Andrew C. Simpson

dblp:s/AndrewCSimpson · also Andrew Clive Simpson, Andrew Simpson 0001 · DBLP profile ↗
← Back
42ranked-venue papers
6as first author
5since 2021 · last 2024
0000-0003-3597-2232ORCID · conflict

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 13 · 1 first-author · 2 since 2021Applied, interdisciplinary, general and emerging computing · 13 · 3 first-author · 2 since 2021Human-computer interaction and ubiquitous computing · 10 · 2 first-author · 1 since 2021Software engineering, systems software and programming languages · 9 · 2 first-authorArtificial intelligence and machine learning · 7 · 2 first-authorSystems, architecture and hardware · 3Theory of computation · 1
YearPublicationVenuePosition
2024 Formalizing Attack Trees To Support Economic Analysis
abstract
Abstract Attack trees and attack graphs are both examples of what one might term attack modelling techniques. The primary purpose of such techniques is to help establish and enumerate the ways in which a system could be compromised; as such, they play a key role in the (security) risk analysis process. Given their role and the consequent need to ensure that they are correct, there are good reasons for capturing such artefacts in a formal manner. We describe such a formal approach, which has been motivated by a desire to model attacks from the perspectives of attackers, to support economic analysis. As an illustration, we consider exploitation cost.
Andrew C. Simpson, Matthias Dellago, Daniel W. Woods
Comput. J.1
2024 The Efficacy Potential of Cyber Security Advice as Presented in News Articles
abstract
Abstract Cyber security advice is a broad church: it is thematically expansive, comprising expert texts, user-generated data consumed by individual users via informal learning and much in-between. While there is evidence that cyber security news articles play a role in disseminating cyber security advice, the nature and extent of that role are not clear. We present a corpus of cyber security advice generated from mainstream news articles. The work was driven by two research objectives. The first objective was to ascertain what kind of actionable advice is being disseminated; the second was to explore ways of determining the efficacy potential of news-mediated security advice. The results show an increase in the generation of cyber security news articles, together with increases in vocabulary complexity and reading difficulty. We argue that these could present challenges for vulnerable users. We believe that this corpus and the accompanying analysis have the potential to inform future efforts to quantify and improve the efficacy potential of security advice dissemination.
Mark Quinlan, Aaron Ceross, Andrew C. Simpson
Interact. Comput.3
2023 Defending Against Data Poisoning Attacks: From Distributed Learning to Federated Learning
abstract
Abstract Federated learning (FL), a variant of distributed learning (DL), supports the training of a shared model without accessing private data from different sources. Despite its benefits with regard to privacy preservation, FL’s distributed nature and privacy constraints make it vulnerable to data poisoning attacks. Existing defenses, primarily designed for DL, are typically not well adapted to FL. In this paper, we study such attacks and defenses. In doing so, we start from the perspective of DL and then give consideration to a real-world FL scenario, with the aim being to explore the requisites of a desirable defense in FL. Our study shows that (i) the batch size used in each training round affects the effectiveness of defenses in DL, (ii) the defenses investigated are somewhat effective and moderately influenced by batch size in FL settings and (iii) the non-IID data makes it more difficult to defend against data poisoning attacks in FL. Based on the findings, we discuss the key challenges and possible directions in defending against such attacks in FL. In addition, we propose detect and suppress the potential outliers(DSPO), a defense against data poisoning attacks in FL scenarios. Our results show that DSPO outperforms other defenses in several cases.
