Mathew Nicho

dblp:28/4941 · DBLP profile ↗
← Back
9ranked-venue papers
6as first author
6since 2021 · last 2025
0000-0001-7129-3988ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 6 · 5 first-author · 3 since 2021Artificial intelligence and machine learning · 1 · 1 since 2021Computer networks · 1 · 1 since 2021Databases, data management, data science and information retrieval · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Towards an Ontological Approach to Browser Fingerprinting Detection and Privacy Risk Assessment
Christopher D. McDermott, Lankeshwara Munasinghe, Mathew Nicho
NLDB (1)3
2025 Robust Attacks Detection Model for Internet of Flying Things Based on Generative Adversarial Network (GAN) and Adversarial Training
abstract
The Internet of Flying Things (IoFT) holds significant promise in fields like disaster management and surveillance. However, it is increasingly vulnerable to cyberattacks that can compromise the confidentiality, integrity, and availability (CIA) of sensitive data. Despite the growing interest in proposing Intrusion Detection Systems (IDSs) for IoFT networks, current literature faces key limitations, particularly the shortage of publicly available IoFT datasets with diverse attacks, and the fact that existing IDSs lack robustness against sophisticated adversarial machine learning attacks. This paper is the first study to address these limitations by proposing a more resilient and accurate IDS tailored for IoFT networks (RIDS-IoFT). We introduce a novel IDS that leverages Generative Adversarial Networks (GANs) to generate a hybrid dataset that combines real IoFT traffic data with GAN-generated adversarial attacks, addressing the dataset diversity issue. Additionally, we introduce an innovative adversarial training method to enhance the system’s defense against evolving threats, such as Fast Gradient Sign Method (FGSM), Basic Iterative Method (BIM), and Carlini & Wagner (C&W) attacks. The proposed RIDS-IoFT was evaluated using four machine learning models, Random Forest (RF), Decision Tree (DT), Support Vector Machine (SVM), and Logistic Regression (LR), on two datasets: ECU-IoFT and CICIDS2018. The IDS’s performance was assessed based on its ability to detect both traditional and adversarial attacks. The results show that the Random Forest model achieved the highest detection accuracy, up to 96.5%, demonstrating superior performance across both real and hybrid datasets. The proposed RIDS-IoFT not only enhances detection accuracy but also strengthens resilience against adversarial threats, making it suitable for resource-constrained IoFT environments. In conclusion, this study presents a comprehensive approach to securing IoFT networks by combining real and synthetic data, improving IDS robustness and accuracy against both traditional and adversarial attacks.
Tarek Gaber, Tarek Ali, Mathew Nicho, Mohamed Torky
IEEE Internet Things J.3
2024 Robust thermal face recognition for law enforcement using optimized deep features with new rough sets-based optimizer
abstract
In the security domain, the growing need for reliable authentication methods highlights the importance of thermal face recognition for enhancing law enforcement surveillance and safety especially in IoT applications. Challenges like computational resources and alterations in facial appearance, e.g., plastic surgery could affect face recognition systems. This study presents a novel, robust thermal face recognition model tailored for law enforcement, leveraging thermal signatures from facial blood vessels using a new CNN architecture (Max and Average Pooling- MAP-CNN). This architecture addresses expression, illumination, and surgical invariance, providing a robust feature set critical for precise recognition in law enforcement and border control. Additionally, the model employs the NM-PSO algorithm, integrating neighborhood multi-granulation rough set (NMGRS) with particle swarm optimization (PSO), which efficiently handles both categorical and numerical data from multi-granulation perspectives, leading to a 57% reduction in feature dimensions while maintaining high classification accuracy outperforming ten contemporary models on the Charlotte-ThermalFace dataset by about 10% across key metrics. Rigorous statistical tests confirm NM-PSO’s superiority, and further robustness testing of the face recognition model against image ambiguity and missing data demonstrated its consistent performance, enhancing its suitability for security-sensitive environments with 99% classification accuracy.
Tarek Gaber, Mathew Nicho, Esraa Ahmed, Ahmed Hamed Attia
J. Inf. Secur. Appl.2
2023 Bypassing Multiple Security Layers Using Malicious USB Human Interface Device
abstract
Cited by: 4 (Scopus)
Mathew Nicho, Ibrahim Sabry
ICISSP1
2023 A System Dynamics Approach to Evaluate Advanced Persistent Threat Vectors
abstract
Cyber-attacks targeting high-profile entities are focused, persistent, and employ common vectors with varying levels of sophistication to exploit social-technical vulnerabilities. Advanced persistent threats (APTs) deploy zero-day malware against such targets to gain entry through multiple security layers, exploiting the dynamic interplay of vulnerabilities in the target network. System dynamics (SD) offers an alternative approach to analyze non-linear, complex, and dynamic social-technical systems. This research applied SD to three high-profile APT attacks - Equifax, Carphone, and Zomato - to identify and simulate socio-technical variables leading to breaches. By modeling APTs using SD, managers can evaluate threats, predict attacks, and reduce damage by mitigating specific socio-technical cues. This study provides valuable insights into the dynamics of cyber threats, making it the first to apply SD to APTs.
