Tanya Jane McGill

dblp:16/10028 · also Tanya McGill · DBLP profile ↗
← Back
25ranked-venue papers
7as first author
7since 2021 · last 2026
0000-0003-4272-1757ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 first-author · 1 since 2021Databases, data management, data science and information retrieval · 4 · 1 since 2021Computer networks · 2 · 1 since 2021Artificial intelligence and machine learning · 1 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 "Not all bad": Determinants and impacts of emotion-focused and problem-focused coping in information security behavior
abstract
Users may respond to threats with a wide range of coping strategies in addition to protective information security behavior. However, relatively little is known about emotion-focused coping (EFC) responses, and prior work has often considered any non-security behavior to be “maladaptive." We examine EFC in the context of phishing and demonstrate that it can, in fact, have a positive influence on security behavior. Our research model builds on the established foundation of protection motivation theory and incorporates threat devaluation and positive reappraisal as forms of EFC. We collected quantitative data from 518 respondents and tested our model with PLS structural equation modeling to provide empirical insights into how threat and coping appraisals can lead to both emotion-focused and problem-focused responses. We find that EFC responses are nuanced and thus classify them according to whether the individual response is to either approach or avoid the threat. As these coping responses may be shaped by user perceptions, our findings provide opportunities to both protect users and develop a more comprehensive understanding of information security behavior.
Tanya Jane McGill, Nik Thompson, Nidhi Narula
Comput. Secur.1
2024 "No point worrying" - The role of threat devaluation in information security behavior
abstract
Extant information security research is characterized by a focus on problem-focussed security behaviours, while overlooking the internal, and emotion-focussed coping responses that humans exhibit. Threat devaluation, where severity is downplayed, is an established dimension of risk perception, and yet it has not been considered in information security research to date. We address this gap by developing and empirically testing a research model of how threat and coping factors from Protection Motivation Theory influence both problem-focused and emotion-focussed coping responses. Data was collected from 518 users and PLS was used to reveal the determinants of, and the relationship between, problem-focused and emotion-focused coping behaviors. The results demonstrate that threat devaluation is a measurable outcome of all threat and coping appraisals considered, providing evidence that multiple coping strategies may be involved in a security threat situation. We also find that many of the well-established determinants of information security behavior, such as self-efficacy, are significantly related to emotion-focused responses. This has implications for researchers and practitioners who seek to create secure environments where users are more likely to enact constructive and problem-focused security behaviors.
Nik Thompson, Tanya Jane McGill, Nidhi Narula
Comput. Secur.2
2022 H.264 and H.265 video traffic modeling using neural networks
Khandu Om, Tanya Jane McGill, Michael W. Dixon, Kevin Kok Wai Wong, Polychronis Koutsakis
Comput. Commun.2
2022 Factors Influencing Consumer Adoption of Electronic Health Records
abstract
Electronic health records (EHRs) are electronic versions of longitudinal individual health records that are easily accessible and can be shared among relevant stakeholders. Their use can contribute to improved health outcomes. This research aimed to identify the key factors influencing healthcare consumer adoption of EHRs by testing an EHR consumer adoption model that extends the Decomposed Theory of Planned Behavior to include security and privacy concerns and perceived health literacy. The model explained 65% of the variation in intention tgo use EHRs, with attitude and subjective norm as the key factors directly influencing it. Security and privacy concerns were found to be an important predictor of attitude toward EHRs, but contrary to expectations perceived health literacy did not play a role. These results can inform healthcare educators and professionals, as well as government policymakers as they try to better understand EHR acceptance from a consumer perspective.
Neethu Mathai, Tanya Jane McGill, Danny Toohey
J. Comput. Inf. Syst.2
2021 Maladaptive behaviour in response to email phishing threats: The roles of rewards and response costs
Samantha Bax, Tanya Jane McGill, Valerie Hobbs
Comput. Secur.2
2021 The Influence of User Culture on Website Usability
Rukshan Alexander, Nik Thompson, Tanya Jane McGill, David Murray
Int. J. Hum. Comput. Stud.3
2021 Exploring potential gender differences in information security and privacy
abstract
Purpose Information technology users often fail to adopt necessary security and privacy measures, leading to increased risk of cybercrimes. There has been limited research on how demographic differences influence information security behaviour and understanding this could be important in identifying users who may be more likely to have poor information security behaviour. This study aims to investigate whether there are any gender differences in security and privacy behaviours and perceptions, to identify potential differences that may have implications for protecting users’ privacy and securing their devices, software and data. Design/methodology/approach This paper addresses this research gap by investigating security behaviours and perceptions in the following two studies: one focussing on information security and one on information privacy. Data was collected in both studies using anonymous online surveys. Findings This study finds significant differences between men and women in over 40% of the security and privacy behaviours considered, suggesting that overall levels of both are significantly lower for women than for men, with behaviours that require more technical skill being adopted less by female users. Furthermore, individual perceptions exhibited some gender differences. Originality/value This research suggests that potential gender differences in some security and privacy behaviours and perceptions should be taken into account when designing information security education, training and awareness initiatives for both organisations and the broader community. This study also provides a strong foundation to explore information security individual differences more deeply.
