EDBT 2026 Demo / reviewers in the wild / expert
Helge Janicke
dblp:69/1646
· DBLP profile ↗
45ranked-venue papers
2as first author
13since 2021 · last 2026
0000-0002-1345-2829ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 1 first-author · 5 since 2021Computer networks · 7 · 3 since 2021Applied, interdisciplinary, general and emerging computing · 5 · 1 first-author · 2 since 2021Software engineering, systems software and programming languages · 2Human-computer interaction and ubiquitous computing · 2 · 2 since 2021Artificial intelligence and machine learning · 1Databases, data management, data science and information retrieval · 1 · 1 since 2021Theory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | From Oversight to Insight: Transforming Cybersecurity Governance in BoardroomsabstractCybersecurity governance is increasingly critical in a digital economy, with board directors playing a central role in shaping organisational resilience. Directors are pivotal in setting cybersecurity strategies and carrying fiduciary obligations that extend to digital risk oversight. This study examines the cybersecurity literacy and governance practices of Australian board directors through a qualitative interview study with 13 participants. Findings reveal a substantial gap in directors’ knowledge and confidence, undermining effective oversight and informed decision-making. This deficit limits their ability to interrogate risk reports, challenge assumptions, and steer investment in line with organisational resilience goals. In response, we propose a Board Cyber Governance Model that integrates targeted education, strategic interventions, and structured board–CISO engagement to improve governance capability. By situating cyber governance at the intersection of executive decision-making, risk perception, and digital security, this work contributes to human-computer interaction by highlighting socio-organisational challenges and offering actionable insights for stronger board-level engagement. Tooba Aamir, Georgia Psaroulis, Marthie Grobler, Helge Janicke |
CHI | 4 |
| 2026 | Bridg-ics: AI-grounded knowledge graphs for intelligent threat analytics in industry 5.0 cyber-physical systemsabstractAbstract Industry 5.0’s increasing integration of IT and OT systems is transforming industrial operations but also expanding the cyber–physical attack surface. Industrial Control Systems (ICS) face escalating security challenges as traditional siloed defenses fail to provide coherent, cross-domain threat insights. We present BRIDG-ICS (BRIDge for Industrial Control Systems), an AI-enriched Knowledge Graph (KG) framework for context-aware threat analysis and quantitative assessment of cyber resilience in smart manufacturing environments. BRIDG-ICS fuses heterogeneous industrial and cybersecurity data into an integrated Industrial Security Knowledge Graph linking assets, vulnerabilities, and adversarial behaviors with probabilistic risk metrics (e.g., exploit likelihood, attack cost). This unified graph representation enables multi-stage attack path simulation using graph-analytic techniques. To enrich the graph’s semantic depth, the framework leverages domain-specific pretrained language models (e.g., SecureBERT, CySecBERT) to extract cybersecurity entities, infer relationships, and transform natural-language threat descriptions into structured graph triples, thereby populating the knowledge graph with missing associations and latent risk indicators. The resulting AI-enriched KG supports multi-hop threat reasoning through graph-based inference, improving visibility into complex attack chains and guiding data-driven mitigation. In simulated industrial scenarios, BRIDG-ICS scales well, reduces potential attack exposure, and can enhance cyber–physical system resilience in Industry 5.0 settings. Padmeswari Nandiya, Ahmad Mohsin, Ahmed Ibrahim 0002, Iqbal H. Sarker, Helge Janicke |
Cybersecur. | 5 |
| 2026 | Mitigating malware prevalence in networks with arbitrary topologies: a Flip-It cyber game approach integrated with epidemic modelingabstractCyber threats have evolved in complexity, aiming at a wide range of sectors using advanced methods and tools. This evolving threat landscape challenges existing cybersecurity frameworks, many of which lack the adaptability to counteract the complex tactics of sophisticated adversaries. Developing robust cyber defense strategies requires simulating dynamic interactions between attackers and defenders across high, moderate, and low-impact scenarios. The Flip-It cyber game serves as an intelligent framework for simulating these interactions, enabling the analysis of adaptive strategies in cybersecurity. This paper aims to address the problem of mitigating malware prevalence in full consideration of attack/defense capabilities in arbitrary network topologies. This paper proposes a sophisticated discrete-time epidemic model to characterize security state transitions over time for all three scenarios within the Flip-It game framework. On this basis, the original problem is modeled as a closed-loop control problem to seek the optimal containment strategy. Deep Reinforcement Learning (DRL) is then used to tackle the problem, generating efficient defense strategies that are well-adapted to changing cybersecurity environments. Numerical simulations based on small-world networks, scale-free networks, and router networks are then carried out to