Mathew Nicho, Christopher D. McDermott, Hussein Fakhry, Shini Girija
Int. J. Inf. Secur. Priv.1
2022 Systems Dynamics Modeling for Evaluating Socio-Technical Vulnerabilities in Advanced Persistent Threats
abstract
The paper focus on the application of Systems Dynamics Modelling (SDM) for simulating socio-technical vulnerabilities of Advanced Persistent Threats (APT) to unravel Human Computer Interaction (HCI) for strategic visibility of threat actors. SDM has been widely applied to analyze nonlinear, complex, and dynamic systems in social sciences and technology. However, its application in the cyber security domain especially APT that involve complex and dynamic human computer interaction is a promising but scant research domain. While HCI deals with the interaction between one or more humans and between one or more computers for greater usability, this same interactive process is exploited by the APT actor. In this respect, using a data breach case study, we applied the socio-technical vulnerabilities classification as a theoretical lens to model socio and technical vulnerabilities on systems dynamics using Vensim software. The variables leading to the breach were identified, entered into Vensim software, and simulated to get the results. The results demonstrated an optimal interactive mix of one or more of the six socio variables and three technical variables leading to the data breach. SDM approach thus provides insights into the dynamics of the threat as well as throw light on the strategies to undertake for minimizing APT risks. This can assist in the reduction of the attack surface and reinforce mitigation efforts (prior to exfiltration) should an APT attack occur. In this paper, we thus propose and validate the application of system dynamics approach for designing a dynamic threat assessment framework for socio-technical vulnerabilities of APT.
Mathew Nicho, Shini Girija
HSI1
2018 A process model for implementing information systems security governance
abstract
Purpose The frequent and increasingly potent cyber-attacks because of lack of an optimal mix of technical as well as non-technical IT controls has led to increased adoption of security governance controls by organizations. The purpose of this paper, thus, is to construct and empirically validate an information security governance (ISG) process model through the plan–do–check–act (PDCA) cycle model of Deming. Design/methodology/approach This descriptive research using an interpretive paradigm follows a qualitative methodology using expert interviews of five respondents working in the ISG domain in United Arab Emirates (UAE) to validate the theoretical model. Findings The findings of this paper suggest the primacy of the PDCA Deming cycle for initiating ISG through a risk-based approach assisted by industry-wide best practices in ISG. Regarding selection of ISG frameworks, respondents preferred to have ISO 27K supported by NIST as the core framework with other relevant ISG frameworks/standards forming the peripheral layer. The implementation focus of the ISG model is on mapping ISO 27K/NIST IT controls relevant IT controls selected from ISG frameworks from a horizontal and vertical perspective. Respondents asserted the automation of measurement and control mechanism through automation to assist in the feedback loop of the PDCA cycle. Originality/value The validated model helps academics and practitioners gain insight into the methodology of the phased implementation of an information systems governance process through the PDCA model, as well as the positioning of ITG and ITG frameworks in ISG. Practitioners can glean valuable insights from the empirical section of the research where experts detail the success factors, the sequential steps and justification of these factors in the ISG implementation process.
Mathew Nicho
Inf. Comput. Secur.1
2014 Identifying Vulnerabilities of Advanced Persistent Threats: An Organizational Perspective
abstract
One of the most serious and persistent threat that has emerged in recent years combining technical as well as non-technical skills is the Advanced Persistent Threat, commonly known as APT where hackers circumvent the organizational defenses and instead target the naivety of the employees in making an unintentional mistake. While this threat has gained prominence in recent years, research on its cause and mitigation is still at the infancy stage. In this paper the authors explore APT vulnerabilities from an organizational perspective to create a taxonomy of non-technical and technical vulnerabilities. The objective is to enhance awareness and detection of APT vulnerabilities by managers and end users. To this end, the authors conducted interviews with senior IT managers in three large organizations in Dubai, United Arab Emirates. The analysis of the findings suggested that the APT threat environment is affected by multiple factors spanning primarily non-technical as well as technical vulnerabilities.
Mathew Nicho, Shafaq Khan
Int. J. Inf. Secur. Priv.1
2011 An Integrated Security Governance Framework for Effective PCI DSS Implementation
abstract
This paper analyses relevant IT governance and security frameworks/standards used in IT assurance and security to propose an integrated framework for ensuring effective PCI DSS implementation. Merchants dealing with credit cards have to comply with the Payment Card Industry Data Security Standards (PCI DSS) or face penalties for non-compliance. With more transactions based on credit cards, merchants are finding it costly and increasingly difficult to implement and interpret the PCI standard. One of the top reasons cited for merchants to fail PCI audit, and a leading factor in data theft, is the failure to adequately protect stored cardholder data. Although implementation of the PCI DSS is not a guarantee for perfect protection, effective implementation of the PCI standards can be ensured through the divergence of the PCI standard into wider information security governance to provide a comprehensive overview of information security based not only on security but also security audit and control. The contribution of this paper is the development of an integrated comprehensive security governance framework for ‘information security’ (rather than data protection) incorporating Control Objectives for Information and related Technology (COBIT), Information Technology Infrastructure Library (ITIL) and ISO 27002.
Mathew Nicho, Hussein Fakhry, Charles Haiber
Int. J. Inf. Secur. Priv.1