EDBT 2026 Demo / reviewers in the wild / expert
Shamal Faily
dblp:68/7861
· DBLP profile ↗
28ranked-venue papers
12as first author
5since 2021 · last 2024
0000-0002-2859-1143ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 16 · 7 first-author · 5 since 2021Software engineering, systems software and programming languages · 6 · 4 first-authorHuman-computer interaction and ubiquitous computing · 4 · 1 first-authorApplied, interdisciplinary, general and emerging computing · 2
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2024 | Human factors and cyber-security risks on the railway - the critical role played by signalling operationsabstractPurpose Railways are a well-known example of complex critical infrastructure, incorporating socio-technical systems with humans such as drivers, signallers, maintainers and passengers at the core. The technological evolution including interconnectedness and new ways of interaction lead to new security and safety risks that can be realised, both in terms of human error, and malicious and non-malicious behaviour. This study aims to identify the human factors (HF) and cyber-security risks relating to the role of signallers on the railways and explores strategies for the improvement of “Digital Resilience” – for the concept of a resilient railway. Design/methodology/approach Overall, 26 interviews were conducted with 21 participants from industry and academia. Findings The results showed that due to increased automation, both cyber-related threats and human error can impact signallers’ day-to-day operations – directly or indirectly (e.g. workload and safety-critical communications) – which could disrupt the railway services and potentially lead to safety-related catastrophic consequences. This study identifies cyber-related problems, including external threats; engineers not considering the human element in designs when specifying security controls; lack of security awareness among the rail industry; training gaps; organisational issues; and many unknown “unknowns”. Originality/value The authors discuss socio-technical principles through a hexagonal socio-technical framework and training needs analysis to mitigate against cyber-security issues and identify the predictive training needs of the signallers. This is supported by a systematic approach which considers both, safety and security factors, rather than waiting to learn from a cyber-attack retrospectively. Eylem Thron, Shamal Faily, Huseyin Dogan, Martin Freer |
Inf. Comput. Secur. | 2 |
| 2022 | Assessing system of systems information security risk with OASoSISabstractThe term System of Systems (SoS) is used to describe the coming together of independent systems, collaborating to achieve a new or higher purpose. However, the SoS concept is often misunderstood within operational environments, providing challenges towards the secure design and operation of SoSs. Limitations in existing literature indicates a need for discovery towards identifying a combination of concepts, models, and techniques suitable for assessing SoS security risk and related human factor concerns for SoS Requirements Engineering. In this article, we present OASoSIS, representing an information security risk assessment and modelling process to assist risk-based decision making in SoS Requirements Engineering. A characterisation process is introduced to capture the SoS context, supporting a SoS security risk assessment process that extends OCTAVE Allegro towards a SoS context. Resulting risk data provides a focused means to assess and model the SoS information security risk and related human factors, integrating tool-support using CAIRIS. A medical evacuation SoS case study scenario was used to test, illustrate, and validate the alignment of concepts, models, and techniques for assessing SoS information security risks with OASoSIS, where findings provide a positive basis for future work. Duncan Ki-Aries, Shamal Faily, Huseyin Dogan, Christopher Williams 0001 |
Comput. Secur. | 2 |
| 2021 | Use-Case Informed Task Analysis for Secure and Usable Design Solutions in Rail
Amna Altaf, Shamal Faily, Huseyin Dogan, Alexios Mylonas, Eylem Thron |
CRITIS | 2 |
| 2021 | Evaluating privacy - determining user privacy expectations on the webabstractIndividuals don’t often have privacy expectations. When asked to consider them, privacy realities were frequently perceived not to meet these expectations. Some websites exploit the trust of individuals by selling, sharing, or analysing their data. Without intervention, individuals do not often understand privacy implications, nor do anything to address it. This study has identified that many users do not have privacy expectations. An extension developed for this study improved privacy awareness, privacy behaviour, and created privacy expectations in participants. The extension also demonstrated that privacy-focused behavioural changes occur when individuals consider the implications of privacy policies, and are exposed to the ways in which their data is being used. Callum Pilton, Shamal Faily, Jane Henriksen-Bulmer |
Comput. Secur. | 2 |
| 2021 | Visualising personas as goal models to find security tensionsabstractPurpose This paper aims to present a tool-supported approach for visualising personas as social goal models, which can subsequently be used to identify security tensions. Design/methodology/approach The authors devised an approach to partially automate the construction of social goal models from personas. The authors provide two examples of how this approach can identify previously hidden implicit vulnerabilities and validate ethical hazards faced by penetration testers and their safeguards. Findings Visualising personas as goal models makes it easier for stakeholders to see implications of their goals being satisfied or denied and designers to incorporate the creation and analysis of such models into the broader requirements engineering (RE) tool-chain. Originality/value The approach can be used with minimal changes to existing user experience and goal modelling approaches and security RE tools. Shamal Faily, Claudia Iacob, Raian Ali, Duncan Ki-Aries |
