VLDB 2026 Research / reviewers in the wild / expert
Nathan L. Clarke
dblp:77/1987 · also Nathan Luke Clarke
· DBLP profile ↗
68ranked-venue papers
10as first author
11since 2021 · last 2025
0000-0002-3595-3800ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 48 · 10 first-author · 5 since 2021Artificial intelligence and machine learning · 5 · 5 since 2021Computer networks · 3Applied, interdisciplinary, general and emerging computing · 2 · 1 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Real-world continuous smartwatch-based user authenticationabstractAbstract User authentication is often regarded as the “gatekeeper” of cyber security. It has, however, long suffered from significant usability issues that have resulted in research focussing upon frictionless and transparent biometric approaches. Activity-based user authentication—a technique that authenticates a user by what they are physically doing at a specific point in time has attracted significant attention, particularly due to the increasing popularity of smartwatches. This research aims to overcome limitations in prior work by exploring the viability of the approach in real-world conditions. The study presents two principal experiments, one focused upon a constrained environment to provide a control and a second reflecting real-life. With over 1000 h of sampled data across 60 participants, the study sought to explore sensor, feature composition, and classifier design to explore the practical viability of the approach. Whilst the control experiment achieved best case Equal Error Rate of 0.29%, an improvement upon the prior art using optimisation, the best-case real-world results were not too far behind at 0.7%. This demonstrates that whilst the feature generated in the real-life experiment are subject to increased levels of noise, the performance is viable within the context of a transparent and continuous user authentication approach. Neamah Al-Naffakh, Nathan L. Clarke, Fudong Li 0001, Paul Dowland 0001 |
Comput. J. | 2 |
| 2024 | Explainable Object Classification: Integrating Object Parts/Attributes and ExpertiseabstractWhile AI's accuracy is impressive, it often operates opaquely, leaving users puzzled by its decisions. Explainable AI (XAI) seeks to demystify these processes, yet it encounters usability hurdles, often favouring developers over end-users. This paper introduces EXPERT-DUO, a flexible framework for Explainable Object Classification. While demonstrated in the domain of surgical tool classification, EXPERT-DUO is a versatile system applicable across domains. Operating as an assistant system for the users, the framework accommodates varying levels of domain knowledge and provides understandable decisions through a hierarchical methodology. The framework pipeline starts by segmenting the object parts, recognizing and classifying the object parts that make up the main object, progresses to attribute classification, and culminates in the classification of the complete object using an expert decision tree that encodes the domain knowledge. EXPERT-DUO aims to assist users by offering transparent and understandable reasoning for the object classifications. This unique approach enables users to make rational and informed judgments regarding their trust in the model's decisions. Experimental results within the surgical context demonstrate the effectiveness of the approach. These results underscore EXPERT-DUO's potential to enhance user confidence in AI systems across a spectrum of domains, thereby facilitating more widespread adoption and utilization of AI technologies. Jan Stodt, Christoph Reich, Martin Knahl, Nathan L. Clarke |
ICTAI | 4 |
| 2024 | Exploring the Efficacy and Limitations of Histogram-Based Fake Image DetectionabstractGenerative image models pose challenges to image authenticity and trustworthiness, blurring the line between real and fake content. This paper addresses these concerns by proposing a histogram-based approach using pre-trained models (vgg16, ResNet50, Xception) to train classification networks for distinguishing real from generated images. Leveraging histograms derived from images, the method aims to accurately classify images as authentic or synthetic. Through experiments, the paper examines the effectiveness of the approach in mitigating the risks associated with fake contents widespread dissemination. Results demonstrate promising advancements in detecting image manipulation and preserving the integrity of visual information amidst the spread of generative models. Using pre-trained models the paper shows high classification accuracy for detecting fake images. Dirk Hölscher, Christoph Reich, Frank Gut, Martin Knahl, Nathan L. Clarke |
KES | 5 |
| 2024 | Editorial: Human aspects of cyber securityabstractHuman aspects are now widely recognised as being a key factor in providing a holistic cyber security solution. The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals. What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area. In July 2023, the 17th event in the series was held in Canterbury, UK. A total of 37 reviewed papers were presented over three days. From these, eight authors were invited to submit extended versions of their work for publication in this special issue. The resulting papers draw upon a range of areas including social engineering, cyber security culture, information security policies and the issue of cyber security awareness.In the first of the studies, Ahmad et al. explores the increasing problem of phishing via mobile instant messaging. Capitalising on the lack of technical safeguards, this attack vector is becoming increasingly popular. The study examines 67 examples of instant message phishing and explores the persuasion techniques attackers utilise.Three of the studies focused explore user behaviour and workload. Wright et al. focussed upon the preventive measures taken by employees towards cybercrime. Drawing upon over 200 participants during the pandemic, the study explored the Theory of Interpersonal Behaviour to demonstrate a strong correlation between the intent to engage in cybercrime preventative behaviour and actual practice. Whitty et al. developed a framework for focussing upon the social-technical variables that impact insider-based intellectual property theft. Drawing upon Situational Crime Prevention Theory, the model offers up novel opportunities to assist policymakers in preventing these types of attack. Reeves et al. explored the workload impact on the cybersecurity workforce. Utilising the Maslach Burnout Inventory (MBI), a survey of 119 cyber security professionals show that gender and job role are significant predictors of emotional exhaustion, with all roles tending to score higher on the MBI when compared to the Australian national population.Information security policies are key instruments used by organisations to define what the organisation wishes to achieve. Two of the papers explored the utility of these policies in practice. Rostami and Karlsson analysed the usefulness of information security policies with respect to the degree to which the policy could easily be actioned in practice. An examination of 15 policies from a range of Swedish public agencies found that just a third of the policies provide over 50% of actionable advice, with two-thirds of policies containing ambiguous advice that employees can use. Gerdin et al. investigated compliance and information security policies. Focussing upon employee compliance/non-compliance they study presents the findings of 17 in-depth interviews to explore the discrepancies between what is claimed to be measured versus what is actually measured and what respondents’ interpretations are.The final two papers focus upon cyber security awareness and preparedness. Stavrou and Piki present the importance of self-efficacy in education to foster professional development in cyber security. Using a skills-first approach, the study presents a novel curriculum design to actively nurture self-efficacy and promote improving attitudes towards upskilling in cyber security. Hedberg et al. undertake a study to explore the readiness of auto workshops in managing and responding to such attacks. Modern cars are increasingly smarter and more connected, thereby becoming a potential target for cybercriminals. Based upon a study of eight auto workshops in Sweden, it was found that there was currently limited capability, awareness and knowledge to deal with such issues.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 1 |
| 2023 | A Novel Metric for XAI Evaluation Incorporating Pixel Analysis and Distance MeasurementabstractExplainable Artificial Intelligence (XAI) seeks to enhance transparency and trust in AI systems. Evaluating the quality of XAI explanation methods remains challenging due to limitations in existing metrics. To address these issues, we propose a novel metric called Explanation Significance Assessment (ESA) and its extension, the Weighted Explanation Significance Assessment (WESA). These metrics offer a comprehensive evaluation of XAI explanations, considering spatial precision, focus overlap, and relevance accuracy. In this paper, we demonstrate the applicability of ESA and WESA on medical data. These metrics quantify the understandability and reliability of XAI explanations, assisting practitioners in interpreting AI-based decisions and promoting informed choices in critical domains like healthcare. Moreover, ESA and WESA can play a crucial role in AI certification, ensuring both accuracy and explainability. By evaluating the performance of XAI methods and underlying AI models, these metrics contribute to trustworthy AI systems. Incorporating ESA and WESA in AI certification efforts advances the field of XAI and bridges the gap between accuracy and interpretability. In summary, ESA and WESA provide comprehensive metrics to evaluate XAI explanations, benefiting research, critical domains, and AI certification, thereby enabling trustworthy and interpretable AI systems. Jan Stodt, Christoph Reich, Nathan L. Clarke |
