VLDB 2026 Research / reviewers in the wild / expert
Asangi Jayatilaka
dblp:164/7182
· DBLP profile ↗
12ranked-venue papers
2as first author
9since 2021 · last 2026
0000-0003-2051-030XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 6 · 6 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 1 since 2021Security and privacy · 2 · 2 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Software vulnerability management in IoT systems: a systematic mapping studyabstractAbstract The Internet of Things (IoT) has rapidly emerged as a ubiquitous and pervasive paradigm in software development, significantly impacting both social life and business environments. However, this growth has also led to a corresponding increase in the number and sophistication of threats and attacks targeting IoT devices and services. The vulnerability of IoT software to security breaches has become a significant concern for the research community. Managing software vulnerabilities in IoT is a hugely challenging process involving several socio-technical decisions. Despite the rapid increase in primary studies focusing on Software Vulnerability Management (SVM) in IoT systems, no secondary studies specifically identify and analyse the socio-technical challenges, solutions, and state-of-the-art evaluation studies in SVM in IoT systems. This paper aims to address this gap by systematically identifying, classifying, comparing, and evaluating state of the art of SVM in IoT systems from a socio-technical point of view. We conducted a systematic mapping study (SMS) based on 73 qualitatively selected studies to i) classify the types, frequency, and demography of published research; ii) identify the socio-technical challenges in this regard; iii) classify the reported solutions; and iv) understand the rigour of the evaluation, including real-world application. In summary, our results point to 32 socio-technical challenges in IoT vulnerability management, where most are practice-related. In terms of the solutions, we found a maximum number of solutions proposed for the software vulnerability identification stage, with 22 frameworks. The software vulnerability disclosure stage has the least amount of solutions reported. This SMS also reveals that there needs to be more rigorous evaluation using more mature forms of evaluations like simulation with real data and case studies. Based on the findings that highlight the important concerns in this domain, we recommend a list of future research directions. Fariha Tasmin Jaigirdar, Asangi Jayatilaka, Muhammad Ali Babar 0001 |
Cybersecur. | 2 |
| 2025 | Understanding practitioners' challenges and requirements in the design, implementation, and evaluation of anti-phishing interventionsabstractBackground: Research shows that the ineffectiveness of anti-phishing interventions can result from practitioners’ failure to consider end-users’ requirements in the intervention design, implementation, and evaluation. To assist practitioners in addressing usability issues , we reported 41 guidelines through a systematic Multi-vocal Literature Review (MLR). The usefulness of these guidelines in real-world scenarios remains uncertain until the involved challenges and requirements to implement them are investigated. Objective: (1) To investigate practitioners’ challenges in the design, implementation, and evaluation of phishing interventions in real-world settings; (2) to understand practitioners’ perspectives on our guidelines and how they can be made easily accessible to the practitioners. Method: We interviewed 18 practitioners (intervention designers, security practitioners, and C-suite employees) from 18 organizations in 6 countries. Results: (1) We identify 8 challenges in training content design, anti-phishing datasets, post-training knowledge assessment , and so on. We compare these challenges with the challenges identified from our MLR to demonstrate the ecological validity of the challenges found in MLR and derive a set of insights to overcome them; (2) we report practitioners’ feedback on our guidelines; (3) we gather actionable features on an envisioned tool to make these guidelines easily accessible. Conclusion: We provide 15 recommendations to improve the anti-phishing defense in the organisations. Orvila Sarker, Asangi Jayatilaka, Sherif Haggag, Chelsea Liu, Muhammad Ali Babar 0001 |
J. Syst. Softw. | 2 |
| 2024 | A Multi-vocal Literature Review on challenges and critical success factors of phishing education, training and awarenessabstractPhishing is a malicious attempt by cyber attackers to steal personal information through deception. Phishing attacks are often aided by carefully crafted phishing emails, which can go undetected by automated anti-phishing tools due to their limited accuracy. Studies found that user education, training, and awareness can thwart phishing attacks. Understanding diverse interconnected challenges and critical success factors of phishing education, training, and awareness (PETA) approaches can help improve organizations’ defense against phishing. This study presents a comprehensive, structured view of the challenges and critical success factors of the design, implementation, and evaluation stages of PETA. We have conducted a Multi-vocal Literature Review (MLR) by systematically collecting 53 academic studies and 16 grey studies from popular databases by following a well-known MLR guideline. We identified 20 challenges and 23 critical success factors, some of which involve human-centric and socio-technical factors in PETA. Our findings point out the need for designing explainable anti-phishing systems and developing automated tools and platforms to conduct real-world phishing studies. Our systematic analysis of 69 studies has enabled us to highlight the need for addressing human-centric issues, incorporating users’ knowledge gaps, and adopting personalized approaches in PETA. Orvila Sarker, Asangi Jayatilaka, Sherif Haggag, Chelsea Liu, Muhammad Ali Babar 0001 |
