EDBT 2026 Demo / reviewers in the wild / expert
Abhishta
dblp:199/3338 · also Abhishta Abhishta
· DBLP profile ↗
7ranked-venue papers
2as first author
4since 2021 · last 2026
0000-0001-7122-3103ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 3 · 3 since 2021Software engineering, systems software and programming languages · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experimentabstractBackground : Humans remain a critical vulnerability in the cybersecurity chain. While research has explored various behavioral factors influencing phishing susceptibility, the role of national culture and individual cultural orientations remains under-researched, representing a significant gap in the literature. Aims : This study investigates the impact of individual cultural orientations on phishing victimization, while taking into account other relevant factors, such as self-control, risk-taking, technical training, email management practices, demographics (age and gender), and country-level economic and ICT development. Methods : Data were collected via an online survey of university students (N = 2,143) across 12 countries in Asia, Africa, North America, and Europe. Outcomes measures included phishing victimization, phishing recognition, and legitimate email recognition; the last two measures were assessed via scenarios. Data were analyzed using Signal Detection Theory and mixed modelling. Results : Phishing victimization was significantly associated with low self-control, high risk-taking, high exposure, and poorer recognition of legitimate emails. Conversely, cultural orientations, religiosity, and country of origin had minimal effects. While phishing recognition was unrelated to victimization, the ability to recognize legitimate emails reduced victimization risk. For culturally diverse organizations, these findings suggest that cultural factors may be less critical to phishing victimization than has been previously assumed. Training users and improved self-control techniques may help protect against phishing victimization. Marianne Junger, Pawel Olber, Rafal Plocki, J. W. (Hans) Luyten, Luka Koning, Caitlyn N. Muniz, Jan-Willem Bullee, Victoria Wang, Reinhardt A. Botha, C. Jordan Howell, Verena Distler, Xiaowei Chen 0013, Cong Hiep Pham 0001, Mohammed Aljohani, Newman U. Richards, Fabian Muhly, Abhishta, Steven Furnell |
Comput. Secur. | 17 |
| 2025 | Victimization in DDoS attacks: The role of popularity and industry sectorabstractDistributed denial-of-service (DDoS) attacks may be driven not only by economic motives such as extortion, but also by social or political goals, including hacktivism and state-sponsored operations. Therefore, the monetary value of a target alone does not fully explain why some organizations are more frequently victimized. While cloud providers deploy advanced defenses — such as Anycast routing, traffic scrubbing, and filtering — they also concentrate many potential targets within a shared infrastructure, increasing their exposure to DDoS attacks. This study aims to understand what makes organizations more suitable DDoS targets by examining two key attributes: visibility and perceived value, represented by website popularity and industry sector. We also investigate how the customer portfolio of cloud and data center providers influences the DDoS threat to their infrastructure. Research Questions: • How do organizational characteristics related to value and visibility — specifically, popularity and industry sector — correlate with the threat of DDoS attacks? • How does the diversity of customer business sectors hosted by a cloud or data center provider influence the DDoS threat to its infrastructure? Methodology: We conducted a large-scale analysis of DDoS incidents inferred from network telescope data spanning five years. We estimated target visibility and value using Alexa ranks and Cisco Umbrella content categories. We also analyzed the relationship between customer sector composition and DDoS threat at the provider level. Key Findings: • Popular websites are more frequently attacked, though this pattern weakened during the COVID-19 pandemic. • Certain industry sectors face significantly higher and repeated DDoS threats. • Cloud providers serving a higher proportion of high-risk sectors are more likely to face frequent DDoS attacks. Muhammad Yasir Muzayan Haq, Antonia Affinito, Alessio Botta, Anna Sperotto, Lambert J. M. Nieuwenhuis, Mattijs Jonker, Abhishta |
J. Inf. Secur. Appl. | 7 |
