EDBT 2026 Demo / reviewers in the wild / expert
Michael Goldsmith
dblp:11/4544
· DBLP profile ↗
32ranked-venue papers
2as first author
7since 2021 · last 2025
—ORCID · conflict
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 22 · 7 since 2021Software engineering, systems software and programming languages · 4 · 1 first-authorTheory of computation · 2 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2Artificial intelligence and machine learning · 1Systems, architecture and hardware · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Enhancing maritime cyber situational awareness: A cybersecurity visualisation for non-expertsabstractCyber situational awareness is key to mitigating the impacts of cyber threats. However, maritime falls short of its comparative industries, with very little attention given to cyber threats despite the growing concern. In this paper, we explore the use of visualisations as a way to improve the situational awareness of non-experts onboard ships. We designed a visualisation tool with focus on systems that are accessible once onboard. In order to elicit requirements for our visualisations, we conducted semi-structured interviews with experts. We further created a synthetic dataset of attacks that target the systems of ships, which we used to assess the usability of our visualisation. In order to evaluate our visualisations, we conducted a user study with both expert and non-expert users. Our results show that non-expert participants were able to accurately and efficiently detect synthetic attacks targeting ships in an experimental setting, and they were able to use the visualisation to consider what the consequences of these attacks might be. Expert evaluations further suggest the visualisation has merit as a training tool for raising awareness among maritime employees. Dominic Too, Louise Axon, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
Comput. Secur. | 4 |
| 2022 | A system to calculate Cyber Value-at-RiskabstractIn the face of increasing numbers of cyber-attacks, it is critical for organisations to understand the risk they are exposed to even after deploying security controls. This residual risk forms part of the ongoing operational environment, and must be understood and planned for if resilience is to be achieved. However, there is a lack of rigorous frameworks to help organisations reason about how their use of risk controls can change the nature of the potential losses they face, given an often changing threat landscape. To address this gap, we present a system that calculates Cyber Value-at-Risk (CVaR) of an organisation. CVaR is a probabilistic density function for losses from cyber-incidents, for any given threats of interest and risk control practice. It can take account of varying effectiveness of controls, the consequences for risk propagation through infrastructures, and the cyber-harms that result. We demonstrate the utility of the system in a real case study by calculating the CVaR of an organisation that experienced a significant cyber-incident. We show that the system is able to produce predictions representative of the actual financial loss. The presented system can be used by insurers offering cyber products to better inform the calculation of insurance premiums, and by organisations to reason about the effects of using particular risk control setups on reducing their exposure to cyber-risk. Arnau Erola, Ioannis Agrafiotis, Jason R. C. Nurse, Louise Axon, Michael Goldsmith, Sadie Creese |
Comput. Secur. | 5 |
| 2022 | Insider-threat detection: Lessons from deploying the CITD tool in three multinational organisationsabstractInsider threat is a persistent concern for organisations and business alike that has attracted the interest of the research community, resulting in numerous behavioural models and tools to tackle it. However, the effectiveness of detection of these tools has scarcely been demonstrated in real environments. In order to fill this gap, we collaborated with three multinational commercial organisations who trialled our anomaly detection system, and worked with us to understand performance constraints for insider threat detection deployment and innate weaknesses in their operational contexts. During a period longer than a year, we were provided access to real data in their premises and interacted with their cybersecurity analysts to understand their systems, validate the results and identify best practices for mitigating insider threat. In this paper, we provide details on the architecture used in our tool, the methodology followed to validate its performance and we elaborate on our experiences in implementing the tool in the three corporate environments. We present the results obtained from deploying the detection system in real network infrastructure over a period of six months, the lessons learned, issues experienced, and potential limitations. Arnau Erola, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
