Maria Papadaki

dblp:69/1571 · DBLP profile ↗
← Back
22ranked-venue papers
2as first author
4since 2021 · last 2024
0000-0003-0817-2651ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 18 · 2 first-author · 4 since 2021Computer networks · 1Human-computer interaction and ubiquitous computing · 1Applied, interdisciplinary, general and emerging computing · 1
YearPublicationVenuePosition
2024 Cybersecurity Incident Response Readiness in Organisations
Aseel Aldabjan, Steven Furnell, Xavier Carpent, Maria Papadaki
ICISSP4
2021 An empirical analysis of the information security culture key factors framework
Alaa Tolah, Steven Furnell, Maria Papadaki
Comput. Secur.3
2021 Towards a cross-cultural education framework for online safety awareness
abstract
Purpose The purpose of this study is to determine effective online safety awareness education for young people in less developed countries. The research followed an explanatory mixed methods design starting with an online survey (quantitative element) and then interesting or anomalous findings were followed up with one-on-one interviews (qualitative element). The data gathered on the online habits and views of young people were fed into the Young People Online Model. It was also used to create online safety workshops. The standout issue from this research is the prevalence of cyberbullying, and this was used as the core theme. They were carried out using the action-research approach, whereby after each workshop, the facilitators would reflect and analyse and suggest improvements for the next one. Design/methodology/approach The majority of online safety awareness education programmes have been developed in and for advanced countries. In less developed countries, there are fewer programmes as well as a lack of research on the factors that influence the online behaviour of young people online. The Young People Online Education Framework seeks to address this and provide educators, researchers and policymakers an evidence driven construct for developing education programmes informed by issues affecting young people in their respective country/region. Findings The framework was applied in Thailand. As there were very few previous studies, original research was conducted via surveys and interviews. It was found that a high proportion of young people had experienced negative interactions online with cyberbullying the main concern. This was confirmed during the workshop phase indicating the need for more research and workshops. There is a plan to continue the research in Thailand, and it is hoped that other researchers will make use of the framework to extend its scope and application. Originality/value A novel feature of this framework is the cultural mask. The cultural context of learners is often overlooked in education, especially when education programmes are imported from other countries. This research contends that effective learning strategies and programmes will have a better chance to succeed if the cultural makeup of the target audience is considered and that all topics and activities are parsed through the cultural mask element of the framework.
Ram Herkanaidu, Steven Furnell, Maria Papadaki
Inf. Comput. Secur.3
2021 A collaborative approach for national cybersecurity incident management
abstract
Purpose Collaborative-based national cybersecurity incident management benefits from the huge size of incident information, large-scale information security devices and aggregation of security skills. However, no existing collaborative approach has been able to cater for multiple regulators, divergent incident views and incident reputation trust issues that national cybersecurity incident management presents. This paper aims to propose a collaborative approach to handle these issues cost-effectively. Design/methodology/approach A collaborative-based national cybersecurity incident management architecture based on ITU-T X.1056 security incident management framework is proposed. It is composed of the cooperative regulatory unit with cooperative and third-party management strategies and an execution unit, with incident handling and response strategies. Novel collaborative incident prioritization and mitigation planning models that are fit for incident handling in national cybersecurity incident management are proposed. Findings Use case depicting how the collaborative-based national cybersecurity incident management would function within a typical information and communication technology ecosystem is illustrated. The proposed collaborative approach is evaluated based on the performances of an experimental cyber-incident management system against two multistage attack scenarios. The results show that the proposed approach is more reliable compared to the existing ones based on descriptive statistics. Originality/value The approach produces better incident impact scores and rankings than standard tools. The approach reduces the total response costs by 8.33% and false positive rate by 97.20% for the first attack scenario, while it reduces the total response costs by 26.67% and false positive rate by 78.83% for the second attack scenario.
