EDBT 2026 Demo / reviewers in the wild / expert
Steven Furnell
dblp:83/2392 · also Steven M. Furnell, Steven Marcus Furnell
· DBLP profile ↗
135ranked-venue papers
31as first author
33since 2021 · last 2026
0000-0003-0984-7542ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 112 · 27 first-author · 25 since 2021Computer networks · 7 · 1 since 2021Databases, data management, data science and information retrieval · 5 · 2 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 5 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 1 first-author · 2 since 2021Artificial intelligence and machine learning · 2 · 1 since 2021Systems, architecture and hardware · 1Software engineering, systems software and programming languages · 1 · 1 first-author
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2026 | Usable authentication: Are we there yet?abstractWith technology increasingly embedded in everyday life, the demand for secure and usable authentication methods has never been greater. Traditional password-based systems continue to dominate, despite well-known usability and security challenges. This paper explores the evolution of user authentication technologies, from secret knowledge and tokens to biometrics and emerging approaches such as Passkeys. It critically evaluates the extent to which usability has been achieved, identifying both successes—such as biometrics integrated into smartphones—and persistent issues, including inconsistent guidance, ecosystem dependence, and accessibility barriers. Drawing on academic and commercial developments, the discussion highlights the growing burden on users who must authenticate across multiple devices and services daily. Future directions including transparent, continuous, and user-choice-driven authentication are discussed as potential solutions to mitigate this burden. Ultimately, it argues that while progress has been made, current solutions remain fragmented and often exclude key user groups. A more inclusive, consistent, and user-centred approach is essential to ensure authentication systems are both secure and truly usable in practice. Nathan Clarke, Steven Furnell |
Comput. Secur. | 2 |
| 2026 | Bending the curve: Operational cyber epidemiology for ransomwareabstractRansomware is often treated as a detection problem, but the most disruptive incidents behave more like outbreaks. A single foothold can spread through identities, administrative tools, and shared services while responders make time-critical decisions with incomplete visibility. This paper presents an operational cyber epidemiology framework that adapts the Susceptible-Exposed-Infectious-Removed (SEIR) model to ransomware incident management. In this ontology, Exposed denotes latent compromise and staging, including the dwell period before confirmed secondary compromise, while Infectious denotes active lateral propagation. Drawing on ISO 5477:2023 guidance for public health emergency preparedness and response information management and the 2025 UNDRR-ISC Hazard Information Profiles, the framework defines interoperable ransomware case definitions and Essential Elements of Information for cross-incident comparison. Basic and effective reproduction numbers, R0 and Re, are used as directional, near-real-time decision aids for security operations centers. Propagation state is separated from observation status to avoid confusing spread dynamics with detection capability. Publicly reported incidents, including WannaCry, NotPetya, SolarWinds, and MGM and Caesars, illustrate how outbreak-style measures can support earlier isolation, credential containment, and restoration sequencing. The paper also derives practical protection-threshold heuristics aimed at reducing Re below 1 and provides a tool-agnostic playbook card linking operational information to explicit action triggers. The primary contribution is a shared language that connects technical telemetry to containment decisions under resource constraints. Stephen Flowerday, Nikolay Lipskiy, Steven Furnell, Callum E. Flowerday, John Hale |
Comput. Secur. | 3 |
| 2026 | Relationships between cultural orientations, phishing victimization, and phishing recognition: A cross-cultural experimentabstractBackground : Humans remain a critical vulnerability in the cybersecurity chain. While research has explored various behavioral factors influencing phishing susceptibility, the role of national culture and individual cultural orientations remains under-researched, representing a significant gap in the literature. Aims : This study investigates the impact of individual cultural orientations on phishing victimization, while taking into account other relevant factors, such as self-control, risk-taking, technical training, email management practices, demographics (age and gender), and country-level economic and ICT development. Methods : Data were collected via an online survey of university students (N = 2,143) across 12 countries in Asia, Africa, North America, and Europe. Outcomes measures included phishing victimization, phishing recognition, and legitimate email recognition; the last two measures were assessed via scenarios. Data were analyzed using Signal Detection Theory and mixed modelling. Results : Phishing victimization was significantly associated with low self-control, high risk-taking, high exposure, and poorer recognition of legitimate emails. Conversely, cultural orientations, religiosity, and country of origin had minimal effects. While phishing recognition was unrelated to victimization, the ability to recognize legitimate emails reduced victimization risk. For culturally diverse organizations, these findings suggest that cultural factors may be less critical to phishing victimization than has been previously assumed. Training users and improved self-control techniques may help protect against phishing victimization. Marianne Junger, Pawel Olber, Rafal Plocki, J. W. (Hans) Luyten, Luka Koning, Caitlyn N. Muniz, Jan-Willem Bullee, Victoria Wang, Reinhardt A. Botha, C. Jordan Howell, Verena Distler, Xiaowei Chen 0013, Cong Hiep Pham 0001, Mohammed Aljohani, Newman U. Richards, Fabian Muhly, Abhishta, Steven Furnell |
Comput. Secur. | 18 |
| 2025 | Designing Cyber Security Communities of Support to Improve SME Cyber Hygiene and Resilience
Neeshe Khan, Ram Herkanaidu, Steven Furnell, Jason R. C. Nurse, Maria Bada, Matthew Rand |
CRITIS | 3 |
| 2025 | Joining the Dots Between Cybersecurity Career Roles, Skills and Knowledge
Eliana Stavrou, Steven Furnell |
CRITIS | 2 |
| 2025 | What's in a Name? How Cyber Security Masters Degrees CompareabstractCyber security is now a prominent topic in university education, forming the focus of dedicated degrees at both undergraduate and postgraduate levels. However, the way it is perceived and understood by students can vary significantly, depending upon how the university concerned has elected to present their program. While many degrees (particularly at Masters level) can be found that address specialized aspects of cyber security, there are also many programs that are presented as offering general coverage and are titled accordingly. However, the actual topic coverage offered within these degrees has the potential to vary considerably, meaning that students may get a very different perspective on cyber security depending upon their choice of program. Building upon earlier phases of investigation, this paper examines the topic coverage and consistency of a series of Masters degrees in cyber security, drawing upon a sample of ten from the UK (which had been the focus of the earlier work) and a further ten from a series of European countries. Each program was assessed in terms of the technical and non-technical cyber security topics being covered, and the proportion of credits afforded to these in the degree overall. While all twenty programs shared the same title, the findings revealed significant variation between them in terms of the topics receiving coverage. Additionally, it was apparent that some topics were more likely to receive attention than others, with a general skew towards addressing technical themes such as digital forensics and security testing, while significant non-technical themes such as security awareness and business continuity are often overlooked in comparison. The paper discusses these findings, including the implications of having degrees that are offered as general Masters in cyber security but with imbalanced coverage of key topics, and how the resulting graduate qualifications are likely to align with industry needs. Finally, consideration is directed towards the potential for establishing unified frameworks for cyber security syllabi and assessment of coverage. Eliana Stavrou, Steven Furnell |
EDUCON | 2 |
| 2025 | Investigating the experiences of providing cyber security support to small- and medium-sized enterprisesabstractSmall- and Medium-Sized Enterprises or SMEs comprise of 99.9 % of all businesses in the UK and make a significant contribution the overall economy. In UK's path to digitalisation, ensuring the cyber security and resilience of SMEs becomes an integral element that must be adequately safeguarded to protect national interests. Despite playing a crucial role, there is limited research on SMEs adopting cyber security practices, becoming cyber secure or improving their resilience to attacks. To examine this journey, a qualitative study was designed to learn from the experiences of organisations that provide cyber security advice or solutions. The three aims of the study were to: (1) understand the various types of support offered by providers; (2) topics for which support is sought and the circumstances that trigger the need for assistance; and (3) the perceived effectiveness of the support provided, associated challenges and opportunities to improve from the lived experiences of providers. Following semi-structured interviews with 12 participants, findings confirm results presented in earlier literature and provides new insights. Each participant had exposure to numerous SMEs, in some instances hundreds, at a regional or national level due to their roles at their respective organisations. The inherent knowledge gained from this exposure results in each participant's experience representing the cumulative experience of several SMEs as opposed to a singular view of one. We conclude that there is a vast amount of cyber security related content aimed at SMEs and our findings reveal providers are playing an assistive role in the understanding, education and implementation of cyber security defences. Despite significant efforts being made, cyber hygiene amongst SMEs remains low and they are unlikely to proactively reach out for support. Additionally, SMEs have low knowledge levels and are hampered in their efforts due to comprehension, capability, attitudes, and resources whilst providers face numerous internal and external challenges when delivering this support. Insights from data reveal several opportunities for improvement can be realised through the creation of security focused communities that can provide support, collaboration and learning. Neeshe Khan, Steven Furnell, Maria Bada, Matthew Rand, Jason R. C. Nurse |
Comput. Secur. | 2 |
| 2025 | Cybersecurity behavior change: A conceptualization of ethical principles for behavioral interventionsabstract• Behavior change is increasingly used to minimize the human attack surface. • There is a lack of ethics related to cybersecurity behavior change interventions. • We propose repurposed and expanded ethical principles from biomedical ethics. • Principles: autonomy, justice, nonmaleficence, beneficence, transparency, privacy. • Survey: all ethical principles, except for autonomy, are perceived as needed/useful. The importance of changing behaviors is gradually being acknowledged in cybersecurity, and the reason is the realization that a notable portion of security incidents have a human-related component. Thus, enhancing behaviors at individual level, can bring a significant reduction in security breaches overall. Behavior change refers to any modification of human behavior through some type of intervention. Interventions from behavioral economics and psychology are being increasingly introduced in the field, however, the ethics surrounding such interventions are largely neglected. In this paper, we raise the ethical issues associated with behavioral intervention approaches. We draw on the traditionally more mature field of biomedical ethics and propose six clusters of ethical principles suitable for cybersecurity behavior change. We conducted a survey ( N = 141) to identify individuals’ perceptions on the proposed ethical principles and validate their perceived usefulness. We analyze an existing intervention in the light of our six-principle conceptualization to showcase how it can be used as a practical apparatus. Our set of ethical principles are aimed for cybersecurity professionals, policy makers, and behavioral intervention designers, and can serve as a starting point for best-practice development in cybersecurity behavior change ethics. Konstantinos Mersinas, Maria Bada, Steven Furnell |