Inf. Comput. Secur. | 1 |
| 2020 | The Impact of Undergraduate Mentorship on Student Satisfaction and Engagement, Teamwork Performance, and Team Dysfunction in a Software Engineering Group ProjectabstractMentorship schemes in software engineering education usually involve professional software engineers guiding and advising teams of undergraduate students working collaboratively to develop a software system. With or without mentorship, teams run the risk of experiencing team dysfunction: a situation where lack of engagement, internal conflicts, and/or poor team management lead to different assessment outcomes for individual team members and overall frustration and dissatisfaction within the team. The paper describes a mentorship scheme devised as part of a 33 week software engineering group project course, where the mentors were undergraduate students who had recently completed the course successfully and possessed at least a year's experience as professional software engineers. We measure and discuss the impact the scheme had on: (1) student satisfaction and engagement, (2) team performance, and (3) team dysfunction. Claudia Iacob, Shamal Faily |
SIGCSE | 2 |
| 2019 | Usable and Secure Requirements Engineering with CAIRISabstractSoftware needs to satisfy a range of security, privacy, and usability requirements. Eliciting them entails using design techniques both within and outside Requirements Engineering, together with tool-support which can analyse and make sense of requirements and other design concepts as early stage designs evolve. This half-day tutorial introduces participants to CAIRIS, and how it can be used to engineer requirements for usable and secure software. Participants will be given the chance to use CAIRIS with selected usability and security design techniques, and learn how CAIRIS has and can be deployed in real-world projects. Shamal Faily, Duncan Ki-Aries |
RE | 1 |
| 2019 | Privacy risk assessment in context: A meta-model based on contextual integrityabstractPublishing data in open format is a growing trend, particularly for public bodies who have a legal obligation to make data available as open data. We look at the privacy implications of publishing open data and, in particular, how organisations can make informed decisions around privacy risks in relation to open data publishing before publication occurs. Using a well established theoretical privacy assessment framework, Contextual Integrity, we illustrate how this can be translated into a practical meta-model that can assist public bodies in assessing what privacy implications or risks might be associated with making a particular dataset available as open data. We validate the meta-model by providing a worked example and illustrate the effectiveness of this by reference to a case study application where the meta-model was successfully applied in practice. Jane Henriksen-Bulmer, Shamal Faily, Sheridan Jeary |
Comput. Secur. | 2 |
| 2019 | A normative decision-making model for cyber securityabstractPurpose The purpose of this paper is to investigate security decision-making during risk and uncertain conditions and to propose a normative model capable of tracing the decision rationale. Design/methodology/approach The proposed risk rationalisation model is grounded in literature and studies on security analysts’ activities. The model design was inspired by established awareness models including the situation awareness and observe–orient–decide–act (OODA). Model validation was conducted using cognitive walkthroughs with security analysts. Findings The results indicate that the model may adequately be used to elicit the rationale or provide traceability for security decision-making. The results also illustrate how the model may be applied to facilitate design for security decision makers. Research limitations/implications The proof of concept is based on a hypothetical risk scenario. Further studies could investigate the model’s application in actual scenarios. Originality/value The paper proposes a novel approach to tracing the rationale behind security decision-making during risk and uncertain conditions. The research also illustrates techniques for adapting decision-making models to inform system design. Andrew M'manga, Shamal Faily, John McAlaney, Christopher Williams 0001, Youki Kadobayashi, Daisuke Miyamoto |
Inf. Comput. Secur. | 2 |
| 2019 | Exploring the gap between the student expectations and the reality of teamwork in undergraduate software engineering group projects
Claudia Iacob, Shamal Faily |
J. Syst. Softw. | 2 |
| 2017 | Using Extreme Characters to Teach Requirements EngineeringabstractOne of the main challenges in teaching Software Engineering as an undergraduate course is making the need for software processes and documentation obvious. Armed with some knowledge of programming, students may feel inclined to skip any development phase not involving coding. This is most pronounced when dealing with the Requirements Engineering practices. In this paper, we describe a practical approach to teaching Requirements Engineering using Extreme Characters. The exercise aimed to achieve the following learning objectives: a) understanding the need of including the end user in any requirements analysis phase, b) identifying the requirements engineering phase as a iterative process, c) understanding the necessity of constantly double checking the analysts interpretation of the user requirements, d) ensuring the rigorous documentation of both user and system requirements, and e) identifying the place of requirements engineering in the overall development process, and the forces and challenges around this phase of development. Claudia Iacob, Shamal Faily |
CSEE&T | 2 |