Oluwafemi Oriola, Adesesan B. Adeyemo, Maria Papadaki, Eduan Kotzé
Inf. Comput. Secur.3
2020 Towards a maturity model for health-care cloud security (M2HCS)
abstract
Purpose The purpose of this paper is to propose a novel maturity model for health-care cloud security (M2HCS), which focuses on assessing cyber security in cloud-based health-care environments by incorporating the sub-domains of health-care cyber security practices and introducing health-care-specific cyber security metrics. This study aims to expand the domain of health-care cyber security maturity model by including cloud-specific aspects than is usually seen in the literature. Design/methodology/approach The intended use of the proposed model was demonstrated using the evaluation method – “construct validity test” as the paper’s aim was to assess the final model and the output of the valuation. The study involved a literature-based case study of a national health-care foundation trust with an overall view because the model is assessed for the entire organisation. The data were complemented by examination of hospitals’ cyber security internal processes through web-accessible documents, and identified relevant literature. Findings The paper provides awareness about how organisational-related challenges have been identified as a main inhibiting factor for the adoption of cloud computing in health care. Regardless of the remunerations of cloud computing, its security maturity and levels of adoption varies, especially in health care. Maturity models provide a structure towards improving an organisation’s capabilities. It suggests that although several cyber security maturity models and standards resolving specific threats exist, there is a lack of maturity models for cloud-based health-care security. Research limitations/implications Due to the selected research method, the research results may lack generalizability. Therefore, future research studies can investigate the propositions further. Another is that the current thresholds were determined empirically, although it worked for the case study assessment. However, to establish more realistic threshold levels, there is a need for more validation of the model using more case studies. Practical implications The paper includes maturity model for the assessment management and improvement of the security posture of a health-care organisation actively using cloud. For executives, it provides a detailed security assessment of the eHealth cloud to aid in decision making. For security experts, its quantitative metrics support proactive and reactive processes. Originality/value The paper fulfils a recognised requirement for security maturity model focussed on health-care cloud. It could be extended to resolve evolving cyber settings.
Opeoluwa Ore Akinsanya, Maria Papadaki, Lingfen Sun
Inf. Comput. Secur.2
2017 The impact of security and its antecedents in behaviour intention of using e-government services
abstract
One of the main challenges associated with e-government adoption is lack of security. Thus, the aim of this research is to investigate the role of security in e-government adoption by integrating security, trust and privacy with the Unified Theory of Acceptance and Use of Technology 2 (UTAUT2). In addition, this research will also investigate the factors that influence the end users’ perception of e-government security. Thus, the research starts with a qualitative study to investigate security antecedents, and this is followed by a quantitative study to validate the qualitative study and determine the role of security in e-government adoption. Data from 625 Saudi citizens were gathered and used in the model assessment. The findings show that user interface quality, security culture and cybersecurity law positively affect security perception. In addition, security perception was found to have a strong effect on trust. Trust is ranked as the third most critical factor affecting behaviour intention after performance expectance and habit. The results make a significant contribution to academic research and have practical implications regarding understanding the role of security in e-government adoption and the factors that affect end users’ perception in e-government security.
Nawaf Sulaiman Alharbi, Maria Papadaki, Paul Dowland 0001
Behav. Inf. Technol.2
2015 FHSD: An Improved IP Spoof Detection Method for Web DDoS Attacks
abstract
Distributed denial of service (DDoS) attacks represent a significant threat for companies, affecting them on a regular basis, as reported in the 2013 Information Security Breaches Survey (Technical Report. http://www.pwc.co.uk/assets/pdf/cyber-security-2013-technical-report.pdf.). The most common target is web services, the downtime of which could lead to significant monetary costs and loss of reputation. IP spoofing is often used in DDoS attacks not only to protect the identity of offending bots but also to overcome IP-based filtering controls. This paper aims to propose a new multi-layer IP Spoofing detection mechanism, called fuzzy hybrid spoofing detector (FHSD), which is based on source MAC address, hop count, GeoIP, OS passive fingerprinting and web browser user agent. The hop count algorithm has been optimized to limit the need for continuous traceroute requests, by querying the subnet IP Address and GeoIP information instead of individual IP addresses. FHSD uses fuzzy empirical rules and fuzzy largest of maximum operator to identify offensive IPs and mitigate offending traffic. The proposed system was developed and tested against the BoNeSi DDoS emulator with encouraging results in terms of detection and performance. Specifically, FHSD analysed 10 000 packets, and correctly identified 99.99% of spoofed traffic in <5 s. It also reduced the need for traceroute requests by 97%.