Comput. Secur. | 3 |
| 2024 | Assessing the Consistency of Cyber Security EducationabstractCyber security is now a well-established topic in higher education contexts internationally. However, while numerous qualifications are available at undergraduate and postgraduate levels, it can be challenging for prospective students and employers to understand the topic coverage that sits under the degree title (and what aspects of cyber security a graduate will have been exposed to as a result). Following an initial illustration of how even the term ‘cyber security’ itself has varying interpretations, this paper evidences the challenge through an examination of the content of ten postgraduate degree programmes. All are titled ‘MSc Cyber Security’ and thus all are ostensibly addressing the same topic. However, a syllabus-level assessment reveals considerable differences in the programme composition (in terms of cyber and non-cyber topic coverage, and the technical and non-technical split within the cyber material). The technical content of the candidate programmes is compared in order to further demonstrate the difference in both the topic emphasis and the resulting student experience. The discussion then proceeds to consider how the actual content of programmes can be communicated and compared in a more informative manner, using mock-ups based on the earlier metrics to illustrate potential approaches. Steven Furnell, Eliana Stavrou |
EDUCON | 1 |
| 2024 | Cybersecurity Incident Response Readiness in Organisations
Aseel Aldabjan, Steven Furnell, Xavier Carpent, Maria Papadaki |
ICISSP | 2 |
| 2024 | Towards a Mobility-Aware Trust Model for the Internet of Underwater Things
Abeer Almutairi, Xavier Carpent, Steven Furnell |
SEC | 3 |
| 2024 | Situational support and information security behavioural intention: a comparative study using conservation of resources theoryabstractThe formation of information security behavioural intention (ISBI) can be complex and dynamic in different contexts. This paper aims to examine and compare different users’ ISBI formalisation mechanisms when dealing with their personal affairs (non-work users) and organisational affairs (work users). Drawing on two principles of Conservation of Resources (COR) theory (i.e. resource loss principle, and resource gain principle), we developed two models to examine how situational support affects ISBI formation. The results of a study of 432 non-worker users and 261 work users indicate a curvilinear relationship between situational support and ISBI through subjective norms and risk perception for non-worker users, whilst a linear relationship via subjective norms is found for worker users. This is the first time that COR has been applied to explain the formation of ISBI. The findings broaden the research scope of individuals’ ISBI by revealing how situational support affects the formalisation mechanism for different users in cross-contexts. The theoretical and practical implications of the findings and the future study are discussed. Yuxiang Hong, Mengyi Xu, Steven Furnell |
Behav. Inf. Technol. | 3 |
| 2024 | Editorial: Human aspects of cyber securityabstractHuman aspects are now widely recognised as being a key factor in providing a holistic cyber security solution. The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals. What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area. In July 2023, the 17th event in the series was held in Canterbury, UK. A total of 37 reviewed papers were presented over three days. From these, eight authors were invited to submit extended versions of their work for publication in this special issue. The resulting papers draw upon a range of areas including social engineering, cyber security culture, information security policies and the issue of cyber security awareness.In the first of the studies, Ahmad et al. explores the increasing problem of phishing via mobile instant messaging. Capitalising on the lack of technical safeguards, this attack vector is becoming increasingly popular. The study examines 67 examples of instant message phishing and explores the persuasion techniques attackers utilise.Three of the studies focused explore user behaviour and workload. Wright et al. focussed upon the preventive measures taken by employees towards cybercrime. Drawing upon over 200 participants during the pandemic, the study explored the Theory of Interpersonal Behaviour to demonstrate a strong correlation between the intent to engage in cybercrime preventative behaviour and actual practice. Whitty et al. developed a framework for focussing upon the social-technical variables that impact insider-based intellectual property theft. Drawing upon Situational Crime Prevention Theory, the model offers up novel opportunities to assist policymakers in preventing these types of attack. Reeves et al. explored the workload impact on the cybersecurity workforce. Utilising the Maslach Burnout Inventory (MBI), a survey of 119 cyber security professionals show that gender and job role are significant predictors of emotional exhaustion, with all roles tending to score higher on the MBI when compared to the Australian national population.Information security policies are key instruments used by organisations to define what the organisation wishes to achieve. Two of the papers explored the utility of these policies in practice. Rostami and Karlsson analysed the usefulness of information security policies with respect to the degree to which the policy could easily be actioned in practice. An examination of 15 policies from a range of Swedish public agencies found that just a third of the policies provide over 50% of actionable advice, with two-thirds of policies containing ambiguous advice that employees can use. Gerdin et al. investigated compliance and information security policies. Focussing upon employee compliance/non-compliance they study presents the findings of 17 in-depth interviews to explore the discrepancies between what is claimed to be measured versus what is actually measured and what respondents’ interpretations are.The final two papers focus upon cyber security awareness and preparedness. Stavrou and Piki present the importance of self-efficacy in education to foster professional development in cyber security. Using a skills-first approach, the study presents a novel curriculum design to actively nurture self-efficacy and promote improving attitudes towards upskilling in cyber security. Hedberg et al. undertake a study to explore the readiness of auto workshops in managing and responding to such attacks. Modern cars are increasingly smarter and more connected, thereby becoming a potential target for cybercriminals. Based upon a study of eight auto workshops in Sweden, it was found that there was currently limited capability, awareness and knowledge to deal with such issues.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 2 |
| 2024 | Usable Cybersecurity: a Contradiction in Terms?abstractAbstract Encounters and interactions with cybersecurity are now regular and routine experiences for information technology users across a variety of devices, systems and services. Unfortunately, however, despite long-term recognition of the importance of usability in the technology context, the user experience of cybersecurity and privacy is by no means guaranteed to address this criterion. This paper presents an outline of usability issues and challenges in the cybersecurity context, with examples of how it has (or indeed has not) evolved in some established contexts (looking in particular at web browsing and user authentication), as well as consideration of the extent to which any better attention is apparent within more recent and emerging technology contexts (considering the presentation of related features in scenarios including app stores and smart devices). Based on the evidence, cybersecurity is clearly yet to reach a stage where its mention would naturally imply usability, but at the same time the two concepts do not have to represent a contradiction in terms. The resulting requirement is for the increasing recognition of the issue to translate into a greater level of resulting attention and action. Steven Furnell |
Interact. Comput. | 1 |
| 2023 | Automatically Labeling Cyber Threat Intelligence reports using Natural Language ProcessingabstractAttribution provides valuable intelligence in the face of Advanced Persistent Threat (APT) attacks. By accurately identifying the culprits and actors behind the attacks, we can gain more insights into their motivations, capabilities, and potential future targets. Cyber Threat Intelligence (CTI) reports are relied upon to attribute these attacks effectively. These reports are compiled by security experts and provide valuable information about threat actors and their attacks. Hamza Abdi, Steven R. Bagley, Steven Furnell, Jamie Twycross |
DocEng | 3 |
| 2023 | Assessing Security and Privacy Insights for Smart Home Users
Samiah Alghamdi, Steven Furnell |
ICISSP | 2 |
| 2023 | Assessing the Impact of Attacks on Connected and Autonomous Vehicles in Vehicular Ad Hoc Networks
Kaushik Krishnan Balaji, Dimah Almani, Steven Furnell |
ICISSP | 3 |
| 2023 | Editorial: Human aspects of cyber securityabstractHuman aspects are now widely recognized as being a key factor in providing a holistic cyber security solution. The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human–computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals. What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area. In July 2022, the 16th event in the series was held in Lesvos, Greece. A total of 25 reviewed papers were presented over three days. From these, seven authors were invited to submit extended versions of their work for publication in this special issue. The resulting papers draw upon a range of areas including cyber security culture, information security management, security fatigue and the issue of privacy from a number of different perspectives.Privacy is a topic that has seen increased interest from the research community in recent years. Three of the selected papers have focused upon this. Lindqvist and Kävrestad explored the degree to which privacy concerns are impacting citizens’ willingness to report crimes. Following widely reported news articles raising the concern, this paper surveys 400 Swedish adults to seek their perspectives. Interestingly, whilst the willingness to share a mobile phone was low, a direct link to privacy was not established. Shanley et al. explored another aspect of privacy; that of Australian attitudes towards surveillance and the impact of COVID tracing applications. A survey of over 900 Australian adults showed a relatively high level of trust in government; however, they remain cautious and concerned over data being collected and had a strong desire to maintain control over their personal privacy. The final privacy-related paper by Chhetri and Motti sought to explore the development of privacy controls for Smart Homes. Using a mixed-methods approach, they undertook a series of evaluations for a novel prototype that helped to address the privacy gap.A further three papers focused upon culture, management and policy-related issues. Da Veiga explores the use of innovation and creativity as enablers to develop information security culture. Through a literature review, the paper identifies a set of elements that help to stimulate creativity and innovation. Rostami et al. present a conceptual model for tailoring information security policies with a view to acting as a foundation for developing software to aid the automated development and tailoring of policies for organisations. Bhana and Ophoff further explore the issue of security fatigue of data specialists. Through a semi-structured interview of stakeholders, they reveal several interlinked themes that evidence security fatigue.The final paper in the selection, from Glas et al., is focused upon security education and awareness – in particular the use of visual programming in cyber range training to improve skill development. Evaluated against a control group, the study found that visual training provided a positive impact on the learning experience.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 2 |
| 2023 | Introduction to the special issue on insider threats in cybersecurity
Adéle da Veiga, Steven Furnell, Yuxiang Hong, Merrill Warkentin |
J. Inf. Secur. Appl. | 2 |
| 2022 | Benchmarking Consumer Data and Privacy Knowledge in Connected and Autonomous Vehicles
Flora Barber, Steven Furnell |
ICISSP | 2 |
| 2022 | A Tailored Model for Cyber Security Education Utilizing a Cyber Range
Gregor Langner, Florian Skopik, Steven Furnell, Gerald Quirchmayr |
ICISSP | 3 |
| 2022 | Assessing website password practices - Unchanged after fifteen years?