J. Syst. Softw. | 2 |
| 2023 | Personalized Guidelines for Design, Implementation and Evaluation of Anti-Phishing InterventionsabstractBackground: Current anti-phishing interventions, which typically involve one-size-fits-all solutions, suffer from limitations such as inadequate usability and poor implementation. Human-centric challenges in anti-phishing technologies remain little understood. Research shows a deficiency in the comprehension of end-user preferences, mental states, and cognitive requirements by developers and practitioners involved in the design, implementation, and evaluation of anti-phishing interventions. Aims: This study addresses the current lack of resources and guidelines for the design, implementation and evaluation of anti-phishing interventions, by presenting personalized guidelines to the developers and practitioners. Method: Through an analysis of 53 academic studies and 16 items of grey literature studies, we systematically identified the challenges and recommendations within the anti-phishing interventions, across different practitioner groups and intervention types. Results: We identified 22 dominant factors at the individual, technical, and organizational levels, that affected the effectiveness of anti-phishing interventions and, accordingly, reported 41 guidelines based on the suggestions and recommendations provided in the studies to improve the outcome of anti-phishing interventions. Conclusions: Our dominant factors can help developers and practitioners enhance their understanding of human-centric, technical and organizational issues in anti-phishing interventions. Our customized guidelines can empower developers and practitioners to counteract phishing attacks. Orvila Sarker, Sherif Haggag, Asangi Jayatilaka, Chelsea Liu |
ESEM | 3 |
| 2023 | Falling for phishing attempts: An investigation of individual differences that are associated with behavior in a naturalistic phishing simulationabstractSocial engineering cyber-attacks such as phishing emails pose a serious threat to the safety of many organizations. Given that the effectiveness of these attacks heavily relies on poor human decision making, an improved understanding of the individual characteristics that increase cybersecurity vulnerability could inform more targeted training. The current study aimed to identify whether several factors, including phishing email detection ability, confidence in one's phishing identification decisions, general attitudes towards one's level of responsibility and efficacy, and employee satisfaction and loyalty to the organization, may predict behavior in a naturalistic phishing simulation in an employment setting. We followed up employees of a large organization who had been recently targeted by a phishing simulation and asked them to complete a survey that included a phishing detection task. The employees’ behavior in the phishing simulation was ranked according to its safety: reporting the suspicious email, neither reporting nor clicking on the embedded link, and clicking on the link. We found that fewer years of employment at the organization and lower employee satisfaction and loyalty predicted increasingly unsafe behavior in the simulation. This suggests that newer and unsatisfied employees are most vulnerable to phishing attempts and might benefit most from targeted cybersecurity training. Nathan Beu, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali Babar 0001, Laura Hartley, Winston Lewinsmith, Irina Baetu |
Comput. Secur. | 2 |
| 2022 | An Empirical Study of Automation in Software Security Patch ManagementabstractSeveral studies have shown that automated support for different activities of the security patch management process has great potential for reducing delays in installing security patches. However, it is also important to understand how automation is used in practice, its limitations in meeting real-world needs and what practitioners really need, an area that has not been empirically investigated in the existing software engineering literature. This paper reports an empirical study aimed at investigating different aspects of automation for security patch management using semi-structured interviews with 17 practitioners from three different organisations in the healthcare domain. The findings are focused on the role of automation in security patch management for providing insights into the as-is state of automation in practice, the limitations of current automation, how automation support can be enhanced to effectively meet practitioners’ needs, and the role of the human in an automated process. Based on the findings, we have derived a set of recommendations for directing future efforts aimed at developing automated support for security patch management. Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali Babar 0001 |
ASE | 2 |
| 2022 | Software security patch management - A systematic literature review of challenges, approaches, tools and practices
Nesara Dissanayake, Asangi Jayatilaka, Mansooreh Zahedi, Muhammad Ali Babar 0001 |
Inf. Softw. Technol. | 2 |
