EDBT 2026 Demo / reviewers in the wild / expert
Jan H. P. Eloff
dblp:09/676 · also Jan Harm Petrus Eloff
· DBLP profile ↗
71ranked-venue papers
6as first author
3since 2021 · last 2026
0000-0003-4683-2198ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 66 · 6 first-author · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Artificial intelligence and machine learning · 2Software engineering, systems software and programming languages · 1Applied, interdisciplinary, general and emerging computing · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | A Privacy Preservation Framework for Vehicular Ad-Hoc Networks
Eunice Naa Korkoi Hammond, Jan H. P. Eloff |
SECRYPT (1) | 2 |
| 2024 | Data Sets for Cyber Security Machine Learning Models: A Methodological Approach
Innocent Mbona, Jan H. P. Eloff |
IoTBDS | 2 |
| 2022 | Feature selection using Benford's law to support detection of malicious social media bots
Innocent Mbona, Jan H. P. Eloff |
Inf. Sci. | 2 |
| 2020 | Discovering "Insider IT Sabotage" based on human behaviourabstractPurpose Malicious activities conducted by disgruntled employees via an email platform can cause profound damage to an organization such as financial and reputational losses. This threat is known as an “Insider IT Sabotage” threat. This involves employees misusing their access rights to harm the organization. Events leading up to the attack are not technical but rather behavioural. The problem is that owing to the high volume and complexity of emails, the risk of insider IT sabotage cannot be diminished with rule-based approaches. Design/methodology/approach Malicious human behaviours that insiders within the insider IT sabotage category would possess are studied and mapped to phrases that would appear in email communications. A large email data set is classified according to behavioural characteristics of these employees. Machine learning algorithms are used to identify occurrences of this insider threat type. The accuracy of these approaches is measured. Findings It is shown in this paper that suspicious behaviour of disgruntled employees can be discovered, by means of machine intelligence techniques. The output of the machine learning classifier depends mainly on the depth and quality of the phrases and behaviour analysis, cleansing and number of email attributes examined. This process of labelling content in isolation could be improved if other attributes of the email data are included, such that a confidence score can be computed for each user. Originality/value This research presents a novel approach to show that the creation of a prototype that can automate the detection of insider IT sabotage within email systems to mitigate the risk within organizations. Antonia Michael, Jan H. P. Eloff |
Inf. Comput. Secur. | 2 |
| 2019 | Identity deception detection: requirements and a modelabstractPurpose This paper aims to describe requirements for a model that can assist in identity deception detection (IDD) on social media platforms (SMPs). The model that was discovered demonstrates the usefulness of the requirements. The aim of the model is to identify humans lying about their identity on SMPs. Design/methodology/approach The requirements of a model for IDD will be determined through a literature study combined with a study that identifies currently available identity related metadata on SMPs. This metadata refers to the attributes that describe a user account on an SMP. The aim is to restrict IDD to be only based on these types of attributes, as opposed to or combined with the contents of a single or multiple communications. Findings Data science experiments were conducted and in particular supervised machine learning models were discovered that indeed detects identity deception on SMPs with an area under the receiver operator characteristics curve (ROC-AUC) of 75.5 per cent. Originality/value SMPs allow any user to easily communicate with their friends or the general public at large. People can now be targeted at great scale, most often for malicious purposes. The reality is that many of these cyber-attacks involve some form of identity deception, where the attackers lie about who they are. Much focus to date has been on the identification of non-human deceptive accounts. This paper focuses on deceptive human accounts that target vulnerable individuals on SMPs. Estée van der Walt, Jan H. P. Eloff |
Inf. Comput. Secur. | 2 |
| 2018 | Cyber-security: Identity deception detection on social media platforms
Estée van der Walt, Jan H. P. Eloff, Jacomine Grobler |
Comput. Secur. | 2 |
| 2017 | Towards Optimized Security-aware (O-Sec) VM Placement Algorithms
Motlatsi i Isaac Thulo, Jan H. P. Eloff |
ICISSP | 2 |