generate corresponding strategies. Additionally, we have evaluated the performance of the proposed method against the State-Of-The-Art (SOTA) in terms of attack/defense objective function, control actions, number of devices under the control of the attacker and defender, stability, execution time, and scalability. This comprehensive approach integrates epidemiological modeling, game theory, and advanced machine learning to effectively tackle the complexities of contemporary cybersecurity threats. • Mitigates malware across low, medium, and high-impact cyberattacks. • Integrates the Flip-It game for attacker-defender dynamic interactions. • Employs DRL to enable adaptive and optimized defense strategies. • Evaluates defense evolution across diverse network topologies. Mousa Tayseer Jafar, Lu-Xing Yang, Gang Li 0009, Robin Doss, Kon Mouzakis, Rajesh Vasa, Helge Janicke, Ahmed Ibrahim 0002, Ahmed Mohsin, Iqbal H. Sarker, Kristen Moore, Seyit Ahmet Çamtepe, Diksha Goel |
Inf. Sci. | 7 |
| 2025 | Systemization of Knowledge (SoK): Goals, Coverage, and Evaluation in Cybersecurity and Privacy GamesabstractThis paper systematized existing knowledge on cybersecurity and privacy game-based approaches, exploring their goals, scope, and evaluation methods. Our review of 93 academic papers revealed that these approaches serve multiple purposes and target diverse player types. We identified 11 key aspects of cybersecurity and privacy that these approaches addressed, such as threats, defensive strategies, and data privacy. Additionally, we analyzed the effectiveness evaluation methods of these approaches, emphasizing the connections between evaluation techniques, types of data used, and their alignment with the approaches' goals. We also summarized the aspects of user experience evaluated in the literature and the types of questions used to capture these experiences. Reflecting on these methods, we provide guidance for future research and practice in designing and evaluating game-based approaches. Finally, we identify key gaps and propose opportunities to enhance user understanding, foster adaptability, and address emerging cybersecurity and privacy challenges. Marthie Grobler, Lauren S. Ferro, Georgia Psaroulis, Sanchari Das 0001, Jing Wei 0002, Helge Janicke |
CHI | 7 |
| 2025 | Enhancing Cybersecurity Training Efficacy: A Comprehensive Analysis of Gamified Learning, Behavioral Strategies and Digital TwinsabstractThis paper delves into enhancing cybersecurity training efficacy through an in-depth examination of gamified learning, behavioural strategies, and the deployment of digital twins. It identifies the critical role of behavioural strategies in bolstering cybersecurity defences by influencing human behaviour. The study explores the benefits of gamified learning in engaging participants and improving knowledge acquisition, alongside applying digital twins and cyber ranges in offering practical, hands-on experience. By analysing these methodologies, the paper aims to bridge the gap between theoretical knowledge and real-world application, encouraging the researchers to work on a forward-looking approach to cybersecurity training using these innovative methodologies that are both effective and engaging. Our findings suggest that by creating an immersive, interactive learning environment, it is possible to enhance the cybersecurity competencies of individuals, making them better prepared to navigate the complexities of the digital age. This paper contributes to cybersecurity training by offering insights using innovative approaches for effective training programs that are both engaging and informative, ultimately aiming to bolster organisations’ cybersecurity posture. Yagmur Yigit, Kitty Kioskli, Laura Bishop, Nestoras Chouliaras, Leandros Maglaras, Helge Janicke |
WoWMoM | 6 |
| 2025 | Zero day ransomware detection with Pulse: Function classification with Transformer models and assembly languageabstractFinding automated AI techniques to proactively defend against malware has become increasingly critical. The ability of an AI model to correctly classify novel malware is dependent on the quality of the features it is trained with and the authenticity of the features is dependent on the analysis tool. Peekaboo, a Dynamic Binary Instrumentation tool defeats evasive malware to capture its genuine behaviour. The ransomware Assembly instructions captured by Peekaboo, follow Zipf’s law, a principle also observed in natural languages, indicating Transformer models are particularly well-suited to binary classification. We propose Pulse, a novel framework for zero day ransomware detection with Transformer models and Assembly language. Pulse, trained with the Peekaboo ransomware and benign software data, uniquely identify truly new samples with high accuracy. Pulse eliminates any familiar functionality across the test and training samples, forcing the Transformer model to detect malicious behaviour based solely on context and novel Assembly instruction combinations. Matthew G. Gaber, Helge Janicke |
Comput. Secur. | 3 |