J. Inf. Secur. Appl. | 3 |
| 2021 | Practitioners' Views on Cybersecurity Control Adoption and EffectivenessabstractCybersecurity practitioners working in organisations implement risk controls aiming to improve the security of their systems. Determining prioritisation of the deployment of controls and understanding their likely impact on overall cybersecurity posture is challenging, yet without this understanding there is a risk of implementing inefficient or even harmful security practices. There is a critical need to comprehend the value of controls in reducing cyber-risk exposure in various organisational contexts, and the factors affecting their usage. Such information is important for research into cybersecurity risk and defences, for supporting cybersecurity decisions within organisations, and for external parties guiding cybersecurity practice such as standards bodies and cyber-insurance companies. Louise Axon, Arnau Erola, Alastair Janse van Rensburg, Jason R. C. Nurse, Michael Goldsmith, Sadie Creese |
ARES | 5 |
| 2021 | Control Effectiveness: a Capture-the-Flag StudyabstractAs cybersecurity breaches continue to increase in number and cost, and the demand for cyber-insurance rises, the ability to reason accurately about an organisation’s residual risk is of paramount importance. Security controls are integral to risk practice and decision-making: organisations deploy controls in order to reduce their risk exposure, and cyber-insurance companies provide coverage to these organisations based on their cybersecurity posture. Therefore, in order to reason about an organisation’s residual risk, it is critical to possess an accurate understanding of the controls organisations have in place and of the influence that these controls have on the likelihood that organisations will be harmed by a cyber-incident. Supporting evidence, however, for the effectiveness of controls is often lacking. With the aim of enriching internal threat data, in this article we explore a practical exercise in the form of a capture-the-flag (CTF) study. We experimented with a set of security controls and invited four professional penetration testers to solve the challenges. The results indicate that CTFs are a viable path for enriching threat intelligence and examining security controls, enabling us to begin to theorise about the relative effectiveness of certain risk controls on the face of threats, and to provide some recommendations for strengthening the cybersecurity posture. Arnau Erola, Louise Axon, Alastair Janse van Rensburg, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
ARES | 5 |
| 2021 | A Novel Behavioural Screenlogger Detection System
Hugo Sbai, Jassim Happa, Michael Goldsmith |
ISC | 3 |
| 2021 | Sonification to Support the Monitoring Tasks of Security Operations CentresabstractSonification (the representation of data as sound) may offer a solution to some of the network-security monitoring challenges faced in security operations centres (SOCs). Prior work has shown that sonification can present network-security information to humans effectively, and indicated that security practitioners foresee potential for sonification to aid in scenarios related to their work. The use of sonification by security practitioners in tasks relevant to SOCs has not been examined, however. To address this gap, we assessed the use of sonification by security practitioners in network-security monitoring tasks in an experimental setting. We report on the results of a study in which we compared the performance of security practitioners using a Security Information and Event Management (SIEM) tool with their performance using a SIEM tool that incorporated sonification, in a primary and a non-primary monitoring task. In both tasks, a number of aspects of the monitoring performance of participants were significantly improved when sonification was used. Our results support the potential for sonification to aid in SOC tasks, and indicate a need to validate the utility of sonification systems by running them in operational SOCs. Louise Axon, Jassim Happa, Alastair Janse van Rensburg, Michael Goldsmith, Sadie Creese |
IEEE Trans. Dependable Secur. Comput. | 4 |
| 2020 | Design and deployment of a real-time AI-based telehealth system for deterioration prediction of critical-care patients in a large children's hospital
Fu-Chiang Tsui, Lingyun Shi, Victor M. Ruiz, Fan Mi, Michael Goldsmith, Maryam Y. Naim, Jorge A. Gálvez, Allan F. Simpao |
AMIA | 5 |