| 2017 | Identity Deception Detection on Social Media PlatformsabstractWhenever they interact on big data platforms such as social media, humans run the \nrisk of being targeted by other malicious individuals. The protection of these humans \nis problematic, even though cyber-attack events have received much attention in public \nin order to create greater awareness. Cyber protection is di cult, largely due to the \nnature of these social media platforms (SMPs), as they allow individuals to create and \nuse almost any persona they choose, with minimal validation. This, together with the \nsheer volume of data being generated, warrants the use of automated threat detection \nmethods. The victims are targeted through di erent forms of cyber threats of which \nidentity deception is but one example. \nIdentity deception is by no means a novel concept. The social sciences, more speci cally \npsychology, have for many years attempted to understand the motive(s) behind human \ndeception. More recently, research work aimed at nding fake or bot accounts has \nhad some success. This study used the abundant knowledge about identity deception, \nin addition to the information already available by default on SMPs, to detect those \nhumans who lie about their identity. \nThe study in hand presents an SMP research environment with a methodology and \nprototype that will assist with the automated detection of human identity deception \non SMPs. This environment enables various supervised machine learning experiments. \nThe rst experiment used those attributes describing an SMP pro le to detect identity \ndeception with a nal F1 score of 32%. The second experiment added additional features \nknown to detect deceptive bots on SMPs with a nal F1 score of 49%. The third \nexperiment added further features from psychology, known to identify deceptive humans, \nwith a nal F1 score of 86%. A critical evaluation of the SMP attributes and engineered \nfeatures reveals that age, name, and location contributed most towards identity deception \nas executed by humans in respect to other humans. The results show that human identity \ndeception detection can be achieved by using SMP attributes and engineered features \nthat describe the identity of the individual only, thus excluding SMP content that can \nbe costly to construe. The prototype furthermore includes an Identity Deception Detection Model (IDDM) \nthat scores a human's perceived deceptiveness and intuitively explains the score. The \nIDDM not only indicates when a human is potentially deceptive but also highlights those \nattributes or features that were most prevalent in the conclusion. This aids investigators, \nlike the police force, to not only identify potential deceptive humans, but to also make \na more informed decision. \nThe results from this research make a signi cant contribution to the elds of both cyber \nsecurity and the social sciences. Estée van der Walt, Jan H. P. Eloff |
ICISSP | 2 |
| 2013 | Integrated digital forensic process model
Michael D. Kohn, Mariki M. Eloff, Jan H. P. Eloff |
Comput. Secur. | 3 |
| 2010 | Editorial
Dimitris Gritzalis, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2010 | A security privacy aware architecture and protocol for a single smart card used for multiple services
A. Maciej Rossudowski, Hein S. Venter, Jan H. P. Eloff, Derrick G. Kourie |
Comput. Secur. | 3 |
| 2010 | A framework and assessment instrument for information security culture
Adéle da Veiga, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2009 | Information security: The moving target
M. T. Dlamini, Jan H. P. Eloff, Mariki M. Eloff |
Comput. Secur. | 2 |
| 2009 | Building access control models with attribute exploration
Sergei A. Obiedkov, Derrick G. Kourie, Jan H. P. Eloff |
Comput. Secur. | 3 |
| 2009 | Adapting usage control as a deterrent to address the inadequacies of access controlsabstractAccess controls are difficult to implement and evidently deficient under certain conditions. Traditional controls offer no protection for unclassified information, such as a telephone list of employees that is unrestricted, yet available only to members of the company. On the opposing side of the continuum, organizations such as hospitals that manage highly sensitive information require stricter access control measures. Yet, traditional access control may well have inadvertent consequences in such a context. Often, in unpredictable circumstances, users that are denied access could have prevented a calamity had they been allowed access. It has been proposed that controls such as auditing and accountability policies be enforced to deter rather than prevent unauthorized usage. In dynamic environments preconfigured access control policies may change dramatically depending on the context. Moreover, the cost of implementing and maintaining complex preconfigured access control policies sometimes far outweighs the benefits. This paper considers an adaptation of usage control as a proactive means of deterrence control to protect information that cannot be adequately or reasonably protected by access control. Keshnee Padayachee, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2008 | Considerations Towards a Cyber Crime Profiling SystemabstractThe field of digital forensics is faced with a number of challenges, given the constant growth in technologies. The reliability and integrity associated with digital evidence from disparate sources is also a perpetual challenge, requiring considerable human interpretation in the reconstruction of any particular sequence of events. In this paper we present a framework for an integrity-aware forensic evidence management system (FEMS). In an effort to automate the analysis process, this system would provide investigators with a holistic view of the forensic evidence at hand; thereby providing insights into the quality of investigative inferences. The Biba integrity model is incorporated to preserve the integrity of digital evidence, while Casey's Certainty Scale is chosen as the integrity classification scheme. A finite state automaton (FSA) is used to model the behaviour of the FEMS. In so doing, cyber crime profiling is achieved. Kweku Kwakye Arthur, Martin S. Olivier, Hein S. Venter, Jan H. P. Eloff |