Steven Furnell |
Comput. Secur. | 1 |
| 2022 | Accessible authentication: Assessing the applicability for users with disabilities
Steven Furnell, Kirsi Helkala, Naomi Woods |
Comput. Secur. | 1 |
| 2022 | Motivating Information Security Policy Compliance: Insights from Perceived Organizational FormalizationabstractPsychological and behavioral characteristics are among the most important factors that instigate information security incidents. Although many previous studies have discussed the influencing factors of information security policy compliance behavior in an organization, few have considered the influence of organizational structures. In this study, the mechanism by which information security policy compliance behavioral intention is formed was studied by integrating the theory of planned behavior (TPB) and perceived organizational formalization. Data analysis was performed using the structural equation modeling (SEM) with data obtained from a survey of 261 company employees. The empirical results reveal that perceived organizational formalization significant affected cognitive processes theorized by TPB, behavioral habits, and deterrent certainty. This study suggests that formalized rules, procedures, and communications should be designed to improve employee information security policy compliance behavioral habits and intentions. Yuxiang Hong, Steven Furnell |
J. Comput. Inf. Syst. | 2 |
| 2021 | Poster: The Need for a Collaborative Approach to Cyber Security EducationabstractTraditional forms of cyber security education mainly focus on knowledge transmission, which means that knowledge is perceived as a tangible object being transferred from an expert (i.e., the teacher) to a beginner. When practiced well, the learner may acquire such knowledge, but not the resilience to apply it in various contexts [1], [2]. This is especially troubling for the cyber security domain, given the dynamic and constantly changing nature of the field and the environments in which it is required. We therefore need forms of education that aim at understanding the interdisciplinary nature of the field of cyber security as well as at the development of joint action in context: being able to quickly analyse and understand evolving and possibly previously unseen situations and take collaborative action to prevent, detect and recover from incidents. Gregor Langner, Jerry Andriessen, Gerald Quirchmayr, Steven Furnell, Vittorio Scarano, Teemu Tokola |
EuroS&P | 4 |
| 2021 | Grano-GT: A granular ground truth collection tool for encrypted browser-based Internet traffic
Faiz Zaki, Abdullah Gani, Hamid Tahaei, Steven Furnell, Nor Badrul Anuar |
Comput. Networks | 4 |
| 2021 | The cybersecurity workforce and skills
Steven Furnell |
Comput. Secur. | 1 |
| 2021 | An empirical analysis of the information security culture key factors framework
Alaa Tolah, Steven Furnell, Maria Papadaki |
Comput. Secur. | 2 |
| 2021 | Developing a cyber security culture: Current practices and future needs
Betsy Uchendu, Jason R. C. Nurse, Maria Bada, Steven Furnell |
Comput. Secur. | 4 |
| 2021 | A novel approach for improving information security management and awareness for home environmentsabstractPurpose The human factor is a major consideration in securing systems. A wide and increasing range of different technologies, devices, platforms, applications and services are being used every day by home users. In parallel, home users are also experiencing a range of different online threats and attacks and are increasingly being targeted as they lack the knowledge and awareness about potential threats and how to protect themselves. The increase in technologies and platforms also increases the burden upon a user to understand how to apply security across differing technologies, operating systems and applications. This results in managing the security across their technology portfolio increasingly more troublesome and time consuming. This paper aims to propose an approach that attempts to propose a system for improving security management and awareness for home users. Design/methodology/approach The proposed system is capable of creating and assigning different security policies for different digital devices in a user-friendly fashion. These assigned policies are monitored, checked and managed to review the user’s compliance with the assigned policies to provide bespoke awareness content based on the user’s current needs. Findings A novel framework was proposed for improving information security management and awareness for home users. In addition, a mock-up design was developed to simulate the proposed approach to visualise the main concept and the functions which might be performed when it is deployed in a real environment. A number of different scenarios have been simulated to show how the system can manage and deal with different types of users, devices and threats. In addition, the proposed approach has been evaluated by experts in the research domain. The overall feedback is positive, constructive and encouraging. The experts agreed that the identified research problem is a real problem. In addition, they agreed that the proposed approach is usable, feasible and effective in improving security management and awareness for home users. Research limitations/implications The proposed design of the system is a mock-up design without real data. Therefore, implementing the proposed approach in a real environment can provide the researcher with a better understanding of the effectiveness and the functionality of the proposed approach. Practical implications This study offers a framework and usable mock-up design which can help in improving information security management for home users. Originality/value Improving the security management and awareness for home users by monitoring, checking and managing different security controls and configurations effectively are the key to strengthen information security. Therefore, when home users have a good level of security management and awareness, this could protect and secure the home network and subsequently business infrastructure and services as well. Fayez Alotaibi, Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 3 |
| 2021 | Towards a cross-cultural education framework for online safety awarenessabstractPurpose The purpose of this study is to determine effective online safety awareness education for young people in less developed countries. The research followed an explanatory mixed methods design starting with an online survey (quantitative element) and then interesting or anomalous findings were followed up with one-on-one interviews (qualitative element). The data gathered on the online habits and views of young people were fed into the Young People Online Model. It was also used to create online safety workshops. The standout issue from this research is the prevalence of cyberbullying, and this was used as the core theme. They were carried out using the action-research approach, whereby after each workshop, the facilitators would reflect and analyse and suggest improvements for the next one. Design/methodology/approach The majority of online safety awareness education programmes have been developed in and for advanced countries. In less developed countries, there are fewer programmes as well as a lack of research on the factors that influence the online behaviour of young people online. The Young People Online Education Framework seeks to address this and provide educators, researchers and policymakers an evidence driven construct for developing education programmes informed by issues affecting young people in their respective country/region. Findings The framework was applied in Thailand. As there were very few previous studies, original research was conducted via surveys and interviews. It was found that a high proportion of young people had experienced negative interactions online with cyberbullying the main concern. This was confirmed during the workshop phase indicating the need for more research and workshops. There is a plan to continue the research in Thailand, and it is hoped that other researchers will make use of the framework to extend its scope and application. Originality/value A novel feature of this framework is the cultural mask. The cultural context of learners is often overlooked in education, especially when education programmes are imported from other countries. This research contends that effective learning strategies and programmes will have a better chance to succeed if the cultural makeup of the target audience is considered and that all topics and activities are parsed through the cultural mask element of the framework. Ram Herkanaidu, Steven Furnell, Maria Papadaki |
Inf. Comput. Secur. | 2 |
| 2021 | Understanding cybersecurity behavioral habits: Insights from situational support
Yuxiang Hong, Steven Furnell |
J. Inf. Secur. Appl. | 2 |
| 2021 | Exploring touch-based behavioral authentication on smartphone email applications in IoT-enabled smart cities
Wenjuan Li 0001, Weizhi Meng 0001, Steven Furnell |
Pattern Recognit. Lett. | 3 |
| 2020 | Education for the Multifaith Community of Cybersecurity
Steven Furnell, Matt Bishop |
WISE | 1 |
| 2020 | Duplicitous social media and data surveillance: An evaluation of privacy risk
Karl van der Schyff, Stephen Flowerday, Steven Furnell |
Comput. Secur. | 3 |
| 2020 | Privacy risk and the use of Facebook Apps: A gender-focused vulnerability assessment
Karl van der Schyff, Stephen Flowerday, Steven Furnell |
Comput. Secur. | 3 |
| 2020 | Comparing the protection and use of online personal information in South Africa and the United Kingdom in line with data protection requirementsabstractPurpose The purpose of this study was to investigate the difference between South Africa (SA) and the United Kingdom (UK) in terms of data protection compliance with the aim to establish if a country that has had data protection in place for a longer period of time has a higher level of compliance with data protection requirements in comparison with a country that is preparing for compliance. Design/methodology/approach An insurance industry multi-case study within the online insurance services environment was conducted. Personal information of four newly created consumer profiles was deposited to 10 random insurance organisation websites in each country to evaluate a number of data privacy requirements of the Data Protection Act and Protection of Personal Information Act. Findings The results demonstrate that not all the insurance organisations honored the selected opt-out preference for receiving direct marketing material. This was evident in direct marketing material that was sent from the insurance organisations in the sample to both the SA and UK consumer profiles who opted out for it. A total of 42 unsolicited third-party contacts were received by the SA consumer profiles, whereas the UK consumer profiles did not receive any third-party direct marketing. It was also found that the minimality principle is not always met by both SA and UK organisations. Research limitations/implications As a jurisdiction with a heavy stance towards privacy implementation and regulation, it was found that the UK is more compliant than SA in terms of implementation of the evaluated data protection requirements included in the scope of this study, however not fully compliant. Originality/value Based upon the results obtained from this research, it suggests that the SA insurance organisations should ensure that the non-compliance aspects relating to direct marketing and sharing data with third parties are addressed. SA insurance companies should learn from the manner in which the UK insurance organisations implement these privacy requirements. Furthermore, the UK insurance organisations should focus on improved compliance for direct marking and the minimality principle. The study indicates the positive role that data protection legislation plays in a county like the UK, with a more mature stance toward compliance with data protection legislation. Adéle da Veiga, Ruthea Vorster, Fudong Li 0001, Nathan L. Clarke, Steven Furnell |
Inf. Comput. Secur. | 5 |
| 2019 | Information Security Risk Communication: A User-Centric ApproachabstractUsers have difficulties in understanding and reacting to security-related threats. Moreover, users only try to protect themselves from risks salient to them. In contrast to the traditional one-message/one-size-fits-all approach when communicating risks, this paper aims to propose an individualized and persuasive approach to information security risk communication that goes beyond alerting the user of his insecure behavior to providing a level of security education. By focusing on the user and that different users react differently to the same stimuli, the authors proposed a targeted user-centric approach that communicates risks in a timely and continuous manner using a proposed gradual response mechanism. This user-centric approach is anticipated to help the user in making security-related decisions by educating him about his risk taking behavior in an individualized way. A scenario is assumed to demonstrate how a response decision is made within the proposed approach. This was useful in demonstrating how risk is not the same for all users and how the proposed approach is effective in adapting to differences between users offering a novel approach to communicating information security risks. Manal Abdullah Alohali, Nathan L. Clarke, Steven Furnell |
AICCSA | 3 |
