EDBT 2026 Demo / reviewers in the wild / expert
William J. Buchanan
dblp:04/5266 · also Bill Buchanan 0001
· DBLP profile ↗
66ranked-venue papers
9as first author
27since 2021 · last 2026
0000-0003-0809-3523ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 31 · 3 first-author · 13 since 2021Applied, interdisciplinary, general and emerging computing · 10 · 4 first-authorComputer networks · 9 · 2 first-author · 5 since 2021Software engineering, systems software and programming languages · 5 · 2 since 2021Artificial intelligence and machine learning · 4 · 3 since 2021Systems, architecture and hardware · 2 · 1 since 2021Databases, data management, data science and information retrieval · 1Graphics, computer vision, multimedia, augmented reality and games · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Lightweight Online Meta-Learning for Intrusion Detection under Drift and Adversarial AttacksabstractIntrusion Detection Systems (IDS) are essential for securing modern communication networks but face challenges in handling concept drift, the evolving nature of traffic and threats, while resisting adversarial attacks. Conventional IDSs often require computationally expensive full retraining, which limits their real-time deployment in resource-constrained communication environments. This paper presents a meta-learning–driven adaptive IDS framework for attack detection and prevention in dynamic networked systems. The proposed design leverages First-Order Model-Agnostic Meta-Learning (FOMAML) to enable rapid online adaptation using a small memory buffer, eliminating the need for complete retraining. To strengthen resilience, adversarial robustness is enhanced by integrating Fast Gradient Sign Method (FGSM)-based adversarial training directly into the meta-adaptation loop. Furthermore, an adaptive controller utilizes rolling-window accuracy monitoring to trigger updates only when significant performance degradation is observed, minimizing computational overhead. Experiments on the IDSIoT2024 dataset demonstrate that the proposed framework maintains robust detection performance, sustaining an F1-score above 0.93 across varying drift severities and exhibiting rapid recovery under simultaneous multi-class drift and adversarial attack scenarios. Its compact model size of 102.40KB and fast adaptation time of 41.41ms confirm its suitability for real-time, resource-constrained communication scenarios, highlighting the potential of meta-learning for attack detection and prevention in next-generation communication systems. Zil e Huma, Sana Ullah Jan, William J. Buchanan |
ICC | 3 |
| 2026 | A Split-Trust Architecture for Confidential NLP Inference with CKKS EncryptionabstractÐThis paper presents a split-trust architecture for confidential natural language processing inference that secures preprocessing inside a Trusted Execution Environment and performs classification under CKKS homomorphic encryption. The design addresses the preprocessing exposure gap present in existing encrypted NLP systems, where tokenization and embedding are performed in plaintext prior to encryption. A linear Support Vector Machine is evaluated homomorphically using logarithmic slot-rotation optimization, enabling CPU-only inference without bootstrapping. On 10,000 IMDB test samples, encrypted inference achieves 89.65% accuracy and reproduces plaintext predictions exactly across all samples. Performance analysis across batch sizes of 500 to 2000 samples shows a minimum per-sample latency of 0.01297 seconds, with ciphertext expansion of approximately 1000× relative to plaintext features. Evaluation on SST-2, Movie Reviews, and Amazon Polarity confirms identical plaintext and encrypted predictions under distribution shift. The results demonstrate that confidential NLP inference is practical when secure preprocessing is combined with depth-aware homomorphic evaluation. Faneela, Baraq Ghaleb, Jawad Ahmad 0001, Ahmed Yassin Al-Dubai, William J. Buchanan, Sana Ullah Jan |
IWCMC | 5 |
| 2026 | Generative adversarial networks-enabled anomaly detection systems: A surveyabstractAnomaly Detection (AD) is an important area of research because it helps identify outliers in data, enabling early detection of errors, fraud, and potential security breaches. Machine Learning (ML) can be utilized for distinct AD systems, and Generative Adversarial Networks (GANs) have emerged as a promising technique due to their ability to generate new data that closely resembles a given dataset, allowing for the creation of realistic images, videos, audio, text, and other types of synthetic data. This paper explores state-of-the-art approaches in AD using GANs. The paper starts by providing a comprehensive overview of ML techniques for AD, including supervised, unsupervised, and semi-supervised approaches. This survey also explores various AD approaches based on GANs and provides an application-based classification of GANs-based AD approaches in the Internet-of-Things (IoT), Industrial IoT, Digital Healthcare, Energy Management Systems, and Cellular Network domains. Moreover, the paper discusses several datasets used in evaluating the performance of GANs-based AD techniques such as BOT-IoT, TON-IoT, CIC-IoT, CIC-IDS, and NSL-KDD. These datasets serve as valuable resources for researchers and practitioners to develop and test AD systems, particularly in the context of IoT and network security. Furthermore, the paper discusses the challenges and limitations of GANs-based AD techniques and proposes future research directions to address these challenges. Umer Saeed, Sana Ullah Jan, Jawad Ahmad 0001, Syed Aziz Shah, Mohammed S. Alshehri, Yazeed Ghadi, Nikolaos Pitropakis, William J. Buchanan |
Expert Syst. Appl. | 8 |
| 2025 | Resilience without AI: Assessing the Viability of Deception-Based Ransomware DetectionabstractFrom the first attack in 1989, to date, it is evident that ransomware is highly destructive. Today the vast majority of research on ransomware detection is focused on the use of AI techniques. While the use of these techniques is very effective, they should not be considered an infallible solution for ransomware detection. As with any solution, AI implementations do have shortcomings of their own; compute resource constraints, collation of training data, data poisoning, and data privacy, to name a few. This paper aims to identify whether traditional methods can still effectively detect ransomware in scenarios where AI solutions may not be viable. Typically, there are three main categories of detection; signature-based, behaviour-based, & deception-based. This paper focuses on deception-based detection, using honey files. Three detection solutions have been implemented on two isolated VMs, one running Windows 10, the other Linux Mint. The solutions include RansomwareLocker, for the Linux VM, R-Locker and 4663 Windows event monitoring on the Windows 10 VM. With these solutions implemented, ransomware samples were executed in turn, up to three times, allowing an initial ‘out of the box’ test run and two subsequent tests after necessary configuration changes were made. Overall, from the ransomware samples chosen and detection solutions implemented, deception-based detection proves to be a promising approach. Testing resulted in two of the three solutions ultimately achieving a 100% detection rate. However, throughout the experiment, it is evident that this approach is not a silver bullet, and very dependent on the configuration of the solutions. Therefore, whether AI-based or traditional, a defence-in-depth approach remains best. Liam Goddard, Muhammad Shahbaz Khan, Maha Driss, Baraq Ghaleb, Mouad Lemoudden, William J. Buchanan, Jawad Ahmad 0001 |
KES | 6 |
| 2025 | Enhancing IoT Security: A Meta-Learning Approach to Adversarial RobustnessabstractThe increasing connectivity of Internet of Things (IoT) devices and networks has significantly raised security concerns. Intrusion detection systems (IDSs) serve as a firstline defense mechanism to detect and identify various cyber threats. However, traditional IDSs frameworks come with their own challenges, such as high computational costs, limited generalization to evolving variants of cyberattacks, increasing complexity, and vulnerability to adversarial attacks. This paper proposes a meta-learning-based IDS framework using Model-Agnostic Meta-Learning (MAML) to particularly combat adversarial attacks in IoT networks. The designed architecture optimizes model initialization by performing inner-loop updates using adversarially perturbed data. It aggregates gradients from these adversarially adapted models in the outer loop to achieve a resilient initialization that generalizes well against adversarial attacks. The proposed approach is rigorously evaluated by training and testing the model on three major adversarial attacks: Fast Gradient Sign Method (FGSM), Projected Gradient Descent (PGD), and DeepFool. The experimental outcomes indicate the promising performance of the proposed architecture with an average attack detection accuracy of 95.97%. The compact model size of 0.06MB makes it suitable for deployment on resource-constrained IoT devices and networks. Furthermore, the lower inferencing time ensures the timely detection of intrusion, which is significant for real-time IDSs. Zil e Huma, Sana Ullah Jan, Jawad Ahmad 0001, William J. Buchanan, Nikolaos Pitropakis |
