Ying He 0004

dblp:39/2405-4 · DBLP profile ↗
← Back
15ranked-venue papers
2as first author
5since 2021 · last 2026
—ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 9 · 4 since 2021Artificial intelligence and machine learning · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 1Databases, data management, data science and information retrieval · 1Human-computer interaction and ubiquitous computing · 1 · 1 first-author
YearPublicationVenuePosition
2026 A cyber risk economics model for organization-wide risk management (CYREM-ORM)
abstract
The increasing sophistication of cyber risks has made it challenging for organizations to assess their business impacts. The key challenge is the technical and language “barrier” between cybersecurity teams and business teams who make strategic investment decisions on cybersecurity. This often leads to delays, budget issues that prevent timely responses to cyber incidents. Existing research lacks a transparent, traceable, and reproducible method to communicate cyber risks and their impacts on businesses. We introduce a novel cyber risk economics model for organization-wide risk management (CYREM-ORM) that captures complex cyber risks and expresses them using financial terms. This is achieved by mapping Cyber Threat Intelligence (CTI) to the Factor Analysis of Information Risk (FAIR) model, enriched by cyber cost typologies. CYREM-ORM provides a traceable workflow that links organisation-related CTI to FAIR factor estimation, cost breakdowns, and ultimately to monetary loss amounts and prioritised risk scenarios. This design improves transparency in risk management, helps organisations prioritise mitigations in line with strategic business objectives, and enables stakeholders to assess the rationale behind results when needed. By grounding risk parameters in CTI, the model also facilitates proactive screening of organisation-relevant threats, instead of reactive, control-gap reporting. We evaluate the CYREM-ORM through three complementary case studies: the 2017 Equifax breach case proves its feasibility with historical data and open-source CTI, while the Small and Medium Enterprise (SME) education company and the large retail company cases show its effectiveness in communicating cyber risks at an organizational-wide strategic level within real-world contexts.
Tong Xin 0003, Ying He 0004, Efpraxia D. Zamani, Mark Glenn Evans, Cunjin Luo
Comput. Secur.2
2024 Poster: Cyber Security Economics Model (CYSEM)
abstract
The increasing sophistication of cyberattacks and the evolution of security risks make it challenging for organizations to understand their impact on businesses.The habitual reliance on the judgment of cyber security experts and communication gaps between cyber security team and board members, responsible for making strategic cyber security investment decisions further weaken organization's capability to respond to cyber threats.Existing research lacks a transparent approach to quantify security risks and their impact on businesses.This paper introduces a novel CYSEM that express security risk in financial terms, through integrating Cyber Threat Intelligence (CTI) with the Factor Analysis of Information Risk (FAIR) model, elaborated with cyber security cost typologies.CYSEM facilitates communication among multi-stakeholders and improves transparency and quality of investment decision-making at the strategic level.We evaluate the CYSEM using a case study, which has showed its effectiveness in understanding the impact of cyber threat from an economics perspective. CCS Concepts• Security and privacy → Human and societal aspects of security and privacy; Economics of security and privacy.
Tong Xin 0003, Ying He 0004, Efpraxia D. Zamani, Cunjin Luo
CCS2
2022 Malware incident response (IR) informed by cyber threat intelligence (CTI)
Ying He 0004, Ellis Inglut, Cunjin Luo
Sci. China Inf. Sci.1
2022 CAESAR8: An agile enterprise architecture approach to managing information security risks
abstract
In theory, implementing an Enterprise Architecture (EA) should enable organizations to increase the accuracy of information security risk assessments. In reality, however, organizations struggle to fully implement EA frameworks because the requirements for implementing an EA and the benefits of commercial frameworks are unclear, and the overhead of maintaining EA artifacts is unacceptable, especially for smaller organizations. In this paper, we describe a novel approach called CAESAR8 (Continuous Agile Enterprise Security Architecture Review in 8 domains) that supports dynamic and holistic reviews of information security risks in IT projects. CAESAR8’s nonlinear design supports continuous reassessment of information security risks, based on a checklist that assesses the maturity of security considerations in eight domains that often cause information security failures. CAESAR8 assessments can be completed by multiple stakeholders independently, thus ensuring consideration of their tacit knowledge while preventing groupthink. Our evaluation with experienced industry professionals showed that CAESAR8 successfully addresses real-world problems in information security risk management, with significant benefits particularly for smaller organizations.
Paul Loft, Ying He 0004, Iryna Yevseyeva, Isabel Wagner
Comput. Secur.2
2021 The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
Richard Smith 0002, Helge Janicke, Ying He 0004, Fenia Ferra, Adham Albakri
Comput. Secur.3
2020 On the Security Risks of the Blockchain
abstract
The adoption of blockchain technology is taking place at a fast pace. Security features inherent in blockchain make it resistant to attack, but they do not make it immune, and blockchain security risks do exists. This paper details the associated risks and concerns of the blockchain. We explore relevant standards and regulations related to blockchain and survey and analyze 38 blockchain incidents to determine the root cause to provide a view of the most frequent vulnerabilities exploited. The paper reviews six of these 38 incidents in greater detail. The selection is made by choosing incidents with the most frequent root cause. In the review of the incidents, the paper details what happened and why and aims to address what could have been done to mitigate the attack. The paper concludes with a recommendation on a framework to reduce cyber security risks when using blockchain technologies.