| 2017 | Re-framing "the AMN": A case study eliciting and modelling a System of Systems using the Afghan Mission NetworkabstractThe term System of Systems (SoS) is often used to classify an arrangement of independent and interdependent systems delivering unique capabilities. There appear to be many examples of SoSs, but the term has become a source of confusion. While many approaches have been proposed for engineering SoSs, there are few illustrative examples demonstrating their initial classification and resulting SoS structure. This paper presents an approach for framing a candidate SoS using the Afghan Mission Network defined as an Acknowledged SoS, and presents issues associated with SoSs stakeholders, human factors and interoperability considerations resulting from such an approach. Duncan Ki-Aries, Shamal Faily, Huseyin Dogan, Christopher Williams 0001 |
RCIS | 2 |
| 2017 | System design considerations for risk perceptionabstractThe perception of risk is a driver for security analysts' decision making. However, security analysts may have conflicting views of a risk based on personal, system and environmental factors. This difference in perception and opinion, may impact effective decision making. In this paper, we propose a model that highlights areas contributing to the perception of risk in a socio-technical environment and their implication to system design. We validate the model through the use of a hypothetical scenario, which is grounded in both the literature and empirical data. Andrew M'manga, Shamal Faily, John McAlaney, Christopher Williams 0001 |
RCIS | 2 |
| 2017 | Folk Risk Analysis: Factors Influencing Security Analysts' Interpretation of Risk
Andrew M'manga, Shamal Faily, John McAlaney, Christopher Williams 0001 |
SOUPS | 2 |
| 2017 | Persona-centred information security awarenessabstractMaintaining Information Security and protecting data assets remains a principal concern for businesses. Many data breaches continue to result from accidental, intentional or malicious human factors, leading to financial or reputational loss. One approach towards improving behaviours and culture is with the application of on-going awareness activities. This paper presents an approach for identifying security related human factors by incorporating personas into information security awareness design and implementation. The personas, which are grounded in empirical data, offer a useful method for identifying audience needs and security risks, enabling a tailored approach to business-specific awareness activities. As a means for integrating personas, we present six on-going steps that can be embedded into business-as-usual activities with 90-day cycles of awareness themes, and evaluate our approach with a case study business. Our findings suggest a persona-centred information security awareness approach has the capacity to adapt to the time and resource required for its implementation within the business, and offer a positive contribution towards reducing or mitigating Information Security risks through security awareness. Duncan Ki-Aries, Shamal Faily |
Comput. Secur. | 2 |
| 2016 | Finding and resolving security misusability with misusability casesabstractAlthough widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. This paper describes how misusability cases, scenarios that describe how design decisions may lead to usability problems subsequently leading to system misuse, address this problem. We describe the related work upon which misusability cases are based before presenting the approach, and illustrating its application using a case study example. Finally, we describe some findings from this approach that further inform the design of usable and secure systems. Shamal Faily, Ivan Flechais |
Requir. Eng. | 1 |
| 2015 | "Water, Water, Every Where": Nuances for a Water Industry Critical Infrastructure Specification Exemplar
Shamal Faily, George Stergiopoulos, Vasilios Katos, Dimitris Gritzalis |
CRITIS | 1 |
| 2015 | Engaging stakeholders during late stage security design with assumption personasabstractPurpose – This paper aims to present an approach where assumption personas are used to engage stakeholders in the elicitation and specification of security requirements at a late stage of a system’s design. Design/methodology/approach – The author has devised an approach for developing assumption personas for use in participatory design sessions during the later stages of a system’s design. The author validates this approach using a case study in the e-Science domain. Findings – Engagement follows by focusing on the indirect, rather than direct, implications of security. More design approaches are needed for treating security at a comparatively late stage. Security design techniques should scale to working with sub-optimal input data. Originality/value – This paper contributes an approach where assumption personas engage project team members when eliciting and specifying security requirements at the late stages of a project. Shamal Faily |
Inf. Comput. Secur. | 1 |
| 2015 | Special section: software quality for mobile apps
Claudia Iacob, Shamal Faily, David Bell |
Softw. Qual. J. | 2 |
| 2012 | On the Design and Development of webinos: A Distributed Mobile Application Middleware
John Lyle, Shamal Faily, Ivan Flechais, André Paul, Ayse Göker, Hans I. Myrhaug, Heiko Desruelle, Andrew P. Martin |
DAIS | 2 |
| 2011 | Here's Johnny: A Methodology for Developing Attacker PersonasabstractThe adversarial element is an intrinsic part of the design of secure systems, but our assumptions about attackers and threat is often limited or stereotypical. Although there has been previous work on applying User-Centered Design on Persona development to build personas for possible attackers, such work is only speculative and fails to build upon recent research. This paper presents an approach for developing Attacker Personas which is both grounded and validated by structured data about attackers. We describe a case study example where the personas were developed and used to support the development of a Context of Use description for the EU FP7 webinos project. Andrea S. Atzeni, Cesare Cameroni, Shamal Faily, John Lyle, Ivan Flechais |
ARES | 3 |