ARES | 4 |
| 2008 | SMSSec: An end-to-end protocol for secure SMS
Johnny Li-Chang Lo, Judith Bishop, Jan H. P. Eloff |
Comput. Secur. | 3 |
| 2008 | Standardising vulnerability categories
Hein S. Venter, Jan H. P. Eloff, Y. L. Li |
Comput. Secur. | 2 |
| 2007 | Defining a Trusted Service-Oriented Network EnvironmentabstractNetwork device availability and reliability are very important in a network environment. The network devices in this environment provide services to the other nodes or devices on the network. Hence we define a service-oriented network environment. We also propose a novel model for a trusted service-oriented network environment by using an Internet Control Message Protocol. We argue that trust representation in this environment must be different from an application-oriented environment Emmanuel A. Adigun, Jan H. P. Eloff |
ARES | 2 |
| 2007 | Personal Anomaly-based Intrusion Detection Smart Card Using Behavioural Analysis
A. Maciej Rossudowski, Hein S. Venter, Jan H. P. Eloff |
SEC | 3 |
| 2007 | A Trust and Context Aware Access Control Model for Web Services Conversations
Marijke Coetzee, Jan H. P. Eloff |
TrustBus | 2 |
| 2007 | Enhancing Optimistic Access Controls with Usage Control
Keshnee Padayachee, Jan H. P. Eloff |
TrustBus | 2 |
| 2006 | Analysis of Web Proxy Logs
Bennie Fei, Jan H. P. Eloff, Martin S. Olivier, Hein S. Venter |
IFIP Int. Conf. Digital Forensics | 2 |
| 2006 | Applying Machine Trust Models to Forensic Investigations
Marika Wojcik, Hein S. Venter, Jan H. P. Eloff, Martin S. Olivier |
IFIP Int. Conf. Digital Forensics | 3 |
| 2006 | A Framework for Web Services Trust
Marijke Coetzee, Jan H. P. Eloff |
SEC | 2 |
| 2006 | Trust Model Architecture: Defining Prejudice by Learning
Marika Wojcik, Jan H. P. Eloff, Hein S. Venter |
TrustBus | 2 |
| 2006 | Uncovering identities: A study into VPN tunnel fingerprinting
Vafa D. Izadinia, Derrick G. Kourie, Jan H. P. Eloff |
Comput. Secur. | 3 |
| 2005 | Exploring Forensic Data with Self-Organizing Maps
Bennie Fei, Jan H. P. Eloff, Hein S. Venter, Martin S. Olivier |
IFIP Int. Conf. Digital Forensics | 2 |
| 2005 | Applying Computer Forensic Principles in Evidence Collection and Analysis for a Computer-Based Programming Assessment
Rut Laubscher, Cobus Rabe, Martin S. Olivier, Jan H. P. Eloff, Hein S. Venter |
IFIP Int. Conf. Digital Forensics | 4 |
| 2005 | An access control framework for web servicesabstractPurpose To define a framework for access control for virtual applications, enabled through web services technologies. The framework supports the loosely coupled manner in which web services are shared between partners. Design/methodology/approach A background discussion on relevant literature, with an example is used to illustrate the problem that exists. To enable access control composition, an extension is proposed to authorisation specification language, together with publication of access control requirements of a web service provider. Findings The framework shows that loosely coupled access control can be made possible by making use of the standard manner in which messages are communicated in XML, and by composing assertions with the access control policy of the provider in a consistent manner. Access to web service methods is only granted if permission can be derived for it, where the derivation step forms a formal proof. Research limitations/implications A basic framework has been defined. An architecture to support it must be defined. Only a very basic level of access control composition has been illustrated. Practical implications The publication of access control requirements in standards such as WS-Policy can be considered. Originality/value This paper offers a practical approach to address access control for web services. Marijke Coetzee, Jan H. P. Eloff |
Inf. Manag. Comput. Security | 2 |
| 2004 | Towards Web Service access control
Marijke Coetzee, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2004 | Vulnerability forecasting - a conceptual model
Hein S. Venter, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2003 | Information Security Management System: Processes and Products
Mariki M. Eloff, Jan H. P. Eloff |
SEC | 2 |
| 2003 | Security and human computer interfaces
J. Johnston, Jan H. P. Eloff, Les Labuschagne |
Comput. Secur. | 2 |
| 2003 | A taxonomy for information security technologies
Hein S. Venter, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2002 | Secure Database Connectivity on the WWW
Marijke Coetzee, Jan H. P. Eloff |
SEC | 2 |
| 2002 | Human Computer Interaction: An Information Security Perspectives
Mariki M. Eloff, Jan H. P. Eloff |
SEC | 2 |
| 2002 | Information Security Culture
A. Martins, Jan H. P. Eloff |
SEC | 2 |
| 2002 | Information security policy what do international information security standards say?