ICTAI | 3 |
| 2023 | Pix2Pix Hyperparameter Optimisation PredictionabstractHyperparameter tuning is an important aspect in machine-learning especially for deep generative models.Tuning models to stabilize training and to get the best accuracy can be a time consuming and protracted process.Generative models have a large search space requiring resources and knowledge to find the best parameters.Therefore, in most cases the search space is reduced and parameters are limited to a selected few to save time and computation time.This paper explores three different strategies to predict high impact hyperparameters for Pix2Pix.The achieved results show, that binary classification and regression achieve good results and reliably predict good hyperparameter combinations. Dirk Hölscher, Christoph Reich, Frank Gut, Martin Knahl, Nathan L. Clarke |
KES | 5 |
| 2023 | Editorial: Human aspects of cyber securityabstractHuman aspects are now widely recognized as being a key factor in providing a holistic cyber security solution. The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human–computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals. What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area. In July 2022, the 16th event in the series was held in Lesvos, Greece. A total of 25 reviewed papers were presented over three days. From these, seven authors were invited to submit extended versions of their work for publication in this special issue. The resulting papers draw upon a range of areas including cyber security culture, information security management, security fatigue and the issue of privacy from a number of different perspectives.Privacy is a topic that has seen increased interest from the research community in recent years. Three of the selected papers have focused upon this. Lindqvist and Kävrestad explored the degree to which privacy concerns are impacting citizens’ willingness to report crimes. Following widely reported news articles raising the concern, this paper surveys 400 Swedish adults to seek their perspectives. Interestingly, whilst the willingness to share a mobile phone was low, a direct link to privacy was not established. Shanley et al. explored another aspect of privacy; that of Australian attitudes towards surveillance and the impact of COVID tracing applications. A survey of over 900 Australian adults showed a relatively high level of trust in government; however, they remain cautious and concerned over data being collected and had a strong desire to maintain control over their personal privacy. The final privacy-related paper by Chhetri and Motti sought to explore the development of privacy controls for Smart Homes. Using a mixed-methods approach, they undertook a series of evaluations for a novel prototype that helped to address the privacy gap.A further three papers focused upon culture, management and policy-related issues. Da Veiga explores the use of innovation and creativity as enablers to develop information security culture. Through a literature review, the paper identifies a set of elements that help to stimulate creativity and innovation. Rostami et al. present a conceptual model for tailoring information security policies with a view to acting as a foundation for developing software to aid the automated development and tailoring of policies for organisations. Bhana and Ophoff further explore the issue of security fatigue of data specialists. Through a semi-structured interview of stakeholders, they reveal several interlinked themes that evidence security fatigue.The final paper in the selection, from Glas et al., is focused upon security education and awareness – in particular the use of visual programming in cyber range training to improve skill development. Evaluated against a control group, the study found that visual training provided a positive impact on the learning experience.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 1 |
| 2022 | Surface Quality Augmentation for Metalworking Industry with Pix2PixabstractImage augmentation has become an important part of the data preprocessing pipeline, helping to acquire more samples by altering existing samples by cutting, shifting, etc.. For some domains, augmenting existing images is not sufficient, due to missing samples in the domains (e.g., faulty work pieces or events that occur infrequently). In such a case, new samples must be generated, since images with surface quality defects are often rare occurrence in metalworking and the amount of samples even with standard augmentation techniques does not meet requirements to train a Convolutional Neural Network (CNN) for fault detection. This paper utilizes Pix2Pix for image augmentation to generate new images with surface quality defects. The approach allows specifying the kind of defect, location, and size and transforms images by adding new defects. Furthermore, metrics to evaluate the augmented images are discussed and a recommendation of the best performing metric within the domain of metalworking is given. Dirk Hölscher, Christoph Reich, Martin Knahl, Frank Gut, Nathan L. Clarke |
KES | 5 |
| 2022 | Real-world smartphone-based gait recognitionabstractAs the smartphone and the services it provides are becoming targets of cybercrime, it is critical to secure smartphones. However, it is important security controls are designed to provide continuous and user-friendly security. Amongst the most important of these is user authentication, where users have experienced a significant rise in the need to authenticate to the device and individually to the numerous apps that it contains. Gait authentication has gained attention as a mean of non-intrusive or transparent authentication on mobile devices, capturing the information required to verify the authenticity of the user whilst the person is walking. Whilst prior research in this field has shown promise with good levels of recognition performance, the results are constrained by the gait datasets utilised being based upon highly controlled laboratory-based experiments which lack the variability of real-life environments. This paper introduces an advanced real-world smartphone-based gait recognition system that recognises the subject within real-world unconstrained environments. The proposed model is applied to the uncontrolled gait dataset, which consists of 44 users over a 7–10 day capture – where users were merely asked to go about their daily activities. No conditions, controls or expectations of particular activities were placed upon the participants. The experiment has modelled four types of motion normal walking, fast walking and down and upstairs for each of the users. The evaluation of the proposed model has achieved an equal error rate of 11.38%, 11.32%, 24.52%, 27.33% and 15.08% for the normal, fast, down and upstairs and all activities respectively. The results illustrate, within an appropriate framework, that gait recognition is a viable technique for real-world use. Hind Alobaidi, Nathan L. Clarke, Fudong Li 0001, Abdulrahman Alruban |
Comput. Secur. | 2 |
| 2021 | A novel approach for improving information security management and awareness for home environmentsabstractPurpose The human factor is a major consideration in securing systems. A wide and increasing range of different technologies, devices, platforms, applications and services are being used every day by home users. In parallel, home users are also experiencing a range of different online threats and attacks and are increasingly being targeted as they lack the knowledge and awareness about potential threats and how to protect themselves. The increase in technologies and platforms also increases the burden upon a user to understand how to apply security across differing technologies, operating systems and applications. This results in managing the security across their technology portfolio increasingly more troublesome and time consuming. This paper aims to propose an approach that attempts to propose a system for improving security management and awareness for home users. Design/methodology/approach The proposed system is capable of creating and assigning different security policies for different digital devices in a user-friendly fashion. These assigned policies are monitored, checked and managed to review the user’s compliance with the assigned policies to provide bespoke awareness content based on the user’s current needs. Findings A novel framework was proposed for improving information security management and awareness for home users. In addition, a mock-up design was developed to simulate the proposed approach to visualise the main concept and the functions which might be performed when it is deployed in a real environment. A number of different scenarios have been simulated to show how the system can manage and deal with different types of users, devices and threats. In addition, the proposed approach has been evaluated by experts in the research domain. The overall feedback is positive, constructive and encouraging. The experts agreed that the identified research problem is a real problem. In addition, they agreed that the proposed approach is usable, feasible and effective in improving security management and awareness for home users. Research limitations/implications The proposed design of the system is a mock-up design without real data. Therefore, implementing the proposed approach in a real environment can provide the researcher with a better understanding of the effectiveness and the functionality of the proposed approach. Practical implications This study offers a framework and usable mock-up design which can help in improving information security management for home users. Originality/value Improving the security management and awareness for home users by monitoring, checking and managing different security controls and configurations effectively are the key to strengthen information security. Therefore, when home users have a good level of security management and awareness, this could protect and secure the home network and subsequently business infrastructure and services as well. Fayez Alotaibi, Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 2 |