| 2025 | Defeating evasive malware with Peekaboo: Extracting authentic malware behavior with dynamic binary instrumentationabstractThe accuracy of Artificial Intelligence (AI) in malware detection is dependent on the features it is trained with, where the quality and authenticity of these features is dependent on the dataset and the analysis tool. Evasive malware, that alters its behavior in analysis environments, is challenging to extract authentic features from where widely used static and dynamic analysis tools have several limitations. However, Dynamic Binary Instrumentation (DBI) allows deep and precise control of the malware sample, thereby facilitating the extraction of authentic behavior from evasive malware. Considering the limitations of malware analysis for use with AI, this research had two primary objectives: investigation of the evasive techniques used by modern malware and the creation of Peekaboo, a DBI tool to extract authentic data from live Windows malware samples. Peekaboo instruments and defeats evasive techniques that target analysis tools and virtual environments. A dataset of 20,500 samples was assembled and each sample was run for up to 15 min to observe not only the anti-analysis techniques used but also its complete behavior. Peekaboo outperforms other tools on several fronts, it is the only tool to measure start and completion rates, capture the executed Assembly (ASM) instructions, record all network traffic and implements the largest coverage against evasive techniques. • Derived 97 anti-analysis techniques used by Windows malware. • Developed Peekaboo, a DBI tool to capture real malware behavior. • Analyzed 18,527 malware and 1,973 benign samples using Peekaboo. • Released a labeled dataset, scripts, and sample hashes for open science. • First to use DBI to defeat evasions and capture API calls, ASM, and network traffic. Matthew G. Gaber, Helge Janicke |
J. Inf. Secur. Appl. | 3 |
| 2024 | Detecting anomalies in blockchain transactions using machine learning classifiers and explainability analysisabstractAs the use of Blockchain for digital payments continues to rise in popularity, it also becomes susceptible to various malicious attacks. Successfully detecting anomalies within Blockchain transactions is essential for bolstering trust in digital payments. However, the task of anomaly detection in Blockchain transaction data is challenging due to the infrequent occurrence of illicit transactions. Although several studies have been conducted in the field, a limitation persists: the lack of explanations for the model's predictions. This study seeks to overcome this limitation by integrating eXplainable Artificial Intelligence (XAI) techniques and anomaly rules into tree-based ensemble classifiers for detecting anomalous Bitcoin transactions. The Shapley Additive exPlanation (SHAP) method is employed to measure the contribution of each feature, and it is compatible with ensemble models. Moreover, we present rules for interpreting whether a Bitcoin transaction is anomalous or not. Additionally, we have introduced an under-sampling algorithm named XGBCLUS, designed to balance anomalous and non-anomalous transaction data. This algorithm is compared against other commonly used under-sampling and over-sampling techniques. Finally, the outcomes of various tree-based single classifiers are compared with those of stacking and voting ensemble classifiers. Our experimental results demonstrate that: (i) XGBCLUS enhances TPR and ROC-AUC scores compared to state-of-the-art under-sampling and over-sampling techniques, and (ii) our proposed ensemble classifiers outperform traditional single tree-based machine learning classifiers in terms of accuracy, TPR, and FPR scores. Mohd. Hasan, Mohammad Shahriar Rahman, Helge Janicke, Iqbal H. Sarker |
Blockchain Res. Appl. | 3 |
| 2023 | The SAir-IIoT Cyber Testbed as a Service: A Novel Cybertwins Architecture in IIoT-Based Smart AirportsabstractRapid technological advancements have resulted in increasingly more efficient and lightweight devices that, coupled with low-power and wide-range wireless connectivity, have given rise to Industrial Internet of Things (IIoT) systems. As a result, the concept of intelligent environments was developed, such as smart airports, where ubiquitous sensors seamlessly cooperate through several types of communication technologies, such as WiFi, BLE, ZigBEE and 5G, enable the collection of data and the dynamic adaption of the system to changing circumstances. However, along with certain benefits, such as augmented communication, enhanced business processes and improved efficiency, IIoT introduces new vulnerabilities, enabling cyber-attackers to compromise not only the digital infrastructure of IIoT architecture-enabled smart airports, but also affecting their physical assets. In this paper, we present a novel smart airport cybertwins security-oriented IIoT testbed, named SAir-IIoT, which comprises multiple heterogeneous IIoT devices and communication protocols, organised into distinct zones, automatically interconnected with each other, that can be remotely accessed as-a-service. To the best of our knowledge, this is the first cybertwins security-oriented testbed that enables researchers and practitioners to remotely practice attack and defence scenarios in smart airport IIoT environments. Additionally, we introduce a new data management technique for dynamically collecting, analysing and tagging heterogeneous data from diverse data sources including IIoT devices and network flows. Finally, we compare SAir-IIoT with other IIoT-based testbeds, revealing its complexity and effectiveness to evaluate new cyber security methods. Nickolaos Koroniotis, Nour Moustafa, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
