Bilal Naqvi

dblp:232/4572 · DBLP profile ↗
← Back
3ranked-venue papers
3as first author
3since 2021 · last 2025
0000-0001-5271-5604ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 2 · 2 first-author · 2 since 2021Software engineering, systems software and programming languages · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Equitable cybersecurity: Towards generating requirements through the lens of security literacy
abstract
Context Users of modern-day systems must understand how these systems operate and their roles in protecting these systems. This requires a degree of security literacy, but, as with all literacies, this varies across the general population. Improving literacy requires time for learning and gaining practical experience, and that does not happen overnight. Therefore, a two-pronged approach is necessary, whereby we ensure that everyone who uses these systems possesses an appropriate level of security literacy and design systems that are intuitive and usable by all users, regardless of their level of security literacy. Objectives This paper aims to demonstrate that traditional requirements-gathering approaches often overlook important requirements related to security literacy. The paper does so by considering a case study featuring the development of a novel biometric e-ID across six cases in five European countries. Methods To address this objective, firstly, the paper synthesized elements from academic and gray literature to conceptualize security literacy. The co-design approach was then used to draft scenarios based on the six cases (in the case study) and to identify security literacy-specific requirements. Results The paper presents a conceptual model of security literacy structured into pillars, core, and specialized knowledge areas and abilities, respectively. Using this model as an analytical lens, the paper presents six co-created scenarios and 11 security literacy-specific requirements that were not captured using standard requirement-gathering approaches. Conclusion The paper demonstrates that traditional requirement-gathering approaches can overlook important, nuanced requirements, particularly those relevant to user groups with lower security literacy. The model presented in this paper helps identify requirements from a security literacy perspective, thereby enhancing user security engagement and interactions.
Bilal Naqvi, Annika Wolff, Domenico Racanelli
Inf. Softw. Technol.1
2023 Mitigation strategies against the phishing attacks: A systematic literature review
abstract
Phishing attacks are among the most prevalent attack mechanisms employed by attackers. The consequences of successful phishing include (and are not limited to) financial losses, impact on reputation, and identity theft. The paper presents a systematic literature review featuring 248 articles (from the beginning of 2018 until March 2023) across the main digital libraries to identify, (1) the existing mitigation strategies against phishing attacks, and the underlying technologies considered in the development of these strategies; (2) the most considered phishing vectors in the development of the mitigation strategies; (3) anti-phishing guidelines and recommendations for organizations and end-users respectively; and (4) gaps and open issues that exist in the state of the art. The paper advocates for the need to consider the abilities of human users during the design and development of the mitigation strategies as only technology-centric solutions will not suffice to cater to the challenges posed by phishing attacks.
Bilal Naqvi, Kseniia Perova, Ali Farooq 0001, Imran Makhdoom, Shola Oyedeji, Jari Porras
Comput. Secur.1
2021 Incorporating the human facet of security in developing systems and services
abstract
Purpose The purpose of this paper is to present an integrative framework for handling the security and usability conflicts during the system development lifecycle. The framework has been formulated while considering key concerns raised after conducting a series of interviews with practitioners from the industry. The framework is aimed at assisting system designers and developers in making reasonably accurate choices when it comes to the trade-offs between security and usability. The outcomes of using the framework are documented as design patterns, which are disseminated among the community of system designers and developers for use in other but similar contexts. Design/methodology/approach A design science research approach was used to develop the integrative framework for usable security. Interviews were conducted for identification of the key concerns; however, the framework was validated during a workshop. Moreover, to validate the patterns’ template and the usable security pattern identified after instantiating the framework, a survey instrument was used. Findings It is important to consider the usability aspect in the development of security systems; otherwise, the systems, despite being secure against attacks, would be susceptible to user mistakes leading to compromises. It is worthwhile to handle usable security concerns right from the start of system development life cycle. Design patterns can help the developers in assessing the usability of their security options. Practical implications Practical implications The framework would assist the designers and developers in handling the security and usability conflicts right from the start of the system development life cycle. The patterns documented after using the framework would help not only the designers and developers working in the industry but also freelancers. Originality/value The authors present a novel framework to handle the security and usability conflicts during the system development life cycle. The development process of the framework was driven by the concerns raised after a series of interviews with the practitioners from industry. The framework presented in this paper was validated during a workshop in which it was exposed for review and comments by the participants from the industry. To demonstrate the use of patterns in general and the framework in particular, a case study featuring smart grids from the domain of cyber-physical systems is presented, which (to the best of the authors’ knowledge) features the first work relevant to usable security in the domain of cyber-physical systems.
Bilal Naqvi, Nathan L. Clarke, Jari Porras
Inf. Comput. Secur.1