| 2020 | Dataset Construction and Analysis of Screenshot MalwareabstractAmong the various types of spyware, screenloggers are distinguished by their ability to capture screenshots. This gives them considerable nuisance capacity, giving rise to theft of sensitive data or, failing that, to serious invasions of the privacy of users. Several examples of attacks relying on this screen capture feature have been documented in recent years. However, there is not sufficient empirical and experimental evidence on this topic. Indeed, to the best of our knowledge, there is no dataset dedicated to screenshot-taking malware until today. The lack of datasets or common testbed platforms makes it difficult to analyse and study their behaviour in order to develop effective countermeasures. The screenshot feature is often a smart feature that does not activate automatically once the malware has infected the machine; the activation mechanisms of this function are often more complex. Consequently, a dataset which is completely dedicated to them would make it possible to better understand the subtleties of triggering screenshots and even to learn to distinguish them from the legitimate applications widely present on devices. The main purpose of this paper is to build such a dataset and analyse the behaviour of screenloggers. Hugo Sbai, Jassim Happa, Michael Goldsmith, Samy Meftali |
TrustCom | 3 |
| 2019 | Leveraging temporal patterns in physiological variables for prediction of critical events in single ventricle infants
Victor M. Ruiz, Jorge A. Gálvez, Michael Goldsmith, Maryam Y. Naim, Alejandro Lopez-Magallon, Ricardo Munoz, Rich Tsui |
AMIA | 3 |
| 2019 | Nonsense Attacks on Google Assistant and Missense Attacks on Amazon AlexaabstractThis paper presents novel attacks on voice-controlled digital assistants using nonsensical word sequences. We present the results of a small-scale experiment which demonstrates that it is possible for malicious actors to gain covert access to a voice-controlled system by hiding commands in apparently nonsensical sounds of which the meaning is opaque to humans. Several instances of nonsensical word sequences were identified which triggered a target command in a voice-controlled digital assistant, but which were incomprehensible to humans, as shown in tests with human experimental subjects. Our work confirms the potential for hiding malicious voice commands to voice-controlled digital assistants or other speech-controlled devices in speech sounds which are perceived by humans as nonsensical. This paper also develops a novel attack concept which involves gaining unauthorised access to a voice-controlled system using apparently unrelated utterances. We present the results of a proof-of-co ncept study showing that it is possible to trigger actions in a voice-controlled digital assistant using utterances which are accepted by the system as a target command despite having a different meaning to the command in terms of human understanding. Mary K. Bispham, Ioannis Agrafiotis, Michael Goldsmith |
ICISSP | 3 |
| 2019 | Attack and Defence Modelling for Attacks via the Speech InterfaceabstractThis paper presents a high-level model of attacks via a speech interface, and of defences against such attacks. Specifically, the paper provides a summary of different types of attacks, and of the defences available to counter them, within the framework of the OODA loop model. The model facilitates an inclusive conceptualisation of attacks via the speech interface, and serves as a basis for critical analysis of the currently available defence measures. Mary K. Bispham, Ioannis Agrafiotis, Michael Goldsmith |
ICISSP | 3 |
| 2019 | Understanding the Radical Mind: Identifying Signals to Detect Extremist Content on TwitterabstractThe Internet and, in particular, Online Social Networks have changed the way that terrorist and extremist groups can influence and radicalise individuals. Recent reports show that the mode of operation of these groups starts by exposing a wide audience to extremist material online, before migrating them to less open online platforms for further radicalization. Thus, identifying radical content online is crucial to limit the reach and spread of the extremist narrative. In this paper, our aim is to identify measures to automatically detect radical content in social media. We identify several signals, including textual, psychological and behavioural, that together allow for the classification of radical messages. Our contribution is threefold: (1) we analyze propaganda material published by extremist groups and create a contextual text-based model of radical content, (2) we build a model of psychological properties inferred from these material, and (3) we evaluate these models on Twitter to determine the extent to which it is possible to automatically identify online radical tweets. Our results show that radical users do exhibit distinguishable textual, psychological, and behavioural properties. We find that the psychological properties are among the most distinguishing features. Additionally, our results show that textual models using vector embedding features significantly improves the detection over TF-IDF features. We validate our approach on two experiments achieving high accuracy. Our findings can be utilized as signals for detecting online radicalization activities. Mariam Nouh, Jason R. C. Nurse, Michael Goldsmith |