| 2021 | Incorporating the human facet of security in developing systems and servicesabstractPurpose The purpose of this paper is to present an integrative framework for handling the security and usability conflicts during the system development lifecycle. The framework has been formulated while considering key concerns raised after conducting a series of interviews with practitioners from the industry. The framework is aimed at assisting system designers and developers in making reasonably accurate choices when it comes to the trade-offs between security and usability. The outcomes of using the framework are documented as design patterns, which are disseminated among the community of system designers and developers for use in other but similar contexts. Design/methodology/approach A design science research approach was used to develop the integrative framework for usable security. Interviews were conducted for identification of the key concerns; however, the framework was validated during a workshop. Moreover, to validate the patterns’ template and the usable security pattern identified after instantiating the framework, a survey instrument was used. Findings It is important to consider the usability aspect in the development of security systems; otherwise, the systems, despite being secure against attacks, would be susceptible to user mistakes leading to compromises. It is worthwhile to handle usable security concerns right from the start of system development life cycle. Design patterns can help the developers in assessing the usability of their security options. Practical implications Practical implications The framework would assist the designers and developers in handling the security and usability conflicts right from the start of the system development life cycle. The patterns documented after using the framework would help not only the designers and developers working in the industry but also freelancers. Originality/value The authors present a novel framework to handle the security and usability conflicts during the system development life cycle. The development process of the framework was driven by the concerns raised after a series of interviews with the practitioners from industry. The framework presented in this paper was validated during a workshop in which it was exposed for review and comments by the participants from the industry. To demonstrate the use of patterns in general and the framework in particular, a case study featuring smart grids from the domain of cyber-physical systems is presented, which (to the best of the authors’ knowledge) features the first work relevant to usable security in the domain of cyber-physical systems. Bilal Naqvi, Nathan L. Clarke, Jari Porras |
Inf. Comput. Secur. | 2 |
| 2020 | Comparing the protection and use of online personal information in South Africa and the United Kingdom in line with data protection requirementsabstractPurpose The purpose of this study was to investigate the difference between South Africa (SA) and the United Kingdom (UK) in terms of data protection compliance with the aim to establish if a country that has had data protection in place for a longer period of time has a higher level of compliance with data protection requirements in comparison with a country that is preparing for compliance. Design/methodology/approach An insurance industry multi-case study within the online insurance services environment was conducted. Personal information of four newly created consumer profiles was deposited to 10 random insurance organisation websites in each country to evaluate a number of data privacy requirements of the Data Protection Act and Protection of Personal Information Act. Findings The results demonstrate that not all the insurance organisations honored the selected opt-out preference for receiving direct marketing material. This was evident in direct marketing material that was sent from the insurance organisations in the sample to both the SA and UK consumer profiles who opted out for it. A total of 42 unsolicited third-party contacts were received by the SA consumer profiles, whereas the UK consumer profiles did not receive any third-party direct marketing. It was also found that the minimality principle is not always met by both SA and UK organisations. Research limitations/implications As a jurisdiction with a heavy stance towards privacy implementation and regulation, it was found that the UK is more compliant than SA in terms of implementation of the evaluated data protection requirements included in the scope of this study, however not fully compliant. Originality/value Based upon the results obtained from this research, it suggests that the SA insurance organisations should ensure that the non-compliance aspects relating to direct marketing and sharing data with third parties are addressed. SA insurance companies should learn from the manner in which the UK insurance organisations implement these privacy requirements. Furthermore, the UK insurance organisations should focus on improved compliance for direct marking and the minimality principle. The study indicates the positive role that data protection legislation plays in a county like the UK, with a more mature stance toward compliance with data protection legislation. Adéle da Veiga, Ruthea Vorster, Fudong Li 0001, Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 4 |
| 2019 | Information Security Risk Communication: A User-Centric ApproachabstractUsers have difficulties in understanding and reacting to security-related threats. Moreover, users only try to protect themselves from risks salient to them. In contrast to the traditional one-message/one-size-fits-all approach when communicating risks, this paper aims to propose an individualized and persuasive approach to information security risk communication that goes beyond alerting the user of his insecure behavior to providing a level of security education. By focusing on the user and that different users react differently to the same stimuli, the authors proposed a targeted user-centric approach that communicates risks in a timely and continuous manner using a proposed gradual response mechanism. This user-centric approach is anticipated to help the user in making security-related decisions by educating him about his risk taking behavior in an individualized way. A scenario is assumed to demonstrate how a response decision is made within the proposed approach. This was useful in demonstrating how risk is not the same for all users and how the proposed approach is effective in adapting to differences between users offering a novel approach to communicating information security risks. Manal Abdullah Alohali, Nathan L. Clarke, Steven Furnell |
AICCSA | 2 |
| 2019 | Rule-based Security Monitoring of Containerized WorkloadsabstractIn order to further support the secure operation of containerized environments and to extend already established security measures, we propose a rule-based security monitoring, which can be used for the detection of a variety of misuse and attacks. The capabilities of the open-source tools used to monitor containers are closely examined and the possibility of detecting undesired behavior is evaluated on the basis of various scenarios. Further, the limits of the approach taken and the associated performance overhead will be discussed. The results show that the proposed approach is effective in many scenarios and comes at a low performance overhead cost. Holger Gantikow, Christoph Reich, Martin Knahl, Nathan L. Clarke |
CLOSER | 4 |
| 2019 | Privacy Enhancing Data Access Control for Ambient Assisted LivingabstractAs private data is key to applications in the field of Ambient Assisted Living, access control has to be in place to regulate data flows within the environment and to preserver the privacy of a user. We present a data access control system based on an easy to understand policy language with the ability to be extended by context information. Context information are enabling applications in the field of Ambient Assisted Living to adapt their behaviour to temporal, emergency or environmental conditions. The system is able to monitor and control data flows in OSGi environments by proxy services, without the need of modifying the core platform or the service logic of bundles. This is necessary to inform data subjects, to enable the data subject to control the environment and to enforce data access policies that are compatible with legal requirements. Hendrik Kuijs, Timo Bayer, Christoph Reich, Martin Knahl, Nathan L. Clarke |
CLOSER | 5 |