| 2019 | A Novel Behaviour Profiling Approach to Continuous Authentication for Mobile ApplicationsabstractThe growth in smartphone usage has led to increased user concerns regarding privacy and security. Smartphones contain sensitive information, such as personal data, images, and emails, and can be used to perform various types of activity, such as transferring money via mobile Internet banking, making calls and sending emails. As a consequence, concerns regarding smartphone security have been expressed and there is a need to devise new solutions to enhance the security of mobile applications, especially after initial access to a mobile device. This paper presents a novel behavioural profiling approach to user identity verification as part of mobile application security. A study involving data collected from 76 users over a 1-month period was conducted, generating over 3 million actions based on users' interactions with their smartphone. The study examines a novel user interaction approach based on supervised machine learning algorithms, thereby enabling a more reliable identity verification method. The experimental results show that users could be distinguished via their behavioural profiling upon each action within the application, with an average equal error rate of 26.98% and the gradient boosting classifier results prove quite compelling. Based on these findings, this approach is able to provide robust, continuous and transparent authentication. Saud Alotaibi, Abdulrahman Alruban, Steven Furnell, Nathan L. Clarke |
ICISSP | 3 |
| 2019 | Efficient Privacy-preserving User Identity with Purpose-based EncryptionabstractIn recent years, users may store their Personal Identifiable Information (PII) in the Cloud environment so that Cloud services may access and use it on demand. When users do not store personal data in their local machines, but in the Cloud, they may be interested in questions such as where their data are, who access it except themselves. Even if Cloud services specify privacy policies, we cannot guarantee that they will follow their policies and will not transfer user data to another party. In the past 10 years, many efforts have been taken in protecting PII. They target certain issues but still have limitations. For instance, users require interacting with the services over the frontend, they do not protect identity propagation between intermediaries and against an untrusted host, or they require Cloud services to accept a new protocol. In this paper, we propose a broader approach that covers all the above issues. We prove that our solution is efficient: the implementation can be easily adapted to existing Identity Management systems and the performance is fast. Most importantly, our approach is compliant with the General Data Protection Regulation from the European Union. Tri Hoang Vo, Woldemar F. Fuhrmann, Klaus Peter Fischer-Hellmann, Steven Furnell |
ISNCC | 4 |
| 2019 | Special issue on security of IoT-enabled infrastructures in smart cities
Ali Ismail Awad, Steven Furnell, Abbas M. Hassan, Theodore Tryfonas |
Ad Hoc Networks | 2 |
| 2019 | Deterrence and prevention-based model to mitigate information security insider threats in organisations
Nader Sohrabi Safa, Carsten Maple, Steven Furnell, Muhammad Ajmal Azad, Charith Perera, Mohammad Dabbagh, Mehdi Sookhak |
Future Gener. Comput. Syst. | 3 |
| 2019 | A framework for reporting and dealing with end-user security policy complianceabstractPurpose It is widely acknowledged that non-compliance of employees with information security polices is one of the major challenges facing organisations. This paper aims to propose a model that is intended to provide a comprehensive framework for raising the level of compliance amongst end-users, with the aim of monitoring, measuring and responding to users’ behaviour with an information security policy. Design/methodology/approach The proposed model is based on two main concepts: a taxonomy of the response strategy to non-compliant behaviour and a compliance points system. The response taxonomy comprises two categories: awareness raising and enforcement of the security policy. The compliance points system is used to reward compliant behaviour and penalise non-compliant behaviour. Findings A prototype system has been developed to simulate the proposed model and work as a real system that responds to the behaviour of users (reflecting both violations and compliance behaviour). In addition, the model has been evaluated by interviewing experts from academic and industry. They considered the proposed model to offers a novel approach for managing end users’ behaviour with the information security policies. Research limitations/implications Psychological factors were out of the research scope at this stage. The proposed model may have some psychological impacts upon users; therefore, this issue needs to be considered by studying the potential impacts and the best solutions. Originality/value Users being compliant with the information security policies of their organisation is the key to strengthen information security. Therefore, when employees have a good level of compliance with security policies, this positively affects the overall security of an organisation. Mutlaq Jalimid Alotaibi, Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 2 |
| 2019 | Information security burnout: Identification of sources and mitigating factors from security demands and resources
Cong Hiep Pham 0001, Linda Brennan, Steven Furnell |
J. Inf. Secur. Appl. | 3 |
| 2018 | Enhancing Security Education - Recognising Threshold Concepts and Other Influencing FactorsabstractThe Publisher's final version can be found by following the DOI link. Ismini Vasileiou, Steven Furnell |
ICISSP | 2 |
| 2018 | Biometrically Linking Document Leakage to the Individuals Responsible
Abdulrahman Alruban, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
TrustBus | 4 |
| 2018 | Enhancing security behaviour by supporting the user
Steven Furnell, Warut Khern-am-nuai, Rawan Esmael, Weining Yang, Ninghui Li 0001 |
Comput. Secur. | 1 |
| 2018 | Information security collaboration formation in organisationsabstractThe protection of organisational information assets requires the collaboration of all employees; information security collaboration (ISC) aggregates the efforts of employees in order to mitigate the effect of information security breaches and incidents. However, it is acknowledged that ISC formation and its development needs more investigation. This research endeavours to show how ISC forms and develops in the context of an organisation based on social bond factors. The social bond theory and theory of planned behaviour describe the effect of social bond factors on the attitude of employees and finally their behaviour regarding collaboration in the domain of information security. The results of the data analysis reveal that personal norms, involvement, and commitment to their organisation significantly influence the employees’ attitude towards ISC intention. However, contrary to the authors expectation, attachment does not influence the attitude of employees towards ISC. In addition, attitudes towards ISC, perceived behavioural control, and personal norms significantly affect the intention of employees towards ISC. The findings also show that the employees’ intention towards ISC and organisational support positively influence ISC, but that trust does not significantly affect ISC behaviour. Nader Sohrabi Safa, Carsten Maple, Tim Watson, Steven Furnell |
IET Inf. Secur. | 4 |
| 2018 | Identifying and predicting the factors affecting end-users' risk-taking behaviorabstractPurpose The end-user has frequently been identified as the weakest link; however, motivated by the fact that different users react differently to the same stimuli, identifying the reasons behind variations in security behavior and why certain users could be “at risk” more than others is a step toward protecting and defending users against security attacks. This paper aims to explore the effect of personality trait variations (through the Big Five Inventory [BFI]) on users’ risk level of their intended security behaviors. In addition, age, gender, service usage and information technology (IT) proficiency are analyzed to identify what role and impact they have on behavior. Design/methodology/approach The authors developed a quantitative-oriented survey that was implemented online. The bi-variate Pearson two-tailed correlation was used to analyze survey responses. Findings The results obtained by analyzing 538 survey responses suggest that personality traits do play a significant role in affecting users’ security behavior risk levels. Furthermore, the results suggest that BFI score of a trait has a significant effect as users’ online personality is linked to their offline personality, especially in the conscientiousness personality trait. Additionally, this effect was stronger when personality was correlated with the factors of IT proficiency, gender, age and online activity. Originality/value The contributions of this paper are two-fold. First, with the aid of a large population sample, end-users’ security practice is assessed from multiple domains, and relationships were found between end-users’ risk-taking behavior and nine user-centric factors. Second, based upon these findings, the predictive ability for these user-centric factors were evaluated to determine the level of risk a user is subject to from an individual behavior perspective. Of 28 behaviors, 11 were found to have a 60 per cent or greater predictive ability, with the highest classification of 92 per cent for several behaviors. This provides a basis for organizations to use behavioral intent alongside personality traits and demographics to understand and, therefore, manage the human aspects of risk. Manal Abdullah Alohali, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
Inf. Comput. Secur. | 4 |
| 2018 | Guest editorialabstractHuman aspects of cyber security Human aspects are now widely recognized as being a key factor in providing a holistic cyber security solution.The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and humancomputer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals.What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area.In November 2017, the 11th event in the series was held in Adelaide, Australia.A total of 25 reviewed papers were presented over three days.From these, seven authors were invited to submit extended versions of their work for publication in this special issue.The resulting papers are mainly focused upon the key issues of awareness and risk, alongside one further paper looking at the impact upon cyber analysts themselves.Five of the papers explore aspects of user behavior with respect to information security practice (or more particularly, intent).Specifically, Jansen and Van Schaik investigate the role fear plays in ensuring compliance to phishing by using protection motivation theory.The study involved surveying over 1,000 people to understand to what degree fear would play a role in how users respond to phishing attacks.McCormac et al. focus upon how understanding the relationship between resilience and work stress impacted information security awareness.Snyman et al. present a study exploring how users' information security decisions or practice is impacted by the decisions made by others.Their study introduces the concept of the "lemmings effect" and demonstrates by experimentation that it exists within information security behaviors.Alohali et al. present a study exploring the factors that affect the end-user risk-taking behavior, focusing upon a range of factors such as personality, age, education and information technology proficiency to understand which ones may have a statistically strong correlation to risk-making decisions.The survey was completed by over 500 participants, and it was found that personality, in particular conscientiousness, does play a role in a large number of risk-taking decisions.In the fifth paper, Ashenden seeks to explore social acceptability bias in information security research.Using personal construct psychology and repertory grids, the study demonstrated that employees who thought that the organization was driven by the need to protect information also thought that the risks were overstated, and their colleagues were overly cautious.The remaining two papers focused upon different areas of the human aspects theme: the first on measuring privacy perceptions and the second on gamification of security education.Da Veiga proposes an information privacy culture index framework to measure privacy perceptions across nations.Applied in a South African context, the paper reveals that South Africans have a high expectation of privacy yet feel that organizations are failing to meet both expectations and regulation.The final paper, by Micallef and Arachchilage, seeks to investigate the value gamification can have within security education.This study found that rewards within games do help to motivate users to have a better learning experience; however, social interactions within games Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 1 |
| 2018 | Towards Bayesian-Based Trust Management for Insider Attacks in Healthcare Software-Defined NetworksabstractThe medical industry is increasingly digitalized and Internet-connected (e.g., Internet of Medical Things), and when deployed in an Internet of Medical Things environment, software-defined networks (SDNs) allow the decoupling of network control from the data plane. There is no debate among security experts that the security of Internet-enabled medical devices is crucial, and an ongoing threat vector is insider attacks. In this paper, we focus on the identification of insider attacks in healthcare SDNs. Specifically, we survey stakeholders from 12 healthcare organizations (i.e., two hospitals and two clinics in Hong Kong, two hospitals and two clinics in Singapore, and two hospitals and two clinics in China). Based on the survey findings, we develop a trust-based approach based on Bayesian inference to figure out malicious devices in a healthcare environment. Experimental results in either a simulated and a real-world network environment demonstrate the feasibility and effectiveness of our proposed approach regarding the detection of malicious healthcare devices, i.e., our approach could decrease the trust values of malicious devices faster than similar approaches. Weizhi Meng 0001, Kim-Kwang Raymond Choo, Steven Furnell, Athanasios V. Vasilakos, Christian W. Probst |