Weizhe Zhang, Andrew C. Simpson, Yang Liu 0039, Zoe Lin Jiang
Comput. J.3
2022 Coordinated Vulnerability Disclosure programme effectiveness: Issues and recommendations
abstract
Coordinated Vulnerability Disclosure (CVD) programmes leverage a global network of independent security researchers (hackers) to support pre- and post-deployment security. Organisations are increasingly adopting Bug Bounty Programmes (BBPs) and Vulnerability Disclosure Programmes (VDPs) to outsource work from internal security teams, and are able to utilise the results from a programme to help shape their Software Development Life Cycle (SDLC) processes. Motivated by the question How effectively are organisations utilising CVD programmes?, we aim to address two issues concerning the operation of CVD programmes. First, it is necessary to identify the pre- and post-launch issues faced by programme operators that inhibit effective operation. Second, organisations stand to benefit if they are able to use the results of a CVD programme outside of the typical reporting-triaging information flow between a hacker and the operator. As such, it is useful to explore how the results of a CVD programme influence change across the SDLCs of real-world organisations and measure the extent to which this occurs. We report upon the results of a qualitative study based on the outcomes of 39 survey responses and eight semi-structured interviews with individuals involved in the operation of CVD programmes. It is found that the fears and issues faced by organisations are similar to those identified in earlier studies, suggesting that there has been little development in preventing prevalent problems faced by CVD programme operators. High volumes of low-quality, low-value reports still burden operators and consume resources. It is also found that organisations use the information contained within vulnerability reports to influence change in a number of security activities, namely testing, communication processes, and the specification of security requirements. Finally, based on the responses from the surveys and interviews, we provide recommendations to those looking to establish a CVD programme.
Thomas Walshe, Andrew C. Simpson
Comput. Secur.2
2021 A success model for cyber threat intelligence management platforms
Adam Zibak, Clemens Sauerwein, Andrew C. Simpson
Comput. Secur.3
2019 Cyber Threat Information Sharing: Perceived Benefits and Barriers
abstract
The literature on cyber security information sharing enumerates an extensive list of potential benefits for organisations in both the public and private sectors. However, despite the potential benefits, successful cyber security information sharing has been difficult to achieve. We report upon a study that sought to measure the extent to which the benefits and barriers suggested by the cyber security information sharing literature are reflected in the attitudes of practising security managers and analysts.
Adam Zibak, Andrew C. Simpson
ARES2
2019 Multiobjective feature selection for microarray data via distributed parallel algorithms
Bin Cao 0005, Jianwei Zhao 0001, Po Yang 0001, Peng Yang 0015, Xin Liu 0055, Jun Qi 0001, Andrew C. Simpson, Mohamed Elhoseny, Irfan Mehmood, Khan Muhammad 0001
Future Gener. Comput. Syst.7
2018 Rethinking the Proposition of Privacy Engineering
abstract
The field of privacy engineering proposes a methodological framework for designing privacy-protecting information systems. Recognising that the utilisation of privacy-enhancing techniques for data storage and analysis does not address the entire scope of individual privacy, privacy engineering incorporates influences from user sentiment, legal norms and risk analysis in order to provide a holistic approach. Framed by related design principles, such as 'Privacy-by-Design', privacy engineering purports to provide a practical, deployable set of methods by which to achieve such a holistic outcome. Yet, despite this aim, there have been difficulties in adequately articulating the value proposition of privacy engineering. Without being able to adequately define privacy or map its contours, any proposed methodology or framework will be difficult to implement in practice, if not self-defeating. This paper identifies and examines the assumptions that underpin privacy engineering, linking them to shortcomings and open questions. Further, we explore possible research avenues that may give rise to alternative frameworks.
Aaron Ceross, Andrew C. Simpson
NSPW2
2018 Analysis and Evaluation of Syntactic Privacy Notions and Games
abstract
Previous contributions have established a framework of privacy games that supports the representation of syntactic privacy notions such as anonymity, unlinkability, pseudonymity and unobservablility in the form of games. The intention is that, via such abstractions, the understanding of, and relationships between, privacy notions can be clarified. Further, an unambiguous understanding of adversarial actions is given. Yet, without any practical context, the potential benefits of these notions and games may be incomprehensible to system designers and software developers. We utilise these games in a case study based on recommender systems. Consequently, we show that the game-based definitions have the potential to interconnect privacy implications and can be utilised to reason about privacy.