| 2022 | Why, How and Where of Delays in Software Security Patch Management: An Empirical Investigation in the Healthcare SectorabstractNumerous security attacks that resulted in devastating consequences can be traced back to a delay in applying a security patch. Despite the criticality of timely patch application, not much is known about why and how delays occur when applying security patches in practice, and how the delays can be mitigated. Based on longitudinal data collected from 132 delayed patching tasks over a period of four years and observations of patch meetings involving eight teams from two organisations in the healthcare domain, and using quantitative and qualitative data analysis approaches, we identify a set of reasons relating to technology, people and organisation as key explanations that cause delays in patching. Our findings also reveal that the most prominent cause of delays is attributable to coordination delays in the patch management process and a majority of delays occur during the patch deployment phase. Towards mitigating the delays, we describe a set of strategies employed by the studied practitioners. This research serves as the first step toward understanding the practical reasons for delays and possible mitigation strategies in vulnerability patch management. Our findings provide useful insights for practitioners to understand what and where improvement is needed in the patch management process and guide them towards taking timely actions against potential attacks. Also, our findings help researchers to invest effort into designing and developing computer-supported tools to better support a timely security patch management process. Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali Babar 0001 |
Proc. ACM Hum. Comput. Interact. | 3 |
| 2021 | A grounded theory of the role of coordination in software security patch managementabstractSeveral disastrous security attacks can be attributed to delays in patching software vulnerabilities. While researchers and practitioners have paid significant attention to automate vulnerabilities identification and patch development activities of software security patch management, there has been relatively little effort dedicated to gain an in-depth understanding of the socio-technical aspects, e.g., coordination of interdependent activities of the patching process and patching decisions, that may cause delays in applying security patches. We report on a Grounded Theory study of the role of coordination in security patch management. The reported theory consists of four inter-related dimensions, i.e., causes, breakdowns, constraints, and mechanisms. The theory explains the causes that define the need for coordination among interdependent software/hardware components and multiple stakeholders’ decisions, the constraints that can negatively impact coordination, the breakdowns in coordination, and the potential corrective measures. This study provides potentially useful insights for researchers and practitioners who can carefully consider the needs of and devise suitable solutions for supporting the coordination of interdependencies involved in security patch management. Nesara Dissanayake, Mansooreh Zahedi, Asangi Jayatilaka, Muhammad Ali Babar 0001 |
ESEC/SIGSOFT FSE | 3 |
| 2019 | Designing batteryless wearables for hospitalized older peopleabstractOlder people have expressed a clear desire for unobtrusive wearable monitoring devices. Emerging batteryless sensor technologies such as sensor enabled RFID (Radio Frequency Identification) create new opportunities for building unobtrusive wearables for older people. This study aims to: i) uncover user perceptions and acceptability of a batteryless wearable sensor concept for hospitalized older people; and ii) present the construction of a new textile integrated wearable sensor incorporating user feedback. We recruited 40 older people (age: 81.0 ± 7.0 years) to wear our initial sensor prototype and used two modified versions of validated questionnaires to evaluate user perceptions and acceptability. Our results showed: i) allowing older people to experience the system created the opportunity for them to develop confidence and trust in the sensing technology, even when they were initially anxious and skeptical: and ii) the first design prototype should ideally be modified to reduce its visibility. To this end, we built a new wearable sensor design. Asangi Jayatilaka, Quoc Hung Dang, Shengjian Jammy Chen, Renuka Visvanathan, Christophe Fumeaux, Damith Chinthana Ranasinghe |
UbiComp | 1 |
| 2019 | Super Low Resolution RF Powered Accelerometers for Alerting on Hospitalized Patient Bed ExitsabstractFalls have serious consequences and are prevalent in acute hospitals and nursing homes caring for older people. Most falls occur in bedrooms and near the bed. Technological interventions to mitigate the risk of falling aim to automatically monitor bed-exit events and subsequently alert healthcare personnel to provide timely supervisions. We observe that frequency-domain information related to patient activities exist predominantly in very low frequencies. Therefore, we recognise the potential to employ a low resolution acceleration sensing modality in contrast to powering and sensing with a conventional MEMS (Micro Electro Mechanical System) accelerometer. Consequently, we investigate a batteryless sensing modality with low cost wirelessly powered Radio Frequency Identification (RFID) technology with the potential for convenient integration into clothing, such as hospital gowns. We design and build a passive accelerometer-based RFID sensor embodiment-ID-Sensor-for our study. The sensor design allows deriving ultra low resolution acceleration data from the rate of change of unique RFID tag identifiers in accordance with the movement of a patient's upper body. We investigate two convolutional neural network architectures for learning from raw RFID-only data streams and compare performance with a traditional shallow classifier with engineered features. We evaluate performance with 23 hospitalized older patients. We demonstrate, for the first time and to the best of knowledge, that: i) the low resolution acceleration data embedded in the RF powered ID-Sensor data stream can provide a practicable method for activity recognition; and ii) highly discriminative features can be efficiently learned from the raw RFID-only data stream using a fully convolutional network architecture. Michael Chesser, Asangi Jayatilaka, Renuka Visvanathan, Christophe Fumeaux, Alanson P. Sample, Damith Chinthana Ranasinghe |
PerCom | 2 |
| 2017 | Real-time fluid intake gesture recognition based on batteryless UHF RFID technology
Asangi Jayatilaka, Damith Chinthana Ranasinghe |
Pervasive Mob. Comput. | 1 |