual decay in the effectiveness of classifiers designed to detect them. In this paper we demonstrate the existence of this concept drift in an online dating fraud classification problem. Working with a dataset of real and fraudulent dating site profiles spread over 6 years, we measure the extent to which dating fraud classification performance may be expected to decay, finding substantial decay in classifier F1 over time, amounting to a decrease of more than 0.2 F1 by the end of our evaluation period. We also evaluate strategies for keeping fraud classification performance robust over time, suggesting mitigations that may be deployed in practice.
Harrison Bullock, Matthew Edwards 0001
ICISSP2
2023 Automatic Scam-Baiting Using ChatGPT
abstract
Automatic scam-baiting is an online fraud countermeasure that involves automated systems responding to online fraudsters in order to waste their time and deplete their resources, diverting attackers away from real potential victims. Previous work has demonstrated that text generation systems are capable of engaging with attackers as automatic scam-baiters, but the fluency and coherence of generated text may be a limit to the effectiveness of such systems.In this paper, we report on the results of a month-long experiment comparing the effectiveness of two ChatGPT-based automatic scam-baiters to a control measure. Within our results, with engagement from over 250 real email fraudsters, we find that ChatGPT-based scam-baiters show a marked increase in scammer response rate and conversation length relative to the control measure, outperforming previous approaches. We discuss the implications of these results and practical considerations for wider deployment of automatic scam-baiting.
Piyush Bajaj, Matthew Edwards 0001
TrustCom2
2022 The Best Laid Plans or Lack Thereof: Security Decision-Making of Different Stakeholder Groups
abstract
Cyber security requirements are influenced by the priorities and decisions of a range of stakeholders. Board members and Chief Information Security Officers (CISOs) determine strategic priorities. Managers have responsibility for resource allocation and project management. Legal professionals concern themselves with regulatory compliance. Little is understood about how the security decision-making approaches of these different stakeholders contrast, and if particular groups of stakeholders have a better appreciation of security requirements during decision-making. Are risk analysts better decision makers than CISOs? Do security experts exhibit more effective strategies than board members? This paper explores the effect that different experience and diversity of expertise has on the quality of a team's cyber security decision-making and whether teams with members from more varied backgrounds perform better than those with more focused, homogeneous skill sets. Using data from 208 sessions and 948 players of a tabletop game runin the wildby a major national organization over 16 months, we explore how choices are affected by player background (e.g., cyber security experts versus risk analysts, board-level decision makers versus technical experts) and different team make-ups (homogeneous teams of security experts versus various mixes). We find that no group of experts makes significantly better game decisions than anyone else, and that their biases lead them to not fully comprehend what they are defending or how the defenses work.
Ben Shreeve, Joseph Hallett, Matthew Edwards 0001, Kopo M. Ramokapane, Richard Atkins, Awais Rashid
IEEE Trans. Software Eng.3
2021 AMoC: A Multifaceted Machine Learning-based Toolkit for Analysing Cybercriminal Communities on the Darknet
abstract
There is an increasing demand for expert analysis of cybercriminal communities. Cybercrime is continually becoming more complex due to the rapid development of digital technologies, on the one hand, in new types of criminal activity, such as hacking, distributing malware and DDoS attacks, and on the other hand, in digitised forms of more traditional crimes, such as email scams, phishing, identity theft, and cryptographically secured black markets. Tackling this broad array of behaviour requires tool support for multi-disciplinary investigations, and a connecting framework that can adjust flexibly to changes in the populations being studied. In this work, we present AMoC, a multi-faceted machine learning toolkit that combines structured queries, anomaly detection, social network analysis, topic modelling and accounts recognition to enable comprehensive analysis of cybercriminal communities and users. The toolkit enables the extraction of findings regarding the motivations, behaviour and characteristics of offenders, and how cybercriminal communities react to interventions such as arrests and take-downs. In our demonstration, the toolkit is deployed to analyse over 150,000 accounts from 35 underground marketplaces.