ISI | 3 |
| 2019 | Hearing attacks in network data: An effectiveness study
Louise Axon, Jassim Happa, Michael Goldsmith, Sadie Creese |
Comput. Secur. | 3 |
| 2017 | PB-PKI: A Privacy-aware Blockchain-based PKIabstractConventional public-key infrastructure (PKI) designs using certificate authorities and web-of-trust are not optimal and have security flaws. The properties afforded by the Bitcoin blockchain are a natural solution to some of the problems with PKI - in particular, certificate transparency and elimination of single points-offailure. Proposed blockchain-based PKI designs are built as public ledgers linking identity with public key, providing no privacy. We consider cases requiring privacy-aware PKIs, which do not link identity with public key. We show that blockchain technology can be used to construct a privacy-aware PKI while eliminating some of the problems of conventional PKI, and present PB-PKI, a privacy-aware blockchain-based PKI. Louise Axon, Michael Goldsmith |
SECRYPT | 2 |
| 2016 | A Pragmatic System-failure Assessment and Response ModelabstractSeveral attack models exist today that attempt to describe cyber-attacks to varying degrees of granularity. Fast and effective decision-making during cyber-attacks is often vital, especially during incidents in which reputation, finance and physical damage can have a crippling effect on people and organisations. Such attacks can render an organisation paralysed, and it may cease to function, we refer to such an incident as a “System Failure”. In this paper we propose a novel conceptual model to help analysts make pragmatic decisions during a System Failure. Our model distils the essence of attacks and provides an easy-to-remember framework intended to help analysts ask relevant questions at the right time, irrespective of what data is available to them. Using abstraction-based reasoning our model allows enterprises to achieve “some” situational awareness during a System Failure, but more importantly, enable them to act upon their understanding and to justify their decisions. Abstraction drives the reasoning process making the approach relevant today and in the future, unlike several existing models that become deprecated over time (as attacks evolve). In the future, it will be necessary to trial the model in exercises to assess its value. Jassim Happa, Graham Fairclough, Jason R. C. Nurse, Ioannis Agrafiotis, Michael Goldsmith, Sadie Creese |
ICISSP | 5 |
| 2015 | An overview of insider attacks in cloud computingabstractSummary Cloud computing offers the potential for significant cost reductions and increased agility for users. However, security concerns continue to be raised as a potential barrier to uptake for private, community and public clouds. A report from the European Network and Information Security Agency on the Priorities for Research on Current and Emerging Network Technologies highlighted trusted cloud models as one of its top priorities for further research. More recently—September 2012—Carnegie Mellon University's computer emergency response team have released a paper describing insider threats to cloud computing as a direction for new research. Further, a project completed at the University of Warwick in 2010 investigated security aspects of cloud computing and in particular the potential for cascade effects. This research involved a detailed modelling of the threat and vulnerability landscape, including the incentives and motivations that might drive attackers. One of the conclusions is that insider threats potentially pose the most significant source of risk. This paper presents the progress made on furthering this research by investigating what attacks are available to insiders together with the damage and implications of such attacks. Copyright © 2014 John Wiley & Sons, Ltd. Adrian J. Duncan, Sadie Creese, Michael Goldsmith |
Concurr. Comput. Pract. Exp. | 3 |