| 2019 | A Novel Behaviour Profiling Approach to Continuous Authentication for Mobile ApplicationsabstractThe growth in smartphone usage has led to increased user concerns regarding privacy and security. Smartphones contain sensitive information, such as personal data, images, and emails, and can be used to perform various types of activity, such as transferring money via mobile Internet banking, making calls and sending emails. As a consequence, concerns regarding smartphone security have been expressed and there is a need to devise new solutions to enhance the security of mobile applications, especially after initial access to a mobile device. This paper presents a novel behavioural profiling approach to user identity verification as part of mobile application security. A study involving data collected from 76 users over a 1-month period was conducted, generating over 3 million actions based on users' interactions with their smartphone. The study examines a novel user interaction approach based on supervised machine learning algorithms, thereby enabling a more reliable identity verification method. The experimental results show that users could be distinguished via their behavioural profiling upon each action within the application, with an average equal error rate of 26.98% and the gradient boosting classifier results prove quite compelling. Based on these findings, this approach is able to provide robust, continuous and transparent authentication. Saud Alotaibi, Abdulrahman Alruban, Steven Furnell, Nathan L. Clarke |
ICISSP | 4 |
| 2019 | Identification and Extraction of Digital Forensic Evidence from Multimedia Data Sources using Multi-algorithmic FusionabstractWith the enormous increase in the use and volume of photographs and videos, multimedia-based digital evidence has come to play an increasingly fundamental role in criminal investigations. However, given the increase in the volume of multimedia data, it is becoming time-consuming and costly for investigators to analyse the images manually. Therefore, a need exists for image analysis and retrieval techniques that are able to process, analyse and retrieve images efficiently and effectively. Outside of forensics, image annotation systems have become increasingly popular for a variety of purposes and major software/IT companies, such as Amazon, Microsoft and Google all have cloud-based image annotation systems. The paper presents a series of experiments that evaluate commercial annotation systems to determine their accuracy and ability to comprehensively annotate images within a forensic image analysis context (rather than simply single object imagery, which is typically the case). The paper further proposes and demonstrates the value of utilizing a multi-algorithmic approach via fusion to achieve the best results. The results of these experiments show that by existing systems the highest Average Recall was achieved by imagga with 53%, whilst the proposed multi-algorithmic system achieved 77% across the selected datasets. These results demonstrate the benefit of using a multi-algorithmic approach. Shahlaa Mashhadani, Nathan L. Clarke, Fudong Li 0001 |
ICISSP | 2 |
| 2019 | Physical Activity Recognition by Utilising Smartphone Sensor SignalsabstractHuman physical motion activity identification has many potential applications in various fields, such as medical diagnosis, military sensing, sports analysis, and human-computer security interaction. With the recent advances in smartphones and wearable technologies, it has become common for such devices to have embedded motion sensors that are able to sense even small body movements. This study collected human activity data from 60 participants across two different days for a total of six activities recorded by gyroscope and accelerometer sensors in a modern smartphone. The paper investigates to what extent different activities can be identified by utilising machine learning algorithms using approaches such as majority algorithmic voting. More analyses are also provided that reveal which time and frequency domain-based features were best able to identify individuals’ motion activity types. Overall, the proposed approach achieved a classification accuracy of 98% in identifying four different activities: walking, walking upstairs, walking downstairs, and sitting (on a chair) while the subject is calm and doing a typical desk-based activity. Abdulrahman Alruban, Hind Alobaidi, Nathan L. Clarke, Fudong Li 0001 |
ICPRAM | 3 |
| 2019 | A framework for reporting and dealing with end-user security policy complianceabstractPurpose It is widely acknowledged that non-compliance of employees with information security polices is one of the major challenges facing organisations. This paper aims to propose a model that is intended to provide a comprehensive framework for raising the level of compliance amongst end-users, with the aim of monitoring, measuring and responding to users’ behaviour with an information security policy. Design/methodology/approach The proposed model is based on two main concepts: a taxonomy of the response strategy to non-compliant behaviour and a compliance points system. The response taxonomy comprises two categories: awareness raising and enforcement of the security policy. The compliance points system is used to reward compliant behaviour and penalise non-compliant behaviour. Findings A prototype system has been developed to simulate the proposed model and work as a real system that responds to the behaviour of users (reflecting both violations and compliance behaviour). In addition, the model has been evaluated by interviewing experts from academic and industry. They considered the proposed model to offers a novel approach for managing end users’ behaviour with the information security policies. Research limitations/implications Psychological factors were out of the research scope at this stage. The proposed model may have some psychological impacts upon users; therefore, this issue needs to be considered by studying the potential impacts and the best solutions. Originality/value Users being compliant with the information security policies of their organisation is the key to strengthen information security. Therefore, when employees have a good level of compliance with security policies, this positively affects the overall security of an organisation. Mutlaq Jalimid Alotaibi, Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 3 |
| 2019 | A proactive malicious software identification approach for digital forensic examiners
Muhammad Ali 0002, Stavros Shiaeles, Nathan L. Clarke, Dimitrios Kontogeorgis |
J. Inf. Secur. Appl. | 3 |
| 2018 | Evidence Identification in Heterogeneous Data Using ClusteringabstractDigital forensics faces several challenges in examining and analyzing data due to an increasing range of technologies at people's disposal. The investigators find themselves having to process and analyze many systems manually (e.g. PC, laptop, Smartphone) in a single case. Unfortunately, current tools such as FTK and Encase have a limited ability to achieve the automation in finding evidence. As a result, a heavy burden is placed on the investigator to both find and analyze evidential artifacts in a heterogenous environment. This paper proposed a clustering approach based on Fuzzy C-Means (FCM) and K-means algorithms to identify the evidential files and isolate the non-related files based on their metadata. A series of experiments using heterogenous real-life forensic cases are conducted to evaluate the approach. Within each case, various types of metadata categories were created based on file systems and applications. The results showed that the clustering based on file systems gave the best results of grouping the evidential artifacts within only five clusters. The proportion across the five clusters was 100% using small configurations of both FCM and K-means with less than 16% of the non-evidential artifacts across all cases -- representing a reduction in having to analyze 84% of the benign files. In terms of the applications, the proportion of evidence was more than 97%, but the proportion of benign files was also relatively high based upon small configurations. However, with a large configuration, the proportion of benign files became very low less than 10%. Successfully prioritizing large proportions of evidence and reducing the volume of benign files to be analyzed, reduces the time taken and cognitive load upon the investigator. Hussam Jasim Mohammed, Nathan L. Clarke, Fudong Li 0001 |
ARES | 2 |
| 2018 | Biometrically Linking Document Leakage to the Individuals Responsible
Abdulrahman Alruban, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
TrustBus | 2 |
| 2018 | Identifying and predicting the factors affecting end-users' risk-taking behaviorabstractPurpose The end-user has frequently been identified as the weakest link; however, motivated by the fact that different users react differently to the same stimuli, identifying the reasons behind variations in security behavior and why certain users could be “at risk” more than others is a step toward protecting and defending users against security attacks. This paper aims to explore the effect of personality trait variations (through the Big Five Inventory [BFI]) on users’ risk level of their intended security behaviors. In addition, age, gender, service usage and information technology (IT) proficiency are analyzed to identify what role and impact they have on behavior. Design/methodology/approach The authors developed a quantitative-oriented survey that was implemented online. The bi-variate Pearson two-tailed correlation was used to analyze survey responses. Findings The results obtained by analyzing 538 survey responses suggest that personality traits do play a significant role in affecting users’ security behavior risk levels. Furthermore, the results suggest that BFI score of a trait has a significant effect as users’ online personality is linked to their offline personality, especially in the conscientiousness personality trait. Additionally, this effect was stronger when personality was correlated with the factors of IT proficiency, gender, age and online activity. Originality/value The contributions of this paper are two-fold. First, with the aid of a large population sample, end-users’ security practice is assessed from multiple domains, and relationships were found between end-users’ risk-taking behavior and nine user-centric factors. Second, based upon these findings, the predictive ability for these user-centric factors were evaluated to determine the level of risk a user is subject to from an individual behavior perspective. Of 28 behaviors, 11 were found to have a 60 per cent or greater predictive ability, with the highest classification of 92 per cent for several behaviors. This provides a basis for organizations to use behavioral intent alongside personality traits and demographics to understand and, therefore, manage the human aspects of risk. Manal Abdullah Alohali, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