Claudia Peersman, Matthew Edwards 0001, Ziauddin Ursani, Awais Rashid
IEEE BigData3
2020 Pets without PETs: on pet owners' under-estimation of privacy concerns in pet wearables
abstract
Abstract We report on a mixed-method, comparative study investigating whether there is a difference between privacy concerns expressed about pet wearables as opposed to human wearables – and more importantly,why. We extracted the privacy concerns found in product reviews (N=8,038) of pet wearables (activity, location, and dual-function trackers), contrasting the (lack of) concerns and misuse to a curated set of reviews for similar human-oriented wearables (N=20,431). Our findings indicate that, while overall very few privacy concerns are expressed in product reviews, for pet wearables they are expressed even less, even though consumers use these devices in a manner which impacts both personal and bystander privacy. An additional survey of pet owners (N=201) eliciting what factors would cause them to not purchase (or stop using) pet wearables indicated comparably few privacy concerns, strengthening the representativeness of our findings. A thematic analysis reveals that the lack of privacy concerns may be explained by, among other factors, emotional drivers to purchase the device, and prioritization of (desired) functionality to support those emotional drivers over privacy requirements. Moreover, we found that pet wearables are used in different ways than originally intended, which raise novel privacy implications to be dealt with. We propose that in order to move towards more privacy-conscious use of pet wearables, a combination of understanding consumer rationale and behavior as well as ensuring data protection legislation is adequate to real-world use is needed.
Dirk van der Linden, Matthew Edwards 0001, Irit Hadar, Anna Zamansky
Proc. Priv. Enhancing Technol.2
2020 Automatically Dismantling Online Dating Fraud
abstract
Online romance scams are a prevalent form of mass-marketing fraud in the West, and yet few studies have presented data-driven responses to this problem. In this type of scam, fraudsters craft fake profiles and manually interact with their victims. Because of the characteristics of this type of fraud and how dating sites operate, traditional detection methods (e.g., those used in spam filtering) are ineffective. In this paper, we investigate the archetype of online dating profiles used in this form of fraud, including their use of demographics, profile descriptions, and images, shedding light on both the strategies deployed by scammers to appeal to victims and the traits of victims themselves. Furthermore, in response to the severe financial and psychological harm caused by dating fraud, we develop a system to detect romance scammers on online dating platforms. This paper presents the first fully described system for automatically detecting this fraud. Our aim is to provide an early detection system to stop romance scammers as they create fraudulent profiles or before they engage with potential victims. Previous research has indicated that the victims of romance scams score highly on scales for idealized romantic beliefs. We combine a range of structured, unstructured, and deep-learned features that capture these beliefs in order to build a detection system. Our ensemble machine-learning approach is robust to the omission of profile details and performs at high accuracy (97%) in a hold-out validation set. The system enables development of automated tools for dating site providers and individual users.
Guillermo Suarez-Tangil, Matthew Edwards 0001, Claudia Peersman, Gianluca Stringhini, Awais Rashid, Monica T. Whitty
IEEE Trans. Inf. Forensics Secur.2
2020 "So if Mr Blue Head here clicks the link..." Risk Thinking in Cyber Security Decision Making
abstract
Cyber security decision making is inherently complicated, with nearly every decision having knock-on consequences for an organisation’s vulnerability and exposure. This is further compounded by the fact that decision-making actors are rarely security experts and may have an incomplete understanding of the security that the organisation currently has in place. They must contend with a multitude of possible security options that they may only partially understand. This challenge is met by decision makers’ risk thinking —their strategies for identifying risks, assessing their severity, and prioritising responses. We study the risk thinking strategies employed by teams of participants in an existing dataset derived from a tabletop cyber-physical systems security game. Our analysis identifies four structural patterns of risk thinking and two reasoning strategies: risk-first and opportunity-first . Our work highlights that risk-first approaches (as prescribed by the likes of NIST-800-53 and ISO 27001) are followed neither substantially nor exclusively when it comes to decision making. Instead, our analysis finds that decision making is affected by the plasticity of teams—that is, the ability to readily switch between ideas and practising both risk-first and opportunity-first reasoning.