IEEE Trans. Intell. Transp. Syst. | 5 |
| 2022 | SmartValidator: A framework for automatic identification and classification of cyber threat data
Chadni Islam, Muhammad Ali Babar 0001, Roland Croft, Helge Janicke |
J. Netw. Comput. Appl. | 4 |
| 2021 | A novel Two-Factor HoneyToken Authentication MechanismabstractThe majority of systems rely on user authentication on passwords, but passwords have so many weaknesses and widespread use that easily raise significant security concerns, regardless of their encrypted form. Users hold the same password for different accounts, administrators never check password files for flaws that might lead to a successful cracking, and the lack of a tight security policy regarding regular password replacement are a few problems that need to be addressed. The proposed research work aims at enhancing this security mechanism, prevent penetrations, password theft, and attempted break-ins towards securing computing systems. The selected solution approach is two-folded; it implements a two-factor authentication scheme to prevent unauthorized access, accompanied by Honeyword principles to detect corrupted or stolen tokens. Both can be integrated into any platform or web application with the use of QR codes and a mobile phone. Vassilis Papaspirou, Leandros Maglaras, Mohamed Amine Ferrag, Ioanna Kantzavelou, Helge Janicke, Christos Douligeris |
ICCCN | 5 |
| 2021 | A Deep Learning-based Penetration Testing Framework for Vulnerability Identification in Internet of Things EnvironmentsabstractThe Internet of Things (IoT) paradigm has displayed tremendous growth in recent years, resulting in innovations like Industry 4.0 and smart environments that provide improvements to efficiency, management of assets and facilitate intelligent decision making. However, these benefits are offset by considerable cybersecurity concerns that arise due to inherent vulnerabilities, which hinder IoT-based systems' Confidentiality, Integrity, and Availability. Security vulnerabilities can be detected through the application of penetration testing, and specifically, a subset of the information-gathering stage, known as vulnerability identification. Yet, existing penetration testing solutions can not discover zero-day vulnerabilities from IoT environments, due to the diversity of generated data, hardware constraints, and environmental complexity. Thus, it is imperative to develop effective penetration testing solutions for the detection of vulnerabilities in smart IoT environments. In this paper, we propose a deep learning-based penetration testing framework, namely Long Short-Term Memory Recurrent Neural Network-Enabled Vulnerability Identification (LSTM-EVI). We utilize this framework through a novel cybersecurity-oriented testbed, which is a smart airport-based testbed comprised of both physical and virtual elements. The framework was evaluated using this testbed and on real-time data sources. Our results revealed that the proposed framework achieves about 99% detection accuracy for scanning attacks, outperforming other four peer techniques. Nickolaos Koroniotis, Nour Moustafa, Benjamin P. Turnbull, Francesco Schiliro, Praveen Gauravaram, Helge Janicke |
TrustCom | 6 |
| 2021 | The Agile Incident Response for Industrial Control Systems (AIR4ICS) framework
Richard Smith 0002, Helge Janicke, Ying He 0004, Fenia Ferra, Adham Albakri |
Comput. Secur. | 2 |
| 2020 | A NIS Directive Compliant Cybersecurity Maturity Assessment FrameworkabstractThe EU NIS Directive introduces obligations related to the security of the network and information systems for Operators of Essential Services and for Digital Service Providers. Moreover, National Competent Authorities for cybersecurity are required to assess the compliance to these obligations. This paper describes a novel Cybersecurity Maturity Assessment Framework (CMAF) that is tailored to the NIS Directive requirements. CMAF can be used either as a self assessment tool from Operators of Essential Services and Digital Service Providers or as an audit tool from the National Competent Authorities for cybersecurity George Drivas, Argyro Chatzopoulou, Leandros Maglaras, Costas Lambrinoudakis, Allan Cook, Helge Janicke |
COMPSAC | 6 |
| 2020 | Federated TON_IoT Windows Datasets for Evaluating AI-based Security ApplicationsabstractExisting cyber security solutions have been basically developed using knowledge-based models that often cannot trigger new cyber-attack families. With the boom of Artificial Intelligence (AI), especially Deep Learning (DL) algorithms, those security solutions have been plugged-in with AI models to discover, trace, mitigate or respond to incidents of new security events. The algorithms demand a large number of heterogeneous data sources to train and validate new security systems. This paper presents the description of new datasets, the so-called ToN_IoT, which involve federated data sources collected from Telemetry datasets of IoT services, Operating system datasets of Windows and Linux, and datasets of Network traffic. The paper introduces the testbed and description of TON_IoT datasets for Windows operating systems. The testbed was implemented in three layers: edge, fog and cloud. The edge layer involves IoT and network devices, the fog layer contains virtual machines and gateways, and the cloud layer involves cloud services, such as data analytics, linked to the other two layers. These layers were dynamically managed using the platforms of software-Defined Network (SDN) and Network-Function Virtualization (NFV) using the VMware NSX and vCloud NFV platform. The Windows datasets were collected from audit traces of memories, processors, networks, processes and hard disks. The datasets would be used to evaluate various AI-based cyber security solutions, including intrusion detection, threat intelligence and hunting, privacy preservation and digital forensics. This is because the datasets have a wide range of recent normal and attack features and observations, as well as authentic ground truth events. The datasets can be publicly accessed from this link [1]. Nour Moustafa, Marwa Keshk, Essam Soliman Debie, Helge Janicke |
