VLDB 2026 Research / reviewers in the wild / expert
Duncan Ki-Aries
dblp:190/9379
· DBLP profile ↗
6ranked-venue papers
4as first author
2since 2021 · last 2022
0000-0001-8114-2737ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2022 | Assessing system of systems information security risk with OASoSISabstractThe term System of Systems (SoS) is used to describe the coming together of independent systems, collaborating to achieve a new or higher purpose. However, the SoS concept is often misunderstood within operational environments, providing challenges towards the secure design and operation of SoSs. Limitations in existing literature indicates a need for discovery towards identifying a combination of concepts, models, and techniques suitable for assessing SoS security risk and related human factor concerns for SoS Requirements Engineering. In this article, we present OASoSIS, representing an information security risk assessment and modelling process to assist risk-based decision making in SoS Requirements Engineering. A characterisation process is introduced to capture the SoS context, supporting a SoS security risk assessment process that extends OCTAVE Allegro towards a SoS context. Resulting risk data provides a focused means to assess and model the SoS information security risk and related human factors, integrating tool-support using CAIRIS. A medical evacuation SoS case study scenario was used to test, illustrate, and validate the alignment of concepts, models, and techniques for assessing SoS information security risks with OASoSIS, where findings provide a positive basis for future work. Duncan Ki-Aries, Shamal Faily, Huseyin Dogan, Christopher Williams 0001 |
Comput. Secur. | 1 |
| 2021 | Visualising personas as goal models to find security tensionsabstractPurpose This paper aims to present a tool-supported approach for visualising personas as social goal models, which can subsequently be used to identify security tensions. Design/methodology/approach The authors devised an approach to partially automate the construction of social goal models from personas. The authors provide two examples of how this approach can identify previously hidden implicit vulnerabilities and validate ethical hazards faced by penetration testers and their safeguards. Findings Visualising personas as goal models makes it easier for stakeholders to see implications of their goals being satisfied or denied and designers to incorporate the creation and analysis of such models into the broader requirements engineering (RE) tool-chain. Originality/value The approach can be used with minimal changes to existing user experience and goal modelling approaches and security RE tools. Shamal Faily, Claudia Iacob, Raian Ali, Duncan Ki-Aries |
Inf. Comput. Secur. | 4 |
| 2019 | Usable and Secure Requirements Engineering with CAIRISabstractSoftware needs to satisfy a range of security, privacy, and usability requirements. Eliciting them entails using design techniques both within and outside Requirements Engineering, together with tool-support which can analyse and make sense of requirements and other design concepts as early stage designs evolve. This half-day tutorial introduces participants to CAIRIS, and how it can be used to engineer requirements for usable and secure software. Participants will be given the chance to use CAIRIS with selected usability and security design techniques, and learn how CAIRIS has and can be deployed in real-world projects. Shamal Faily, Duncan Ki-Aries |
RE | 2 |
| 2018 | Assessing Security Risk and Requirements for Systems of SystemsabstractA System of Systems (SoS) is a term used to describe independent systems converging for a purpose that could only be carried out through this interdependent collaboration. Many examples of SoSs exist, but the term has become a source of confusion across domains. Moreover, there are few illustrative SoS examples demonstrating their initial classification and structure. While there are many approaches for engineering of systems, less exist for SoS engineering. More specifically, there is a research gap towards approaches addressing SoS security risk assessment for engineering and operational needs, with a need for tool-support to assist modelling and visualising security risk and requirements in an interconnected SoS. From this, security requirements can provide a systematic means to identify constraints and related risks of the SoS, mitigated by human-user and system requirements. This work investigates specific challenges and current approaches for SoS security and risk, and aims to identify the alignment of SoS factors and concepts suitable for eliciting, analysing, validating risks with use of a tool-support for assessing security risk in the SoS context. Duncan Ki-Aries |
RE | 1 |
| 2017 | Re-framing "the AMN": A case study eliciting and modelling a System of Systems using the Afghan Mission NetworkabstractThe term System of Systems (SoS) is often used to classify an arrangement of independent and interdependent systems delivering unique capabilities. There appear to be many examples of SoSs, but the term has become a source of confusion. While many approaches have been proposed for engineering SoSs, there are few illustrative examples demonstrating their initial classification and resulting SoS structure. This paper presents an approach for framing a candidate SoS using the Afghan Mission Network defined as an Acknowledged SoS, and presents issues associated with SoSs stakeholders, human factors and interoperability considerations resulting from such an approach. Duncan Ki-Aries, Shamal Faily, Huseyin Dogan, Christopher Williams 0001 |
RCIS | 1 |
| 2017 | Persona-centred information security awarenessabstractMaintaining Information Security and protecting data assets remains a principal concern for businesses. Many data breaches continue to result from accidental, intentional or malicious human factors, leading to financial or reputational loss. One approach towards improving behaviours and culture is with the application of on-going awareness activities. This paper presents an approach for identifying security related human factors by incorporating personas into information security awareness design and implementation. The personas, which are grounded in empirical data, offer a useful method for identifying audience needs and security risks, enabling a tailored approach to business-specific awareness activities. As a means for integrating personas, we present six on-going steps that can be embedded into business-as-usual activities with 90-day cycles of awareness themes, and evaluate our approach with a case study business. Our findings suggest a persona-centred information security awareness approach has the capacity to adapt to the time and resource required for its implementation within the business, and offer a positive contribution towards reducing or mitigating Information Security risks through security awareness. Duncan Ki-Aries, Shamal Faily |
Comput. Secur. | 1 |