Ben Shreeve, Joseph Hallett, Matthew Edwards 0001, Pauline Anthonysamy, Sylvain Frey, Awais Rashid
ACM Trans. Priv. Secur.3
2018 Data exfiltration: A review of external attack vectors and countermeasures
Faheem Ullah, Matthew Edwards 0001, Rajiv Ramdhany, Ruzanna Chitchyan, Muhammad Ali Babar 0001, Awais Rashid
J. Netw. Comput. Appl.2
2017 Panning for gold: Automatically analysing online social engineering attack surfaces
abstract
The process of social engineering targets people rather than IT infrastructure. Attackers use deceptive ploys to create compelling behavioural and cosmetic hooks, which in turn lead a target to disclose sensitive information or to interact with a malicious payload. The creation of such hooks requires background information on targets. Individuals are increasingly releasing information about themselves online, particularly on social networks. Though existing research has demonstrated the social engineering risks posed by such open source intelligence, this has been accomplished either through resource-intensive manual analysis or via interactive information harvesting techniques. As manual analysis of large-scale online information is impractical, and interactive methods risk alerting the target, alternatives are desirable. In this paper, we demonstrate that key information pertinent to social engineering attacks on organisations can be passively harvested on a large-scale in an automated fashion. We address two key problems. We demonstrate that it is possible to automatically identify employees of an organisation using only information which is visible to a remote attacker as a member of the public. Secondly, we show that, once identified, employee profiles can be linked across multiple online social networks to harvest additional information pertinent to successful social engineering attacks. We further demonstrate our approach through analysis of the social engineering attack surface of real critical infrastructure organisations. Based on our analysis we propose a set of countermeasures including an automated social engineering vulnerability scanner that organisations can use to analyse their exposure to potential social engineering attacks arising from open source intelligence.
Matthew Edwards 0001, Robert Larson, Benjamin Green 0001, Awais Rashid, Alistair Baron
Comput. Secur.1
2016 Sampling labelled profile data for identity resolution
abstract
Identity resolution capability for social networking profiles is important for a range of purposes, from open-source intelligence applications to forming semantic web connections. Yet replication of research in this area is hampered by the lack of access to ground-truth data linking the identities of profiles from different networks. Almost all data sources previously used by researchers are no longer available, and historic datasets are both of decreasing relevance to the modern social networking landscape and ethically troublesome regarding the preservation and publication of personal data. We present and evaluate a method which provides researchers in identity resolution with easy access to a realistically-challenging labelled dataset of online profiles, drawing on four of the currently largest and most influential online social networks. We validate the comparability of samples drawn through this method and discuss the implications of this mechanism for researchers as well as potential alternatives and extensions.
Matthew Edwards 0001, Stephen Wattam, Paul Rayson, Awais Rashid
IEEE BigData1
2016 Discovering "unknown known" security requirements
abstract
Security is one of the biggest challenges facing organisations in the modern hyper-connected world. A number of theoretical security models are available that provide best practice security guidelines and are widely utilised as a basis to identify and operationalise security requirements. Such models often capture high-level security concepts (e.g., whitelisting, secure configurations, wireless access control, data recovery, etc.), strategies for operationalising such concepts through specific security controls, and relationships between the various concepts and controls. The threat landscape, however, evolves leading to new tacit knowledge that is embedded in or across a variety of security incidents. These unknown knowns alter, or at least demand reconsideration of the theoretical security models underpinning security requirements. In this paper, we present an approach to discover such unknown knowns through multi-incident analysis. The approach is based on a novel combination of grounded theory and incident fault trees. We demonstrate the effectiveness of the approach through its application to identify revisions to a theoretical security model widely used in industry.
Awais Rashid, Syed Asad Naqvi, Rajiv Ramdhany, Matthew Edwards 0001, Ruzanna Chitchyan, Muhammad Ali Babar 0001
ICSE4