IEEE Trans. Netw. Serv. Manag. | 3 |
| 2017 | Insider Misuse Attribution using BiometricsabstractInsider misuse has become a major risk for many organizations. One of the most common forms of misuses is data leakage. Such threats have turned into a real challenge to overcome and mitigate. Whilst prevention is important, incidents will inevitably occur and as such attribution of the leakage is key to ensuring appropriate recourse. Although digital forensics capability has grown rapidly in the process of analyzing the digital evidences, a key barrier is often being able to associate the evidence back to an individual who leaked the data. Stolen credentials and the Trojan defense are two commonly cited arguments used to complicate the issue of attribution. Furthermore, the use of a digital certificate or user ID would only associate to the account not to the individual. This paper proposes a more proactive model whereby a user's biometric information is transparently captured (during normal interactions) and embedding within the digital objects they interact with (thereby providing a direct link between the last user using any document or object). An investigation into the possibility of embedding individuals' biometric signals into image files is presented, with a particular focus upon the ability to recover the biometric information under varying degrees of modification attack. The experimental results show that even when the watermarked object is significantly modified (e.g. only 25% of the image is available) it is still possible to recover those embedded biometric information. Abdulrahman Alruban, Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
ARES | 4 |
| 2017 | Toward an Automatic Classification of Negotiation Styles Using Natural Language Processing
Daniela Pacella, Elena Dell'Aquila, Davide Marocco, Steven Furnell |
IVA | 4 |
| 2017 | A novel privacy preserving user identification approach for network trafficabstractThe prevalence of the Internet and cloud-based applications, alongside the technological evolution of smartphones, tablets and smartwatches, has resulted in users relying upon network connectivity more than ever before. This results in an increasingly voluminous footprint with respect to the network traffic that is created as a consequence. For network forensic examiners, this traffic represents a vital source of independent evidence in an environment where anti-forensics is increasingly challenging the validity of computer-based forensics. Performing network forensics today largely focuses upon an analysis based upon the Internet Protocol (IP) address – as this is the only characteristic available. More typically, however, investigators are not actually interested in the IP address but rather the associated user (whose account might have been compromised). However, given the range of devices (e.g., laptop, mobile, and tablet) that a user might be using and the widespread use of DHCP, IP is not a reliable and consistent means of understanding the traffic from a user. This paper presents a novel approach to the identification of users from network traffic using only the meta-data of the traffic (i.e. rather than payload) and the creation of application-level user interactions, which are proven to provide a far richer discriminatory feature set to enable more reliable identity verification. A study involving data collected from 46 users over a two-month period generated over 112 GBs of meta-data traffic was undertaken to examine the novel user-interaction based feature extraction algorithm. On an individual application basis, the approach can achieve recognition rates of 90%, with some users experiencing recognition performance of 100%. The consequence of this recognition is an enormous reduction in the volume of traffic an investigator has to analyse, allowing them to focus upon a particular suspect or enabling them to disregard traffic and focus upon what is left. Nathan L. Clarke, Fudong Li 0001, Steven Furnell |
Comput. Secur. | 3 |
| 2017 | AndroDialysis: Analysis of Android Intent Effectiveness in Malware DetectionabstractThe wide popularity of Android systems has been accompanied by increase in the number of malware targeting these systems. This is largely due to the open nature of the Android framework that facilitates the incorporation of third-party applications running on top of any Android device. Inter-process communication is one of the most notable features of the Android framework as it allows the reuse of components across process boundaries. This mechanism is used as gateway to access different sensitive services in the Android framework. In the Android platform, this communication system is usually driven by a late runtime binding messaging object known as Intent. In this paper, we evaluate the effectiveness of Android Intents (explicit and implicit) as a distinguishing feature for identifying malicious applications . We show that Intents are semantically rich features that are able to encode the intentions of malware when compared to other well-studied features such as permissions. We also argue that this type of feature is not the ultimate solution. It should be used in conjunction with other known features. We conducted experiments using a dataset containing 7406 applications that comprise 1846 clean and 5560 infected applications. The results show detection rate of 91% using Android Intent against 83% using Android permission. Additionally, experiment on combination of both features results in detection rate of 95.5%. Ali Feizollah, Nor Badrul Anuar, Rosli Salleh, Guillermo Suarez-Tangil, Steven Furnell |
Comput. Secur. | 5 |
| 2016 | A Forensic Acquisition and Analysis System for IaaS: Architectural Model and ExperimentabstractCloud computing has been advancing at a feverish pace. It has become one of the most important research topics in computer science and information systems. Cloud computing offers enterprise-scale platforms in a short time frame with little effort. Thus, it delivers significant economic benefits to both commercial and public entities. Despite this, the security and subsequent incident management requirements are major obstacles to adopting the cloud. Current cloud architectures do not support digital forensic investigators, nor comply with today's digital forensics procedures - largely due to the dynamic nature of the cloud. When an incident has occurred, an organization-based investigation will seek to provide potential digital evidence while minimizing the cost of investigation. However, all members engaging in digital forensics must rely, to a very significant degree, upon the assistance of cloud providers to present relevant evidence. Unfortunately, providers often lack appropriate tools and features to perform adequate acquisition and analysis. Therefore, dependence on the CSPs is considered one of the most significant challenges when investigators need to acquire evidence in a timely yet forensically sound manner from cloud systems. This paper aims to achieve two objectives: the first objective is the development and validation of a forensic acquisition system in an Infrastructure as a Service (IaaS) model in order to ensure organizations remain in complete control, remove the burden/liability from the CSPs and make it easy to acquire the evidence in a forensically sound and timely manner. Secondly, it is to investigate the technical implications and costs resulting from such a system on the day-to-day operation of a cloud system. Saad Alqahtany, Nathan L. Clarke, Steven Furnell, Christoph Reich |
ARES | 3 |
| 2016 | Information security policy compliance model in organizations
Nader Sohrabi Safa, Rossouw von Solms, Steven Furnell |
Comput. Secur. | 3 |
| 2016 | Guest editorialabstractHuman aspects of cyber securityHuman aspects are now widely recognized as being a key factor in providing a holistic cyber security solution.The nature of what we mean by human aspects can vary quite considerably, from intuitive aspects such as information security awareness and human-computer interaction to the less instinctive yet still important aspects such as the development of technical solutions that remove or reduce the security burden placed upon individuals.What all these areas have in common is the impact they have upon the people involved.With this in mind, the Human Aspects of Information Security and Assurance symposium series seeks to provide a forum for a community of related researchers working in this area.In July 2015, the ninth event in the series was held in Mytilene in Lesvos, Greece.A total of 25 reviewed papers were presented over three days.From these, seven authors were invited to submit extended versions of their work for publication in this special issue.The resulting papers are mainly focused upon the key issues of awareness and risk, alongside one further paper looking at the impact upon cyber analysts themselves.Four of the papers explore aspects of the information security awareness and education domain.Specifically, Da Veiga focuses upon investigating the impact that an information security policy has upon employees through an experimental approach involving 2,000 participants.Meanwhile, Kelley and Bertenthal undertook a study to explore the factors that affect user decision making (focusing specifically on logins to insecure websites), highlighting that attention and past behavior are strong indicators more so than security knowledge.Reid and Van Niekerk present a study into the impact of awareness campaigns using a South African school as a baseline measure.The final awareness paper, from Pattinson et al., seeks to determine the extent to which attitude data could be elicited from the repertory grid technique.The two risk-related papers seek to better understand the role that people play within the process.Sommestad et al. present an empirical study of the relationship between risk and the constituents of severity and probability.Meanwhile, Alavi et al. present a risk-driven investment model for analyzing human factors.The final paper takes a different perspective and focuses upon security analysts themselves.In recognition of human error, the study seeks to investigate the factors that affect improvement in analyst's performance, which in turn is intended to lead to better security as a result.The papers collectively illustrate a range of relevant activities in the domain of human aspects, and it is certain that the breadth of the area as a whole will continue to offer rich opportunities for further research in the years to come. Steven Furnell, Nathan L. Clarke |
Inf. Comput. Secur. | 1 |
| 2015 | From Passwords to Biometrics - In Pursuit of a Panacea
Steven Furnell |
ICISSP | 1 |
| 2015 | Security, Privacy and Usability - A Survey of Users' Perceptions and Attitudes
Abdulwahid Al Abdulwahid, Nathan L. Clarke, Ingo Stengel, Steven Furnell, Christoph Reich |
TrustBus | 4 |
| 2015 | Continuous user authentication using multi-modal biometrics
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell, Valerio Biscione |
Comput. Secur. | 3 |
| 2015 | Information security conscious care behaviour formation in organizations
Nader Sohrabi Safa, Mehdi Sookhak, Rossouw von Solms, Steven Furnell, Norjihan Binti Abdul Ghani, Tutut Herawan |
Comput. Secur. | 4 |
| 2015 | Editorial
Steven Furnell |
Inf. Comput. Secur. | 1 |
| 2015 | Man-At-The-End attacks: Analysis, taxonomy, human aspects, motivation and future directions
Adnan Akhunzada, Mehdi Sookhak, Nor Badrul Anuar, Abdullah Gani, Ejaz Ahmed 0003, Muhammad Shiraz, Steven Furnell, Amir Hayat, Muhammad Khurram Khan |
J. Netw. Comput. Appl. | 7 |
| 2014 | Text-Based Active Authentication for Mobile Devices
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell, Valerio Biscione |
SEC | 3 |
| 2014 | Performance evaluation of a Technology Independent Security Gateway for Next Generation NetworksabstractWith the all IP based Next Generation Networks being deployed around the world, the use of real-time multimedia service applications is being extended from normal daily communications to emergency situations. However, currently different emergency providers utilise differing networks and different technologies. As such, conversations could be terminated at the setup phase or data could be transmitted in plaintext should incompatibility issues exit between terminals. To this end, a novel security gateway that can provide the necessary security support for incompatible terminals was proposed, developed and implemented to ensure the successful establishment of secure real-time multimedia conversations. A series of experiments were conducted to evaluate the security gateway through the use 40 Boghe softphone acting as the terminals. The experimental results demonstrate that the best performance of the prototype was achieved by utilising a multithreading and multi-buffering technique, with an average of 582 microseconds processing overhead. Based upon the ITU-Ts 150 milliseconds one way delay recommendation for voice communications, it is envisaged that such a marginal overhead will not be noticed by users in practice. Fudong Li 0001, Nathan L. Clarke, Steven Furnell, Is-Haka Mkwawa |