Karin Höne, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2002 | A Prototype for Assessing Information Technology Risks in Health Care
Elmé Smith, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2002 | Vulnerabilities categories for intrusion detection system
Hein S. Venter, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2001 | Designing Role Hierarchies for Access Control in Workflow SystemsabstractDue to the correspondence between the role abstraction in Role-based Access Control (RBAC) and the notion of organizational positions, it seems easy to construct role hierarchies. This is, however, a misconception. This paper argues that, in order to reflect the functional requirements, a role hierarchy becomes very complex. In a bid to simplify the design of role hierarchies suitable for the expression of access control requirements in workflow systems, the paper proposes a "typed" role hierarchy. In a "typed" role hierarchy a role is of a specific type. The associations between different types of roles are limited by rules that govern the construction of a role hierarchy. This paper proposes a methodology to systematically construct a "typed" role hierarchy. Since the "typed" nature of the role hierarchy is only relevant during the construction of the role hierarchy, it can seamlessly be integrated into existing RBAC schemes that support the concept of role hierarchies. Reinhardt A. Botha, Jan H. P. Eloff |
COMPSAC | 2 |
| 2001 | Access Control in Document-centric Workflow Systems An Agent-based Approach
Reinhardt A. Botha, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2001 | A Framework for the Implementation of Socio-ethical Controls in Information Security
Colette M. Trompeter, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 2001 | A framework for access control in workflow systemsabstractWorkflow systems are often associated with business process re‐engineering (BPR). This paper argues that the functional access control requirements in workflow systems are rooted in the scope of a BPR project. A framework for access control in workflow systems is developed. The framework suggests that existing role‐based access control mechanisms can be used as a foundation in workflow systems. The framework separates the administration‐time and the run‐time aspects. Key areas that must be investigated to meet the functional requirements imposed by workflow systems on access control services are identified. Reinhardt A. Botha, Jan H. P. Eloff |
Inf. Manag. Comput. Secur. | 2 |
| 2000 | A Context-Sensitive Access Control Model and Prototype Implementation
Damian G. Cholewka, Reinhardt A. Botha, Jan H. P. Eloff |
SEC | 3 |
| 2000 | MASS: Model for an Auditing Security System
Alida Liebenberg, Jan H. P. Eloff |
SEC | 2 |
| 2000 | Electronic commerce: the information-security challengeabstractThe major reason why most people are still sceptical about electronic commerce is the perceived security risks associated with electronic transactions over the Internet. The Internet, however, holds many opportunities that could mean survival or competitive advantage for many organisations. To exploit these opportunities, it is important to first analyse the risks they hold. Electronic commerce is based on business as well as technological risks, making it a very difficult environment to secure. Apart from these two types of risk categories there are several other issues and problems that need to be addressed. Les Labuschagne, Jan H. P. Eloff |
Inf. Manag. Comput. Secur. | 2 |
| 1998 | The use of real-time risk analysis to enable dynamic activation of countermeasures
Les Labuschagne, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1998 | Software source code, visual risk analysis: an example
Gert van der Merwe, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1998 | Data packet intercepting on the internet: How and why? A closer look at existing data packet-intercepting tools