TrustCom | 4 |
| 2020 | Deep learning for cyber security intrusion detection: Approaches, datasets, and comparative study
Mohamed Amine Ferrag, Leandros Maglaras, Sotiris Moschoyiannis, Helge Janicke |
J. Inf. Secur. Appl. | 4 |
| 2020 | Introduction to the special issue of the journal of information security and applications on" cyber security in ICS & SCADA systems"
Kevin I. Jones, Helge Janicke, Leandros Maglaras, Christos Xenakis |
J. Inf. Secur. Appl. | 2 |
| 2019 | A Novel Hierarchical Intrusion Detection System Based on Decision Tree and Rules-Based ModelsabstractThis paper proposes a novel intrusion detection system (IDS) that combines different classifier approaches which are based on decision tree and rules-based concepts, namely, REP Tree, JRip algorithm and Forest PA. Specifically, the first and second method take as inputs features of the data set, and classify the network traffic as Attack/Benign. The third classifier uses features of the initial data set in addition to the outputs of the first and the second classifier as inputs. The experimental results obtained by analyzing the proposed IDS using the CICIDS2017 dataset, attest their superiority in terms of accuracy, detection rate, false alarm rate and time overhead as compared to state of the art existing schemes. Ahmed Ahmim, Leandros Maglaras, Mohamed Amine Ferrag, Makhlouf Derdour, Helge Janicke |
DCOSS | 5 |
| 2019 | HEART-IS: A novel technique for evaluating human error-related information security incidents
Mark Glenn Evans, Ying He 0004, Leandros Maglaras, Helge Janicke |
Comput. Secur. | 4 |
| 2019 | Exploring the role of work identity and work locus of control in information security awareness
Lee Hadlington, Masa Popovac, Helge Janicke, Iryna Yevseyeva, Kevin I. Jones |
Comput. Secur. | 3 |
| 2019 | AIDIS: Detecting and classifying anomalous behavior in ubiquitous kernel processes
Robert Luh, Helge Janicke, Sebastian Schrittwieser |
Comput. Secur. | 2 |
| 2019 | Smart cities and cyber security: Are we there yet?A comparative study on the role of standards, third party risk management and security ownership
Morta Vitunskaite, Ying He 0004, Thomas Brandstetter, Helge Janicke |
Comput. Secur. | 4 |
| 2019 | Published incidents and their proportions of human errorabstractPurpose This paper aims to provide an understanding of the proportions of incidents that relate to human error. The information security field experiences a continuous stream of information security incidents and breaches, which are publicised by the media, public bodies and regulators. Despite the need for information security practices being recognised and in existence for some time, the underlying general information security affecting tasks and causes of these incidents and breaches are not consistently understood, particularly with regard to human error. Design/methodology/approach This paper analyses recent published incidents and breaches to establish the proportions of human error and where possible subsequently uses the HEART (human error assessment and reduction technique) human reliability analysis technique, which is established within the safety field. Findings This analysis provides an understanding of the proportions of incidents and breaches that relate to human error, as well as the common types of tasks that result in these incidents and breaches through adoption of methods applied within the safety field. Originality/value This research provides original contribution to knowledge through the analysis of recent public sector information security incidents and breaches to understand the proportions that relate to human error. Mark Glenn Evans, Ying He 0004, Iryna Yevseyeva, Helge Janicke |
Inf. Comput. Secur. | 4 |
| 2019 | Blockchain Technologies for the Internet of Things: Research Issues and ChallengesabstractThis paper presents a comprehensive survey of the existing blockchain protocols for the Internet of Things (IoT) networks. We start by describing the blockchains and summarizing the existing surveys that deal with blockchain technologies. Then, we provide an overview of the application domains of blockchain technologies in IoT, e.g., Internet of Vehicles, Internet of Energy, Internet of Cloud, Edge computing, etc. Moreover, we provide a classification of threat models, which are considered by blockchain protocols in IoT networks, into five main categories, namely identity-based attacks, manipulation-based attacks, cryptanalytic attacks, reputation-based attacks, and service-based attacks. In addition, we provide a taxonomy and a side-by-side comparison of the state-of-the-art methods toward secure and privacy-preserving blockchain technologies with respect to the blockchain model, specific security goals, performance, limitations, computation complexity, and communication overhead. Based on the current survey, we highlight open research challenges and discuss possible future research directions in the blockchain technologies for IoT. Mohamed Amine Ferrag, Makhlouf Derdour, Mithun Mukherjee 0001, Abdelouahid Derhab, Leandros Maglaras, Helge Janicke |