Inf. Comput. Secur. | 2 |
| 2018 | Guest editorialabstractHuman aspects of cyber security Human aspects are now widely recognized as being a key factor in providing a holistic cyber security solution.The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and humancomputer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals.What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area.In November 2017, the 11th event in the series was held in Adelaide, Australia.A total of 25 reviewed papers were presented over three days.From these, seven authors were invited to submit extended versions of their work for publication in this special issue.The resulting papers are mainly focused upon the key issues of awareness and risk, alongside one further paper looking at the impact upon cyber analysts themselves.Five of the papers explore aspects of user behavior with respect to information security practice (or more particularly, intent).Specifically, Jansen and Van Schaik investigate the role fear plays in ensuring compliance to phishing by using protection motivation theory.The study involved surveying over 1,000 people to understand to what degree fear would play a role in how users respond to phishing attacks.McCormac et al. focus upon how understanding the relationship between resilience and work stress impacted information security awareness.Snyman et al. present a study exploring how users' information security decisions or practice is impacted by the decisions made by others.Their study introduces the concept of the "lemmings effect" and demonstrates by experimentation that it exists within information security behaviors.Alohali et al. present a study exploring the factors that affect the end-user risk-taking behavior, focusing upon a range of factors such as personality, age, education and information technology proficiency to understand which ones may have a statistically strong correlation to risk-making decisions.The survey was completed by over 500 participants, and it was found that personality, in particular conscientiousness, does play a role in a large number of risk-taking decisions.In the fifth paper, Ashenden seeks to explore social acceptability bias in information security research.Using personal construct psychology and repertory grids, the study demonstrated that employees who thought that the organization was driven by the need to protect information also thought that the risks were overstated, and their colleagues were overly cautious.The remaining two papers focused upon different areas of the human aspects theme: the first on measuring privacy perceptions and the second on gamification of security education.Da Veiga proposes an information privacy culture index framework to measure privacy perceptions across nations.Applied in a South African context, the paper reveals that South Africans have a high expectation of privacy yet feel that organizations are failing to meet both expectations and regulation.The final paper, by Micallef and Arachchilage, seeks to investigate the value gamification can have within security education.This study found that rewards within games do help to motivate users to have a better learning experience; however, social interactions within games Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 2 |
| 2017 | Insider Misuse Attribution using BiometricsabstractInsider misuse has become a major risk for many organizations. One of the most common forms of misuses is data leakage. Such threats have turned into a real challenge to overcome and mitigate. Whilst prevention is important, incidents will inevitably occur and as such attribution of the leakage is key to ensuring appropriate recourse. Although digital forensics capability has grown rapidly in the process of analyzing the digital evidences, a key barrier is often being able to associate the evidence back to an individual who leaked the data. Stolen credentials and the Trojan defense are two commonly cited arguments used to complicate the issue of attribution. Furthermore, the use of a digital certificate or user ID would only associate to the account not to the individual. This paper proposes a more proactive model whereby a user's biometric information is transparently captured (during normal interactions) and embedding within the digital objects they interact with (thereby providing a direct link between the last user using any document or object). An investigation into the possibility of embedding individuals' biometric signals into image files is presented, with a particular focus upon the ability to recover the biometric information under varying degrees of modification attack. The experimental results show that even when the watermarked object is significantly modified (e.g. only 25% of the image is available) it is still possible to recover those embedded biometric information. Abdulrahman Alruban, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
ARES | 2 |
| 2017 | A novel privacy preserving user identification approach for network trafficabstractThe prevalence of the Internet and cloud-based applications, alongside the technological evolution of smartphones, tablets and smartwatches, has resulted in users relying upon network connectivity more than ever before. This results in an increasingly voluminous footprint with respect to the network traffic that is created as a consequence. For network forensic examiners, this traffic represents a vital source of independent evidence in an environment where anti-forensics is increasingly challenging the validity of computer-based forensics. Performing network forensics today largely focuses upon an analysis based upon the Internet Protocol (IP) address – as this is the only characteristic available. More typically, however, investigators are not actually interested in the IP address but rather the associated user (whose account might have been compromised). However, given the range of devices (e.g., laptop, mobile, and tablet) that a user might be using and the widespread use of DHCP, IP is not a reliable and consistent means of understanding the traffic from a user. This paper presents a novel approach to the identification of users from network traffic using only the meta-data of the traffic (i.e. rather than payload) and the creation of application-level user interactions, which are proven to provide a far richer discriminatory feature set to enable more reliable identity verification. A study involving data collected from 46 users over a two-month period generated over 112 GBs of meta-data traffic was undertaken to examine the novel user-interaction based feature extraction algorithm. On an individual application basis, the approach can achieve recognition rates of 90%, with some users experiencing recognition performance of 100%. The consequence of this recognition is an enormous reduction in the volume of traffic an investigator has to analyse, allowing them to focus upon a particular suspect or enabling them to disregard traffic and focus upon what is left. Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
Comput. Secur. | 1 |
| 2016 | A Forensic Acquisition and Analysis System for IaaS: Architectural Model and ExperimentabstractCloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital forensic investigators, nor comply with today's digital forensics procedures - largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet forensically sound manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a forensic acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a forensically sound and timely manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system. Saad Alqahtany, Nathan L. Clarke, Steven Furnell, Christoph Reich |
ARES | 2 |
| 2016 | A Scalable Architecture for Distributed OSGi in the CloudabstractElasticity is one of the essential characteristics for cloud computing. The presented use case is a Software as
a Service for Ambient Assisted Living that is configurable and extensible by the user. By adding or deleting
functionality to the application, the environment has to support the increase or decrease of computational
demand by scaling. This is achieved by customizing the auto scaling components of a PaaS management
platform and introducing new components to scale a distributed OSGi environment across virtual machines.
We present different scaling and load balancing scenarios to show the mechanics of the involved components. Hendrik Kuijs, Christoph Reich, Martin Knahl, Nathan L. Clarke |
CLOSER (2) | 4 |
| 2016 | Evidence Collection in Cloud Provider ChainsabstractWith the increasing importance of cloud computing, compliance concerns get into the focus of businesses
more often. Furthermore, businesses still consider security and privacy related issues to be the most prominent
inhibitors for an even more widespread adoption of cloud computing services. Several frameworks try to address
these concerns by building comprehensive guidelines for security controls for the use of cloud services.