| 2014 | Inferring social relationships from technology-level device connectionsabstractTechnology is present in every area of our lives and, for many, life without it has become unthinkable. As a consequence of this dependence and the extent to which technology devices (computers, tablets and smartphones) are being used for work and social activities, a clear coupling between devices and their owners can now be observed. By coupling, we specifically refer to the fact that information present on a person's device, be it user-generated or created by the native OS, can produce great insight into their life. In this paper, we look to exploit this coupling to investigate whether connections between technology devices recorded in system log-files, can be used to make inferences about the social relationships between device owners. A key motivation here is to better understand and elucidate the privacy risks associated with the digital footprints that we as humans (often inadvertently) create. Our work draws upon Social Network Analysis and basic Computer Forensics to develop and achieve the inference goals. From our preliminary experimentation, we demonstrate that human social relationships can indeed be inferred even within our limited initial scope. To further investigate the level of privacy exposure from technology-level links, we outline a more comprehensive plan of experimentation that will be conducted in future work. Jason R. C. Nurse, Jess Pumphrey, Thomas Gibson-Robinson, Michael Goldsmith, Sadie Creese |
PST | 4 |
| 2013 | Communicating trustworthiness using radar graphs: A detailed lookabstractThe amount of trust we, as human-beings, place in each other or an object (e.g., online information) is typically guided by several trust factors and antecedents. These factors can vary in importance depending on the individual making the trust decision and also on the situation - such is actually the subjective nature of trust. In this paper, we explore this notion of factors' importance by delving into detail on some of our recent user experiments and subsequent findings, partly described in previous work. These experiments used radar graphs to communicate trustworthiness as a function of five trust factors, namely competence, popularity, recency, corroboration and proximity. Here, we expand that work by further considering the importance of each of the factors to participants, while also investigating the correlations between individuals' perceptions of trust, and aspects such as graph area or size and expected scores as calculated by linear regression analysis. More specifically, we focus on outliers and endeavour to understand what is the cause of their existence. This research contributes to the field of communicating trustworthiness now, but is also meant to act as a platform for future, more directed research on visuals intended to communicate trustworthiness. Jason R. C. Nurse, Ioannis Agrafiotis, Sadie Creese, Michael Goldsmith, Koen Lamberts |
PST | 4 |
| 2012 | Recent Developments in FDR
Philip J. Armstrong, Michael Goldsmith, Gavin Lowe, Joël Ouaknine, Hristina Palikareva, A. W. Roscoe 0001, James Worrell 0001 |
CAV | 2 |
| 2012 | Reasoning about Vulnerabilities in Dependent Information Infrastructures: A Cyber Range Experiment
Adedayo Adetoye, Sadie Creese, Michael Goldsmith |
CRITIS | 3 |
| 2012 | A Data-Reachability Model for Elucidating Privacy and Security Risks Related to the Use of Online Social NetworksabstractPrivacy and security within Online Social Networks (OSNs) has become a major concern over recent years. As individuals continue to actively use and engage with these mediums, one of the key questions that arises pertains to what unknown risks users face as a result of unchecked publishing and sharing of content and information in this space. There are numerous tools and methods under development that claim to facilitate the extraction of specific classes of personal data from online sources, either directly or through correlation across a range of inputs. In this paper we present a model which specifically aims to understand the potential risks faced should all of these tools and methods be accessible to a malicious entity. The model enables easy and direct capture of the data extraction methods through the encoding of a data-reachability matrix for which each row represents an inference or data-derivation step. Specifically, the model elucidates potential linkages between data typically exposed on social-media and networking sites, and other potentially sensitive data which may prove to be damaging in the hands of malicious parties, i.e., fraudsters, stalkers and other online and offline criminals. In essence, we view this work as a key method by which we might make cyber risk more tangible to users of OSNs. Sadie Creese, Michael Goldsmith, Jason R. C. Nurse, Elizabeth Phillips |
TrustCom | 2 |