WiMob | 4 |
| 2025 | LEAGAN: A Decentralized Version-Control Framework for Upgradeable Smart ContractsabstractSmart contracts are integral to decentralized systems like blockchains and enable the automation of processes through programmable conditions. However, their immutability, once deployed, poses challenges when addressing errors or bugs. Existing solutions, such as proxy contracts, facilitate upgrades while preserving application integrity. Yet, proxy contracts bring issues such as storage constraints and proxy selector clashes - along with complex inheritance management. This paper introduces a novel upgradeable smart contract framework with version control, named ”decentraLized vErsion control and updAte manaGement in upgrAdeable smart coNtracts (LEAGAN).” LEAGAN is the first decentralized updatable smart contract framework that employs data separation with Incremental Hash (IH) and Revision Control System (RCS). It updates multiple contract versions without starting anew for each update, and reduces time complexity, and where RCS optimizes space utilization through differentiated version control. LEAGAN also introduces the first status contract in upgradeable smart contracts, and which reduces overhead while maintaining immutability. In Ethereum Virtual Machine (EVM) experiments, LEAGAN shows 40% better space utilization, 30% improved time complexity, and 25% lower gas consumption compared to state-of-the-art models. It thus stands as a promising solution for enhancing blockchain system efficiency. Gulshan Kumar, Rahul Saha, Mauro Conti, William J. Buchanan |
IEEE Trans. Serv. Comput. | 4 |
| 2024 | Privacy-Aware Single-Nucleotide Polymorphisms (SNPs) Using Bilinear Group Accumulators in Batch ModeabstractBiometric data is often highly sensitive, and a leak of this data can lead to serious privacy breaches. Some of the most sensitive of this type of data relates to the usage of DNA data on individuals. A leak of this type of data without consent could lead to privacy breaches of data protection laws. Along with this, there have been several recent data breaches related to the leak of DNA information, including from 23andMe and Ancestry. It is thus fundamental that a citizen should have the right to know if their DNA data is contained within a DNA database and ask for it to be removed if they are concerned about its usage. This paper outlines a method of hashing the core information contained within the data stores - known as Single-Nucleotide Polymorphisms (SNPs) - into a bilinear group accumulator in batch mode, which can then be searched by a trusted entity for matches. The time to create the witness proof and to verify were measured at 0.86~ms and 10.90~ms, respectively. William J. Buchanan, Sam Grierson, Daniel Uribe |
ICISSP | 1 |
| 2024 | A Novel Cosine-Modulated-Polynomial Chaotic Map to Strengthen Image Encryption Algorithms in IoT EnvironmentsabstractWith the widespread use of the Internet of Things (IoT), securing the storage and transmission of multimedia content across IoT devices is a critical concern. Chaos-based Pseudo-Random Number Generators (PRNGs) play an essential role in enhancing the security of image encryption algorithms. This paper introduces a novel 1-dimensional cosine-modulated-polynomial chaotic map to be used as a PRNG in image encryption algorithms. The proposed map utilizes a cosine function to modulate the outcome of a polynomial expression, resulting in complex chaotic behaviour. The designed map acts as a self-modulating system and offers a larger chaotic range, reduced structural complexity, and enhanced chaotic properties, such as aperiodicity, unpredictability, ergodicity, and sensitivity to control parameters and initial conditions, in comparison to the traditional 1-dimensional chaotic maps. An extensive evaluation is performed to gauge the chaotic behaviour of the proposed map, including bifurcation diagrams, chaotic trajectory analysis, fixed point and stability analysis, Lyapunov Exponent, Kolmogorov Entropy and NIST SP800-22 tests demonstrating its effectiveness to be used as a secure PRNG in image encryption algorithms. Muhammad Shahbaz Khan, Jawad Ahmad 0001, Ahmed Yassin Al-Dubai, Nikolaos Pitropakis, Maha Driss, William J. Buchanan |
KES | 6 |
| 2024 | Transforming EU Governance: The Digital Integration Through EBSI and GLASS
Dimitrios Kasimatis, William J. Buchanan, Mwrwan Abubakar, Owen Lo, Christos Chrysoulas, Nikolaos Pitropakis, Pavlos Papadopoulos, Sarwar Sayeed, Marc Sel |
SEC | 2 |
| 2024 | AI-Enhanced Digital Twin Framework for Cyber-Resilient 6G Internet of Vehicles NetworksabstractDigital twin technology is crucial to the development of the sixth-generation (6G) Internet of Vehicles (IoV) as it allows the monitoring and assessment of the dynamic and complicated vehicular environment. However, 6G IoV networks have critical challenges in network security and computational efficiency, which need to be addressed. Existing digital twin technologies in 6G IoV networks often suffer from limitations, such as reliance on static models and high computational demands, leading to unstable attack detection and inefficiencies. Their results for attack detection performance metrics, precision, detection rate, and F1-Score are insufficient for 6G IoV. Moreover, these systems concentrate all computational processes within the digital twin’s service layer, leading to inefficiencies. To address these challenges, we introduce a novel artificial intelligence (AI) enhanced digital twin framework designed to significantly improve 6G IoV network security and computational efficiency under dynamic conditions. Our framework employs an advanced feature engineering module that uses feature selection methods and stacked sparse autoencoders (ssAE) to reduce feature dimensions within the cyber twin layer, effectively distributing the overall computational load. It also utilizes an online learning module which enables a network-aware attack detection mechanism for precise attack detection. The proposed solution exhibits a stable performance of around 98% success rate regarding attack detection metrics against two data sets. Specifically, our solution reduces system latency by 12%, energy consumption by 15%, RAM usage by 20%, and improves packet delivery rates by 6.1%. These findings underscore the potential of our framework to enhance the robustness and responsiveness of 6G IoV systems, offering a significant contribution to vehicular network security and management. Yagmur Yigit, Leandros Maglaras, William J. Buchanan, Berk Canberk, Hyundong Shin, Trung Quang Duong |
IEEE Internet Things J. | 3 |
| 2024 | Application of Randomness for Security and Privacy in Multi-Party ComputationabstractA secure Multi-Party Computation (MPC) is one of the distributed computational methods, where it computes a function over the inputs given by more than one party jointly and keeps those inputs private from the parties involved in the process. Randomization in secret sharing leading to MPC is a requirement for privacy enhancements; however, most of the available MPC models use the trust assumptions of sharing and combining values. Thus, randomization in secret sharing and MPC modules is neglected. As a result, the available MPC models are prone to information leakage problems, where the models can reveal the partial values of the sharing secrets. In this paper, we propose the first model of utilizing a random function generator as an MPC primitive. More specifically, we analyze our previous development of the Symmetric Random Function Generator (SRFG) for information-theoretic security, where the system is considered to have unconditional security if it is secure against adversaries with unlimited computing resources and time. Further, we apply SRFG to eradicate the problem of information leakage in the general MPC model. Through a set of experiments, we show that SRFG is a function generator that can generate the combined functions (combination of logic GATEs) with$n/2$-private to$n$-private norms. As the main goal of MPC is privacy preservation of the inputs, we analyze the applicability of SRFG properties in secret sharing and MPC and observe that SRFG is eligible to be a cryptographic primitive in MPC developments. We also measure the performance of our proposed SRFG-based MPC framework with the other randomness generation-based MPC frameworks and analyze the comparative attributes with the state-of-the-art models. We observe that our posed SRFG-based MPC is$\approx$30% better in terms of throughput and also shows 100% privacy attainment. Rahul Saha, Gulshan Kumar, G. Geetha 0001, Mauro Conti, William J. Buchanan |
