VLDB 2026 Research / reviewers in the wild / expert
Ali Mohammad Padyab
dblp:142/8085 · also Ali Padyab
· DBLP profile ↗
4ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0002-5286-4850ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 2 · 1 first-author · 2 since 2021Databases, data management, data science and information retrieval · 1 · 1 first-authorHuman-computer interaction and ubiquitous computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Privacy risk in contact tracing systemsabstractFor over a century, contact tracing has been an integral public health strategy for infectious disease control when there is no pharmaceutical treatment. Contact tracing for the coronavirus disease COVID-19 introduced a variety of automated methods deployed across several countries. The present paper examines privacy risk to infected persons and their physical contacts in contact tracing systems. Automated contact tracing systems implemented during the early months of COVID-19 are compared to conventional manual methods. Solove’s taxonomy of privacy is applied to examine privacy risks in both conventional and automated contact tracing systems. As a method of epidemiological surveillance, all contact tracing systems inherently incur privacy risk. However, compared to conventional methods, automated contact tracing systems amplify privacy risk with pre-emptive data collection on all app users, regardless of exposure to an infectious disease; continuous, granular data collection on all users’ location and proximity contacts; insecurities in proximity app technologies and interconnectivity; and in many cases, the use of centralised systems. Reducing these risk factors can reduce privacy harms, such as identification, distortion, secondary use, stigma, and social control. Janine L. Spears, Ali Mohammad Padyab |
Behav. Inf. Technol. | 2 |
| 2022 | From rationale to lessons learned in the cloud information security risk assessment: a study of organizations in SwedenabstractPurpose This study aims to address the issue of practicing information security risk assessment (ISRA) on cloud solutions by studying municipalities and large organizations in Sweden. Design/methodology/approach Four large organizations and five municipalities that use cloud services and conduct ISRA to adhere to their information security risk management practices were studied. Data were gathered qualitatively to answer the study’s research question: How is ISRA practiced on the cloud? The Coat Hanger model was used as a theoretical lens to study and theorize the practices. Findings The results showed that the organizations aimed to follow the guidelines, in the form of frameworks or their own experience, to conduct ISRA; furthermore, the frameworks were altered to fit the organizations’ needs. The results further indicated that one of the main concerns with the cloud ISRA was the absence of a culture that integrates risk management. Finally, the findings also stressed the importance of a good understanding and a well-written legal contract between the cloud providers and the organizations using the cloud services. Originality/value As opposed to the previous research, which was more inclined to try out and evaluate various cloud ISRA, the study provides insights into the practice of cloud ISRA experienced by the organizations. This study represents the first attempt to investigate cloud ISRA that organizations practice in managing their information security. Ana Faizi, Ali Mohammad Padyab, Andreas Naess |
Inf. Comput. Secur. | 2 |
| 2021 | Perceived Privacy Problems Within Digital Contact Tracing: A Study Among Swedish Citizens
Ali Mohammad Padyab, Joakim Kävrestad |
SEC | 1 |
| 2014 | Genre-Based Approach to Assessing Information and Knowledge Security RisksabstractContemporary methods for assessing information security risks have adopted mainly technical views on information and technology assets. Organizational dynamics of information management and knowledge sharing have gained less attention. This article outlines a new, genre-based, approach to information security risk assessment in order to orientate toward organization- and knowledge-centric identification and analysis of security risks. In order to operationalize the genre-based approach, we suggest the use of a genre-based analytical method for identifying organizational communication patterns through which organizational knowledge is shared. The genre-based method is then complemented with tasks and techniques from a textbook risk assessment method (OCTAVE Allegro). We discuss the initial experiences of three experienced information security professionals who tested the method. The article concludes with implications of the genre-based approach to analyzing information and knowledge security risks for future research and practice. Ali Mohammad Padyab, Tero Päivärinta, Dan Harnesk |
Int. J. Knowl. Manag. | 1 |