Robin Ankele, Andrew C. Simpson
PST2
2018 Towards an Effective Privacy Impact and Risk Assessment Methodology: Risk Assessment
Majed Alshammari, Andrew C. Simpson
TrustBus2
2018 Risk and the Small-Scale Cyber Security Decision Making Dialogue - a UK Case Study
abstract
Despite a long-standing understanding that developments in personal and cloud computing practices would change the way we approach security, small-scale IT users (SSITUs) remain ill-served by existing cyber security practices. This paper discusses results from a survey that considered (in part) cyber security decisions made by SSITUs. We determine that SSITUs are focusing on easy-to-implement technical measures, leading to a disconnect between the security implemented and any risks identified; available resources, knowledge, prioritization of business processes, reduced system control and a lack of threat intelligence all combine to limit the ability to make cyber security decisions; and assessing risk in SSITUs will not lead to sufficient investment to mitigate risks for risk-holding stakeholders in the supply chain. We conclude that the constraints faced by SSITUs have far greater impact on the decisions they make than either our risk-holding, or security-providing, participants may have anticipated. Any limitations faced by SSITUs as they make their security decisions will have a significant impact on both the measures they are able to apply and the security of the supply chain as a whole.
Emma Osborn, Andrew C. Simpson
Comput. J.2
2018 A model-based approach to support privacy compliance
abstract
Purpose Concerns over data-processing activities that may lead to privacy violations or harms have motivated the development of legal frameworks and standards. Further, software engineers are increasingly expected to develop and maintain privacy-aware systems that both comply with such frameworks and standards and meet reasonable expectations of privacy. This paper aims to facilitate reasoning about privacy compliance, from legal frameworks and standards, with a view to providing necessary technical assurances. Design/methodology/approach The authors show how the standard extension mechanisms of the UML meta-model might be used to specify and represent data-processing activities in a way that is amenable to privacy compliance checking and assurance. Findings The authors demonstrate the usefulness and applicability of the extension mechanisms in specifying key aspects of privacy principles as assumptions and requirements, as well as in providing criteria for the evaluation of these aspects to assess whether the model meets these requirements. Originality/value First, the authors show how key aspects of abstract privacy principles can be modelled using stereotypes and tagged values as privacy assumptions and requirements. Second, the authors show how compliance with these principles can be assured via constraints that establish rules for the evaluation of these requirements.
Majed Alshammari, Andrew C. Simpson
Inf. Comput. Secur.2
2017 AdSelector: A Privacy-Preserving Advertisement Selection Mechanism for Mobile Devices
abstract
Targeted mobile advertising (TMA) enables organizations to tailor advertisements to specific consumers by analysing the personal information collected from consumers’ mobile devices. Although TMA offers great benefits to advertisers, the privacy concerns associated with it may reduce the advertising effectiveness. It follows that there is a need for an advertisement selection mechanism that can support the existing TMA business model in a manner that takes into account consumers’ privacy concerns. We present such an ad selection mechanism that has the potential to provide benefits to both consumers and advertisers. The mechanism is novel in its combination of a user subscription mechanism, a two-stage ad selection process, and the application of a trustworthy billing system. In particular, (i) the user subscription mechanism helps users to identify their interests and subscribe to desirable categories of ads; (ii) the two-stage ad selection process ensures that ad servers can only obtain coarse-grained user profiles, with fine-grained user profiles stored and used only on the mobile devices and (iii) the trustworthy billing system helps to report ad-clicks without revealing users’ identities and assists in detecting click-fraud attacks. The performance of the mechanism is evaluated in the context of a prototype privacy-preserving TMA framework.
Yang Liu 0039, Andrew C. Simpson
Comput. J.2
2017 On small-scale IT users' system architectures and cyber security: A UK case study
Emma Osborn, Andrew C. Simpson
Comput. Secur.2
2017 On the formal interpretation and behavioural consistency checking of SysML blocks
Jaco Jacobs, Andrew C. Simpson
Softw. Syst. Model.2
2016 Misuse, Abuse and Reuse: Economic Utility Functions for Characterising Security Requirements
abstract
Negative use cases - in the form of 'misuse' or 'abuse' cases - have found a broad following within the security community due to their ability to make explicit the knowledge, assumptions and desires of stakeholders regarding real and perceived threats to systems. As an accepted threat modelling tool, they have become a standard part of many Secure Software Engineering (SSE) processes. Despite this widespread adoption, aspects of the original misuse case concept have yet to receive a formal treatment in the literature. This paper considers the application of economic utility functions within the negative use case development process, as a means of addressing existing challenges. We provide a simple demonstration of how existing practice might integrate economic factors to describe the business, management and functional concerns that surround system security and software development.