Tanya Jane McGill, Nik Thompson
Inf. Comput. Secur.1
2020 Cultural factors and the role of privacy concerns in acceptance of government surveillance
abstract
Abstract Though there is a tension between citizens' privacy concerns and their acceptance of government surveillance, there is little systematic research in this space and less still in a cross‐cultural context. We address the research gap by modeling the factors that drive public acceptance of government surveillance, and by exploring the influence of national culture. The research involved an online survey of 242 Australian and Sri Lankan residents. Data were analyzed using partial least squares, revealing that privacy concerns around initial collection of citizens' data influenced levels of acceptance of surveillance in Australia but not Sri Lanka, whereas concerns about secondary use of data did not influence levels of acceptance in either country. These findings suggest that respondents conflate surveillance with the collection of data and may not consider subsequent secondary use. We also investigate cultural differences, finding that societal collectivism and power distance significantly affect the strength of the relationships between privacy concerns and acceptance of surveillance, on the one hand, and adoption of privacy protections, on the other. Our research also considers the role of trust in government, and perceived need for surveillance. Findings are discussed with their implications for theory and practice.
Nik Thompson, Tanya Jane McGill, Anna Bunn, Rukshan Alexander
J. Assoc. Inf. Sci. Technol.2
2020 I Want It Anyway: Consumer Perceptions of Smart Home Devices
abstract
Smart home devices form a significant part of the Internet of Things market and can provide benefits such as convenience and energy efficiency. They also have potential privacy and security risks as they collect information constantly. In order to examine how benefit and risk factors influence individuals’ intentions to adopt smart home devices, we developed a net valence model that integrates both positive factors and risk factors. The model was tested using data collected using an online questionnaire. The results show that individuals tend to ignore the potential risks and focus more on potential benefits resulting from using smart home devices. Performance expectancy and compatibility were found to be positively related to perceived benefits. However, neither effort expectancy nor image were. Among the proposed dimensions of risk, only privacy risk, performance risk, and time risk significantly influenced perceived risk. Security risk and financial risk did not influence it.
Xuequn Wang, Tanya Jane McGill, Jane E. Klobas
J. Comput. Inf. Syst.2
2019 How perceived security risk affects intention to use smart home devices: A reasoned action explanation
Jane E. Klobas, Tanya Jane McGill, Xuequn Wang
Comput. Secur.2
2017 Experimental evaluation of less-than-best-effort TCP over 802.11 wireless networks
Kevin Ong, Sebastian Zander, David Murray, Tanya Jane McGill
APCC4
2017 Experimental Evaluation of Less-Than-Best-Effort TCP Congestion Control Mechanisms
abstract
Increasing use of online backup services, as well as the popularity of user-generated content, has increased the demand for bandwidth. However, traffic generated by these applications can impact on the responsiveness of delay-sensitive applications if they receive a 'fair-share' of the available bandwidth. Less-than-Best-Effort TCP congestion control mechanisms aim to allow lower-priority applications to utilise excess bandwidth with minimum impact to regular TCP traffic. We evaluated the performance of six Less-than-Best-Effort congestion control algorithms in different scenarios in a Linux testbed, only three of which had existing implementations for modern operating systems. The findings of this study suggest that Nice provides background throughput comparable to that of regular TCP, while maintaining low queuing delay, while CAIA Delay-Gradient (CDG) has the least impact on regular TCP traffic, at the expense of reduced throughput.
Kevin Ong, Sebastian Zander, David Murray, Tanya Jane McGill
LCN4
2017 Old risks, new challenges: exploring differences in security between home computer and mobile device use
abstract
Home users are particularly vulnerable to information security threats as they must make decisions about how to protect themselves, often with little knowledge of the technology. Furthermore, information for home users tends to focus on the traditional PC and may downplay threats faced on mobile devices, transforming well-known and old risks into new challenges for information security. To address the need for more behavioural information security research that focusses on mobile devices, this paper reports on the first large-scale study comparing security perceptions and behaviours on home computer and mobile devices. Data from 629 users revealed that in addition to differences in information security behaviour, the following security-related perceptions all differ significantly between home computer and mobile device use: perceived severity, security self-efficacy, response efficacy, response cost, descriptive norm, psychological ownership and intention to perform security behaviours. In each case, the direction of the difference was such that mobile devices were more likely to be at risk than a home computer. The practical implications of these differences are discussed.