| 2024 | Deception in double extortion ransomware attacks: An analysis of profitability and credibilityabstractRansomware attacks have evolved with criminals using double extortion schemes, where they signal data exfiltration to inflate ransom demands. This development is further complicated by information asymmetry, where victims are compelled to respond to ambiguous and often deceptive signals from attackers. This study explores the complex interactions between criminals and victims during ransomware attacks, especially focusing on how data exfiltration is communicated. We use a signaling game to understand the strategies both parties use when dealing with uncertain information. We identify five distinct equilibria, each characterized by the criminals' varied approaches to signaling data exfiltration, influenced by the strategic parameters inherent in each attack scenario. Calibrating the game parameters with real-world like values, we identify the most probable equilibrium, offering insights into anticipated ransom amounts and corresponding payoffs for both victims and criminals. Our findings suggest criminals are likely to claim data exfiltration, true or not, highlighting a strategic advantage for intensifying attack efforts. The study underscores the need for victims' caution towards criminals' claims and highlights the unintended consequences of policies making false claims costlier for criminals. Tom Meurs, Edward J. Cartwright, Anna Cartwright 0001, Marianne Junger, Abhishta |
Comput. Secur. | 5 |
| 2023 | Industry 4.0 and healthcare: Context, applications, benefits and challengesabstractAbstract Industry 4.0 refers to the digital transformation in the manufacturing domain through new technology. Currently, it expands well beyond manufacturing, affecting many areas of life and posing implications for all types of business. This paper focuses on the relationships between Industry 4.0 and Healthcare which transitions to increased interconnectivity, automation and smart decision making. The integration context of Industry 4.0 into Healthcare is only partly understood. Little was done until now to consolidate what is known on the integration benefits and the challenges. This article reports results of a systematic mapping study that analysed 69 papers to extract knowledge about the concepts of Industry 4.0 and the emerging Healthcare 4.0., and the relationships between them. We found 10 different perspectives of Healthcare 4.0, ranging from strategic to tactical and operational levels. Next, our results show: (i) nine applications of Industry 4.0 in the Healthcare domain: Augmented Reality and Simulation, Autonomous Robotics, Cybersecurity, Big Data Analytics, Internet of Things, Cloud Computing, Additive Manufacturing and Systems Integration; and (ii) 10 benefits and nine challenges in Healthcare 4.0. The most frequently mentioned benefits are patients' diagnosis, monitoring, treatment, and financial benefits. The most researched challenges are data fragmentation, heterogeneity, complexity, and privacy. Konstantinos Kotzias, Faiza Allah Bukhsh, Jeewanie Jayasinghe Arachchige, Maya Daneva, Abhishta |
IET Softw. | 5 |
| 2019 | Impact of Successful DDoS Attacks on a Major Crypto-Currency ExchangeabstractDistributed Denial of Service (DDoS) attacks provide an easy option for these criminals to disrupt the business of these online platforms. We analyse the economic impact of DDoS attacks on a crypto-currency exchange using event analysis. Our contributions are fourfold: Firstly, we develop an estimation model utilising ideas from behavioural finance to predict volume of crypto-currency traded on the basis of changes in price. Secondly, we perform an event analysis to evaluate whether there is an impact of a DDoS attack on the volume traded on the exchange in 17 different cases. Thirdly, we find that in 13 cases the negative impact due to a DDoS attack is recovered within the same day by the exchange. Finally, we evaluate hourly trade data to show why in most cases the volume traded recovers within a single day. Abhishta, Reinoud Joosten, Sergey Dragomiretskiy, Lambert J. M. Nieuwenhuis |
PDP | 1 |
| 2018 | Business Model of a BotnetabstractBotnets continue to be an active threat against firms or companies and individuals worldwide. Previous research regarding botnets has unveiled information on how the system and their stakeholders operate, but an insight on the economic structure that supports these stakeholders is lacking. The objective of this research is to analyse the business model and determine the revenue stream of a botnet owner. We also study the botnet life-cycle and determine the costs associated with it on the basis of four case studies. We conclude that building a full scale cyber army from scratch is very expensive where as acquiring a previously developed botnet requires a little cost. We find that initial setup and monthly costs were minimal compared to total revenue. C. G. J. Putman, Abhishta, Lambert J. M. Nieuwenhuis |
PDP | 2 |
| 2017 | Analysing the Impact of a DDoS Attack Announcement on Victim Stock PricesabstractDDoS attacks are increasingly used by 'hackers' and 'hacktivists' for various purposes. A number of on-line tools are available to launch an attack of significant intensity. These attacks lead to a variety of losses at the victim's end. We analyse the impact of Distributed Denial-of-Service (DDoS) attack announcements over a period of 5 years on the stock prices of the victim firms. We propose a method for event studies that does not assume the cumulative abnormal returns to be normally distributed, instead we use the empirical distribution for testing purposes. In most cases we find no significant impact on the stock returns but in cases where a DDoS attack creates an interruption in the services provided to the customer, we find a significant negative impact. Abhishta, Reinoud Joosten, Lambert J. M. Nieuwenhuis |
PDP | 1 |