However, assurance of the correct and effective implementation of such controls is required by businesses
to attenuate the loss of control that is inherently associated with using cloud services. Giving this kind of
assurance is traditionally the task of audits and certification. Cloud auditing becomes increasingly challenging
for the auditor the more complex the cloud service provision chain becomes. There are many examples
for Software as a Service (SaaS) providers that do not own dedicated hardware anymore for operating their
services, but rely solely on other cloud providers of the lower layers, such as platform as a service (PaaS)
or infrastructure as a service (IaaS) providers. The collection of data (evidence) for the assessment of policy
compliance during a technical audit is aggravated the more complex the combination of cloud providers becomes.
Nevertheless, the collection at all participating providers is required to assess policy compliance in the
whole chain. The main contribution of this paper is an analysis of potential ways of collecting evidence in an
automated way across cloud provider boundaries to facilitate cloud audits. Furthermore, a way of integrating
the most suitable approaches in the system for automated evidence collection and auditing is proposed. Thomas Rübsamen, Christoph Reich, Nathan L. Clarke, Martin Knahl |
CLOSER (1) | 3 |
| 2016 | Guest editorialabstractHuman aspects of cyber securityHuman aspects are now widely recognized as being a key factor in providing a holistic cyber security solution.The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human-computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals.What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area.In July 2015, the ninth event in the series was held in Mytilene in Lesvos, Greece.A total of 25 reviewed papers were presented over three days.From these, seven authors were invited to submit extended versions of their work for publication in this special issue.The resulting papers are mainly focused upon the key issues of awareness and risk, alongside one further paper looking at the impact upon cyber analysts themselves.Four of the papers explore aspects of the information security awareness and education domain.Specifically, Da Veiga focuses upon investigating the impact that an information security policy has upon employees through an experimental approach involving 2,000 participants.Meanwhile, Kelley and Bertenthal undertook a study to explore the factors that affect user decision making (focusing specifically on logins to insecure websites), highlighting that attention and past behavior are strong indicators more so than security knowledge.Reid and Van Niekerk present a study into the impact of awareness campaigns using a South African school as a baseline measure.The final awareness paper, from Pattinson et al., seeks to determine the extent to which attitude data could be elicited from the repertory grid technique.The two risk-related papers seek to better understand the role that people play within the process.Sommestad et al. present an empirical study of the relationship between risk and the constituents of severity and probability.Meanwhile, Alavi et al. present a risk-driven investment model for analyzing human factors.The final paper takes a different perspective and focuses upon security analysts themselves.In recognition of human error, the study seeks to investigate the factors that affect improvement in analyst's performance, which in turn is intended to lead to better security as a result.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 2 |
| 2015 | Security, Privacy and Usability - A Survey of Users' Perceptions and Attitudes
Abdulwahid Al Abdulwahid, Nathan L. Clarke, Ingo Stengel, Steven Furnell, Christoph Reich |
TrustBus | 2 |
| 2015 | Continuous user authentication using multi-modal biometrics
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell, Valerio Biscione |
Comput. Secur. | 2 |
| 2015 | Language-independent gender identification through keystroke analysisabstractPurpose – The purpose of this paper is to investigate the feasibility of identifying the gender of an author by measuring the keystroke duration when typing a message. Design/methodology/approach – Three classifiers were constructed and tested. The authors empirically evaluated the effectiveness of the classifiers by using empirical data. The authors used primary data as well as a publicly available dataset containing keystrokes from a different language to validate the language independence assumption. Findings – The results of this paper indicate that it is possible to identify the gender of an author by analyzing keystroke durations with a probability of success in the region of 70 per cent. Research limitations/implications – The proposed approach was validated with a limited number of participants and languages, yet the statistical tests show the significance of the results. However, this approach will be further tested with other languages. Practical implications – Having the ability to identify the gender of an author of a certain piece of text has value in digital forensics, as the proposed method will be a source of circumstantial evidence for “putting fingers on keyboard” and for arbitrating cases where the true origin of a message needs to be identified. Social implications – If the proposed method is included as part of a text-composing system (such as e-mail, and instant messaging applications), it could increase trust toward the applications that use it and may also work as a deterrent for crimes involving forgery. Originality/value – The proposed approach combines and adapts techniques from the domains of biometric authentication and data classification. Ioannis Tsimperidis, Vasilios Katos, Nathan L. Clarke |
Inf. Comput. Secur. | 3 |
| 2014 | Cloud QoS Scaling by Fuzzy LogicabstractOne of the biggest advantages of cloud infrastructures is the elasticity. Cloud services are monitored and based on the resource utilization and performance load, they get scaled up or down, by provision or de-provision of cloud resources. The goal is to guarantee the customers an acceptable performance with a minimum of resources. Such Quality of Service (QoS) characteristics are stated in a contract, called Service Level Agreement (SLA) negotiated between customer and provider. The approach of this paper shows that with additional imprecise information (e.g. expected daytime/week- time performance) modeled with fuzzy logic and used in a behavior, load and performance prediction model, the up and down scaling mechanism of a cloud service can be optimized. Evaluation results confirm, that using this approach, SLA violation can be minimized. Stefan Frey, Claudia Lüthje, Christoph Reich, Nathan L. Clarke |
IC2E | 4 |
| 2014 | Performance-driven evaluation for deploying IMS-based interoperability scenariosabstractThis paper deals with the performance evaluation of deploying an IMS-based media plane interoperability framework. The 3GPP standards describe two possible operating modes based on either a reactive or a proactive approach. We show that both approaches entail some advantages and drawbacks in terms of signaling overhead and call setup times at different ratios of incompatible calls. A prototype implementation of the required elements was carried out in order to use experimental delay contributions. Additionally, the evaluation focuses on the impact of deploying the interoperability solutions over current UMTS and LTE radio access networks. Jose Oscar Fajardo, Fidel Liberal, Fudong Li 0001, Nathan L. Clarke, Is-Haka Mkwawa, Lingfen Sun |
ICC | 4 |
| 2014 | Text-Based Active Authentication for Mobile Devices
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell, Valerio Biscione |
SEC | 2 |
| 2014 | Performance evaluation of a Technology Independent Security Gateway for Next Generation NetworksabstractWith the all IP based Next Generation Networks being deployed around the world, the use of real-time multimedia service applications is being extended from normal daily communications to emergency situations. However, currently different emergency providers utilise differing networks and different technologies. As such, conversations could be terminated at the setup phase or data could be transmitted in plaintext should incompatibility issues exit between terminals. To this end, a novel security gateway that can provide the necessary security support for incompatible terminals was proposed, developed and implemented to ensure the successful establishment of secure real-time multimedia conversations. A series of experiments were conducted to evaluate the security gateway through the use 40 Boghe softphone acting as the terminals. The experimental results demonstrate that the best performance of the prototype was achieved by utilising a multithreading and multi-buffering technique, with an average of 582 microseconds processing overhead. Based upon the ITU-Ts 150 milliseconds one way delay recommendation for voice communications, it is envisaged that such a marginal overhead will not be noticed by users in practice. Fudong Li 0001, Nathan L. Clarke, Steven Furnell, Is-Haka Mkwawa |