WiMob | 3 |
| 2014 | A security education Q&AabstractPurpose – The purpose of this paper is to highlight the importance of cyber security education as a means of enabling skilled professionals and ensuring adequate awareness amongst end users. Design/methodology/approach – The discussion examines the contribution made by the Kaspersky Academy student conference series, and then proceeds to consider some related questions posed to Eugene Kaspersky as the founder of the programme. Findings – The question and answer segment of the discussion identifies the ways in which academic qualifications and professional certifications can align to support a rounded security education for those aiming to become practitioners. Originality/value – The discussion provides a clear insight into the importance of security education and how it is being actively supported by one of the leading companies in the industry. Eugene Kaspersky, Steven Furnell |
Inf. Manag. Comput. Secur. | 2 |
| 2014 | A response selection model for intrusion response systems: Response Strategy Model (RSM)abstractABSTRACT Intrusion response systems aim to provide a systematic procedure to respond to incidents. However, with different type of response options, an automatic response system is designed to select appropriate response options automatically in order to act fast to respond to only true and critical incidents as well as minimise their impact. In addition, incidents also can be prioritised into different level of priority where some incidents may cause a serious impact (i.e. high priority) and other may not (i.e. low priority). The existing strategies inherit some limitation such as using complex approaches and less efficient in mapping appropriate response based upon incidents' priority. Therefore, this study introduces a model called response strategy model to address the aforementioned limitation. In order to validate, it was evaluated using two datasets: DARPA 2000 and private dataset. The case study results have shown a significant relationship between the incident classification and incident priorities where false incidents are likely to be categorised as low priority and true incidents are likely to be categorised as the high priority. In particular, with response strategy model, an average of 92.68% of the false incidents was prioritised as the lowest priority is better compared with only 67.07% with Snort priority. Copyright © 2013 John Wiley & Sons, Ltd. Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
Secur. Commun. Networks | 3 |
| 2013 | A Technology Independent Security Gateway for Real-Time Multimedia Communication
Fudong Li 0001, Nathan L. Clarke, Steven Furnell |
NSS | 3 |
| 2013 | Assessing the Feasibility of Security Metrics
Bernhard Heinzle, Steven Furnell |
TrustBus | 2 |
| 2013 | Co-operative user identity verification using an Authentication Aura
Chris G. Hocking, Steven Furnell, Nathan L. Clarke, Paul L. Reynolds |
Comput. Secur. | 2 |
| 2013 | Editorial for Security and Privacy in Wireless Networks Special Issue
Muttukrishnan Rajarajan, Steven Furnell |
Mob. Networks Appl. | 2 |
| 2013 | Incident prioritisation using analytic hierarchy process (AHP): Risk Index Model (RIM)abstractABSTRACT The landscape of security threats continues to evolve, with attacks becoming more serious and the number of vulnerabilities rising. For these threats to be managed, many security studies have been undertaken in recent years, mainly focusing on improving detection, prevention and response efficiency. This paper proposes an incident prioritisation model, the Risk Index Model (RIM), which is based on risk assessment and the analytic hierarchy process. For incidents to be prioritised, the model uses indicators, such as criticality, as decision factors to calculate incidents' risk index. The model also adopts different strategies to enhance the prioritisation process. To evaluate the model, two stages of evaluation study were conducted. The first stage aims to validate the model by comparing its results with the Common Vulnerability Scoring System and Snort. The second stage aims to enhance RIM by analysing the effect of using different strategies in the model. The experimental results in the first stage have shown that 100% of incidents could be rated with RIM, compared with only 17.23% with the Common Vulnerability Scoring System. The experiments in the second stage have shown significant changes in the resultant risk index as well as some of the top‐priority incidents. Copyright © 2012 John Wiley & Sons, Ltd. Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
Secur. Commun. Networks | 3 |
| 2012 | A Response Strategy Model for Intrusion Response Systems
Nor Badrul Anuar, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
SEC | 3 |
| 2012 | Multi-modal Behavioural Biometric Authentication for Mobile Devices
Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell |
SEC | 3 |
| 2012 | Power to the people? The evolving recognition of human aspects of security
Steven Furnell, Nathan L. Clarke |
Comput. Secur. | 1 |
| 2011 | Multifactor graphical passwords: An assessment of end-user performanceabstractThis paper reports on the usability study carried out to assess the feasibility of combining two graphical password methods for better security. The methods involved clicking on the image (i.e. click-based) and selecting a series of images (i.e. choice-based). A graphical password prototype was developed (Enhanced Graphical Authentication System) and tested by thirty participants, who were randomly chosen from the authors' university. Two evaluations were made; namely user performance of the combined method and the feasibility of authentication strategies towards the introduced method itself. From both evaluations, it is found that positive results have been obtained, which suggest that these methods could be combined together effectively without giving impediment to users. However, there are issues relating to predictability as a consequence of insecure user behaviour. Mohd Zalisham Jali, Steven Furnell, Paul Dowland 0001 |
IAS | 2 |
| 2011 | SMS linguistic profiling authentication on mobile deviceabstractIt is commonly acknowledged that mobile devices now form an integral part of an individual's everyday life. As the amount of valuable and sensitive information stored on a mobile device increases, so does the need for effective security. In order to protect unauthorised access, an authentication system is required. Biometric authentication has proven to be a more reliable solution than knowledge based and token based techniques. Indeed, biometric techniques are uniquely individual, impossible to forget or lose, difficult to reproduce or falsify and difficult to change or hide. Despite the well known advantages of biometric authentication approaches, the majority of current state-of-the-art mobile devices embrace point of entry authentication systems including PIN/passwords and one time fingerprint verification. This paper introduces a feasibility study into a novel biometric technique for mobile devices, linguistic profiling. This investigation sought to authenticate users based on their writing vocabulary and style of SMS messages. The findings, based upon 30 participants, revealed the feasibility of the approach. While an overall average Equal Error Rate (EER) of 24% is unacceptably high, several users experienced an EER of 0%, suggesting significant potential to apply the technique for a subset of the population. Hataichanok Saevanee, Nathan L. Clarke, Steven Furnell |
NSS | 3 |
| 2011 | Quantifying the Effect of Graphical Password Guidelines for Better Security
Mohd Zalisham Jali, Steven Furnell, Paul Dowland 0001 |
SEC | 2 |
| 2010 | An Analysis of Information Security Awareness within Home and Work EnvironmentsabstractAs technology such as the Internet, computers and mobile devices become ubiquitous throughout society, the need to ensure our information remains secure is imperative. Unfortunately, it has long been understood that good security cannot be achieved through technical means alone and a solid understanding of the issues and how to protect yourself is required from users. Whilst many initiatives, programs and strategies have been proposed to improve the level of information security awareness, most have been directed at organizations, with a few national programs focused upon home users. Given people's use of technology is primarily focused upon those two areas: the workplace and home, this paper seeks to understand the knowledge and practice relationship between these environments. Through the survey that was developed, it was identified that the majority of the learning about information security occurred in the workplace, where clear motivations, such as legislation and regulation, existed. It was also found that user's were more than willing to engage with such awareness raising initiatives. From a comparison of practice between work and home environments, it was found that this knowledge and practice obtained at the workplace was transferred to the home environment. Given this positive transferability of knowledge and the willingness to learn about how to remain secure, an opportunity exists to move away from specific organizational awareness programs and to move towards awareness raising strategies that, whilst deployed in the organization, will develop an all-round individual security culture for users independent of the environment within which they are operating. Shuhaili Talib, Nathan L. Clarke, Steven Furnell |
ARES | 3 |
| 2010 | A distributed and cooperative user authentication frameworkabstractAs the requirement for companies and individuals to protect information and personal details comes more into focus, the implementation of security that goes beyond the ubiquitous password or Personal Identification Number (PIN) is paramount. With the ever growing number of us utilizing more than one device simultaneously, the problem and need is compounded. This paper proposes a novel approach to security that leverages the collective confidence of user identity held by the multiplicity of devices present at any given time. User identity confidence is reinforced by sharing established credentials between devices, enabling them to make informed judgments on their own security position. An Adaptive Security Control Engine (ASCE) is outlined, illustrating how an environment sensitive and adaptive security envelope can be established and maintained around an individual. Chris G. Hocking, Steven Furnell, Nathan L. Clarke, Paul L. Reynolds |
IAS | 2 |
| 2010 | Online addiction: privacy risks in online gaming environmentsabstractIn this paper we investigated the levels of addiction and personal data disclosure within Massively Multiplayer Online Role Playing Game environments (MMORPG's). The study made use of an online survey which embraced a combination of a six point behavioural addiction framework, Self Determination Theory and Impression Management theory to assess addictive behaviour and consequential data disclosure amongst a sample representative of 188 Singaporean based MMORPG gamers. Results found that pathological gaming addiction had a direct effect on levels of personal and sensitive data disclosure and participants who were disclosing high amounts of data were considered more vulnerable to exploitation and predation. Benjamin George Sanders, Vivian Chen, Daniel Zahra, Paul Dowland 0001, Shirley Atkinson, Maria Papadaki, Steven Furnell |
MEDES | 7 |
| 2010 | Assessing the Usability of End-User Security Software
Tarik Ibrahim, Steven Furnell, Maria Papadaki, Nathan L. Clarke |
TrustBus | 2 |
| 2010 | A preliminary two-stage alarm correlation and filtering system using SOM neural network and K-means algorithm
Gina C. Tjhai, Steven Furnell, Maria Papadaki, Nathan L. Clarke |
Comput. Secur. | 2 |
| 2010 | Assessing image-based authentication techniques in a web-based environmentabstractThe purpose of this paper is to assess the usability of two image-based authentication methods when used in the web-based environment. The evaluated approaches involve clicking secret points within a single image (click-based) and remembering a set of images in the correct sequence (choice-based). A “one-to-one” usability study was conducted in which participants had to complete three main tasks; namely authentication tasks (register, confirm and login), spot the difference activity and provide feedback. From analysing the results in terms of timing, number of attempts, user feedback, accuracy and predictability, it is found that the choice-based approach is better in terms of usability, whereas the click-based method performed better in terms of timing and is ratedmore secure against social engineering.The majority of participants are from the academic sector (students, lecturers, etc.) and had up to seven years’ IT experience. To obtain more statistically significant results, it is proposed that participants should be obtained from various sectors, having a more varied IT experience. The results suggest that in order for image-based authentication to be used in the web environment, more work is needed to increase the usability, while at the same time maintaining the security of both techniques. This paper enables a direct comparison of the usability of two alternative image-based techniques, with the studies using the same set of participants and the same set of environment settings. Mohd Zalisham Jali, Steven Furnell, Paul Dowland 0001 |
Inf. Manag. Comput. Secur. | 2 |
| 2010 | Online identity: Giving it all away?
