Ruti Gafni

dblp:222/2009 · DBLP profile ↗
← Back
8ranked-venue papers
6as first author
7since 2021 · last 2024
0000-0002-7120-2115ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 4 · 3 first-author · 4 since 2021Databases, data management, data science and information retrieval · 3 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2024 The role of artificial intelligence (AI) in improving technical and managerial cybersecurity tasks' efficiency
abstract
Purpose Artificial intelligence (AI) can assist in the worldwide shortage of cybersecurity workers in technical and managerial roles. Thus, the purpose of this study was to investigate the role of AI in automating many of the routine tasks associated with cybersecurity. As such, AI enables cybersecurity personnel to reduce their workloads and focus on more strategic aspects of their work. Design/methodology/approach This study is an exploratory field study. The authors started by conducting a literature review to assess the possibility that AI tools can provide and how they can improve cybersecurity efficacy. Following this, the authors identified the specific core tasks for two cybersecurity work roles (technical and managerial) and searched for specific commercial tools that can perform each of the tasks. Then, the authors used the free ChatGPT 3.5 to list the current cybersecurity systems that use AI for the associated tasks, which the authors then reviewed with the tools’ documentation and websites to confirm these tasks were conducted or assisted by AI. Findings Results indicated that all 14 cybersecurity tasks of the technical work role are currently noted to be performed by commercial cybersecurity systems with AI-integrated capabilities, while only 11 of the 17 managerial work role tasks currently appear to be performed by AI. Practical implications The rapid integration of AI capabilities into commercial cybersecurity systems may suggest that the cybersecurity workforce must be currently trained on how to use AI tools in their daily operations, especially as it pertains to technical cybersecurity work roles. Social implications The cybersecurity workforce shortage is reported to exceed four million cybersecurity workers worldwide in 2023. Thus, further understanding of the role of AI in improving the efficiency of technical and managerial cybersecurity tasks is significant. Originality/value The value of this research lies in the initial assessment of the current AI capabilities of commercial cybersecurity systems, which will ultimately provide the “super-human” performances resulting from human-AI teaming.
Ruti Gafni, Yair Levy
Inf. Comput. Secur.1
2024 Objectivity by design: The impact of AI-driven approach on employees' soft skills evaluation
Ruti Gafni, Itzhak Aviv, Boris Kantsepolsky, Sofia Sherman, Havana Rika, Yariv Itzkovich, Artem Barger
Inf. Softw. Technol.1
2024 Multi-Party Secured Collaboration Architecture from Cloud to Edge
abstract
Distributed Federated Collaboration Secured Services is a proposed novel secure distributed Unified Communication and Collaboration (UCC) reference architecture planned for multi-environment ecosystems (including hybrid cloud, edge computing for IoT and real-time usages, and portable scenarios). DFCS-RA encourages new businesses and models, connecting people, “things,” and processes in secured and sensitive workloads, supporting efficient and cost-effective enhancements to traditional UCC (mostly centralized/monolithic services) tailored for different vertical markets having varying requirements. It provides a novel secure multi-environment communication and collaboration technology and services between large numbers of players. Key security concepts developed are secure separation, federation, and collaboration. The cryptographic architecture extends the Signal messenger security and encryption architecture. DFCS-RA comprises a toolbox for security modeling, a set of security design principles, and a set of security functions and mechanisms to implement controls to achieve stated security objectives. It was tested in diverse use cases; and found suitable, secure, and reliable.
Ruti Gafni, Itzhak Aviv, Dror Haim
J. Comput. Inf. Syst.1
2023 Experts' feedback on the cybersecurity footprint elements: in pursuit of a quantifiable measure of SMBs' cybersecurity posture
abstract
Purpose While data breaches are reported daily, organizations are struggling with quantifying their cybersecurity posture. This paper aims to introduce the Universal Cybersecurity Footprint Index (UCFI), an organizational measure of Cybersecurity Footprint. The UCFI helps organizations understand the challenges related to their overall cybersecurity posture and be able to assess it for their supply chain cybersecurity. The Theory of Cybersecurity Footprint states that the risk and damage that can be caused by an attacked organization are not related to the size of the organization but to a range of parameters that may affect the interconnected entities in their supply chain. Design/methodology/approach Based on the 26 elements found in prior research, a survey was conducted, using 27 subject matter experts to reveal the most relevant elements and then specify their importance level to calculate their relative weight. Findings Results indicated that 20 of the 26 elements were validated, and their weights were calculated. Finally, an equation representing the UCFI for an organization is introduced. Practical implications Organizations can choose their partners according to a minimum value of the UCFI to reduce their cybersecurity risks. Social implications Supply chain cybersecurity incidents have demonstrated in the past several years to provide a massive impact on society. Thus, further assisting in mitigation of cyberattacks to the supply chain is significant. Originality/value This research aims to provide further assistance for organizations in quantifying their cybersecurity footprint in effort to help reduce cyber incidents, especially those for small organizations.