IEEE Internet Things J. | 6 |
| 2018 | Class Balanced Similarity-Based Instance Transfer Learning for Botnet Family Classification
Basil Alothman, Helge Janicke, Suleiman Y. Yerima |
DS | 2 |
| 2018 | Security for 4G and 5G cellular networks: A survey of existing authentication and privacy-preserving schemes
Mohamed Amine Ferrag, Leandros Maglaras, Antonios Argyriou, Dimitrios Kosmanos, Helge Janicke |
J. Netw. Comput. Appl. | 5 |
| 2018 | An introduction to cyber peacekeeping
Michael Robinson 0004, Kevin I. Jones, Helge Janicke, Leandros Maglaras |
J. Netw. Comput. Appl. | 3 |
| 2018 | Editorial: Industrial Internet of Things (I2oT)
Leandros Maglaras, Lei Shu 0001, Athanasios Maglaras, Jianmin Jiang, Helge Janicke, Dimitrios Katsaros 0001, Tiago Cruz 0001 |
Mob. Networks Appl. | 5 |
| 2018 | Vulnerability Analysis of Network Scanning on SCADA SystemsabstractSupervisory Control and Data Acquisition (SCADA) systems and Industrial Control Systems (ICSs) have controlled the regulation and management of Critical National Infrastructure environments for decades. With the demand for remote facilities to be controlled and monitored, industries have continued to adopt Internet technology into their ICS and SCADA systems so that their enterprise can span across international borders in order to meet the demand of modern living. Although this is a necessity, it could prove to be potentially dangerous. The devices that make up ICS and SCADA systems have bespoke purposes and are often inherently vulnerable and difficult to merge with newer technologies. The focus of this article is to explore, test, and critically analyse the use of network scanning tools against bespoke SCADA equipment in order to identify the issues with conducting asset discovery or service detection on SCADA systems with the same tools used on conventional IP networks. The observations and results of the experiments conducted are helpful in evaluating their feasibility and whether they have a negative impact on how they operate. This in turn helps deduce whether network scanners open a new set of vulnerabilities unique to SCADA systems. Kyle Coffey, Richard Smith 0002, Leandros Maglaras, Helge Janicke |
Secur. Commun. Networks | 4 |
| 2017 | Design of an Anomaly-based Threat Detection & Explication System
Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke |
ICISSP | 4 |
| 2017 | Poster: Design of an Anomaly-based Threat Detection & Explication SystemabstractThe poster corresponding to this summary depicts a proposition of a system able to explain anomalous behavior within a user session by considering anomalies identified through their deviation from a set of baseline process graphs. We adapt star structures, a bipartite representation used to approximate the edit distance between two graphs. Relevant processes are selected from a dictionary of benign and malicious traces generated through a sentiment-like bigram extraction and scoring system based on the log likelihood ratio test. We prototypically implemented smart anomaly explication through a number of competency questions derived and evaluated by a decision tree. The determined key factors are ultimately mapped to a dedicated APT attack stage ontology that considers actions, actors, as well as target assets. Robert Luh, Sebastian Schrittwieser, Stefan Marschalek, Helge Janicke, Edgar R. Weippl |
SACMAT | 4 |
| 2017 | The industrial control system cyber defence triage process
Allan Cook, Helge Janicke, Richard Smith 0002, Leandros Maglaras |
Comput. Secur. | 2 |
| 2017 | On data leakage from non-production systemsabstractPurpose This study is an exploration of areas pertaining to the use of production data in non-production environments. During the software development life cycle, non-production environments are used to serve various purposes to include unit, component, integration, system, user acceptance, performance and configuration testing. Organisations and third parties have been and are continuing to use copies of production data in non-production environments. This can lead to personal and sensitive data being accidentally leaked if appropriate and rigorous security guidelines are not implemented. This paper aims to propose a comprehensive framework for minimising data leakage from non-production environments. The framework was evaluated using guided interviews and was proven effective in helping organisation manage sensitive data in non-production environments. Design/methodology/approach Authors conducted a thorough literature review on areas related to data leakage from non-production systems. By doing an analysis of advice, guidelines and frameworks that aims at finding a practical solution for selecting and implementing a de-identification solution of sensitive data, the authors managed to highlight the importance of all areas related to sensitive data protection. Based on these areas, a framework was proposed which was evaluated by conducting set of guided interviews. Findings This paper has researched the background