Stavros Shiaeles, Maria Papadaki
Comput. J.2
2014 Vulnerability of opportunistic parking assistance systems to vehicular node selfishness
Evangelia Kokolaki, Merkourios Karaliopoulos, Georgios Kollias, Maria Papadaki, Ioannis Stavrakakis
Comput. Commun.4
2014 A response selection model for intrusion response systems: Response Strategy Model (RSM)
abstract
ABSTRACT Intrusion response systems aim to provide a systematic procedure to respond to incidents. However, with different type of response options, an automatic response system is designed to select appropriate response options automatically in order to act fast to respond to only true and critical incidents as well as minimise their impact. In addition, incidents also can be prioritised into different level of priority where some incidents may cause a serious impact (i.e. high priority) and other may not (i.e. low priority). The existing strategies inherit some limitation such as using complex approaches and less efficient in mapping appropriate response based upon incidents' priority. Therefore, this study introduces a model called response strategy model to address the aforementioned limitation. In order to validate, it was evaluated using two datasets: DARPA 2000 and private dataset. The case study results have shown a significant relationship between the incident classification and incident priorities where false incidents are likely to be categorised as low priority and true incidents are likely to be categorised as the high priority. In particular, with response strategy model, an average of 92.68% of the false incidents was prioritised as the lowest priority is better compared with only 67.07% with Snort priority. Copyright © 2013 John Wiley & Sons, Ltd.
Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke
Secur. Commun. Networks2
2013 Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)
abstract
ABSTRACT The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top‐priority incidents. Copyright © 2012 John Wiley & Sons, Ltd.
Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke
Secur. Commun. Networks2
2012 A Response Strategy Model for Intrusion Response Systems
Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke
SEC2
2012 Evaluation of anomaly-based IDS for mobile devices using machine learning classifiers
abstract
ABSTRACT Mobile devices have evolved and experienced an immense popularity over the last few years. This growth however has exposed mobile devices to an increasing number of security threats. Despite the variety of peripheral protection mechanisms described in the literature, authentication and access control cannot provide integral protection against intrusions. Thus, a need for more intelligent and sophisticated security controls such as intrusion detection systems (IDSs) is necessary. Whilst much work has been devoted to mobile device IDSs, research on anomaly‐based or behaviour‐based IDS for such devices has been limited leaving several problems unsolved. Motivated by this fact, in this paper, we focus on anomaly‐based IDS for modern mobile devices. A dataset consisting of iPhone users data logs has been created, and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. Specifically, the experimental procedure includes and cross‐evaluates four machine learning algorithms (i.e. Bayesian networks, radial basis function,K‐nearest neighbours and random Forest), which classify the behaviour of the end‐user in terms of telephone calls, SMS and Web browsing history. In order to detect illegitimate use of service by a potential malware or a thief, the experimental procedure examines the aforementioned services independently as well as in combination in a multimodal fashion. The results are very promising showing the ability of at least one classifier to detect intrusions with a high true positive rate of 99.8%. Copyright © 2011 John Wiley & Sons, Ltd.
Dimitrios Damopoulos, Sofia-Anna Menesidou, Georgios Kambourakis, Maria Papadaki, Nathan L. Clarke, Stefanos Gritzalis
Secur. Commun. Networks4
2010 Online addiction: privacy risks in online gaming environments
abstract
In this paper we investigated the levels of addiction and personal data disclosure within Massively Multiplayer Online Role Playing Game environments (MMORPG's). The study made use of an online survey which embraced a combination of a six point behavioural addiction framework, Self Determination Theory and Impression Management theory to assess addictive behaviour and consequential data disclosure amongst a sample representative of 188 Singaporean based MMORPG gamers. Results found that pathological gaming addiction had a direct effect on levels of personal and sensitive data disclosure and participants who were disclosing high amounts of data were considered more vulnerable to exploitation and predation.