Efpraxia D. Zamani, Ying He 0004, Matthew Phillips
J. Comput. Inf. Syst.2
2019 HEART-IS: A novel technique for evaluating human error-related information security incidents
Mark Glenn Evans, Ying He 0004, Leandros Maglaras, Helge Janicke
Comput. Secur.2
2019 Smart cities and cyber security: Are we there yet?A comparative study on the role of standards, third party risk management and security ownership
Morta Vitunskaite, Ying He 0004, Thomas Brandstetter, Helge Janicke
Comput. Secur.2
2019 Published incidents and their proportions of human error
abstract
Purpose This paper aims to provide an understanding of the proportions of incidents that relate to human error. The information security field experiences a continuous stream of information security incidents and breaches, which are publicised by the media, public bodies and regulators. Despite the need for information security practices being recognised and in existence for some time, the underlying general information security affecting tasks and causes of these incidents and breaches are not consistently understood, particularly with regard to human error. Design/methodology/approach This paper analyses recent published incidents and breaches to establish the proportions of human error and where possible subsequently uses the HEART (human error assessment and reduction technique) human reliability analysis technique, which is established within the safety field. Findings This analysis provides an understanding of the proportions of incidents and breaches that relate to human error, as well as the common types of tasks that result in these incidents and breaches through adoption of methods applied within the safety field. Originality/value This research provides original contribution to knowledge through the analysis of recent public sector information security incidents and breaches to understand the proportions that relate to human error.
Mark Glenn Evans, Ying He 0004, Iryna Yevseyeva, Helge Janicke
Inf. Comput. Secur.2
2017 A Game-Theoretic Based QoS-Aware Capacity Management for Real-Time EdgeIoT Applications
abstract
More and more real-time IoT applications such as smart cities or autonomous vehicles require big data analytics with reduced latencies. However, data streams produced from distributed sensing devices may not suffice to be processed traditionally in the remote cloud due to: (i) longer Wide Area Network (WAN) latencies and (ii) limited resources held by a single Cloud. To solve this problem, a novel Software-Defined Network (SDN) based InterCloud architecture is presented for mobile edge computing environments, known as EdgeIoT. An adaptive resource capacity management approach is proposed to employ a policy-based QoS control framework using principles in coalition games with externalities. To optimise resource capacity policy, the proposed QoS management technique solves, adaptively, a lexicographic ordering bi-criteria Coalition Structure Generation (CSG) problem. It is an onerous task to guarantee in a deterministic way that a real-time EdgeIoT application satisfies low latency requirement specified in Service Level Agreements (SLA). CloudSim 4.0 toolkit is used to simulate an SDN-based InterCloud scenario, and the empirical results suggest that the proposed approach can adapt, from an operational perspective, to ensure low latency QoS for real-time EdgeIoT application instances.
Suleiman Onimisi Aliyu, Feng Chen 0004, Ying He 0004
QRS3
2016 User interface design for privacy awareness in eHealth technologies
abstract
In this paper we investigate privacy issues relating to Human Computer Interfaces for mobile eHealth technologies. We present the Inform-Alert-Mitigate (I-AM) cycle, a novel approach to address privacy concerns that are associated with the use of these technologies. The I-AM approach supports the responsible innovation of new technologies. We demonstrate the effectiveness of I-AM by applying it to examples taken from mobile applications relating to personal health. We discuss three classes of applications: a) fitness trackers b) personal wellbeing applications and c) medical applications, and evaluate the privacy exposure of their users using representative applications from these classes. The paper evaluates the current privacy enhancing features of these applications against the identified risks and demonstrates how the I-AM approach can be applied to yield additional and more effective privacy protection for these technologies.
Isabel Wagner, Ying He 0004, Duska Rosenberg, Helge Janicke
CCNC2
2016 POSTER: Design Ideas for Privacy-aware User Interfaces for Mobile Devices
abstract
Privacy in mobile applications is an important topic, especially when it concerns applications that gather and process health data. Using MyFitnessPal as an example eHealth app, we analyze how privacy-aware its user interface is, i.e. how well users are informed about privacy and how much control they have. We find several issues with the current interface and develop five design ideas that make the interface more privacy-aware. In a small pilot user study, we find that most of the design ideas seem to work well and enhance end users' understanding and awareness of privacy.
Neel Tailor, Ying He 0004, Isabel Wagner
WISEC2
2016 Human behaviour as an aspect of cybersecurity assurance
abstract
Abstract There continue to be numerous breaches publicised pertaining to cybersecurity despite security practices being applied within industry for many years. This paper is intended to be the first in a number of papers as research into cybersecurity assurance processes. This paper is compiled based on current research related to cybersecurity assurance and the impact of the human element on it. The objective of this work is to identify elements of cybersecurity that would benefit from further research and development based on the literature review findings. The results outlined in this paper present a need for the cybersecurity field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The paper proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide or are intended not to negatively affect cybersecurity assurance. Copyright © 2016 John Wiley & Sons, Ltd.
Mark Glenn Evans, Leandros Maglaras, Ying He 0004, Helge Janicke
Secur. Commun. Networks3
2014 Improving the Information Security Management: An Industrial Study in the Privacy of Electronic Patient Records
abstract
Adverse incidents in the privacy of patients' medical records can result in multiple negative impacts. Effective mechanisms are needed to communicate the lessons from the incidents into the Information Security Management Systems (ISMS) so as to prevent similar incidents. The Generic Security Template (G.S.T.) has been developed to enhance current mechanism and has demonstrated significant benefits in communicating the lessons compared to the more conventional use of text-based incident reports. This paper extends the work to evaluate the G.S.T. in healthcare. A case study with healthcare professionals working in a China healthcare organization shows that, the G.S.T. can enhance the current mechanism in communicating the lessons with the ISMS.
Ying He 0004, Christopher W. Johnson 0001, Yu Lu 0001, Yixia Lin
CBMS1
2014 Towards the Computation of a Nash Equilibrium
Yu Lu 0001, Ying He 0004
ISNN2