Barnaby Craggs

dblp:144/5293 · DBLP profile ↗
← Back
7ranked-venue papers
1as first author
4since 2021 · last 2026
0000-0002-6706-9745ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 5 · 4 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2026 Can secure habits counter phishing? An exploration using a novel in-tray simulation
abstract
Cyber attacks are increasing in frequency year by year, presenting a substantial and growing threat to the security of organisations (Verizon, 2023). (Spear) phishing—or the practice of sending (targeted) fraudulent emails to employees—is one means by which cyber attackers attempt to infiltrate secure systems. These messages typically exploit vulnerabilities in human decision-making, aiming to elicit sensitive information or distribute malware via fraudulent emails. Although various factors including individual, cultural, environmental, and message-related factors are known to influence susceptibility to phishing emails, current understanding of the nature of their interplay remains severely limited (Williams et al., 2017a).Addressing this gap, the current study investigates the role of habit in the context of phishing susceptibility, leveraging data from the pilot launch of PhiT. This tool—a collaboration between the UK’s National Protective Security Authority (NPSA), the authors, and other stakeholders—is a sophisticated browser-based simulated email client for ecologically valid research and training on phishing. PhiT provides realistic scenarios for roles such as IT Specialist, HR Assistant, and Procurement Manager, and has extensive data-gathering capabilities, facilitating a nuanced exploration of email interaction patterns and their impact on phishing vulnerability.While engaging with emails in an automatic, habitual way can be detrimental to one’s ability to spot phishing emails, the current study explores whether certain ‘good’ security habits, like consistently verifying sender email addresses, might offer protective benefits. We explore patterns in participants’ email interactions using Markov chains and k-medoids clustering. Our analysis indicates that individuals who reliably verify sender email addresses may be less likely to fall for phishing attacks. However, correlations between sender checks and phishing rates were significant only in the IT specialist scenario, suggesting role-specific differences in the effectiveness of this security behaviour. The various critical implications of this finding for cybersecurity research and practice are discussed in the context of habit theory. Based on this, we suggest that future research should explore the possibility of ‘cue engineering’—making changes to the UI with the aim of facilitating habit formation by designing better cues.
Tobias D. Weickert, Adam N. Joinson, Barnaby Craggs
Comput. Secur.3
2024 Adopting a Systemic Design Approach to Cyber Security Incident Response
abstract
Computer security incident response teams (CSIRTs) are critical to maintaining business continuity in the face of cyber-attacks. Yet there has been little research conducted in the last decade to understand the root causes of the challenges they face to sustain their effectiveness. Moreover, they operate in complex sociotechnical multiteam systems, making it challenging to understand the causes of problems and how to bring about improvements. This paper proposes the use of a Systemic Design approach to develop a more in-depth understanding of the complex sociotechnical system(s) of cyber security incident response, in order to find intervention points that can be leveraged in one area to transition the whole system into a better state. We present the first steps of a case study that uses Gigamap workshops and in-depth interviews with a range of stakeholders to frame the system and understand its effectiveness.
Emma Woodward, Barnaby Craggs, Danaë Emma Beckford Stanton Fraser, Adam N. Joinson
NSPW2
2023 Is cybersecurity research missing a trick? Integrating insights from the psychology of habit into research and practice
abstract
The idea that people should form positive security habits is gaining increasing attention amongst security practitioners. Habit is a well-studied concept in psychology, but the extent to which the richness of that literature has been fully utilised for security is currently unclear. In order to address this gap, we compared usage of the term “habit”—and connected constructs —in the cybersecurity and habit fields using a co-occurrence networks-based analysis. We aimed to answer three research questions: 1. What is the context within which habit has been discussed in the habit literature and the cybersecurity literature; 2. How does the discussion in these two fields compare; and 3. What are the implications of the outcomes of this analysis for the future research agenda for cybersecurity behaviour? The analysis showed that the habit construct tended to be discussed primarily in the context of other models, rather than on its own. The depth of discussion was therefore limited; resulting gaps in knowledge have important implications for security, like the idea that habits moderate the relationship between intention and behaviour. Given the popularity of the theory of planned behaviour in security research, this represents a key omission. Furthermore, the cybersecurity literature we surveyed contained very little discussion surrounding methods for formation and changing of habits, nor of the role of cues in triggering habitual behaviours. Habits require a different behaviour change approach than intentional behaviours, and many day-to-day security behaviours may in fact be habits. For that reason, these topics represents a potentially productive avenue of research for both security and privacy behaviour.
Tobias D. Weickert, Adam N. Joinson, Barnaby Craggs
Comput. Secur.3
2021 Beware suppliers bearing gifts!: Analysing coverage of supply chain cyber security in critical national infrastructure sectorial and cross-sectorial frameworks
Colin Topping, Andrew C. Dwyer, Ola Aleksandra Michalec, Barnaby Craggs, Awais Rashid
Comput. Secur.4
2019 Everything Is Awesome! or Is It? Cyber Security Risks in Critical Infrastructure
Awais Rashid, Joseph Gardiner, Benjamin Green 0001, Barnaby Craggs
CRITIS4
2018 A Cross-Virtual Machine Network Channel Attack via Mirroring and TAP Impersonation
abstract
Data privacy and security is a leading concern for providers and customers of cloud computing, where Virtual Machines (VMs) can co-reside within the same underlying physical machine. Side channel attacks within multi-tenant virtualized cloud environments are an established problem, where attackers are able to monitor and exfiltrate data from co-resident VMs. Virtualization services have attempted to mitigate such attacks by preventing VM-to-VM interference on shared hardware by providing logical resource isolation between co-located VMs via an internal virtual network. However, such approaches are also insecure, with attackers capable of performing network channel attacks which bypass mitigation strategies using vectors such as ARP Spoofing, TCP/IP steganography, and DNS poisoning. In this paper we identify a new vulnerability within the internal cloud virtual network, showing that through a combination of TAP impersonation and mirroring, a malicious VM can successfully redirect and monitor network traffic of VMs co-located within the same physical machine. We demonstrate the feasibility of this attack in a prominent cloud platform - OpenStack - under various security requirements and system conditions, and propose countermeasures for mitigation.
Atif Saeed, Peter Garraghan, Barnaby Craggs, Dirk van der Linden, Awais Rashid, Syed Asad Hussain
IEEE CLOUD3
2014 ThumbReels: query sensitive web video previews based on temporal, crowdsourced, semantic tagging
abstract
During online search, the user's expectations often differ from those of the author. This is known as the "intention gap" and is particularly problematic when searching for and discriminating between online video content. An author uses description and meta-data tags to label their content, but often cannot predict alternate interpretations or appropriations of their work. To address this intention gap, we present ThumbReels, a concept for query-sensitive video previews generated from crowdsourced, temporally defined semantic tagging. Further, we supply an open-source tool that supports on-the-fly temporal tagging of videos, whose output can be used for later search queries. A first user study validates the tool and concept. We then present a second study that shows participants found ThumbReels to better represent search terms than contemporary preview techniques.
Barnaby Craggs, Myles Kilgallon Scott, Jason Alexander
CHI1