| 2011 | User-Centered Information Security Policy Development in a Post-Stuxnet WorldabstractA balanced approach is needed for developing information security policies in Critical National Infrastructure (CNI) contexts. Requirements Engineering methods can facilitate such an approach, but these tend to focus on either security at the expense of usability, or vice-versa, it is also uncertain whether existing techniques are useful when the time available for applying them is limited. In this paper, we describe a case study where Usability and Requirements Engineering techniques were used to derive missing requirements for an information security policy for a UK water company following reports of the Stuxnet worm. We motivate and describe the approach taken while carrying out this case study, and conclude with three lessons informing future efforts to integrate Security, Usability, and Requirements Engineering techniques for secure system design. Shamal Faily, Ivan Flechais |
ARES | 1 |
| 2011 | Persona cases: a technique for grounding personasabstractPersonas are a popular technique in User-Centered Design, however their validity can be called into question. While the techniques used to developed personas and their integration with other design activities provide some measure of validity, a persona's legitimacy can be threatened by challenging its characteristics. This note presents Persona Cases: personas whose characteristics are both grounded in, and traceable to their originating source of empirical data. This approach builds on the premise that sense-making in qualitative data analysis is an argumentative activity, and aligns concepts associated with a Grounded Theory analysis with recent work on arguing the characteristics of personas. We illustrate this approach using a case study in the Critical Infrastructure Protection domain. Shamal Faily, Ivan Flechais |
CHI | 1 |
| 2011 | Eliciting usable security requirements with misusability casesabstractAlthough widely used for both security and usability concerns, scenarios used in security design may not necessarily inform the design of usability, and vice-versa. One way of using scenarios to bridge security and usability involves explicitly describing how design decisions can lead to users inadvertently exploiting vulnerabilities to carry out their production tasks. We present Mis-usability Cases: scenarios which describe how design decisions may lead to usability problems subsequently leading to system misuse. We describe the steps carried out to develop and apply misusability cases to elicit requirements and report preliminary results applying this technique in a recent case study. Shamal Faily, Ivan Flechais |
RE | 1 |
| 2010 | Analysing and Visualising Security and Usability in IRISabstractDespite a long standing need to incorporate human factors into security risk analysis, taking a balanced approach to analysing security and usability concerns remains a challenge. Balancing security and usability is difficult due to human biases in security perception, and managing the sheer volume of data arising from risk and task analysis. This paper presents an approach for qualitatively and quantitively analysing and visualising the results of risk and task analysis. We demonstrate this approach using a realistic example, and we discuss how these techniques fit within the larger context of secure systems design. Shamal Faily, Ivan Flechais |
ARES | 1 |
| 2010 | To boldly go where invention isn't secure: applying security entrepreneurship to secure systems designabstractWhen designing secure systems, we are inundated with an eclectic mix of security and non-security requirements; this makes predicting a successful outcome from the universe of possible security design decisions a difficult problem. We propose augmenting the process of security design with the paradigm of Security Entrepreneurship: the application of innovation models and principles to organise, create, and manage security design elements to bring about improved system security. We propose three initial Security Entrepreneurship techniques as examples of this paradigm, describe how their underlying models align with secure systems design, and help predict the social and technical impact of possible design decisions. We also pose a number of thought experiments, and suggest possible research agendas for Security Entrepreneurship. Shamal Faily, Ivan Flechais |
NSPW | 1 |
| 2010 | Designing and Aligning e-Science Security Culture with DesignabstractPurpose The purpose of this paper is to identify the key cultural concepts effecting security in multi‐organisational systems and align these with design techniques and tools. Design/methodology/approach A grounded theory model of security culture was derived from the related security culture literature and empirical data from an e‐Science project. Influencing concepts were derived from these and aligned with recent work on techniques and tools for usable secure systems design. Findings Roles and responsibility, sub‐cultural norms and contexts, and different perceptions of requirements were found to be influencing concepts towards a culture of security. These concepts align with recent work on personas, environment models, and related tool support. Originality/value This paper contributes a theoretically and empirically grounded model of security culture. This is also the first paper explicitly aligning key concepts of security culture to design techniques and tools. Shamal Faily, Ivan Flechais |
Inf. Manag. Comput. Secur. | 1 |
| 2009 | Context-Sensitive Requirements and Risk Management with IRISabstractMany systems are not designed for their contexts of operation. Subtle changes to context may lead to an increase in severity and likelihood of vulnerabilities and threats. The IRIS framework integrates the notion of context into requirements and risk management, by means of an integrated meta-model, design method, and software prototype. By applying this framework, requirements and risk analysis can be better situated for system contexts of operation. Shamal Faily, Ivan Flechais |
RE | 1 |