information and produced a framework for an organisation to manage sensitive data in its non-production environments. This paper presents a proposed framework that describes a process flow from the legal and regulatory requirements to data treatment and protection, gained through understanding the organisation’s business, the production system, the purpose and the requirements of the non-production environment. The paper shows that there is some conflict between security and perceived usability, which may be addressed by challenging the perceptions of usability or identifying the compromise required. Non-production environments need not be the sole responsibility of the IT section, they should be of interest to the business area that is responsible for the data held. Originality/value This paper proposes a simplified business model and framework. The proposed model diagrammatically describes the interactions of elements affecting the organisation. It highlights how non-production environments may be perceived as separate from the business systems, but despite the perceptions, these are still subject to the same legal requirements and constraints. It shows the interdependency of data, software, technical infrastructure and human interaction and how the change of one element may affect the others. The proposed framework describes the process flow and forms a practical solution in assisting the decision-making process and providing documentary evidence for assurance and audit purposes. It looks at the requirements of the non-production system in relation to the legal and regulatory constraints, as well as the organisational requirements and business systems. The impact of human factors on the data is also considered to bring a holistic approach to the protection of non-production environments. Jacqueline Cope, François Siewe, Feng Chen 0004, Leandros Maglaras, Helge Janicke |
Inf. Comput. Secur. | 5 |
| 2017 | Introduction to the special issue of the journal of information security and applications on "ICS & SCADA cyber security"
Kevin I. Jones, Helge Janicke, Christian Facchi, Leandros Maglaras |
J. Inf. Secur. Appl. | 2 |
| 2017 | Authentication Protocols for Internet of Things: A Comprehensive SurveyabstractIn this paper, a comprehensive survey of authentication protocols for Internet of Things (IoT) is presented. Specifically more than forty authentication protocols developed for or applied in the context of the IoT are selected and examined in detail. These protocols are categorized based on the target environment: (1) Machine to Machine Communications (M2M), (2) Internet of Vehicles (IoV), (3) Internet of Energy (IoE), and (4) Internet of Sensors (IoS). Threat models, countermeasures, and formal security verification techniques used in authentication protocols for the IoT are presented. In addition a taxonomy and comparison of authentication protocols that are developed for the IoT in terms of network model, specific security goals, main processes, computation complexity, and communication overhead are provided. Based on the current survey, open issues are identified and future research directions are proposed. Mohamed Amine Ferrag, Leandros Maglaras, Helge Janicke, Jianmin Jiang, Lei Shu 0001 |
Secur. Commun. Networks | 3 |
| 2016 | User interface design for privacy awareness in eHealth technologiesabstractIn this paper we investigate privacy issues relating to Human Computer Interfaces for mobile eHealth technologies. We present the Inform-Alert-Mitigate (I-AM) cycle, a novel approach to address privacy concerns that are associated with the use of these technologies. The I-AM approach supports the responsible innovation of new technologies. We demonstrate the effectiveness of I-AM by applying it to examples taken from mobile applications relating to personal health. We discuss three classes of applications: a) fitness trackers b) personal wellbeing applications and c) medical applications, and evaluate the privacy exposure of their users using representative applications from these classes. The paper evaluates the current privacy enhancing features of these applications against the identified risks and demonstrates how the I-AM approach can be applied to yield additional and more effective privacy protection for these technologies. Isabel Wagner, Ying He 0004, Duska Rosenberg, Helge Janicke |
CCNC | 4 |
| 2016 | Human behaviour as an aspect of cybersecurity assuranceabstractAbstract There continue to be numerous breaches publicised pertaining to cybersecurity despite security practices being applied within industry for many years. This paper is intended to be the first in a number of papers as research into cybersecurity assurance processes. This paper is compiled based on current research related to cybersecurity assurance and the impact of the human element on it. The objective of this work is to identify elements of cybersecurity that would benefit from further research and development based on the literature review findings. The results outlined in this paper present a need for the cybersecurity field to look in to established industry areas to benefit from effective practices such as human reliability assessment, along with improved methods of validation such as statistical quality control in order to obtain true assurance. The paper proposes the development of a framework that will be based upon defined and repeatable quantification, specifically relating to the range of human aspect tasks that provide or are intended not to negatively affect cybersecurity assurance. Copyright © 2016 John Wiley & Sons, Ltd. Mark Glenn Evans, Leandros Maglaras, Ying He 0004, Helge Janicke |
