Andrew Reeves

dblp:167/9807 · DBLP profile ↗
← Back
10ranked-venue papers
4as first author
10since 2021 · last 2025
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 7 · 4 first-author · 7 since 2021Computer networks · 2 · 2 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 How to De-CyFa the actor-observer bias in cybersecurity fatigue: Building the CyFa measure of attribution styles and mitigation strategies
abstract
Cybersecurity fatigue and burnout, driven by an overload of security demands, are pressing concerns in the industry. Research increasingly shows that fatigued employees are more likely to engage in unsafe cyber behaviours, making it essential for cybersecurity leaders to implement targeted mitigation strategies. However, the extent to which these leaders understand the causes of cybersecurity fatigue and can identify effective solutions remains unclear. There is concern that cybersecurity professionals and non-cyber employees may view each other as distinct groups, potentially leading to biased decision-making, where each group recommends different interventions for themselves versus others. This actor-observer bias could have significant implications for leadership decisions, yet it remains underexplored in this context. This study examines what cybersecurity professionals believe are the causes of cybersecurity fatigue in their workplaces and the strategies they would adopt to mitigate it. It compares these views with those of non-cybersecurity managers and regular employees. Using attribution theory, we developed a novel measure, CyFa (pronounced “cipher”), to assess mitigation strategy preferences and attribution styles. Data from 506 participants across these groups were analysed. The findings suggest that actor-observer bias is present in all groups, with cybersecurity professionals and managers being no better at avoiding this bias than others. Differences between the groups often reflected a tendency to avoid responsibility rather than superior decision-making. Additionally, cybersecurity professionals were found to rely heavily on certain strategies, like employee awareness training, while neglecting others, such as organisational system changes.
Andrew Reeves, Dragana Calic, Paul H. Delfabbro
Comput. Secur.1
2024 TbDd: A new trust-based, DRL-driven framework for blockchain sharding in IoT
abstract
Integrating sharded blockchain with IoT presents a solution for trust issues and optimized data flow. Sharding boosts blockchain scalability by dividing its nodes into parallel shards, yet it is vulnerable to the 1% attacks where dishonest nodes target a shard to corrupt the entire blockchain. Balancing security with scalability is pivotal for such systems. Deep Reinforcement Learning (DRL) adeptly handles dynamic, complex systems and multi-dimensional optimization. This paper introduces a Trust-based and DRL-driven (TbDd) framework, crafted to counter collusion attack risks and dynamically adjust node allocation, enhancing throughput while maintaining network security. With a comprehensive trust evaluation mechanism, TbDd discerns node types and performs targeted resharding against potential threats. The TbDd framework maximizes the tolerance for dishonest nodes, optimizes node movement frequency, ensures even node distribution in shards, and balances sharding risks. Extensive evaluations validate TbDd’s superiority over conventional random-, community-, and trust-based sharding methods in shard risk equilibrium and reducing cross-shard transactions.
Zixu Zhang, Guangsheng Yu, Caijun Sun, Xu Wang 0004, Ying Wang 0096, Wei Ni 0001, Ren Ping Liu 0001, Andrew Reeves, Nektarios Georgalas
Comput. Networks9
2024 The sleepless sentinel: factors that predict burnout and sleep quality in cybersecurity professionals
abstract
Purpose The purpose of this study is to investigate the extent to which a sample of the Australian cybersecurity industry is impacted by burnout. Design/methodology/approach Based on the review of the literature, this research investigates the following three hypotheses. Gender will significantly predict burnout scores. Those who identify as women will score higher on average than those who identify as men (because of being in a male-dominated industry). Self-reported burnout will differ across job roles. In addition, the authors expect these relationships to hold across the three dimensions of burnout, namely, emotional exhaustion, depersonalisation and professional efficacy. Sleep quality will be associated with burnout. Findings Gender and job role were significant predictors of emotional exhaustion, but not depersonalisation or professional efficacy. The interaction between gender and job role was also significant. Senior managers experienced poorer quality sleep, and poorer sleep quality was associated with greater reported emotional exhaustion at work. For emotional exhaustion, female respondents who worked in security consultant roles tended to score higher than their male counterparts. Practical implications Left unaddressed, the high level of workplace burnout may add to the well-being and retention problems developing within the cybersecurity community. These results indicate that organisations should look to measure the well-being of their own cyber workforce and implement meaningful changes if they wish to keep their cyber talent and enable them to thrive at work. Originality/value This research paper is an extension of a previous paper by the same authors which is titled “Is Your CISO Burnt Out Yet”. This paper examined the demographic differences in workplace burnout among cybersecurity professionals.