IEEE Trans. Dependable Secur. Comput. | 5 |
| 2023 | TRUSTEE: Towards the creation of secure, trustworthy and privacy-preserving frameworkabstractDigital transformation is a method where new technologies replace the old to meet essential organisational requirements and enhance the end-user experience. Technological transformation often improvises the manner in which a facility or resources are delivered to the recipient. Data is one of the key assets of every organisation which influences significantly reaching the long-term objective. Thus, the entities, as well as technologies involved in the data management process, have a significant role to play to secure different data types. However, the traditional data governance process often follows a centralised approach and thus resulting in various cyber attacks, whereas the distributed approaches are mostly research prototypes and often comprise various security challenges. Security incidents such as data theft fabricate the integrity of confidential data and thus the consequences are often disastrous. To address the challenges, we introduce TRUSTEE, a data-driven platform which aims to provide a secure and privacy-by-design framework to empower companies, organisations, and individuals to access different data domains, use and re-use the data and metadata to extract knowledge with trust and confidentiality. In this paper, we assess the effectiveness of the platform by reviewing the potential challenges and threats associated with the incorporated technologies. Our research emphasises the efficacy of distributed technologies to indicate their significance in data integrity and security. Sarwar Sayeed, Nikolaos Pitropakis, William J. Buchanan, Evangelos Markakis 0002, Dimitra Papatsaroucha, Ilias Politis |
ARES | 3 |
| 2023 | TouchEnc: a Novel Behavioural Encoding Technique to Enable Computer Vision for Continuous Smartphone User AuthenticationabstractWe are increasingly required to prove our identity when using smartphones through explicit authentication processes such as passwords or physiological biometrics, e.g., authorising online banking transactions or unlocking smartphones. However, these methods are often annoying to input and do not guarantee that the genuine user remains the same. Thus, a modern verification process should differ from traditional authentication. In touch-based biometrics, a new approach must not verify what we draw but how we draw it. Our research proposes TouchEnc, a Deep Learning approach that outperforms conventional methods. Unlike Machine Learning methods, TouchEnc automates the feature extraction from touch gestures. TouchEnc achieves this by transforming and encoding touch behaviour into images, enabling continuous authentication through modern computer vision. Our approach has been tested on a popular and publicly available dataset to demonstrate its effectiveness. Results show that users can authenticate using TouchEnc with a single gesture containing users’ on-screen navigational behaviour, independent of drawing up, down, left, or right. TouchEnc achieves an 8.4% Equal Error Rate and a 96.7% Area Under the Curve using a single gesture. Furthermore, TouchEnc achieves up to 65% better Equal Error Rates when combining gestures compared to the related work. Peter Aaby, Mario Valerio Giuffrida, William J. Buchanan, Zhiyuan Tan 0001 |
TrustCom | 3 |
| 2023 | CellSecure: Securing Image Data in Industrial Internet-of-Things via Cellular Automata and Chaos-Based EncryptionabstractIn the era of Industrial IoT (IIoT) and Industry 4.0, ensuring secure data transmission has become a critical concern. Among other data types, images are widely transmitted and utilized across various IIoT applications, ranging from sensor-generated visual data and real-time remote monitoring to quality control in production lines. The encryption of these images is essential for maintaining operational integrity, data confidentiality, and seamless integration with analytics platforms. This paper addresses these critical concerns by proposing a robust image encryption algorithm tailored for IIoT and Cyber-Physical Systems (CPS). The algorithm combines Rule-30 cellular automata with chaotic scrambling and substitution. The Rule 30 cellular automata serves as an efficient mechanism for generating pseudo-random sequences that enable fast encryption and decryption cycles suitable for realtime sensor data in industrial settings. Most importantly, it induces non-linearity in the encryption algorithm. Furthermore, to increase the chaotic range and keyspace of the algorithm, which is vital for security in distributed industrial networks, a hybrid chaotic map, i.e., logistic-sine map is utilized. Extensive security analysis has been carried out to validate the efficacy of the proposed algorithm. Results indicate that our algorithm achieves close-to-ideal values, with an entropy of 7.99 and a correlation of 0.002. This enhances the algorithm's resilience against potential cyber-attacks in the industrial domain. Muhammad Shahbaz Khan, Maha Driss, Jawad Ahmad 0001, William J. Buchanan, Nikolaos Pitropakis |
VTC Fall | 5 |
| 2023 | An omnidirectional approach to touch-based continuous authenticationabstractThis paper focuses on how touch interactions on smartphones can provide a continuous user authentication service through behaviour captured by a touchscreen. While efforts are made to advance touch-based behavioural authentication, researchers often focus on gathering data, tuning classifiers, and enhancing performance by evaluating touch interactions in a sequence rather than independently. However, such systems only work by providing data representing distinct behavioural traits. The typical approach separates behaviour into touch directions and creates multiple user profiles. This work presents an omnidirectional approach which outperforms the traditional method independent of the touch direction - depending on optimal behavioural features and a balanced training set. Thus, we evaluate five behavioural feature sets using the conventional approach against our direction-agnostic method while testing several classifiers, including an Extra-Tree and Gradient Boosting Classifier, which is often overlooked. Results show that in comparison with the traditional, an Extra-Trees classifier and the proposed approach are superior when combining strokes. However, the performance depends on the applied feature set. We find that the TouchAlytics feature set outperforms others when using our approach when combining three or more strokes. Finally, we highlight the importance of reporting the mean area under the curve and equal error rate for single-stroke performance and varying the sequence of strokes separately. Peter Aaby, Mario Valerio Giuffrida, William J. Buchanan, Zhiyuan Tan 0001 |
Comput. Secur. | 3 |
| 2023 | A DNA Based Colour Image Encryption Scheme Using A Convolutional AutoencoderabstractWith the advancement in technology, digital images can easily be transmitted and stored over the Internet. Encryption is used to avoid illegal interception of digital images. Encrypting large-sized colour images in their original dimension generally results in low encryption/decryption speed along with exerting a burden on the limited bandwidth of the transmission channel. To address the aforementioned issues, a new encryption scheme for colour images employing convolutional autoencoder, DNA and chaos is presented in this paper. The proposed scheme has two main modules, the dimensionality conversion module using the proposed convolutional autoencoder, and the encryption/decryption module using DNA and chaos. The dimension of the input colour image is first reduced from N × M × 3 to P × Q gray-scale image using the encoder. Encryption and decryption are then performed in the reduced dimension space. The decrypted gray-scale image is upsampled to obtain the original colour image having dimension N × M × 3 . The training and validation accuracy of the proposed autoencoder is 97% and 95%, respectively. Once the autoencoder is trained, it can be used to reduce and subsequently increase the dimension of any arbitrary input colour image. The efficacy of the designed autoencoder has been demonstrated by the successful reconstruction of the compressed image into the original colour image with negligible perceptual distortion. The second major contribution presented in this paper is an image encryption scheme using DNA along with multiple chaotic sequences and substitution boxes. The security of the proposed image encryption algorithm has been gauged using several evaluation parameters, such as histogram of the cipher image, entropy, NPCR, UACI, key sensitivity, contrast, and so on. The experimental results of the proposed scheme demonstrate its effectiveness to perform colour image encryption. Fawad Ahmed, Muneeb Ur Rehman, Jawad Ahmad 0001, Muhammad Shahbaz Khan, Wadii Boulila, Gautam Srivastava 0001, Jerry Chun-Wei Lin, William J. Buchanan |