Ruti Gafni, Yair Levy
Inf. Comput. Secur.1
2023 Using Web Frameworks in Server Side Programming Courses
abstract
Teaching undergraduate students skills needed for employment is one of the aims of the curriculum of Information Systems studies. The “Server-Side Programming” course is an advanced course, studied during the last academic year, to provide theoretical and practical knowledge of building the server-side of a web project. The course included teaching a commercial web framework based on Model-View-Controller, a model used by practitioners, and Object-Oriented Programming (OOP). This study investigates whether a framework for developing projects should be incorporated into the course. The lecturer’s remarks on 63 projects delivered during six courses were analyzed to find the difficulties when programming a project for the first time. The course lecturer was interviewed to gain her insights. Results showed difficulties using a web framework, although this can assist in implementing the OOP design, as manifested by fewer errors. Conclusions recommend enlarging the practical part of the course, and the use of frameworks.
Orly Barzilai, Ruti Gafni
J. Comput. Inf. Syst.2
2022 Cyberattacks against the health-care sectors during the COVID-19 pandemic
abstract
Purpose This paper aims to analyze the changes in cyberattacks against the health-care sector during the COVID-19 pandemic. Design/methodology/approach The changes in cyberattacks of the health-care sector are analyzed by examination of the number and essence of published news concerning cybersecurity attacks on the health-care sector during 2019 and compared them to those published during 2020, based on two main websites, which review such incidents. Findings This study found that there was a significant growth in reports of cyberattacks on the health-care sector. Moreover, the number of cyberattacks fit interestingly to the pattern of waves of the disease, which expanded worldwide. During the first wave the number of reports was doubled or even tripled, compared to the same period in 2019, a tendency that was slightly waned afterwards. Practical implications This study helps to deepen the awareness of information security implications of a potential global devastating crisis, even in the cybersecurity domain, and on the health-care sector, among various other affected sectors and domains. Social implications COVID-19 pandemic created long-term wide-range changes that affect every individual and sector, mainly owing to the shift to remote working model, which impose long-term new cybersecurity changes, among them to the health-care industry. Originality/value This paper extends the existing information on implication of remote working model on information security and of the COVID-19 pandemic on the cybersecurity of health-care institutions around the world.
Ruti Gafni, Tal Pavel
Inf. Comput. Secur.1
2021 Introducing the concept of cybersecurity footprint
abstract
Purpose This paper aims to introduce the concept of cybersecurity footprint. Design/methodology/approach Characteristics of cybersecurity footprint are presented based on documented cases, and the domino effect of cybersecurity is illustrated. Organizational and individual cybersecurity footprints are outlined. Active and passive – digital vs cybersecurity footprints are then reviewed. Taxonomy of aware/unaware vs active/passive cybersecurity footprints are presented, followed by brief discussion of the implications for future research. Findings The concept of cybersecurity footprint is defined, and the evidence from prior cyber incidents is shown to emphasize the concept. Smaller organizations may have a large cybersecurity footprint, whereas larger organizations may have smaller one. Cyberattacks are focusing on the individuals or small organizations that are in the supply chain of larger organizations causing the domino effect. Practical implications Implications of cybersecurity footprint to individuals, organizations, societies and governments are discussed. The authors present organizations with ways to lower cybersecurity footprint along with recommendations for future research. Social implications Cybersecurity has a significant social implication worldwide, as the world is becoming cyber dependent. With the authors’ introduction of the cybersecurity footprint concept and call to further understand how organizations can measure and reduce it, the authors envision it as another perspective of assessing cyber risk and further help mitigate future cyber incidents. Originality/value This paper extends the existing information and computer security body of knowledge on the concept of cybersecurity footprint with illustrated cases.
Yair Levy, Ruti Gafni
Inf. Comput. Secur.2
2014 Daily Deals Websites: Mostly but not all about Location
abstract
This study examined the main factors that affect purchasing of coupons on daily deals Websites. The study included a survey of attitudes toward pictures, trust in suppliers, and trust in the intermediary, and also examined exposure to coupons, as recalled by visitors of the Website. A/B testing analyzed 34 offered deals, and compared the actual purchased coupons when the offer was positioned relatively high, and when it was located lower. The findings suggested authentic pictures of the deal are the most important. A negative correlation between perceived trust in suppliers and trust in the intermediary indicated that intermediary good reputation is valuable and may enable deals with unknown suppliers. Offers located among the first 10 deals received the highest exposure, and when the offer was displayed higher, significantly more coupons were purchased.
Ruti Gafni, Nitza Geri, Yoav Aziz
J. Comput. Inf. Syst.1