Hein S. Venter, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1998 | Real-time risk analysis using Java conceptsabstractUsing new concepts, such as those on which Java is based, it is now possible to define a new framework within which risk analyses can be performed on electronic communications. In order truly to be effective, risk analyses must be done in real time, owing to the dynamic nature of open, distributed public networks. The strength of these public networks lies in the many routes available for a message to travel from point A to point B, thus ensuring that the message will be delivered. These many routes, however, also constitute the biggest security weakness in public networks, as it is impossible proactively to determine the route a message will follow. In a bid to compensate for the said weakness, this article will be devoted to a discussion on a framework in terms of which Real‐time Risk Analysis (RtRA) can, henceforth, be performed to determine a risk value for a communications session, rather than for the network components used on routes that need to be fixed and known in advance, as for conventional risk analysis. A communication session is defined as the transfer of data between two hosts; for example, exchanging e‐mail messages over open, distributed public networks RtRA produces a risk value that can be used to determine the appropriate countermeasures with which to minimise the risk associated with a communication session. Les Labuschagne, Jan H. P. Eloff |
Inf. Manag. Comput. Secur. | 2 |
| 1997 | A methodology for accrediting a commercial distributed database
Jan H. P. Eloff, R. Körner |
SEC | 1 |
| 1997 | A common criteria framework for the evaluation of information technology systems security
R. Kruger, Jan H. P. Eloff |
SEC | 2 |
| 1997 | Improved system-access control using complementary technologies
Les Labuschagne, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1996 | Activating dynamic counter measures to reduce risk
Les Labuschagne, Jan H. P. Eloff |
SEC | 2 |
| 1996 | Security classification for documents
Jan H. P. Eloff, Ralph Holbein, Stephanie Teufel |
Comput. Secur. | 1 |
| 1996 | Risk analysis modelling with the use of fuzzy logic
Willem G. de Ru, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1995 | Information Security Concepts in Computer Supported Cooperative Work
Stephanie Teufel, Jan H. P. Eloff, Kurt Bauknecht, Dimitris Karagiannis |
DEXA | 2 |
| 1995 | Classification of objects for improved access control
H. A. S. Booysen, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1994 | TOPM: a formal approach to the optimization of information technology risk management
Karin P. Badenhorst, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1993 | Improved password mechanisms through expert system technologyabstractThe successful verification of a user or entity wishing to use a computer based information system, lies at the core of the security of these systems. Although a vast number of different verification techniques have been proposed, password based methods remain the predominant method of choice. For this reason, if is essential that these methods be as effective as possible. The extensive ongoing research on more sophisticated methods are a clear indication that password techniques are not fully coping with the demands set by computer security authorities. This paper explores the use of expert system technology in the improvement of password mechanisms. It is proposed as a means of breaking through the "simultaneous-memorable-and-difficult-to-guess-barrier", which is the single most important factor hampering the coming of age of password systems.> Willem G. de Ru, Jan H. P. Eloff |
ACSAC | 2 |
| 1993 | MethoDex: A Methodology for Expert Systems Development
J. P. Klut, Jan H. P. Eloff |
ISMIS | 2 |
| 1993 | International Standards and Organizational Security Needs: Bridging the Gap
C. J. Bosch, Jan H. P. Eloff, John M. Carroll 0002 |
SEC | 2 |
| 1993 | A comparative framework for risk analysis methods
Jan H. P. Eloff, Les Labuschagne, Karin P. Badenhorst |
Comput. Secur. | 1 |
| 1990 | Computer security methodology: Risk analysis and project definition
Karin P. Badenhorst, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1989 | Framework of a methodology for the life cycle of computer security in an organization
Karin P. Badenhorst, Jan H. P. Eloff |
Comput. Secur. | 2 |
| 1989 | A methodology for measuring user satisfaction
D. N. J. Mostert, Jan H. P. Eloff, Sebastiaan H. von Solms |
Inf. Process. Manag. | 2 |
| 1988 | Computer security policy: Important issues
Jan H. P. Eloff |
Comput. Secur. | 1 |
| 1985 | The development of a specification language for a computer security system
Jan H. P. Eloff |
Comput. Secur. | 1 |
| 1983 | Selection process for security packages
Jan H. P. Eloff |
Comput. Secur. | 1 |