ACM Trans. Multim. Comput. Commun. Appl. | 8 |
| 2023 | A Blockchain Framework in Post-Quantum DecentralizationabstractThe decentralization and transparency have provided wide acceptance of blockchain technology in various sectors through numerous applications. The claimed security services by blockchain have been proved using various cryptographic techniques, mainly public key infrastructure and digital signatures. However, the use of generic cryptographic primitives using large prime numbers or elliptic curves with logarithms is going to be an issue with quantum computers as those techniques are vulnerable in post-quantum era. Therefore, the paradigm shift from pre-quantum to the post-quantum era has necessitated new cryptographic developments which are robust against quantum attacks and applicable in blockchain for post-quantum decentralization. Therefore, we have presented a solution for post-quantum decentralization in the blockchain. It uses lattices with polynomials for identity-based encryption (IBE) and aggregate signatures for the consensus to ensure efficiency and suitability in post-quantum blockchain applications. We experiment the proposed approach based on delay, throughput, energy consumption and complexity. The comparative results prove that the presented work is efficient. Rahul Saha, Gulshan Kumar, Tannishtha Devgun, William J. Buchanan, Reji Thomas, Mamoun Alazab, Tai-Hoon Kim, Joel J. P. C. Rodrigues |
IEEE Trans. Serv. Comput. | 4 |
| 2022 | Post Quantum Cryptography Analysis of TLS Tunneling on a Constrained DeviceabstractAdvances in quantum computing make Shor’s algorithm for factorising numbers ever more tractable. This threatens the security of any cryptographic system which often relies on the difficulty of factorisation. It also threatens methods based on discrete logarithms, such as with the Diffie-Hellman key exchange method. For a cryptographic system to remain secure against a quantum adversary, we need to build methods based on a hard mathematical problem, which are not susceptible to Shor’s algorithm and create Post Quantum Cryptography (PQC). While high-powered computing devices may be able to run these new methods, we need to investigate how well these methods run on limited powered devices. This paper outlines an evaluation framework for PQC within constrained devices, and contributes to the area by providing benchmarks of the front-running algorithms on a popular single-board low-power device. It also introduces a set of five notions which can be considered to determine the robustness of particular algorithms. Jon Barton, William J. Buchanan, Nikolaos Pitropakis, Sarwar Sayeed, Will Abramson |
ICISSP | 2 |
| 2022 | A comprehensive survey of authentication methods in Internet-of-Things and its conjunctions
Rahul Saha, Mauro Conti, Gulshan Kumar, William J. Buchanan, Tai-Hoon Kim |
J. Netw. Comput. Appl. | 5 |
| 2021 | PAN-DOMAIN: Privacy-preserving Sharing and Auditing of Infection Identifier MatchingabstractThe spread of COVID-19 has highlighted the need for a robust contact tracing infrastructure that enables infected individuals to have their contacts traced, and followed up with a test. The key entities involved within a contact tracing infrastructure may include the Citizen, a Testing Centre (TC), a Health Authority (HA), and a Government Authority (GA). Typically, these different domains need to communicate with each other about an individual. A common approach is when a citizen discloses his personally identifiable information to both the HA a TC, if the test result comes positive, the information is used by the TC to alert the HA. Along with this, there can be other trusted entities that have other key elements of data related to the citizen. However, the existing approaches comprise severe flaws in terms of privacy and security. Additionally, the aforementioned approaches are not transparent and often being questioned for the efficacy of the implementations. In order to overcome the challenges, this paper outlines the PAN-DOMAIN infrastructure that allows for citizen identifiers to be matched amongst the TA, the HA and the GA. PAN-DOMAIN ensures that the citizen can keep control of the mapping between the trusted entities using a trusted converter, and has access to an audit log. Will Abramson, William J. Buchanan, Sarwar Sayeed, Nikolaos Pitropakis, Owen Lo |
SIN | 2 |
| 2021 | Blockchain-based Platform for Secure Sharing and Validation of Vaccination CertificatesabstractThe COVID-19 pandemic has recently emerged as a worldwide health emergency that necessitates coordinated international measures. To contain the virus's spread, governments and health organisations raced to develop vaccines that would lower Covid-19 morbidity, relieve pressure on healthcare systems, and allow economies to open. Following the COVID-19 vaccine, the vaccination certificate has been adopted to help the authorities formulate policies by controlling cross-border travelling. To address serious privacy concerns and eliminate the need for third parties to retain the trust and govern user data, in this paper, we leverage blockchain technologies in developing a secure and verifiable vaccination certificate. Our approach has the advantage of utilising a hybrid approach that implements different advanced technologies, such as the self-sovereignty concept, smart contracts and interPlanetary File System (IPFS). We rely on verifiable credentials paired with smart contracts to make decisions about who can access the system and provide on-chain verification and validation of the user and issuer DIDs. The approach was further analysed, with a focus on performance and security. Our analysis shows that our solution satisfies the security requirements for immunisation certificates. Mwrwan Abubakar, Pádraig McCarron, Zakwan Jaroucheh, Ahmed Yassin Al-Dubai, William J. Buchanan |
SIN | 5 |
| 2021 | Privacy-preserving and Trusted Threat Intelligence Sharing using Distributed LedgersabstractThreat information sharing is considered as one of the proactive defensive approaches for enhancing the over-all security of trusted partners. Trusted partner organizations can provide access to past and current cybersecurity threats for reducing the risk of a potential cyberattack—the requirements for threat information sharing range from simplistic sharing of documents to threat intelligence sharing. Therefore, the storage and sharing of highly sensitive threat information raises considerable concerns regarding constructing a secure, trusted threat information exchange infrastructure. Establishing a trusted ecosystem for threat sharing will promote the validity, security, anonymity, scalability, latency efficiency, and traceability of the stored information that protects it from unauthorized disclosure. This paper proposes a system that ensures the security principles mentioned above by utilizing a distributed ledger technology that provides secure decentralized operations through smart contracts and provides a privacy-preserving ecosystem for threat information storage and sharing regarding the MITRE ATT&CK framework. Hisham Ali, Pavlos Papadopoulos, Jawad Ahmad 0001, Nikolaos Pitropakis, Zakwan Jaroucheh, William J. Buchanan |
SIN | 6 |