Tanya Jane McGill, Nik Thompson
Behav. Inf. Technol.1
2017 "Security begins at home": Determinants of home computer and mobile device security behavior
Nik Thompson, Tanya Jane McGill, Xuequn Wang
Comput. Secur.2
2013 The state of the art of application restrictions and sandboxes: A survey of application-oriented access controls and their shortfalls
Z. Cliffe Schreuders, Tanya Jane McGill, Christian Payne
Comput. Secur.2
2012 Towards Usable Application-Oriented Access Controls: Qualitative Results from a Usability Study of SELinux, AppArmor and FBAC-LSM
abstract
A number of security mechanisms are available for improving the security of systems by restricting the actions of individual programs to activities that are authorised. However, configuring these systems to enforce end users’ own security goals is often beyond their expertise. Little research has investigated the usability issues associated with application-oriented access controls. This paper presents the results of a qualitative analysis of user perceptions of the usability of three application-oriented security systems: SELinux, AppArmor, and FBAC-LSM. Qualitative analysis identified a number of factors that affect the usability of application-restriction mechanisms. These themes are used to compare the usability of the three systems studied, and it is proposed that these factors can be used to inform the design of new systems and development of existing ones. Changes to the three security systems are also proposed to address or mitigate specific usability issues that were identified.
Z. Cliffe Schreuders, Tanya Jane McGill, Christian Payne
Int. J. Inf. Secur. Priv.2
2012 The Teaching-Research-Industry-Learning Nexus in Information and Communications Technology
abstract
The teaching-research nexus concept has been extensively examined in the higher education literature, and the importance of industry linkages in information and communications technology (ICT) education has also been widely discussed. However, to date there has been little recognition of the full extent of relationships between aspects of teaching, learning, research, and industry, and of the synergy possible from exploiting these relationships. Koppi and Naghdy [2009] introduced the concept of the teaching-research-industry-learning (TRIL) nexus in ICT education and this article attempts to advance understanding of the concept by exploring the literature that underpins it. The article contributes to a clearer understanding of the nature of the relationships involved as they apply to ICT education, and makes comprehensive recommendations to support strengthening the TRIL nexus in ICT education.
Tanya Jane McGill, Jocelyn Armarego, Tony Koppi
ACM Trans. Comput. Educ.1
2011 Techniques for Automating Policy Specification for Application-oriented Access Controls
abstract
By managing the authority assigned to each application, rule-based application-oriented access controls can significantly mitigate the threats posed by malicious code due to software vulnerabilities or malware. However, these policies are typically complex and difficult to develop. Learning modes can ease specification, however, they still require high levels of expertise to utilise correctly, and are most suited to confining non-malicious software. This paper presents a novel approach to automating policy specification for rule-based application-oriented access controls. The functionality-based application confinement (FBAC) model provides reusable parameterised abstractions. A number of straightforward yet effective techniques are presented that use these functionality-based abstractions to create application policies a priori, that is, without running programs before policies are specified. These techniques automate the specification of policy details by analysing program dependencies, program management information, and file system contents.
Z. Cliffe Schreuders, Christian Payne, Tanya Jane McGill
ARES3
2011 Empowering End Users to Confine Their Own Applications: The Results of a Usability Study Comparing SELinux, AppArmor, and FBAC-LSM
abstract
Protecting end users from security threats is an extremely difficult, but increasingly critical, problem. Traditional security models that focused on separating users from each other have proven ineffective in an environment of widespread software vulnerabilities and rampant malware. However, alternative approaches that provide more finely grained security generally require greater expertise than typical end users can reasonably be expected to have, and consequently have had limited success. The functionality-based application confinement (FBAC) model is designed to allow end users with limited expertise to assign applications hierarchical and parameterised policy abstractions based upon the functionalities each program is intended to perform. To validate the feasibility of this approach and assess the usability of existing mechanisms, a usability study was conducted comparing an implementation of the FBAC model with the widely used Linux-based SELinux and AppArmor security schemes. The results showed that the functionality-based mechanism enabled end users to effectively control the privileges of their applications with far greater success than widely used alternatives. In particular, policies created using FBAC were more likely to be enforced and exhibited significantly lower risk exposure, while not interfering with the ability of the application to perform its intended task. In addition to the success of the functionality-based approach, the usability study also highlighted a number of limitations and problems with existing mechanisms. These results indicate that a functionality-based approach has significant potential in terms of enabling end users with limited expertise to defend themselves against insecure and malicious software.