Steven Furnell |
Inf. Secur. Tech. Rep. | 1 |
| 2009 | Flexible and Transparent User Authentication for Mobile Devices
Nathan L. Clarke, Sevasti Karatzouni, Steven Furnell |
SEC | 3 |
| 2009 | From desktop to mobile: Examining the security experience
Reinhardt A. Botha, Steven Furnell, Nathan L. Clarke |
Comput. Secur. | 2 |
| 2009 | Editorial
Dimitris Gritzalis, Steven Furnell |
Comput. Secur. | 2 |
| 2009 | Social engineering: assessing vulnerabilities in practiceabstractPurpose The purpose of this paper is to investigate the level of susceptibility to social engineering amongst staff within a cooperating organisation. Design/methodology/approach An e‐mail‐based experiment was conducted, in which 152 staff members were sent a message asking them to follow a link to an external web site and install a claimed software update. The message utilised a number of social engineering techniques, but was also designed to convey signs of a deception in order to alert security‐aware users. The external web site, to which the link was pointing, was intentionally badly designed in the hope of raising the users' suspicions and preventing them from proceeding with the software installation. Findings In spite of a short window of operation for the experiment, the results revealed that 23 per‐cent of recipients were fooled by the attack, suggesting that many users lack a baseline level of security awareness that is useful to protect them online. Research limitations/implications After running for approximately 3.5 h, the experiment was ceased, after a request from the organisation's IT department. Thus, the correct percentage of unique visits is likely to have been higher. Also, the mailings were sent towards the end of a working day, thus limiting the number of people who got to read and respond to the message before the experiment was ended. Practical implications Despite its limitations, the experiment clearly revealed a significant level of vulnerability to social engineering attacks. As a consequence, the need to raise user awareness of social engineering and the related techniques is crucial. Originality/value This paper provides further evidence of users' susceptibility to the problems, by presenting the results of an e‐mail‐based social engineering study that was conducted amongst staff within a cooperating organisation. Taimur Bakhshi, Maria Papadaki, Steven Furnell |
Inf. Manag. Comput. Secur. | 3 |
| 2009 | The irreversible march of technology
Steven Furnell |
Inf. Secur. Tech. Rep. | 1 |
| 2008 | Investigating the problem of IDS false alarms: An experimental study using Snort
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
SEC | 3 |
| 2008 | The Problem of False Alarms: Evaluation with Snort and DARPA 1999 Dataset
Gina C. Tjhai, Maria Papadaki, Steven Furnell, Nathan L. Clarke |
TrustBus | 3 |
| 2008 | Friend-assisted intrusion detection and response mechanisms for mobile ad hoc networks
Shukor Abd Razak, Steven Furnell, Nathan L. Clarke, Phillip J. Brooke |
Ad Hoc Networks | 2 |
| 2008 | Security beliefs and barriers for novice Internet users
Steven Furnell, Valleria Tsaganidi, Andy D. Phippen |
Comput. Secur. | 1 |
| 2007 | A Practical Usability Evaluation of Security Features in End-User Applications
Steven Furnell, Dimitris Katsabas, Paul Dowland 0001, Fraser Reid |
SEC | 1 |
| 2007 | Pre-execution Security Policy Assessment of Remotely Defined BPEL-Based Grid Processes
Klaus Peter Fischer-Hellmann, Udo Bleimann, Steven Furnell |
TrustBus | 3 |
| 2007 | Advanced user authentication for mobile devices
Nathan L. Clarke, Steven Furnell |
Comput. Secur. | 2 |
| 2007 | IFIP workshop - Information security culture
Steven Furnell |
Comput. Secur. | 1 |
| 2007 | Making security usable: Are things improving?
Steven Furnell |
Comput. Secur. | 1 |
| 2007 | An assessment of website password practices
Steven Furnell |
Comput. Secur. | 1 |
| 2007 | Assessing the security perceptions of personal Internet users
Steven Furnell, P. Bryant, Andy D. Phippen |
Comput. Secur. | 1 |
| 2007 | A non-intrusive biometric authentication mechanism utilising physiological characteristics of the human head
Philip M. Rodwell, Steven Furnell, Paul L. Reynolds |
Comput. Secur. | 2 |
| 2007 | Analysis of security-relevant semantics of BPEL in cross-domain defined business processesabstractPurpose Aims to identify security‐relevant semantics of business processes being defined by WS‐BPEL (Web Services Business Process Execution Language, BPEL for short) scripts, in particular, when such scripts defining collaborative business processes on top of web services are deployed across security domain boundaries. Design/methodology/approach Analysing potential of BPEL to define behaviour of business processes violating restrictions implied by security policies. Findings Semantic patterns being combinations of particular BPEL features and web services with specific access restrictions implied by security policies are defined and their implications for analysis of BPEL scripts during compliance assessment of cross‐domain defined business processes are identified. Research limitations/implications The results of the research part of which is reported here have been applied in a research prototype to BPEL scripts of limited size and comparatively simple business logic. Real‐world examples of BPEL scripts with respect to size and complexity should be examined for further approving suitability of the algorithms used. Originality/value The results can be used to specify security policies in terms of security‐critical semantics of BPEL scripts in order to facilitate compliance assessment. In conjunction with other results of this research, this will help to overcome security issues arising from cross‐domain definition of business processes by enabling automatic compliance assessment prior to execution. Klaus Peter Fischer-Hellmann, Udo Bleimann, Woldemar F. Fuhrmann, Steven Furnell |
Inf. Manag. Comput. Secur. | 4 |
| 2006 | A Two-Tier Intrusion Detection System for Mobile Ad Hoc Networks - A Friend Approach
Shukor Abd Razak, Steven Furnell, Nathan L. Clarke, Phillip J. Brooke |
ISI | 2 |
| 2006 | Considering the Usability of End-User Security Software
Steven Furnell, Adila Jusoh, Dimitris Katsabas, Paul Dowland 0001 |
SEC | 1 |
| 2006 | The challenges of understanding and using security: A survey of end-users
Steven Furnell, Adila Jusoh, Dimitris Katsabas |
Comput. Secur. | 1 |
| 2006 | Risk and restitution: Assessing how users establish online trust
Hazel Lacohée, Andy D. Phippen, Steven Furnell |
Comput. Secur. | 3 |
| 2006 | Towards an insider threat prediction specification languageabstractPurpose This paper presents the process of constructing a language tailored to describing insider threat incidents, for the purposes of mitigating threats originating from legitimate users in an IT infrastructure. Design/methodology/approach Various information security surveys indicate that misuse by legitimate (insider) users has serious implications for the health of IT environments. A brief discussion of survey data and insider threat concepts is followed by an overview of existing research efforts to mitigate this particular problem. None of the existing insider threat mitigation frameworks provide facilities for systematically describing the elements of misuse incidents, and thus all threat mitigation frameworks could benefit from the existence of a domain specific language for describing legitimate user actions. Findings The paper presents a language development methodology which centres upon ways to abstract the insider threat domain and approaches to encode the abstracted information into language semantics. The language construction methodology is based upon observed information security survey trends and the study of existing insider threat and intrusion specification frameworks. Originality/value This paper summarizes the picture of the insider threat in IT infrastructures and provides a useful reference for insider threat modeling researchers by indicating ways to abstract insider threats. George Magklaras, Steven Furnell, Phillip J. Brooke |
Inf. Manag. Comput. Secur. | 2 |
| 2006 | Achieving automated intrusion response: a prototype implementationabstractPurpose The increasing speed and volume of attacks against networked systems highlights the need to automate the intrusion response process. This paper proposes a means by which such automation may be achieved, and presents details of a practical implementation. Design/methodology/approach The paper outlines the architecture of a flexible and intelligent automated response system that is able to adapt response decisions according to the context in which a detected incident has occurred. The discussion presents details of a prototype implementation that has been used to evaluate the concept in practice, and demonstrates the feasibility of assessing contextual factors associated with detected incidents. Findings A series of worked examples are presented to show how the same incident occurring in different contexts will trigger different decisions from the response system. Originality/value The paper contributes towards the domain of intrusion response, and proposes an approach that would enable automation of the response process to be more acceptable to security administrators. Maria Papadaki, Steven Furnell |
Inf. Manag. Comput. Secur. | 2 |
| 2005 | Authentication of users on mobile telephones - A survey of attitudes and practices
Nathan L. Clarke, Steven Furnell |
Comput. Secur. | 2 |
| 2005 | Why users cannot use security
Steven Furnell |
Comput. Secur. | 1 |
| 2005 | A preliminary model of end user sophistication for insider threat prediction in IT systems
George Magklaras, Steven Furnell |
Comput. Secur. | 2 |
| 2005 | An automated framework for managing security vulnerabilitiesabstractPurpose This paper aims to look at unpatched software which represents a significant problem for internet‐based systems, with a myriad malware incidents and hacker exploits taking advantage of vulnerable targets. Unfortunately, vulnerability management is a non‐trivial task, and is complicated by an increasing number of vulnerabilities and the workload implications associated with handling the associated security advisories and updates. Design/methodology/approach As a step towards addressing the problem, this paper presents an automated framework that is designed to provide a vendor‐independent means of vulnerability notification and rectification for system administrators. Findings In the proposed framework, incoming vulnerability advisory messages may be obtained from multiple sources, and then filtered and prioritised according to the specific requirements of the target environment (as determined by the security administrator). In addition to notification management, the framework provides an automated facility for the download and deployment of any associated patches. The framework has been implemented in prototype form, with particular focus on the notification manager. Originality/value This paper presents an automated framework, providing a valuable and comprehensive solution for managing vulnerabilities in terms of notification and rectification systems. A. Al-Ayed, Steven Furnell, D. Zhao, Paul Dowland 0001 |
Inf. Manag. Comput. Security | 2 |
| 2005 | Informing the decision process in an automated intrusion response system
Maria Papadaki, Steven Furnell |
Inf. Secur. Tech. Rep. | 2 |