| 2021 | Min-max Training: Adversarially Robust Learning Models for Network Intrusion Detection SystemsabstractIntrusion detection systems are integral to the security of networked systems for detecting malicious or anomalous network traffic. As traditional approaches are becoming less effective, machine learning and deep learning-based intrusion detection systems are vital research areas for improved detection systems. Past research into computer vision using deep learning revealed that the deep learning-based classifiers themselves are vulnerable to adversarial attacks, and these attacks have been investigated extensively. However, adversarial attacks are restricted not only to the domain of image recognition. As indicated by previous research, various domains employing machine learning/deep learning classifiers are vulnerable to attack. Our work evaluates the effectiveness of adversarial robustness training when applied to intrusion detection systems based on deep learning classification models. We propose a novel, simple adversarial retraining method to build models robust to adversarial evasion attacks. Sam Grierson, Craig Thomson, Pavlos Papadopoulos, William J. Buchanan |
SIN | 4 |
| 2021 | Launching Adversarial Label Contamination Attacks Against Malicious URL Detection
Bruno Marchand, Nikolaos Pitropakis, William J. Buchanan, Costas Lambrinoudakis |
TrustBus | 3 |
| 2021 | Differential area analysis for ransomware attack detection within mixed file datasets
Simon R. Davies, Richard Macfarlane, William J. Buchanan |
Comput. Secur. | 3 |
| 2021 | BeepTrace: Blockchain-Enabled Privacy-Preserving Contact Tracing for COVID-19 Pandemic and BeyondabstractThe outbreak of the coronavirus disease 2019 (COVID-19) pandemic has exposed an urgent need for effective contact tracing solutions through mobile phone applications to prevent the infection from spreading further. However, due to the nature of contact tracing, public concern on privacy issues has been a bottleneck to the existing solutions, which is significantly affecting the uptake of contact tracing applications across the globe. In this article, we present a blockchain-enabled privacy-preserving contact tracing scheme: BeepTrace, where we propose to adopt blockchain bridging the user/patient and the authorized solvers to desensitize the user ID and location information. Compared with recently proposed contact tracing solutions, our approach shows higher security and privacy with the additional advantages of being battery friendly and globally accessible. Results show viability in terms of the required resource at both server and mobile phone perspectives. Through breaking the privacy concerns of the public, the proposed BeepTrace solution can provide a timely framework for authorities, companies, software developers, and researchers to fast develop and deploy effective digital contact tracing applications, to conquer the COVID-19 pandemic soon. Meanwhile, the open initiative of BeepTrace allows worldwide collaborations, integrate existing tracing and positioning solutions with the help of blockchain technology. Hao Xu 0013, Lei Zhang 0035, Oluwakayode Onireti, William J. Buchanan, Muhammad Ali Imran 0001 |
IEEE Internet Things J. | 5 |
| 2021 | FPC-BI: Fast Probabilistic Consensus within Byzantine Infrastructures
Serguei Popov 0001, William J. Buchanan |
J. Parallel Distributed Comput. | 2 |
| 2020 | Recent Advances and Trends in Lightweight Cryptography for IoT SecurityabstractLightweight cryptography is a novel diversion from conventional cryptography to minimise its high level of resource requirements, thus it would impeccably fit in the internet-of-things (IoT) environment. The IoT platform is constrained in terms of physical size, internal capacity, other storage allocations like RAM/ROM and data rates. The devices are often battery powered, hence maintenance of the charged energy at least for a few years is essential. However, provision of sufficient security is challenging because the existing cryptographic methods are too heavy to adopt in the IoT. Consequently, an interest arose in the recent past to construct new cryptographic algorithms in a lightweight scale, but the attempts are still struggling to gain robustness against improved IoT threats and hazards.There exists a lack of literature studies to offer overall and up-to-date knowledge on lightweight cryptography. Therefore, this effort is to bridge the areas in the subject by summarising the content we explored during our complete survey recently. This work contains the development of lightweight cryptographic algorithms, its current advancements and futuristic enhancements. In contrast, this covers the history, parametric limitations of the invented methods, research progresses of cryptology as well as cryptanalysis. Nilupulee Anuradha Gunathilake, Ahmed Yassin Al-Dubai, William J. Buchanan |
CNSM | 3 |
| 2020 | TRUSTD: Combat Fake Content using Blockchain and Collective Signature TechnologiesabstractThe growing trend of sharing news/contents, through social media platforms and the World Wide Web has been seen to impact our perception of the truth, altering our views about politics, economics, relationships, needs and wants. This is because of the growing spread of misinformation and disinformation intentionally or unintentionally by individuals and organizations. This trend has grave political, social, ethical, and privacy implications for society due to 1) the rapid developments in the field of Machine Learning (ML) and Deep Learning (DL) algorithms in creating realistic-looking yet fake digital content (such as text, images, and videos), 2) the ability to customize the content feeds and to create a polarized so-called "filter-bubbles" leveraging the availability of the big-data. Therefore, there is an ethical need to combat the flow of fake content. This paper attempts to resolves some of the aspects of this combat by presenting a high-level overview of TRUSTD, a blockchain and collective signature based ecosystem to help content creators in getting their content backed by the community, and to help users judge on the credibility and correctness of these contents. Zakwan Jaroucheh, Mohamad Alissa, William J. Buchanan, Xiaodong Liu 0002 |
COMPSAC | 3 |
| 2020 | Privacy-preserving Surveillance Methods using Homomorphic EncryptionabstractData analysis and machine learning methods often involve the processing of cleartext data, and where this could breach the rights to privacy. Increasingly, we must use encryption to protect all states of the data: in-transit, at-rest, and in-memory. While tunnelling and symmetric key encryption are often used to protect data in-transit and at-rest, our major challenge is to protect data within memory, while still retaining its value. Ho-momorphic encryption, thus, could have a major role in protecting the rights to privacy, while providing ways to learn from captured data. Our work presents a novel use case and evaluation of the usage of homomorphic encryption and machine learning for privacy respecting state surveillance. William Bowditch, Will Abramson, William J. Buchanan, Nikolaos Pitropakis, Adam J. Hall |
ICISSP | 3 |
| 2020 | Phishing URL Detection Through Top-level Domain Analysis: A Descriptive ApproachabstractPhishing is considered to be one of the most prevalent cyber-attacks because of its immense flexibility and alarmingly high success rate. Even with adequate training and high situational awareness, it can still be hard for users to continually be aware of the URL of the website they are visiting. Traditional detection methods rely on blacklists and content analysis, both of which require time-consuming human verification. Thus, there have been attempts focusing on the predictive filtering of such URLs. This study aims to develop a machine-learning model to detect fraudulent URLs and be used within the Splunk platform. Inspired from similar approaches in the literature, we trained the SVM and Random Forests algorithms using malicious and benign datasets found in the literature and one dataset that we created. We evaluated the algorithms' performance with precision and recall reaching up to 85% precision and 87% recall in the case of Random Forests while SVM achieved up to 90% precision and 88% recall using only descriptive features. Orestis Christou, Nikolaos Pitropakis, Pavlos Papadopoulos, Sean McKeown, William J. Buchanan |
ICISSP | 5 |
| 2020 | A Distributed Trust Framework for Privacy-Preserving Machine Learning
Will Abramson, Adam J. Hall, Pavlos Papadopoulos, Nikolaos Pitropakis, William J. Buchanan |
TrustBus | 5 |
| 2019 | Building the Future: Tokenization, Blockchain and Citizen-focused Systems
William J. Buchanan |
ICISSP | 1 |