Benjamin George Sanders, Vivian Chen, Daniel Zahra, Paul Dowland 0001, Shirley Atkinson, Maria Papadaki, Steven Furnell
MEDES6
2010 Assessing the Usability of End-User Security Software
Tarik Ibrahim, Steven Furnell, Maria Papadaki, Nathan L. Clarke
TrustBus3
2010 A preliminary two-stage alarm correlation and filtering system using SOM neural network and K-means algorithm
Gina C. Tjhai, Steven Furnell, Maria Papadaki, Nathan L. Clarke
Comput. Secur.3
2009 Social engineering: assessing vulnerabilities in practice
abstract
Purpose The purpose of this paper is to investigate the level of susceptibility to social engineering amongst staff within a cooperating organisation. Design/methodology/approach An e‐mail‐based experiment was conducted, in which 152 staff members were sent a message asking them to follow a link to an external web site and install a claimed software update. The message utilised a number of social engineering techniques, but was also designed to convey signs of a deception in order to alert security‐aware users. The external web site, to which the link was pointing, was intentionally badly designed in the hope of raising the users' suspicions and preventing them from proceeding with the software installation. Findings In spite of a short window of operation for the experiment, the results revealed that 23 per‐cent of recipients were fooled by the attack, suggesting that many users lack a baseline level of security awareness that is useful to protect them online. Research limitations/implications After running for approximately 3.5 h, the experiment was ceased, after a request from the organisation's IT department. Thus, the correct percentage of unique visits is likely to have been higher. Also, the mailings were sent towards the end of a working day, thus limiting the number of people who got to read and respond to the message before the experiment was ended. Practical implications Despite its limitations, the experiment clearly revealed a significant level of vulnerability to social engineering attacks. As a consequence, the need to raise user awareness of social engineering and the related techniques is crucial. Originality/value This paper provides further evidence of users' susceptibility to the problems, by presenting the results of an e‐mail‐based social engineering study that was conducted amongst staff within a cooperating organisation.
Taimur Bakhshi, Maria Papadaki, Steven Furnell
Inf. Manag. Comput. Secur.2
2008 Investigating the problem of IDS false alarms: An experimental study using Snort
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke
SEC2
2008 The Problem of False Alarms: Evaluation with Snort and DARPA 1999 Dataset
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke
TrustBus2
2006 Achieving automated intrusion response: a prototype implementation
abstract
Purpose The increasing speed and volume of attacks against networked systems highlights the need to automate the intrusion response process. This paper proposes a means by which such automation may be achieved, and presents details of a practical implementation. Design/methodology/approach The paper outlines the architecture of a flexible and intelligent automated response system that is able to adapt response decisions according to the context in which a detected incident has occurred. The discussion presents details of a prototype implementation that has been used to evaluate the concept in practice, and demonstrates the feasibility of assessing contextual factors associated with detected incidents. Findings A series of worked examples are presented to show how the same incident occurring in different contexts will trigger different decisions from the response system. Originality/value The paper contributes towards the domain of intrusion response, and proposes an approach that would enable automation of the response process to be more acceptable to security administrators.
Maria Papadaki, Steven Furnell
Inf. Manag. Comput. Secur.1
2005 Informing the decision process in an automated intrusion response system
Maria Papadaki, Steven Furnell
Inf. Secur. Tech. Rep.1
2002 Keystroke Analysis as a Method of Advanced User Authentication and Response
Paul Dowland 0001, Steven Furnell, Maria Papadaki
SEC3
2002 An experimental comparison of secret-based user authentication technologies
abstract
The paper presents a comparative study of software‐based user authentication techniques, contrasting the use of traditional password and personal identifier numbers (PIN) against alternative methods involving question and answer responses and graphical representation. All methods share the common basis of some secret knowledge and rely upon the user’s ability to recall it in order to achieve authentication. An experimental trial is described, along with the results based upon 27 participants. The alternative methods are assessed in terms of practical effectiveness (in this context relating to the participant’s ability to authenticate themselves a significant time after initial use of the methods), as well as the perceived levels of user friendliness and security that they provide. The investigation concludes that while passwords and PIN approaches garner good ratings on the basis of their existing familiarity to the participants, other methods based upon image recall and cognitive questions also achieved sufficiently positive results to suggest them as viable alternatives in certain contexts.
I. Irakleous, Steven Furnell, Paul Dowland 0001, Maria Papadaki
Inf. Manag. Comput. Secur.4