Chad Heitzenrater, Andrew C. Simpson
ARES2
2016 A case for the economics of secure software development
abstract
Over the past 15 years the topic of information security economics has grown to become a large and diverse field, influencing security thinking on issues as diverse as bitcoin markets and cybersecurity insurance. An aspect yet to receive much attention in this respect is that of secure software development, or 'SWSec' --- another area that has seen a surge of research since 2000. SWSec provides paradigms, practices and procedures that offer some promise to address current security problems, yet those solutions face financial and technical barriers that necessitate a more thorough approach to planning and execution. Meanwhile, information security economics has developed theory and practice to support a particular world-view; however, it has yet to account for the investments, constructs and benefits of SWSec. As the frequency and severity of computer misuse has increased, both areas have struggled to impart a new mindset for addressing the inherent issues that arise in a diverse, connected and functionality-driven landscape.
Chad Heitzenrater, Andrew C. Simpson
NSPW2
2016 On Safety and Security Requirements in Emerging Ubiquitous Computing Models
abstract
The fields of safety and security are converging due to a number of factors, including the rise in system interconnectivity and an increased dependence on the Internet as part of critical national infrastructures. Partly as a reflection of this, there is a wealth of literature pertaining to the increasing interdependence between safety and security. While much of this research has been concerned with large-scale industrial systems, the rapid emergence of what might be termed Consumer cyber physical systems (Consumer CPS) means that it is crucial that such issues are considered in that context also. We evaluate the motivations for implementing Consumer CPS and the novelty of safety and security concerns that such systems give rise to. This evaluation is subsequently used to establish a collection of cyber security requirements for this emerging domain. We also consider how these requirements might impact upon product lifecycles. Our contribution is motivated and illustrated by three representative scenarios.
Emma Osborn, Andrew C. Simpson
Comput. J.2
2016 Privacy-preserving targeted mobile advertising: requirements, design and a prototype implementation
abstract
Summary With the continued proliferation of mobile devices, the collection of information associated with such devices and their users—such as location, installed applications and cookies associated with built‐in browsers—has become increasingly straightforward. By analysing such information, organisations are often able to deliver more relevant and better focused advertisements. Of course, such targeted mobile advertising gives rise to a number of concerns, with privacy‐related concerns being prominent. In this paper, we discuss the necessary balance that needs to be struck between privacy and utility in this emerging area and propose privacy‐preserving targeted mobile advertising as a solution that tries to achieve that balance. Our aim is to develop a solution that can be deployed by users but is also palatable to businesses that operate in this space. This paper focuses on the requirements and design of privacy‐preserving targeted mobile advertising and also describes an initial prototype. We also discuss how more detailed technical aspects and a complete evaluation will underpin our future work in this area. Copyright © 2016 John Wiley & Sons, Ltd.
Yang Liu 0039, Andrew C. Simpson
Softw. Pract. Exp.2
2015 Small-Scale Cyber Security
abstract
The nature of cyberspace continues to evolve, and so do the associated threats. The focus of the cyber security industry is typically (and understandably) on high-value assets. However, there is a large user group intersecting with corporate and government IT users, which lacks the resources -- in terms of finance, time and/or knowledge -- to deal with the threats that they face. We argue that greater attention needs to be given to this user group, differentiating these small-scale IT users when thinking about cyber security. Going further, we argue that it is essential that the research community starts to give consideration to what we term Small-Scale Cyber Security. To this end, we describe the results of an initial feasibility study, as well as a research agenda for tackling this cross-disciplinary problem.
Emma Osborn, Andrew C. Simpson
CSCloud2
2015 Experiences in Developing and Delivering a Programme of Part-Time Education in Software and Systems Security
abstract
We report upon our experiences in developing and delivering a programme of part-time education in Software and Systems Security at the University of Oxford. The MSc in Software and Systems Security is delivered as part of the Software Engineering Programme at Oxford - a collection of one-week intensive courses aimed at individuals who are responsible for the procurement, development, deployment and maintenance of large-scale software-based systems. We expect that our experiences will be useful to those considering a similar journey.