| 2019 | IoT Forensics: Amazon Echo as a Use CaseabstractInternet of Things (IoT) are increasingly common in our society, and can be found in civilian settings as well as sensitive applications, such as battlefields and national security. Given the potential of these devices to be targeted by attackers, they are a valuable source in digital forensic investigations. In addition, incriminating evidence may be stored on an IoT device (e.g., Amazon Echo in a home environment and Fitbit worn by the victim or an accused person). In comparison to IoT security and privacy literature, IoT forensics is relatively under-studied. IoT forensics is also challenging in practice, particularly due to the complexity, diversity, and heterogeneity of IoT devices and ecosystems. In this paper, we present an IoT-based forensic model that supports the identification, acquisition, analysis, and presentation of potential artifacts of forensic interest from IoT devices and the underpinning infrastructure. Specifically, we use the popular Amazon Echo as a use case to demonstrate how our proposed model can be used to guide forensics analysis of IoT devices. Shancang Li, Kim-Kwang Raymond Choo, Qindong Sun, William J. Buchanan, Jiuxin Cao |
IEEE Internet Things J. | 4 |
| 2019 | Deriving ChaCha20 key streams from targeted memory analysis
Peter McLaren, William J. Buchanan, Gordon Russell 0001, Zhiyuan Tan 0001 |
J. Inf. Secur. Appl. | 2 |
| 2019 | Corrigendum to "Quantum-to-the-Home: Achieving Gbits/s Secure Key Rates via Commercial Off-the-Shelf Telecommunication Equipment"abstractKey Rates via Commercial Off-the-Shelf Telecommunication Equipment" [1] was found to contain materials from the following published article that was cited but not properly attributed [2 Rameez Asif, William J. Buchanan |
Secur. Commun. Networks | 2 |
| 2019 | Guest Editorial Special Issue on Blockchain-Based Secure and Trusted Computing for IoTabstractThe Internet of Things (IoT) is expected to connect a massive number of smart devices to the Internet. The existing centralized architecture for handling the huge volume of data created in the IoT is facing many research challenges, including security and privacy, trustworthiness, operational challenges, business models and the practical aspects, and legal and compliance issues. These challenges ask for new approaches to online identity, trustworthy transactions, and resilient networks. Shancang Li, Yong Yuan 0003, Jun Jason Zhang, William J. Buchanan, Erwu Liu, Ramesh Ramadoss |
IEEE Trans. Comput. Soc. Syst. | 4 |
| 2018 | Correlation Power Analysis on the PRESENT Block Cipher on an Embedded DeviceabstractTraditional cryptographic techniques have proven to work well on most modern computing devices but they are unsuitable for devices (e.g. IoT devices) where memory, power consumption or processing power is limited. Thus, there has been an increasing amount of work on the design and implementation of lightweight cryptographic algorithms to provide a solution for running cryptography on low resource devices. One particular cryptographic algorithm designed specifically to be used on low resource devices is the PRESENT algorithm. Although the design of PRESENT provides a small memory footprint alongside low power consumption our results show it is susceptible to information leakage when power analysis is performed against a device running this algorithm. In this paper, we present our methodology and results on performing correlation power analysis against this light weight block cipher. Our chosen device under test is an Arduino Uno which was programmed to run the Add Round Key and S-Box functions of PRESENT during the first round of encryptions. Results demonstrate that the Add Round Key function is susceptible to information leakage but a high number of false-positives were observed. Greater success was obtained when targeting the S-Box of the PRESENT algorithm and we were able to derive the first 8 bytes of the key. Owen Lo, William J. Buchanan, Douglas Carson |
ARES | 2 |
| 2018 | Predicting Malicious Insider Threat Scenarios Using Organizational Data and a Heterogeneous Stack-ClassifierabstractInsider threats continue to present a major challenge for the information security community. Despite constant research taking place in this area; a substantial gap still exists between the requirements of this community and the solutions that are currently available. This paper uses the CERT dataset r4.2 along with a series of machine learning classifiers to predict the occurrence of a particular malicious insider threat scenario - the uploading sensitive information to wiki leaks before leaving the organization. These algorithms are aggregated into a meta-classifier which has a stronger predictive performance than its constituent models. It also defines a methodology for performing pre-processing on organizational log data into daily user summaries for classification, and is used to train multiple classifiers. Boosting is also applied to optimise classifier accuracy. Overall the models are evaluated through analysis of their associated confusion matrix and Receiver Operating Characteristic (ROC) curve, and the best performing classifiers are aggregated into an ensemble classifier. This meta-classifier has an accuracy of 96.2% with an area under the ROC curve of 0.988. Adam J. Hall, Nikolaos Pitropakis, William J. Buchanan, Naghmeh Moradpoor Sheykhkanloo |
IEEE BigData | 3 |
| 2018 | Requirements for 5G based telemetric cardiac monitoringabstractSeveral white papers have been published on general requirements for 5G in the health vertical. As 5G research and implementation continue more detailed real world information for application research are needed. This paper is focusing on the requirements for telemetric cardiac monitoring based on real world experiences from a joint project on early geriatric rehabilitation of elderly patients in a care of the elderly department after minimal invasive and conservative treatment in a highly specialized cardiology unit in Leipzig, Germany. Christoph Thuemmler, Claudia Rolffs, Andreas Bollmann, Gerhard Hindricks, William J. Buchanan |
WiMob | 5 |
| 2018 | Security Risk Assessment of Critical Infrastructure Systems: A Comparative StudyabstractRecent cyberattacks on critical infrastructure systems coupled with the technology-induced complexity of the system of systems have necessitated a review of existing methods of assessing critical systems security risk exposure. The question is; do existing security risk assessment methods adequately address the threats of modern critical infrastructure systems? Having examined six existing assessment frameworks, we argue, the complexities associated with modern critical infrastructure systems make existing methods insufficient to assess systems security risks exposure. From systems dynamics perspectives, this paper proposes a dynamic modelling approach as an alternative. Samuel Tweneboah-Koduah 0001, William J. Buchanan |
Comput. J. | 2 |
| 2018 | Machine learning and semantic analysis of in-game chat for cyberbullying
Shane Murnion, William J. Buchanan, Adrian Smales, Gordon Russell 0001 |
Comput. Secur. | 2 |
| 2018 | Analysis of the adoption of security headers in HTTPabstractWith the increase in the number of threats within web‐based systems, a more integrated approach is required to ensure the enforcement of security policies from the server to the client. These policies aim to stop man‐in‐the‐middle attacks, code injection, and so on. This study analyses some of the newest security options used within HTTP responses, and scans the Alexa Top 1 Million sites for their implementation within HTTP responses. These options scanned for include: content security policy, public key pinning extension for HTTP, HTTP strict transport security, and HTTP header field X‐frame‐options, in order to understand the impact that these options have on the most popular websites. The results show that, while the implementation of the parameters is increasing, it is still not implemented on many of the top sites. Along with this, the study shows the profile of adoption of Let's Encrypt digital certificates across the one million sites, along with a way of assessing the quality of the security headers. William J. Buchanan, Scott Helme, Alan Woodward |
IET Inf. Secur. | 1 |
