VLDB 2026 Research / reviewers in the wild / expert
Jassim Happa
dblp:92/1858
· DBLP profile ↗
8ranked-venue papers
2as first author
3since 2021 · last 2023
0000-0002-0860-5130ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 7 · 1 first-author · 3 since 2021Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2023 | Detecting CAN Attacks on J1939 and NMEA 2000 NetworksabstractJ1939 is a networking layer built on top of the widespread CAN bus used for communication between different subsystems within a vehicle. The J1939 and NMEA 2000 protocols standardize data enrichment for these subsystems, and are used for trucks, weapon systems, naval vessels, and other industrial systems. Practical security solutions for existing CAN based communication systems are notoriously difficult because of the lack of cryptographic capabilities of the devices involved. In this paper we propose a novel intrusion detection system (IDS) for J1939 and NMEA 2000 networks. Our IDS (CANDID) combines timing analysis with a packet manipulation detection system and data analysis. This data analysis enables us to capture the state of the vehicle, detect messages with irregular timing intervals, and take advantage of the dependencies between different Electronic Control Units (ECUs) to restrict even the most advanced attacker. Our IDS is deployed and tested on multiple vehicles, and has demonstrated greater accuracy and detection capabilities than previous work. Matthew Rogers, Phillip Weigand, Jassim Happa, Kasper Bonne Rasmussen |
IEEE Trans. Dependable Secur. Comput. | 3 |
| 2021 | A Novel Behavioural Screenlogger Detection System
Hugo Sbai, Jassim Happa, Michael Goldsmith |
ISC | 2 |
| 2021 | Sonification to Support the Monitoring Tasks of Security Operations CentresabstractSonification (the representation of data as sound) may offer a solution to some of the network-security monitoring challenges faced in security operations centres (SOCs). Prior work has shown that sonification can present network-security information to humans effectively, and indicated that security practitioners foresee potential for sonification to aid in scenarios related to their work. The use of sonification by security practitioners in tasks relevant to SOCs has not been examined, however. To address this gap, we assessed the use of sonification by security practitioners in network-security monitoring tasks in an experimental setting. We report on the results of a study in which we compared the performance of security practitioners using a Security Information and Event Management (SIEM) tool with their performance using a SIEM tool that incorporated sonification, in a primary and a non-primary monitoring task. In both tasks, a number of aspects of the monitoring performance of participants were significantly improved when sonification was used. Our results support the potential for sonification to aid in SOC tasks, and indicate a need to validate the utility of sonification systems by running them in operational SOCs. Louise Axon, Jassim Happa, Alastair Janse van Rensburg, Michael Goldsmith, Sadie Creese |
IEEE Trans. Dependable Secur. Comput. | 2 |
| 2020 | Dataset Construction and Analysis of Screenshot MalwareabstractAmong the various types of spyware, screenloggers are distinguished by their ability to capture screenshots. This gives them considerable nuisance capacity, giving rise to theft of sensitive data or, failing that, to serious invasions of the privacy of users. Several examples of attacks relying on this screen capture feature have been documented in recent years. However, there is not sufficient empirical and experimental evidence on this topic. Indeed, to the best of our knowledge, there is no dataset dedicated to screenshot-taking malware until today. The lack of datasets or common testbed platforms makes it difficult to analyse and study their behaviour in order to develop effective countermeasures. The screenshot feature is often a smart feature that does not activate automatically once the malware has infected the machine; the activation mechanisms of this function are often more complex. Consequently, a dataset which is completely dedicated to them would make it possible to better understand the subtleties of triggering screenshots and even to learn to distinguish them from the legitimate applications widely present on devices. The main purpose of this paper is to build such a dataset and analyse the behaviour of screenloggers. Hugo Sbai, Jassim Happa, Michael Goldsmith, Samy Meftali |
TrustCom | 2 |
| 2019 | Hearing attacks in network data: An effectiveness study
Louise Axon, Jassim Happa, Michael Goldsmith, Sadie Creese |
Comput. Secur. | 2 |
| 2018 | Insider-threat detection using Gaussian Mixture Models and Sensitivity Profiles
Kholood Al Tabash, Jassim Happa |
Comput. Secur. | 2 |
| 2016 | A Pragmatic System-failure Assessment and Response ModelabstractSeveral attack models exist today that attempt to describe cyber-attacks to varying degrees of granularity. Fast and effective decision-making during cyber-attacks is often vital, especially during incidents in which reputation, finance and physical damage can have a crippling effect on people and organisations. Such attacks can render an organisation paralysed, and it may cease to function, we refer to such an incident as a “System Failure”. In this paper we propose a novel conceptual model to help analysts make pragmatic decisions during a System Failure. Our model distils the essence of attacks and provides an easy-to-remember framework intended to help analysts ask relevant questions at the right time, irrespective of what data is available to them. Using abstraction-based reasoning our model allows enterprises to achieve “some” situational awareness during a System Failure, but more importantly, enable them to act upon their understanding and to justify their decisions. Abstraction drives the reasoning process making the approach relevant today and in the future, unlike several existing models that become deprecated over time (as attacks evolve). In the future, it will be necessary to trial the model in exercises to assess its value. Jassim Happa, Graham Fairclough, Jason R. C. Nurse, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
ICISSP | 1 |
| 2012 | Cultural Heritage Predictive RenderingabstractAbstract High‐fidelity rendering can be used to investigate Cultural Heritage (CH) sites in a scientifically rigorous manner. However, a high degree of realism in the reconstruction of a CH site can be misleading insofar as it can be seen to imply a high degree of certainty about the displayed scene—which is frequently not the case, especially when investigating the past. So far, little effort has gone into adapting and formulating a Predictive Rendering pipeline for CH research applications. In this paper, we first discuss the goals and the workflow of CH reconstructions in general, as well as those of traditional Predictive Rendering. Based on this, we then propose a research framework for CH research, which we refer to as ‘Cultural Heritage Predictive Rendering’ (CHPR). This is an extension to Predictive Rendering that introduces a temporal component and addresses uncertainty that is important for the scene’s historical interpretation. To demonstrate these concepts, two example case studies are detailed. Jassim Happa, Thomas Bashford-Rogers, Alexander Wilkie, Alessandro Artusi, Kurt Debattista, Alan Chalmers |
Comput. Graph. Forum | 1 |