Secur. Commun. Networks | 4 |
| 2015 | Cyber warfare: Issues and challenges
Michael Robinson 0004, Kevin I. Jones, Helge Janicke |
Comput. Secur. | 3 |
| 2014 | Low-Latency Service Data Aggregation Using Policy ObligationsabstractThe Internet of Things, large scale sensor networks or even in social media, are now well established and their use is growing daily. Usage scenarios in these fields highlight the requirement to process, procure, and provide information with almost zero latency. This work is introducing new concepts for enabling fast communication by limiting information flow through filtering concepts combined with data processing techniques adopted from complex event processing. Specifically we introduce a novel mediation services architecture using filter policies to reduce latency. The filter policies define when and what data services need to provide to the mediator and thus save on bandwidth. The filter policies describe temporal conditions between two events removing the need to keep a complete history while still allowing temporal reasoning. Promising experimental results highlight the advantages to be gained from the approach. Stephan Reiff-Marganiec, Marcel Tilly, Helge Janicke |
ICWS | 3 |
| 2013 | Dynamic Access Control Policies: Specification and VerificationabstractSecurity requirements deal with the protection of assets against unauthorized access (disclosure or modification) and their availability to authorized users. Temporal constraints of history-based access control policies are difficult to express naturally in traditional policy languages. We propose a compositional formal framework for the specification and verification of temporal access control policies for security critical systems in which history-based policies and other temporal constraints can be expressed. In particular, our framework allows for the specification of policies that can change dynamically in response to time or events enabling dynamic reconfiguration of the access control mechanisms. The framework utilizes a single well-defined formalism, interval temporal logic, for defining the semantics of these policies and to reason about them. We illustrate our approach with a detailed case study of an electronic paper submission system showing the compositional verification of their safety, liveness and information flow properties. Helge Janicke, Antonio Cau, François Siewe, Hussein Zedan |
Comput. J. | 1 |
| 2013 | Verification and enforcement of access control policies
Antonio Cau, Helge Janicke, Ben C. Moszkowski |
Formal Methods Syst. Des. | 2 |
| 2012 | Efficient Data Processing for Large-Scale Cloud ServicesabstractThe cloud concept and its implementations are gaining in importance for systems that connect evermore new devices which in turn require communication with each other. In scenarios where we can find large numbers of data providers on one side and data consumers on the other side, such as in the Internet of Things, large scale sensor networks, machine to machine communication or even in social media, one emerging requirement is to process, procure, and provide information efficiently and with almost zero latency. This work is introducing new concepts to describe the flow of data to and from sources to cloud services in a formal way by limiting information flow with filtering concepts and combining data processing techniques adopted from complex event processing. Marcel Tilly, Stephan Reiff-Marganiec, Helge Janicke |
SERVICES | 3 |
| 2012 | SCADA security in the light of Cyber-Warfare
Andrew Nicholson, Stuart Webber, Shaun Dyer, Tanuja Patel, Helge Janicke |
Comput. Secur. | 5 |
| 2011 | New Framework for Policy Support for Mobile Grid ServicesabstractIn a multi-organization environment like the GRID, each institute might want to apply some boundaries on how its resources are being utlized by other institutes. A disagreement between the multi-Virtual Organizations (VOs) might happen in the security aspect for the policy framework. Mobile Grid Services has given the ability to move jobs, data and application software from nodes to nodes during jobs execution in the grid environment. It has also solved some of the lack in finding suitable resources for the jobs, but not a lot of attention was given to the policy in this solution. This paper presents a new framework for dynamic policy management to support mobility services in the grid environment. Tariq Falah Alwada'n, Helge Janicke, Omar Aldabbas 0001, Mai Alfawair |
CRiSIS | 2 |
| 2007 | A note on the formalisation of UCONabstractUsage Control (UCON) Models, similar to Access Control Models, control and govern the users' access to resources and services that are available in the system. One of the major improvements of UCON over traditional access control models is the continuity of the control and the concept of attribute mutability. In this paper we provide an alternative formalisation of the UCON model that relaxes many of the assumptions made in earlier formalisations of the model. We question the enforceability of UCON policies as described by previous formalisations and improve on it. Helge Janicke, Antonio Cau, Hussein Zedan |
SACMAT | 1 |