| 2018 | Impact of cyberattacks on stock performance: a comparative studyabstractPurpose The study uses cyberattacks announcements on 96 firms that are listed on S&P 500 over the period from January 03, 2013, to December 29, 2017. Design/methodology/approach The empirical analysis was performed in two ways: cross-section and industry level. The authors use statistical tests that account for the effects of cross-section correlation in returns, returns series correlation, volatility changes and skewness in the returns. Findings These imply that studying the cumulative effects of cyberattacks on prices of listed firms without grouping them into the various sectors may be non-informative; financial sector firms tend to react cumulatively to cyberattacks over a three-day period than other sectors; and technology firms tend to be less reactive to the announcement of a data breach. Such firms may possibly have the necessary tools and techniques to address large-scale cyberattacks. Research limitations/implications For cross-section analysis, the outcome shows that the market does not significantly react to cyberattacks for all the event windows, except [−30, 30], while for the sector-level analysis, the analysis offers two main results. Practical implications First, while there is a firm reaction to cyberattacks for long event window for retail sector, there is no evidence of a cumulative firm reaction to cyberattacks for both short and long event windows for the industrial, information technology and health sectors. Second, the firms in the financial sector, there is a strong evidence of cumulative reaction to cyberattacks for [−1, 1] for the financial industry, and the reactions disappear for relatively longer event windows. Social implications These imply that studying the cumulative effects of cyberattacks on prices of listed firms without grouping them into the various sectors may be non-informative, the financial sector firms tend to react cumulatively to cyberattacks over a three-day period than other sectors, technology firms tend to be less reactive to the announcement of a data breach, possibly such firms may have the necessary tools and techniques to address large-scale cyberattacks. Originality/value The work provides new insights into the effect of cyber security on stock prices. Samuel Tweneboah-Koduah 0001, Francis Atsu, William J. Buchanan |
Inf. Comput. Secur. | 3 |
| 2018 | Distance Measurement Methods for Improved Insider Threat DetectionabstractInsider threats are a considerable problem within cyber security and it is often difficult to detect these threats using signature detection. Increasing machine learning can provide a solution, but these methods often fail to take into account changes of behaviour of users. This work builds on a published method of detecting insider threats and applies Hidden Markov method on a CERT data set (CERT r4.2) and analyses a number of distance vector methods (Damerau–Levenshtein Distance, Cosine Distance, and Jaccard Distance) in order to detect changes of behaviour, which are shown to have success in determining different insider threats. Owen Lo, William J. Buchanan, Richard Macfarlane |
Secur. Commun. Networks | 2 |
| 2017 | Applied Machine Learning predictive analytics to SQL Injection Attack detection and preventionabstractThe back-end database is pivotal to the storage of the massive size of big data Internet exchanges stemming from cloud-hosted web applications to Internet of Things (IoT) smart devices. Structured Query Language (SQL) Injection Attack (SQLIA) remains an intruder's exploit of choice on vulnerable web applications to pilfer confidential data from the database with potentially damaging consequences. The existing solutions of mostly signature approaches were all before the recent challenges of big data mining and at such lacks the functionality and ability to cope with new signatures concealed in web requests. An alternative Machine Learning (ML) predictive analytics provides a functional and scalable mining to big data in detection and prevention of SQLIA. Unfortunately, lack of availability of readymade robust corpus or data set with patterns and historical data items to train a classifier are issues well known in SQLIA research. In this paper, we explore the generation of data set containing extraction from known attack patterns including SQL tokens and symbols present at injection points. Also, as a test case, we build a web application that expects dictionary word list as vector variables to demonstrate massive quantities of learning data. The data set is pre-processed, labelled and feature hashing for supervised learning. The trained classifier to be deployed as a web service that is consumed in a custom dot NET application implementing a web proxy Application Programming Interface (API) to intercept and accurately predict SQLIA in web requests thereby preventing malicious web requests from reaching the protected back-end database. This paper demonstrates a full proof of concept implementation of an ML predictive analytics and deployment of resultant web service that accurately predicts and prevents SQLIA with empirical evaluations presented in Confusion Matrix (CM) and Receiver Operating Curve (ROC). Solomon Ogbomon Uwagbole, William J. Buchanan |
IM | 2 |
| 2017 | Sticky policies approach within cloud computing
Grzegorz Spyra, William J. Buchanan, Elias Ekonomou |
Comput. Secur. | 2 |
| 2017 | Quantum-to-the-Home: Achieving Gbits/s Secure Key Rates via Commercial Off-the-Shelf Telecommunication EquipmentabstractThere is current significant interest in Fiber-to-the-Home (FTTH) networks, that is, end-to-end optical connectivity. Currently, it may be limited due to the presence of last-mile copper wire connections. However, in near future, it is envisaged that FTTH connections will exist, and a key offering would be the possibility of optical encryption that can best be implemented using Quantum Key Distribution (QKD). However, it is very important that the QKD infrastructure is compatible with the already existing networks for a smooth transition and integration with the classical data traffic. In this paper, we report the feasibility of using off-the-shelf telecommunication components to enable high performance Continuous Variable-Quantum Key Distribution (CV-QKD) systems that can yield secure key rates in the range of 100 Mbits/s under practical operating conditions. Multilevel phase modulated signals ( m -PSK) are evaluated in terms of secure key rates and transmission distances. The traditional receiver is discussed, aided by the phase noise cancellation based digital signal processing module for detecting the complex quantum signals. Furthermore, we have discussed the compatibility of multiplexers and demultiplexers for wavelength division multiplexed Quantum-to-the-Home (QTTH) network and the impact of splitting ratio is analyzed. The results are thoroughly compared with the commercially available high-cost encryption modules. Rameez Asif, William J. Buchanan |
Secur. Commun. Networks | 2 |
| 2016 | HI-risk: A method to analyse health information risk intelligenceabstractInformation security threat intelligence is a prevalent topic amongst researchers, long-established IT-vendors and start-ups. The possibilities of Big Data analytics to security threat and vulnerability scanning offer a significant development in the protection of infrastructures. At the same time, industry research reports continue to state that the main contributing factor in the events leading to a data breach is human error. The common response of information security professionals is to resort to technological solutions to prevent these human errors. However, some very important information security intelligence is not hidden within the network traffic: it's available from the people that work with sensitive information. This article describes the Health Information risk (HI-risk) method to identify non-technical information security risks in healthcare. The method includes risks related to skills, behaviour, processes, organisational culture, physical security, and external influences. HI-risk offers a solution to collect intelligence about nontechnical information security incidents from across the healthcare sector to demonstrate past trends and to be ahead of future incidents. A test of a HI-risk forecast proved the feasibility of this approach in healthcare and beyond. It is suggested that HI-risk could become a valuable addition to existing technical threat and vulnerability monitoring tools. William J. Buchanan, Nicole van Deursen |
HealthCom | 1 |