Andrew C. Simpson, Andrew P. Martin, Cas Cremers, Ivan Flechais, Ivan Martinovic, Kasper Bonne Rasmussen
ICSE (2)1
2014 Formal relational database design: an exercise in extending the formal template language
abstract
Abstract The use of formal description techniques aims to prevent the defects found in software that arise due to poor planning at the design stage. However, the ensuing specifications are often designed with only a single application in mind and are not easily generalised. One area in which these deficiencies arise is that of the formal modelling of relational databases: many authors have drawn parallels between the formal description language, Z, and the relational model of data, but none of these contributions have managed to be both close to the relational model in terms of providing a practical means of database design and fully formal in terms of providing an appropriate metamodel. In this paper, we describe a generative template language, based on the formal template language (FTL). In particular, we extend the FTL, which was developed originally as means of expressing templates, to underpin an approach that facilitates the reuse of specifications in Z, paying particular attention to the formal design of relational databases. These templates encapsulate the common structure found in specifications and can be instantiated to produce specifications tailored to suit particular needs. To achieve this, we extend the FTL and present a mechanism for naming and referencing templates. We also introduce the semantics of template annotations to enforce the syntactic correctness of instantiations.
Nicolas Wu, Andrew C. Simpson
Formal Aspects Comput.2
2013 Towards a Process Algebra Framework for Supporting Behavioural Consistency and Requirements Traceability in SysML
Jaco Jacobs, Andrew C. Simpson
ICFEM2
2011 Conformance Checking of Dynamic Access Control Policies
David J. Power, Mark Slaymaker, Andrew C. Simpson
ICFEM3
2009 On the utilisation of a service-oriented infrastructure to support radiologist training
abstract
The rise of service-oriented architectures and technology has, in recent years, started to lead to the opportunity for data sharing on a large-scale. In this paper we report upon how a service-oriented framework has been leveraged to support the development of a training application for radiologists. The application and framework have been developed separately - but sympathetically - with experience in both domains being leveraged to develop the prototype of an end-to-end training system. While the initial system utilises previously collected data, it is intended that in the future the system will interoperate with systems deployed within hospital environments.
Andrew C. Simpson, Mark Slaymaker, David J. Power, Douglas Russell, Moi Hoon Yap, Alastair G. Gale
CBMS1
2009 On Formalizing and Normalizing Role-Based Access Control Systems
abstract
Role-based access control (RBAC) has emerged as the dominant access control paradigm for service-oriented systems, with this dominance being reflected by the popularity of RBAC both with the research community and with information technology vendors. RBAC's dominance was solidified in 2004 when an American National Standards Institute standard for RBAC was approved. In this paper, we consider some of the drawbacks of this standard and show how the formal description technique, Z, has been used to underpin a model of RBAC. The model builds on the work of Li et al. and adopts a modular approach. In particular, we consider the relationships between different types of inheritance within our model. We show our model can be used to define a notion of equivalence between different RBAC systems. Finally, we show how—via our model—a particular RBAC system can be normalized to produce a simpler—but semantically equivalent—representation. We illustrate this process via two examples.
David J. Power, Mark Slaymaker, Andrew C. Simpson
Comput. J.3
2008 On the need for user-defined fine-grained access control policies for social networking applications
abstract
The increasing popularity in social network web sites is giving rise to new classes of security and privacy concerns. The effective management of these threats will require a three-pronged approach, involving a combination of social, legal and technical solutions. At the heart of the issue is the notion of trust: in sharing personal data, individuals are placing their trust not only in those responsible for these sites, but in other members of their virtual communities. In this paper we draw parallels with the issues of data sharing and trust that have arisen in the e-* (by which we mean e-Science, e-Research, e-Health, e-Business, etc.) arenas. Specifically, we concern ourselves with authorisation, and argue that members of such social networks should have the opportunity to construct fine-grained access control policies that meet their particular requirements and circumstances, and, in addition, should be able to observe appropriate audit information.
Andrew C. Simpson
SecureComm1
2007 Switched Lightpaths for e-Health Applications: Issues and Challenges
abstract
The Exploitation of Switched Lightpaths for e-Science Applications (ESLEA) project is evaluating the feasibility of using switched lightpath networks to support various e-Science applications. This feasibility is being investigated via case studies, one of which pertains to the use of such networks to support distributed healthcare research and delivery. In this paper we consider some of the issues associated with the use of switched lightpath networks in this context. Despite the fact that much of the discussion is necessarily focused on the situation in the UK, many of the issues will be relevant to the wider community.