| 2004 | A Long-term Trial of Keystroke Profiling using Digraph, Trigraph and Keyword LatenciesabstractA number of previous studies have investigated the use of keystroke analysis as a means of authenticating users’ identities at the point of initial login. By contrast, relatively little research has focused upon the potential of applying the technique for identity verification during the logged-in session. Previous work by the authors has determined that keystroke analysis is a viable metric for continuous monitoring, provided that sufficient data is captured to create a reliable profile. This paper presents a series of results from a three-month trial in which profiles were created using digraph, trigraph and keyword-based keystroke latencies. The profiles were based upon a total of over 5 million keystroke samples, collected from 35 participants. The results demonstrate that the techniques offer significant promise as a means of non-intrusive identity verification during keyboard-related activities, with an optimum false acceptance rate of 4.9% being observed at a rate of 0% false rejection. Paul Dowland 0001, Steven Furnell |
SEC | 2 |
| 2004 | A long-term trial of alternative user authentication technologiesabstractModern IT systems have a continued requirement for reliable user authentication at login. However, the majority of systems are still using username/password combinations, in spite of a variety of recognised weaknesses. Identifies the need for improved login authentication, and investigates the suitability of two alternative methods, using cognitive questions and an image‐based PIN. The effectiveness of these techniques has already been evaluated in an earlier study, which assessed users' ability to recall the necessary information after a prolonged period of inactivity. Here, the evaluation is focused on the perceived acceptability of the techniques, based upon users' longer‐term opinions arising from a period of regular usage. Discovers that 56 per cent of the participants would support the use of such techniques as a replacement for traditional password or numeric PIN‐based authentication. However, also discovers that some users have the potential to compromise the security of the methods by using them inappropriately. As such, concludes that, although the use of alternative authentication techniques is viable, further research is needed to refine the approaches and identify the best combination of methods across a larger base of users. Steven Furnell, I. Papadopoulos, Paul Dowland 0001 |
Inf. Manag. Comput. Secur. | 1 |
| 2003 | Cybercrime: Vandalizing the Information Society
Steven Furnell |
ICWE | 1 |
| 2003 | Using Keystroke Analysis as a Mechanism for Subscriber Authentication on Mobile Handsets
Nathan L. Clarke, Steven Furnell, Benn Lines, Paul L. Reynolds |
SEC | 2 |
| 2003 | Keystroke dynamics on a mobile handset: a feasibility studyabstractThe ability of third generation telephones to store sensitive information, such as financial records, digital certificates and company records, makes them desirable targets for impostors. This paper details the feasibility of a non‐intrusive subscriber authentication technique – the use of keystroke dynamics. This feasibility study comprises a number of investigations into the ability of neural networks to authenticate users successfully based on their interactions with a mobile phone keypad. The initial results are promising with network classification performing well, achieving a 9.8 per cent false rejection rate and an 11.0 per cent false acceptance rate. Nathan L. Clarke, Steven Furnell, Benn Lines, Paul L. Reynolds |
Inf. Manag. Comput. Secur. | 2 |
| 2002 | Addressing Internet Security Vulnerabilities: A Benchmarking Study
A. Alayed, Steven Furnell, I. M. Barlow |
SEC | 2 |
| 2002 | Keystroke Analysis as a Method of Advanced User Authentication and Response
Paul Dowland 0001, Steven Furnell, Maria Papadaki |
SEC | 2 |
| 2002 | A web-based resource migration protocol using WebDAVabstractThe web's hyperlinks are notoriously brittle, and break whenever a resource migrates. One solution to this problem is a transparent resource migration mechanism, which separates a resource's location from its identity, and helps provide referential integrity. However, although several such mechanisms have been designed, they have not been widely adopted, due largely to a lack of compliance with current web standards. In addition, these mechanisms must be updated manually whenever a resource migrates, limiting their effectiveness for large web sites. Recently, however, new web protocols such as WebDAV (Web Distributed Authoring and Versioning) have emerged, which extend the HTTP protocol and provide a new level of control over web resources. In this paper, we show how we have used these protocols in the design of a new Resource Migration Protocol (RMP), which enables transparent resource migration across standard web servers. The RMP works with a new resource migration mechanism we have developed called the Resource Locator Service (RLS), and is fully backwards compatible with the web's architecture, enabling all web servers and all web content to be involved in the migration process. We describe the protocol and the new RLS in full, together with a prototype implementation and demonstration applications that we have developed. The paper concludes by presenting performance data taken from the prototype that show how the RLS will scale well beyond the size of today's web. Michael P. Evans, Steven Furnell |
WWW | 2 |
| 2002 | Acceptance of Subscriber Authentication Methods For Mobile Telephony Devices
Nathan L. Clarke, Steven Furnell, Philip M. Rodwell, Paul L. Reynolds |
Comput. Secur. | 2 |
| 2002 | Insider Threat Prediction Tool: Evaluating the probability of IT misuse
George Magklaras, Steven Furnell |
Comput. Secur. | 2 |
| 2002 | An experimental comparison of secret-based user authentication technologiesabstractThe paper presents a comparative study of software‐based user authentication techniques, contrasting the use of traditional password and personal identifier numbers (PIN) against alternative methods involving question and answer responses and graphical representation. All methods share the common basis of some secret knowledge and rely upon the user’s ability to recall it in order to achieve authentication. An experimental trial is described, along with the results based upon 27 participants. The alternative methods are assessed in terms of practical effectiveness (in this context relating to the participant’s ability to authenticate themselves a significant time after initial use of the methods), as well as the perceived levels of user friendliness and security that they provide. The investigation concludes that while passwords and PIN approaches garner good ratings on the basis of their existing familiarity to the participants, other methods based upon image recall and cognitive questions also achieved sufficiently positive results to suggest them as viable alternatives in certain contexts. I. Irakleous, Steven Furnell, Paul Dowland 0001, Maria Papadaki |
Inf. Manag. Comput. Secur. | 2 |
| 2001 | The Resource Locator Service: fixing a flaw in the web
Michael P. Evans, Steven Furnell |
Comput. Networks | 2 |
| 2001 | Security analysers: administrator assistants or hacker helpers?abstractSecurity analyser tools provide a useful means of automatically identifying, and potentially exploiting, vulnerabilities within computer systems and networks but they are also of assistance to hackers looking for ways to break in. The paper highlights the range of tools that are available and of potential use to both audiences and considers the extent to which each group is likely to benefit from them in practice. It is considered that the ease of use of tools such as Back Orifice 2000 provides a means by which even the relatively unskilled hacker may inflict damage upon a system. Although tools are generally equally available to hackers and administrators, the hacker community is likely to be more aware of the opportunities available. Even where adminstrators are aware of the existence of particular tools, survey results indicate that they make relatively limited use of them. Factors that may account for this include their overall workload and lack of security awareness. Appropriate countermeasures can be identified to combat the individual categories of tool, but the problem of ensuring that these safeguards are implemented still remains. Steven Furnell, Pelagia Chiliarchaki, Paul Dowland 0001 |
Inf. Manag. Comput. Secur. | 1 |
| 2000 | Authentication and Supervision: A Survey of User Attitudes
Steven Furnell, Paul Dowland 0001, H. M. Illingworth, Paul L. Reynolds |
Comput. Secur. | 1 |
| 2000 | A conceptual architecture for real-time intrusion monitoringabstractThe detection and prevention of authorised activities, by both external parties and internal personnel, is an important issue within IT systems. Traditional methods of user authentication and access control do not provide comprehensive protection and offer opportunities for compromise by various classes of abuser. A potential solution is provided in the form of intrusion detection systems, which are able to provide proactive monitoring of system activity and apply automatic responses in the event of suspected problems. This paper presents the principles of intrusion monitoring and then proceeds to describe the conceptual architecture of the Intrusion Monitoring System (IMS), an approach that is the focus of current research and development by the authors. The main functional elements of the IMS architecture are described, followed by thoughts regarding the practical implementation and the associated advantages (and potential disadvantages) that this would deliver. It is concluded that whilst an IMS‐type approach would not represent a total replacement for conventional controls, it would represent an effective means to complement the protection already provided. Steven Furnell, Paul Dowland 0001 |
Inf. Manag. Comput. Secur. | 1 |
| 1999 | Computer crime and abuse: A survey of public attitudes and awareness
Paul Dowland 0001, Steven Furnell, H. M. Illingworth, Paul L. Reynolds |
Comput. Secur. | 2 |
| 1999 | Computer hacking and cyber terrorism: the real threats in the new millennium?
Steven Furnell, Matthew J. Warren |
Comput. Secur. | 1 |
| 1999 | Dissecting the "Hacker Manifesto"abstractTwelve years ago, a text was written within the hacking community which is widely referred to as the “Hacker Manifesto”. This text, and the opinions that it offers, have since been widely embraced by the hacker community and the document is referenced from numerous sites on the Internet. This paper sets out to examine the content of the Manifesto and considers the validity of many of the messages that it imparts. The Manifesto is considered to present an undoubtedly pro‐hacker message, without acknowledging other perspectives or the wider implications of the activities that it is advocating. The paper explores some of these issues, examining both the consequences of the Manifesto’s dissemination and ways in which security professionals and society at large should respond. It is concluded that whilst the Manifesto obviously cannot bear the sole responsibility for promoting and encouraging hacker activity, it at best sends out an incomplete message that should be balanced with appropriate counter‐argument. Steven Furnell, Paul Dowland 0001, Peter W. Sanders |
Inf. Manag. Comput. Secur. | 1 |
| 1997 | ODESSA - a new approach to healthcare risk analysis
Matthew J. Warren, Steven Furnell, Peter W. Sanders |
SEC | 2 |
| 1996 | Applications of keystroke analysis for improved login security and continuous user authentication
Steven Furnell, Joseph P. Morrissey, Peter W. Sanders, Colin T. Stockel |
SEC | 1 |