| 2016 | Numerical encoding to Tame SQL injection attacksabstractRecent years have seen an astronomical rise in SQL Injection Attacks (SQLIAs) used to compromise the confidentiality, authentication and integrity of organisations' databases. Intruders becoming smarter in obfuscating web requests to evade detection combined with increasing volumes of web traffic from the Internet of Things (IoT), cloud-hosted and on-premise business applications have made it evident that the existing approaches of mostly static signature lack the ability to cope with novel signatures. A SQLIA detection and prevention solution can be achieved through exploring an alternative bio-inspired supervised learning approach that uses input of labelled dataset of numerical attributes in classifying true positives and negatives. We present in this paper a Numerical Encoding to Tame SQLIA (NETsQlIA) that implements a proof of concept for scalable numerical encoding of features to a dataset attributes with labelled class obtained from deep web traffic analysis. In the numerical attributes encoding: the model leverages proxy in the interception and decryption of web traffic. The intercepted web requests are then assembled for front-end SQL parsing and pattern matching by applying traditional Non-Deterministic Finite Automaton (NFA). This paper is intended for a technique of numerical attributes extraction of any size primed as an input dataset to an Artificial Neural Network (ANN) and statistical Machine Learning (ML) algorithms implemented using Two-Class Averaged Perceptron (TCAP) and Two-Class Logistic Regression (TCLR) respectively. This methodology then forms the subject of the empirical evaluation of the suitability of this model in the accurate classification of both legitimate web requests and SQLIA payloads. Solomon Ogbomon Uwagbole, William J. Buchanan |
NOMS | 2 |
| 2016 | Evaluation of TFTP DDoS amplification attack
Boris Sieklik, Richard Macfarlane, William J. Buchanan |
Comput. Secur. | 3 |
| 2015 | Secret shares to protect health records in Cloud-based infrastructuresabstractIncreasingly health records are stored in cloud-based systems, and often protected by a private key. Unfortunately the loss of this key can cause large-scale data loss. This paper outlines a novel Cloud-based architecture (SECRET) which supports keyless encryption methods and which can be used for the storage of patient information, along with supporting failover and a break-glass policy. William J. Buchanan, Elochukwu Ukwandu, Nicole van Deursen, Gordon Russell 0001, Owen Lo, Christoph Thuemmler |
HealthCom | 1 |
| 2013 | Norms and standards in modular medical architecturesabstractRecent Internet of Things (IoT) research has been aiming at interoperability of devices and the integration of sensor networks. The Future Internet - Private Public Partnership (FI-PPP) has created a whole array of different purpose-oriented modules with defined specifications, better known as Generic Enablers. This article gives an overview of legal, ethical and technical norms and standards to be considered when planning, developing and implementing modular medical architectures, integrating the Internet of Things (IoT) and Generic Enablers (GEs) in cutting edge, latest generation medical data networks. Christoph Thuemmler, Oli H. Mival, David Benyon, William J. Buchanan, Alois Paulin, Samuel Fricker, Markus Fiedler, Astrid Grøttland, Thomas Jell, Thomas Magedanz, Ioana Ispas, Bert-Jaap Koops, Eleni Kosta, Armin Schneider, Anastasius Gavras, Maria Barros, Philippe Cousin, Euripides G. M. Petrakis |
Healthcom | 4 |
| 2013 | Monitoring information security risks within health care
Nicole van Deursen, William J. Buchanan, Alistair S. Duff |
Comput. Secur. | 2 |
| 2013 | A Privacy Preserving Method Using Privacy Enhancing Techniques for Location Based Services
William J. Buchanan, Zbigniew Kwecka, Elias Ekonomou |
Mob. Networks Appl. | 1 |
| 2012 | Computational data protection law: trusting each other offline and onlineabstractThe paper reports of a collaborative project between computer scientists, lawyers, police officers, medical professionals and social workers to develop a communication in infrastructure that allows information sharing while observing Data Protection law “by design”, through a formal representation of legal rules in a firewall type system. William J. Buchanan, Alistair Lawson, Burkhard Schafer 0001, Russel Scott, Christoph Thuemmler, Omair Uthmani |
JURIX | 1 |
| 2012 | Formal security policy implementations in network firewalls
Richard Macfarlane, William J. Buchanan, Elias Ekonomou, Omair Uthmani, Owen Lo |
Comput. Secur. | 2 |
| 2011 | DACAR Platform for eHealth Services CloudabstractThe use of digital technologies in providing health care services is collectively known as eHealth. Considerable progress has been made in the development of eHealth services, but concerns over service integration, large scale deployment, and security, integrity and confidentiality of sensitive medical data still need to be addressed. This paper presents a solution proposed by the Data Capture and Auto Identification Reference (DACAR) project to overcoming these challenges. The key contributions of this paper include a Single Point of Contact (SPoC), a novel rule based information sharing policy syntax, and Data Buckets hosted by a scalable and cost-effective Cloud infrastructure. These key components and other system services constitute DACAR's eHealth platform, which allows the secure capture, storage and consumption of sensitive health care data. Currently, a prototype of the DACAR platform has been implemented. To assess the viability and performance of the platform, a demonstration application, namely the Early Warning Score (EWS), has been developed and deployed within a private Cloud infrastructure at Edinburgh Napier University. Simulated experimental results show that the end-to-end communication latency of 97.8% of application messages were below 100ms. Hence, the DACAR platform is efficient enough to support the development and integration of time critical eHealth services. A more comprehensive evaluation of the DACAR platform in a real life clinical environment is under development at Chelsea & Westminster Hospital in London. William J. Buchanan, Christoph Thuemmler, Owen Lo, Abou Sofyane Khedim, Omair Uthmani, Alistair Lawson, Derek Bell |
IEEE CLOUD | 2 |
| 2011 | An Integrated Cloud-based Healthcare InfrastructureabstractWe present a cloud-based healthcare system that integrates a formal care system (DACAR) with an informal care system (Microsoft Health Vault). The system provides high levels of security and privacy within a cloud environment, enabling sharing of both health records and the access rights, along the patient pathway. We also define a case study that can help in evaluating and in demonstrating the usefulness of a cloud-based integrated health care system. Elias Ekonomou, William J. Buchanan, Christoph Thuemmler |
CloudCom | 3 |
| 2010 | Interagency data exchange protocols as computational data protection lawabstractThe paper describes a collaborative project between computer scientists, lawyers, police officers, medical professionals and social workers to develop a communication infrastructure that allows information sharing while observing Data Protection law “by design”, through a formal representation of legal rules in a firewall type system. William J. Buchanan, Alistair Lawson, Burkhard Schafer 0001, Russel Scott, Christoph Thuemmler, Omair Uthmani |
JURIX | 1 |
| 2010 | Special issue: Performance evaluation and optimization of ubiquitous computing and networked systems
Ahmed Yassin Al-Dubai, Geyong Min, Mohamed Ould-Khaoua, Xiaolong Jin 0001, William J. Buchanan |
J. Syst. Softw. | 5 |
| 2009 | Protecting mobile agents from external replay attacks
Carles Garrigues, Nikos Migas, William J. Buchanan, Sergi Robles, Joan Borrell |
J. Syst. Softw. | 3 |
| 2008 | Ad-hoc Routing Metrics and Applied Weighting for QoS supportabstractIn the vast majority of ad-hoc routing protocols, the hop-counting mechanisms for identifying the optimal route are dominant. However, this approach oversimplifies such a complex decision by ignoring the fact that participating devices may have considerably unequal performance characteristics and current utilisation status. Accordingly, it is possible for an optimal route to be composed of devices with high utilisation status, or, low battery reserves, which results in an overall unreliable route. This research work tackles this by identifying the best metrics that can describe any route within a graph, in terms of overall throughput, reliability, and minimum energy consumption. Simulations were carried out by varying critical factors of mobile devices such as battery reserves, memory and CPU utilisation, and results recorded the effect that this has on the device’s overall routing metric. This paper also presents the threshold values, which turn the device from routing-capable to routing-incapable state. Nikos Migas, William J. Buchanan |
IPDPS | 2 |
| 2006 | Analysis of an agent-based metric-driven method for ad-hoc, on-demand routing
William J. Buchanan, Nikos Migas, G. Sinclair, Kevin A. McArtney |
Ad Hoc Networks | 1 |
| 2006 | NetHost-Sensor: Investigating the capture of end-to-end encrypted intrusive data
A. A. Abimbola, Jose Munoz, William J. Buchanan |
Comput. Secur. | 3 |
| 2006 | NetHost-sensor: Monitoring a target host's application via system calls
A. A. Abimbola, J. M. Munoz, William J. Buchanan |
Inf. Secur. Tech. Rep. | 3 |