Lee Momtahan, Sharon Lloyd, Andrew C. Simpson
CBMS3
2007 Developing collaborative technology for neuro-science
abstract
Using the NeuroGrid project as a case study, this paper explores the experiences and challenges in collaboratively developing technology and in the use of collaborative technology to enhance the science for the diverse scientific community of neuroscience. It explores methodologies adopted for ensuring continual engagement with a disparate clinical and technical community, the methods used for communication and the perceptions of technology from the perspective of the clinical scientific researchers. It explores the experiences of the multidisciplinary project staff in developing solutions and in the use and potential use of collaborative tools to achieve these goals.
Sharon Lloyd, Andrew C. Simpson, David J. Power, John R. Geddes, Ali Khanban, Jeb Palmer
CollaborateCom2
2007 Integrative Biology - the challenges of developing a collaborative research environment for heart and cancer modelling
Sharon Lloyd, David Gavaghan, Andrew C. Simpson, Matthew Mascord, Clint Seneurine, Geoff Williams, Joe Pitt-Francis, David R. S. Boyd, Damian Mac Randal, Lakshmi Sastry
Future Gener. Comput. Syst.3
2006 The Challenges of Developing a Collaborative Data and Compute Grid for Neurosciences
abstract
The three-year UK NeuroGrid project aims to develop a Grid-based collaborative research environment to support the data and compute needs for a UK Neurosciences community. This paper describes the challenges in developing this architecture and details initial results from the development of its first prototype to support psychosis, dementia and stroke research and the social challenges of such a collaborative research project. The paper discusses approaches being taken to explore the collaborative science process to inform the requirements for follow on prototypes and methods utilized to develop an effective project team.
John R. Geddes, Clare E. Mackay, Sharon Lloyd, Andrew C. Simpson, David J. Power, Douglas Russell, Mila Katzarova, Martin Rossor, Nick C. Fox, Jonathon Fletcher, Derek L. G. Hill, Kate McLeish, Joseph V. Hajnal, Stephen M. Lawrie, Dominic Job, Andrew M. McIntosh, Joanna M. Wardlaw, Peter Sandercock, Jeb Palmer, Dave Perry, Rob Procter, Jenny Ure, Philip M. Bath, Graham Watson
CBMS4
2006 Switched Lightpaths for e-Health Applications: a Feasibility Study
abstract
The exploitation of switch lightpaths for e-science applications (ESLEA) project is evaluating the feasibility of using switched lightpath networks to support various e-science applications, with this feasibility being investigated through a number of case studies. In this paper we report on progress to date with respect to determining how such networks might be utilised to support distributed healthcare applications. In particular, we consider the context of the work undertaken, introduce our use cases, and discuss some of the challenges faced
Lee Momtahan, Andrew C. Simpson
CBMS2
2006 A Prototype Infrastructure for the Secure Aggregation of Imaging and Pathology Data for Colorectal Cancer Care
abstract
In recent years, a significant number of developments across a broad range of disciplines have allowed researchers and clinicians to start to build up a picture of cancer development. In this paper we report upon the development of a prototype of a secure distributed infrastructure that links imaging data from pathology and radiology. The intention is that a fully-developed system will be capable of supporting studies that will examine whether prognostic and diagnostic features which are apparent in histopathological sections and clinical scans are related. Further, these studies will consider whether these features can be meaningfully linked into a diagnostic or predictive profile. The project in which the prototype is being developed naturally involves a large degree of cooperation across various disciplines. The focus of this paper is primarily on the development of the underlying prototype infrastructure.
Mark Slaymaker, Andrew C. Simpson, J. Michael Brady, David Gavaghan, Fiona Reddington, Philip Quirke
CBMS2
2006 Towards a Fully Generic Theory of Data
Douglas A. Creager, Andrew C. Simpson
ICFEM2
2006 Delegation in a Distributed Healthcare Context: A Survey of Current Approaches
Mila Katzarova, Andrew C. Simpson
ISC2
2006 Securing web services for deployment in health grids
David J. Power, Eugenia A. Politou, Mark Slaymaker, Andrew C. Simpson
Future Gener. Comput. Syst.4
2005 NeuroGrid: Using Grid Technology to Advance Neuroscience
abstract
Large-scale clinical studies in neuro-imaging are hampered by several factors including variances in acquisition techniques, quality assurance and access to remote datasets. The Neurogrid project will build on the experience of other UK e-science projects to assemble a grid infrastructure, and apply this to three exemplar areas: stroke, dementia and psychosis, to conduct collaborative neuroscience research.