Z. Cliffe Schreuders, Tanya Jane McGill, Christian Payne
ACM Trans. Inf. Syst. Secur.2
2009 Understanding User Behavior towards Passwords through Acceptance and Use Modelling
abstract
The security of computer systems that store our data is a major issue facing the world. This research project investigated the roles of ease of use, facilitating conditions, intention to use passwords securely, experience and age on usage of passwords, using a model based on the Unified Theory of Acceptance and Use of technology. Data was collected via an online survey of computer users, and analyzed using PLS. The results show there is a significant relationship between ease of use of passwords, intention to use them securely and the secure usage of passwords. Despite expectations, facilitating conditions only had a weak impact on intention to use passwords securely and did not influence actual secure usage. Computing experience was found to have an effect on intention to use passwords securely, but age did not. The results of this research lend themselves to assisting in policy design and better understanding user behavior.
Lee Novakovic, Tanya Jane McGill, Michael W. Dixon
Int. J. Inf. Secur. Priv.2
2008 User developed application success: sources and effects of involvement
abstract
User participation and involvement have long been associated with system success. This paper reports on a study to investigate the role of involvement in user developed application success. The experimental study explored the chain of influences between involvement and the different forms of information systems success and clarified how these influences differ for participants and non-participants in the development process. While participation was shown to result in greater success on all the measures included in the study, the effect of participation is mediated by involvement. In this study, involvement was derived from one of two sources, depending on participation: for participants in development, involvement was derived from their participation but was unaffected by system quality, while for non-participants, involvement was derived partially from system quality. Involvement also acted differently: involvement derived from system quality directly affected both perceived system quality and user satisfaction, while involvement derived from participation directly affected only perceived system quality.
Tanya Jane McGill, Jane E. Klobas
Behav. Inf. Technol.1
2005 The role of spreadsheet knowledge in user-developed application success
Tanya Jane McGill, Jane E. Klobas
Decis. Support Syst.1
1997 Using a network simulation package to teach the client-server model
abstract
The client-server model is fast becoming the most common form of network architecture used in data communications. It's popularity can be seen in the phenomenal expansion of the World Wide Web. It is essential that students understand the client-server model, and that they learn how to design client-server networks and to analyze their performance. This paper describes a project to achieve this via problem solving sessions using simulation to facilitate understanding of the design and performance analysis of networks using a client-server architecture. Students will be able to gain experience designing client-server networks and testing their designs for efficiency and expandability.
Michael W. Dixon, Tanya Jane McGill, Johan M. Karlsson
ITiCSE2
1996 A supplementary package for distance education students studying introductory programming
abstract
Teaching introductory programming can be a challenging task.Students can become too concerned with learning syntax at the expense of more general conceptual understanding.Distance education students m particular often have problems as the difficulty of the course content 1s compounded by the problems of lsolatlon from other students and their tutor.Although instructional strategies for emphasismg conceptual knowledge are well known for face-to-face mstructlon.there has been little attempt to apply them to the external situation.This paper describes a supplementary package for external students designed to address some of these problems.The package has been used for two semesters and feedback from students indicates that they find It a valuable resource
Tanya Jane McGill, Valerie Hobbs
SIGCSE1
1995 Identification of Technological Gatekeepers in the Information Technology Profession
abstract
Business organizations have become interested in recognizing gatekeepers who may improve business prospects through informal external communication. Past research has identified gatekeepers within organizations, but no technique existed for identifying gatekeepers among groups of people working in an industry, profession, or other external group. This paper develops and tests a simple rule for identifying gatekeepers among members of a profession with a common group of potential interpersonal communication channels. The rule is used to classify gatekeepers among information technology professionals, based on self-reported information dissemination behavior. The rule passes five tests that compare the characteristics and information-seeking strategies of individuals classified using this rule with other members of the profession. The results of the study confirm that self-reported information dissemination behavior can be used to identify gatekeepers among individuals with diverse information-gathering behaviors, but a common group of potential interpersonal communication channels. © 1995 John Wiley & Sons, Inc.
Jane E. Klobas, Tanya Jane McGill
J. Am. Soc. Inf. Sci.2