| 2012 | Insider Attacks in Cloud ComputingabstractThe computer-security industry is familiar with the concept of a Malicious Insider. However, a malicious insider in the cloud might have access to an unprecedented amount of information and on a much greater scale. Given the level of threat posed by insiders, and the rapid growth of the cloud computing ecosystem, we examine here the concept of insider attacks in cloud computing. Specifically, if more of our assets are going to reside in the cloud, and as increasingly our lives, enterprises and prosperity may depend upon cloud, it is imperative that we understand the scope for insider attacks so that we might best prepare defenses. We need to understand whether cloud might expose our assets to increased threat in terms of both actors and attack surface. We present here an assessment of current insider threat definitions and classifications, and their applicability to the cloud. We elucidate the nature of insiders with reference to the cloud ecosystem and close with examples of insider attacks which are specific to cloud environments (and hence hard to detect using current techniques). Adrian J. Duncan, Sadie Creese, Michael Goldsmith |
TrustCom | 3 |
| 2012 | Refinement checking for privacy policies
Nikolaos Papanikolaou 0001, Sadie Creese, Michael Goldsmith |
Sci. Comput. Program. | 3 |
| 2011 | Analysis of Dependencies in Critical Infrastructures
Adedayo Adetoye, Michael Goldsmith, Sadie Creese |
CRITIS | 2 |
| 2010 | Inadequacies of Current Risk Controls for the CloudabstractIn this paper we describe where current risk controls (as documented in ISO27001/27002) for mitigating information security risks are likely to be inadequate for use in the cloud. Such an analysis could provide a rationale for prioritizing protection research, and the work presented here is part of a larger exercise designed to identify the potential for cascade attacks in the cloud, and those areas most likely to be targeted based on both an understanding of threat motivations and likely areas of vulnerability. M. Auty, Sadie Creese, Michael Goldsmith, Paul Hopkins |
CloudCom | 3 |
| 2010 | A Modelling Approach for Interdependency in Digital Systems-of-Systems Security - Extended Abstract
Adedayo Adetoye, Sadie Creese, Michael Goldsmith, Paul Hopkins |
CRITIS | 3 |
| 2010 | EnCoRe: Towards a Holistic Approach to Privacy
Nikolaos Papanikolaou 0001, Sadie Creese, Michael Goldsmith, Marco Casassa Mont, Siani Pearson |
SECRYPT | 3 |
| 2010 | Refinement-Friendly Bigraphs and SpygraphsabstractOver the past decade the successful approach to specification and mechanical analysis of correctness and security properties using CSP and its refinement checker FDR has been extended to contexts including mobile ad-hoc networks and pervasive systems. But the more scope for network reconfiguration the system exhibits, the more intricate and less obviously accurate the models must become in order to accommodate such dynamic behaviour in a language with a basically static process and communication graph. Milner's Bigraph framework, on the other hand, and in particular Blackwell's Spygraph specialisation, are ideally suited for describing intuitively such dynamic reconfigurations of a system and support notions of locality and adjacency which fit them well for reasoning, for instance, about the interface between physical and electronic security; but they lack powerful analytic tool support. Our long-term goal is to combine the best of both approaches. Unfortunately the canonical labelled transition system induced by the category-theoretic semantics of a bigraphical reactive system present a number of challenges to the refinement-based approach. Prominent amongst these is the feature that the label on a transition is the 'borrowed context' required to make the redex of some reaction rule appear in the augmented source bigraph; this means that any reaction which can already take place entirely within a given bigraph gives rise to a transition labelled only with the trivial identity context, equivalent to a tau transition in CCS or CSP, with the result that neither the reaction rule nor the agents involved can be distinguished. This makes it quite impossible for an observer of the transition system to determine whether such a reaction was desirable with respect to any specification. We are investigating ways to remedy this situation. Here we present a systematic transformation of a bigraphical reactive system, both its rules and the underlying bigraphs, with the effect that every transition becomes labelled with the specific rule that gave rise to it and the set of agents involved. We also consider how that now possibly over-precise labelling can be restricted through selective hiding and judicious forgetful renaming. Michael Goldsmith, Sadie Creese |
SEFM | 1 |
| 2008 | A Representative Function Approach to Symmetry Exploitation for CSP Refinement Checking
Nick Moffat, Michael Goldsmith, A. W. Roscoe 0001 |
ICFEM | 2 |
| 2008 | Assumption-Commitment Support for CSP Model Checking
Nick Moffat, Michael Goldsmith |
J. Autom. Reason. | 2 |
| 1987 | An Algebraic Transformation System for Occam Programs
Michael Goldsmith, A. Cox, Geoff Barrett |
STACS | 1 |