WiMob | 2 |
| 2014 | A response selection model for intrusion response systems: Response Strategy Model (RSM)abstractABSTRACT Intrusion response systems aim to provide a systematic procedure to respond to incidents. However, with different type of response options, an automatic response system is designed to select appropriate response options automatically in order to act fast to respond to only true and critical incidents as well as minimise their impact. In addition, incidents also can be prioritised into different level of priority where some incidents may cause a serious impact (i.e. high priority) and other may not (i.e. low priority). The existing strategies inherit some limitation such as using complex approaches and less efficient in mapping appropriate response based upon incidents' priority. Therefore, this study introduces a model called response strategy model to address the aforementioned limitation. In order to validate, it was evaluated using two datasets: DARPA 2000 and private dataset. The case study results have shown a significant relationship between the incident classification and incident priorities where false incidents are likely to be categorised as low priority and true incidents are likely to be categorised as the high priority. In particular, with response strategy model, an average of 92.68% of the false incidents was prioritised as the lowest priority is better compared with only 67.07% with Snort priority. Copyright © 2013 John Wiley & Sons, Ltd. Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
Secur. Commun. Networks | 4 |
| 2013 | Anomaly Detection in IaaS CloudsabstractSecurity is still a major concern in Cloud computing, especially the detection of nefarious use or abuse of cloud instances. One reason for this, is the ever-growing complexity and dynamic of the underlying system design and architecture. To be able to detect misuse of cloud instances, this work presents an anomaly detection system for Infrastructure as a Service Clouds. It is based on Cloud customers' usage behaviour analysis. Neural networks are used to analyse and learn the normal usage behaviour of Cloud customers, to then detect anomalies which could originate from a cloud security incident caused by an overtaken virtual machine. It increases transparency for Cloud customers about the security of their Cloud instances and supports the Cloud provider to detect misuse of their infrastructure. A simulation environment and an anomaly detection prototype get presented. Experiments validate the effectiveness of the proposed system. Frank Dölitzscher, Martin Knahl, Christoph Reich, Nathan L. Clarke |
CloudCom (1) | 4 |
| 2013 | A Technology Independent Security Gateway for Real-Time Multimedia Communication
Fudong Li 0001, Nathan L. Clarke, Steven Furnell |
NSS | 2 |
| 2013 | Co-operative user identity verification using an Authentication Aura
Chris G. Hocking, Steven Furnell, Nathan L. Clarke, Paul L. Reynolds |
Comput. Secur. | 3 |
| 2013 | Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)abstractABSTRACT The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top‐priority incidents. Copyright © 2012 John Wiley & Sons, Ltd. Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
Secur. Commun. Networks | 4 |
| 2012 | A Response Strategy Model for Intrusion Response Systems
Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
SEC | 4 |
| 2012 | Multi-modal Behavioural Biometric Authentication for Mobile Devices
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell |
SEC | 2 |
| 2012 | Validating Cloud Infrastructure Changes by Cloud AuditsabstractOne characteristic of a cloud computing infrastructure are their frequently changing virtual infrastructure. New Virtual Machines (VMs) get deployed, existing VMs migrate to a different host or network segment and VMs vanish since they get deleted by their user. Classic incidence monitoring mechanisms are not flexible enough to cope with cloud specific characteristics such as frequent infrastructure changes. In this paper we present a prototype demonstration of the Security Audit as a Service (SAaaS) architecture, a cloud audit system which aims to increase trust in cloud infrastructures by introducing more transparency to user and cloud provider on what is happening in the cloud. Especially in the event of a changing infrastructure the demonstration shows, how autonomous agents detect this change, automatically reevaluate the security status of the cloud and inform the user through an audit report. Frank Dölitzscher, Denis Moskal, Christoph Reich, Martin Knahl, Nathan L. Clarke |
SERVICES | 6 |
| 2012 | Power to the people? The evolving recognition of human aspects of security
Steven Furnell, Nathan L. Clarke |
Comput. Secur. | 2 |
| 2012 | Evaluation of anomaly-based IDS for mobile devices using machine learning classifiersabstractABSTRACT Mobile devices have evolved and experienced an immense popularity over the last few years. This growth however has exposed mobile devices to an increasing number of security threats. Despite the variety of peripheral protection mechanisms described in the literature, authentication and access control cannot provide integral protection against intrusions. Thus, a need for more intelligent and sophisticated security controls such as intrusion detection systems (IDSs) is necessary. Whilst much work has been devoted to mobile device IDSs, research on anomaly‐based or behaviour‐based IDS for such devices has been limited leaving several problems unsolved. Motivated by this fact, in this paper, we focus on anomaly‐based IDS for modern mobile devices. A dataset consisting of iPhone users data logs has been created, and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. Specifically, the experimental procedure includes and cross‐evaluates four machine learning algorithms (i.e. Bayesian networks, radial basis function,K‐nearest neighbours and random Forest), which classify the behaviour of the end‐user in terms of telephone calls, SMS and Web browsing history. In order to detect illegitimate use of service by a potential malware or a thief, the experimental procedure examines the aforementioned services independently as well as in combination in a multimodal fashion. The results are very promising showing the ability of at least one classifier to detect intrusions with a high true positive rate of 99.8%. Copyright © 2011 John Wiley & Sons, Ltd. Dimitrios Damopoulos, Sofia-Anna Menesidou, Georgios Kambourakis, Maria Papadaki, Nathan L. Clarke, Stefanos Gritzalis |
Secur. Commun. Networks | 5 |
| 2011 | An Autonomous Agent Based Incident Detection System for Cloud EnvironmentsabstractClassic intrusion detection mechanisms are not flexible enough to cope with cloud specific characteristics such as frequent infrastructure changes. This makes them unable to address new cloud specific security issues. In this paper we introduce the cloud incident detection system Security Audit as a Service (SAaaS). It is build upon intelligent autonomous agents, which are aware of underlying business flows of deployed cloud instances. Business flows are modelled in form of Security Service Level Agreements, which enable the SAaaS architecture to be flexible and to supported cross customer event monitoring of a cloud infrastructure. As contribution of this paper we provide a high-level design of the SAaaS architecture, an introduction into the concept of Security Service Level Agreements, a first prototype of an autonomous agent and an evaluation about, which cloud specific security problems are addressed by the presented architecture. Frank Dölitzscher, Christoph Reich, Martin Knahl, Nathan L. Clarke |
CloudCom | 4 |
| 2011 | SMS linguistic profiling authentication on mobile deviceabstractIt is commonly acknowledged that mobile devices now form an integral part of an individual's everyday life. As the amount of valuable and sensitive information stored on a mobile device increases, so does the need for effective security. In order to protect unauthorised access, an authentication system is required. Biometric authentication has proven to be a more reliable solution than knowledge based and token based techniques. Indeed, biometric techniques are uniquely individual, impossible to forget or lose, difficult to reproduce or falsify and difficult to change or hide. Despite the well known advantages of biometric authentication approaches, the majority of current state-of-the-art mobile devices embrace point of entry authentication systems including PIN/passwords and one time fingerprint verification. This paper introduces a feasibility study into a novel biometric technique for mobile devices, linguistic profiling. This investigation sought to authenticate users based on their writing vocabulary and style of SMS messages. The findings, based upon 30 participants, revealed the feasibility of the approach. While an overall average Equal Error Rate (EER) of 24% is unacceptably high, several users experienced an EER of 0%, suggesting significant potential to apply the technique for a subset of the population. Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell |
NSS | 2 |
| 2011 | Risk Assessment for Mobile Devices
Thomas Lederm, Nathan L. Clarke |
TrustBus | 2 |
| 2010 | An Analysis of Information Security Awareness within Home and Work EnvironmentsabstractAs technology such as the Internet, computers and mobile devices become ubiquitous throughout society, the need to ensure our information remains secure is imperative. Unfortunately, it has long been understood that good security cannot be achieved through technical means alone and a solid understanding of the issues and how to protect yourself is required from users. Whilst many initiatives, programs and strategies have been proposed to improve the level of information security awareness, most have been directed at organizations, with a few national programs focused upon home users. Given people's use of technology is primarily focused upon those two areas: the workplace and home, this paper seeks to understand the knowledge and practice relationship between these environments. Through the survey that was developed, it was identified that the majority of the learning about information security occurred in the workplace, where clear motivations, such as legislation and regulation, existed. It was also found that user's were more than willing to engage with such awareness raising initiatives. From a comparison of practice between work and home environments, it was found that this knowledge and practice obtained at the workplace was transferred to the home environment. Given this positive transferability of knowledge and the willingness to learn about how to remain secure, an opportunity exists to move away from specific organizational awareness programs and to move towards awareness raising strategies that, whilst deployed in the organization, will develop an all-round individual security culture for users independent of the environment within which they are operating. Shuhaili Talib, Nathan L. Clarke, Steven Furnell |
ARES | 2 |
| 2010 | A distributed and cooperative user authentication frameworkabstractAs the requirement for companies and individuals to protect information and personal details comes more into focus, the implementation of security that goes beyond the ubiquitous password or Personal Identification Number (PIN) is paramount. With the ever growing number of us utilizing more than one device simultaneously, the problem and need is compounded. This paper proposes a novel approach to security that leverages the collective confidence of user identity held by the multiplicity of devices present at any given time. User identity confidence is reinforced by sharing established credentials between devices, enabling them to make informed judgments on their own security position. An Adaptive Security Control Engine (ASCE) is outlined, illustrating how an environment sensitive and adaptive security envelope can be established and maintained around an individual. Chris G. Hocking, Steven Furnell, Nathan L. Clarke, Paul L. Reynolds |
IAS | 3 |
| 2010 | Assessing the Usability of End-User Security Software
Tarik Ibrahim, Steven Furnell, Maria Papadaki, Nathan L. Clarke |
TrustBus | 4 |
| 2010 | A preliminary two-stage alarm correlation and filtering system using SOM neural network and K-means algorithm
Gina C. Tjhai, Steven Furnell, Maria Papadaki, Nathan L. Clarke |
Comput. Secur. | 4 |
| 2009 | Flexible and Transparent User Authentication for Mobile Devices
Nathan L. Clarke, Sevasti Karatzouni, Steven Furnell |
SEC | 1 |
| 2009 | From desktop to mobile: Examining the security experience
Reinhardt A. Botha, Steven Furnell, Nathan L. Clarke |
Comput. Secur. | 3 |
| 2008 | Investigating the problem of IDS false alarms: An experimental study using Snort
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
SEC | 4 |
| 2008 | The Problem of False Alarms: Evaluation with Snort and DARPA 1999 Dataset
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
TrustBus | 4 |
| 2008 | Friend-assisted intrusion detection and response mechanisms for mobile ad hoc networks
Shukor Abd Razak, Steven Furnell, Nathan L. Clarke, Phillip J. Brooke |
Ad Hoc Networks | 3 |
| 2007 | Keystroke Analysis for Thumb-based Keyboards on Mobile Devices
Sevasti Karatzouni, Nathan L. Clarke |
SEC | 2 |
| 2007 | Advanced user authentication for mobile devices
Nathan L. Clarke, Steven Furnell |
Comput. Secur. | 1 |
| 2007 | The application of signature recognition to transparent handwriting verification for mobile devicesabstractPurpose The popularity of mobile devices and the evolving nature of the services and information they can delivery make them increasingly desirable targets for misuse. The ability to provide effective authentication of the user becomes imperative if protection against misuse of personally and financially sensitive information is to be provided. This paper discusses the application of biometrics to a mobile device in a transparent and continuous fashion and the subsequent advantages and disadvantages that are in contention with various biometric techniques. Design/methodology/approach An investigation was conducted to evaluate the feasibility of utilising signature recognition, to verify users based upon written words and not signatures, thereby enabling transparent handwriting verification. Participants were required to write a number of common words, such as “hello” “sorry” and “thank you”. The ability to correctly verify against their own template and to reject impostors was then established. Findings Totally, 20 users participated in the study and an average FAR and FRR of 0 and 1.2 per cent, respectively, were experienced across eight common words. Research limitations/implications The initial study has proven very successful, however, further investigations need to be established with a larger population of users and a wider vocabulary of words. Originality/value This study has verified the feasibility of applying an existing signature recognition technique to transparent handwriting verification. Nathan L. Clarke, A. R. Mekala |
Inf. Manag. Comput. Secur. | 1 |
| 2006 | A Two-Tier Intrusion Detection System for Mobile Ad Hoc Networks - A Friend Approach
Shukor Abd Razak, Steven Furnell, Nathan L. Clarke, Phillip J. Brooke |
ISI | 3 |
| 2005 | Authentication of users on mobile telephones - A survey of attitudes and practices
Nathan L. Clarke, Steven Furnell |
Comput. Secur. | 1 |
| 2003 | Using Keystroke Analysis as a Mechanism for Subscriber Authentication on Mobile Handsets
Nathan L. Clarke, Steven Furnell, Benn Lines, Paul L. Reynolds |
SEC | 1 |
| 2003 | Keystroke dynamics on a mobile handset: a feasibility studyabstractThe ability of third generation telephones to store sensitive information, such as financial records, digital certificates and company records, makes them desirable targets for impostors. This paper details the feasibility of a non‐intrusive subscriber authentication technique – the use of keystroke dynamics. This feasibility study comprises a number of investigations into the ability of neural networks to authenticate users successfully based on their interactions with a mobile phone keypad. The initial results are promising with network classification performing well, achieving a 9.8 per cent false rejection rate and an 11.0 per cent false acceptance rate. Nathan L. Clarke, Steven Furnell, Benn Lines, Paul L. Reynolds |
Inf. Manag. Comput. Secur. | 1 |
| 2002 | Acceptance of Subscriber Authentication Methods For Mobile Telephony Devices
Nathan L. Clarke, Steven Furnell, Philip M. Rodwell, Paul L. Reynolds |
Comput. Secur. | 1 |
| 1994 | Implementing Traffic ShapingabstractTraffic shaping is important in ATM networks, especially those that are interconnected or provide service guarantees. We examine what shaping may be considered ideal, and what is attainable under the constraints of transmission systems and cost. We justify the use of FCFS multiplexing of multiple single-stream shaper outputs as a performance reference for multi-stream shapers, but also point out some of its deficiencies. Shaper implementations in which transmissions are scheduled on cell arrivals, emissions, and transmissions are examined and compared both qualitatively and through simulation. We identify the problem of shaping cells that must conform to multiple traffic constraints (e.g. when the rate of a multicast connection must be adapted to suit multiple links) and examine implementations to achieve this. Shaping in which inevitable cell delay variation is intentionally distributed inequitably amongst connections (to assist CDV-intolerant connections) is also examined.> Tim Moors, Nathan L. Clarke, Guven Mercankosk |
LCN | 2 |