John R. Geddes, Sharon Lloyd, Andrew C. Simpson, Martin Rossor, Nick C. Fox, Derek L. G. Hill, Joseph V. Hajnal, Stephen M. Lawrie, Andrew M. McIntosh, Eve C. Johnstone, Joanna M. Wardlaw, Dave Perry, Rob Procter, Philip M. Bath, Edward T. Bullmore
CBMS3
2005 GIMI: Generic Infrastructure for Medical Informatics
abstract
Breakthroughs in medical informatics have yielded a wealth of data across all aspects of patient care. One of the fundamental goals of e-Science should be facilitate the appropriate use of such data to improve patient care: both in the short-term and the long-term. Developments in Grid technology have brought about the promise of such data being used to, for example, support research into evidence-based patient centred care and facilitate on-demand decision support for practitioners. For such health grid dreams to become reality, however, it will first be necessary to tackle key technical challenges, such as those of interoperability and security. The GIMI (Generic Infrastructure for Medical Informatics) proposes to tackle exactly these generic problems within the context of healthcare in the United Kingdom.
Andrew C. Simpson, David J. Power, Mark Slaymaker, Eugenia A. Politou
CBMS1
2005 Collaboration and Trust in Healthcare Innovation: The eDiaMoND Case Study
Marina Jirotka, Rob Procter, Mark Hartswood, Roger Slack, Andrew C. Simpson, Catelijne Coopmans, Chris Hinds, Alexander Voß
Comput. Support. Cooperative Work.5
2005 Towards secure Grid-enabled healthcare
abstract
Abstract The primary focus of the UK e‐Science Programme is the development of software architectures, middleware and applications to support the end‐user scientific community in the undertaking of large‐scale research. A significant subset of e‐Science projects is concerned with the healthcare domain: as well as satisfying the needs of the end users, such projects have to consider the legal, ethical and security constraints associated with the use of sensitive patient data—these concerns are particularly relevant within the context of the U.K.'s National Health Service (NHS). In this paper we present a vision for Grid‐enabled healthcare that is sensitive to the information security requirements both of the NHS and the projects themselves. Although our motivation is principally derived from U.K.‐based e‐Health projects, this paper should be of interest to the worldwide health Grid community. By restricting ourselves to information security, we do not consider, for example, physical security or audit trail capabilities, which are outside the scope of this paper. The vision we describe is grounded in terms of experience, and reflects the challenges faced by the e‐DiaMoND project team. Copyright © 2005 John Wiley & Sons, Ltd.
David J. Power, Eugenia A. Politou, Mark Slaymaker, Andrew C. Simpson
Softw. Pract. Exp.4
2003 Generalising the Z Schema Calculus: Database Schemas and Beyond
abstract
The theory of relational databases has much in common with the mathematical structures central to the Z notation. Many authors have noted these connections in the past, but the development of the Z standard has provided a more natural way of making these links explicit. We explore extensions to the schema calculus that may help to model the familiar relational algebra operations in a clear way. Potential areas of application for this work include pedagogy, practical database design, and helping to point the way towards a more general means for defining a broader class of schema calculus operations.
Andrew P. Martin, Andrew C. Simpson
APSEC2
2003 On The Supervision and Assessment Of Part-Time Postgraduate Software Engineering Projects
abstract
This paper describes existing practices in the supervision and assessment of projects undertaken by part-time, postgraduate students in Software Engineering. It considers this aspect of the learning experience, and the educational issues raised, in the context of existing literature-much of which is focussed upon the experience of full-time, undergraduate students. The importance of these issues will increase with the popularity of part-time study at a postgraduate level; the paper presents a set of guidelines for project supervision and assessment.
Andrew C. Simpson, Andrew P. Martin, Jeremy Gibbons, Jim Davies, Steve McKeever
ICSE1