Andrew Reeves, Malcolm Pattinson, Marcus A. Butavicius
Inf. Comput. Secur.1
2024 Toward Web3 Applications: Easing the Access and Transition
abstract
Web3 is leading a wave of the next generation of web services that even many Web2 applications are keen to ride. However, the lack of Web3 background for Web2 developers hinders easy and effective access and transition. On the other hand, Web3 applications desire encouragement and advertisement from conventional Web2 companies and projects due to their low market shares. In this article, we propose a seamless transition framework that transits Web2 to Web3, named WEBTTCOM [WEBTTCOM stands for Web2 (two)–Web3 (three) Communicator], after exploring the connotation of Web3 and the key differences betweenWeb2 andWeb3 applications.We also provide a full-stack implementation as a use case to support the proposed framework, followed by performance evaluation and surveys with ~1000 participants that show ~80% positive and ~20% neutral responses. We confirm that the proposed framework WEBTTCOM addresses the defined research question, and the implementation well satisfies the framework WEBTTCOM in terms of strong necessity,usability, andcompletenessbased on the survey results.
Guangsheng Yu, Xu Wang 0004, Qin Wang 0008, Tingting Bi, Yifei Dong 0003, Ren Ping Liu 0001, Nektarios Georgalas, Andrew Reeves
IEEE Trans. Comput. Soc. Syst.8
2023 Matrix Platform: Empowering Smart Ports with Advanced Video Analytics for Enhanced Security, Safety, and Efficiency
abstract
This paper underscores the crucial role of video anonymization in smart ports, were data privacy and security hold critical importance. It introduces the Matrix Platform, specifically designed for smart environments, and highlights its strong video anonymization capabilities. The platform employs advanced Video Anonymization techniques to effectively balance the preservation of data confidentiality with the enhancement of port security. Furthermore, the paper discusses how object detection and anonymization methods are strategically employed to protect sensitive information while still allowing access to critical operational details such as cargo and vessel types. Emphasis is placed on video anonymization's pivotal role in strengthening port security by concealing high-value assets and minimizing the risk of exposing sensitive data. By integrating the Matrix Platform, ports gain the capability to proactively manage security risks, safeguard assets, and secure information. This adaptable platform can be deployed in both Edge and Cloud environments, ensuring alignment with the specific needs of smart ports, with a primary focus on data anonymization. In conclusion, as the port industry continues to evolve, this paper asserts that the adoption of video anonymization techniques is fundamental for future growth and development, providing assurance of privacy and security in this dynamic landscape.
Brendan Black, Philip Perry, Joseph Rafferty, Claudia Cristina, Tom Bowman, Cathryn Peoples, Andrew Ennis, Andrew Reeves, Nektarios Georgalas, Adrian Moore 0001, Bryan W. Scotney
TrustCom8
2023 Proactive Device Management for the Internet of Things
abstract
IoT ecosystems are rapidly expanding, and device management is emerging as a key challenge due to the scale, complexity, and dynamism of IoT systems. The adoption of autonomous techniques shows promise to alleviate key issues including maintaining organisational security when large volumes of IoT devices are being added and removed from a telecommunications network. Here we propose a proactive IoT device management approach that addresses the need to control network access in a risk-based manner. The proposed system comprises of two novel core components, a Management Platform for IoT (MP-IoT) component and an Intent-Based Microsegmentation (IBMS) component. The MP-IoT component carries out a risk management role and combines with IBMS to provide risk-based network segmentation. The two components work together to proactively manage risks by migrating devices between isolated network segments according to a dynamic assessment of the risk to the system from an individual device. Self-healing techniques may then be used to mitigate risks associated with a device and consequently change the network segment that it resides in. Here we present the key challenges associated with typical IoT environments and demonstrate how they are addressed by the proposed Proactive IoT Device Management architecture. A prototype implementation is also presented to validate the operation of the proposed architecture.
Tom Bowman, Nektarios Georgalas, Andrew Reeves, Andrew Ennis, Cathryn Peoples, Brendan Black, Fadi El-Moussa 0001, Adrian Moore 0001
TrustCom3
2023 IoT Device Lifecycle Management
abstract
This paper presents an approach to autonomous IoT device lifecycle management for our developed Matrix IoT platform. We discuss our approach for zero touch onboarding, IoT device failure, device end-of-life offboarding and SLAs to support device lifecycle management. We collected timings on the key stages of our proposed onboarding process. The total onboarding time takes on average 6.4 seconds to onboard a device. Therefore, when scaled to many hundreds of devices, there is a very significant time saving benefit to onboarding devices automatically, along with the benefits of reducing human error.
Nektarios Georgalas, Andrew Ennis, Cathryn Peoples, Joseph Rafferty, Philip Perry, Claudia Cristina, Brendan Black, Adrian Moore 0001, Tom Bowman, Bryan W. Scotney, Andrew Reeves
TrustCom11
2023 "Generic and unusable"1: Understanding employee perceptions of cybersecurity training and measuring advice fatigue
Andrew Reeves, Dragana Calic, Paul H. Delfabbro
Comput. Secur.1
2021 Capacity analysis of public blockchain
Xu Wang 0004, Wei Ni 0001, Xuan Zha, Guangsheng Yu, Ren Ping Liu 0001, Nektarios Georgalas, Andrew Reeves
Comput. Commun.7
2021 "Get a red-hot poker and open up my eyes, it's so boring"1: Employee perceptions of cybersecurity training
Andrew Reeves, Dragana Calic, Paul H. Delfabbro
Comput. Secur.1