Publications
Peer-reviewed research exploring human factors in cybersecurity, security education, usable privacy and implications of security.
Conference papers
A Physically Unclonable Function Authentication Protocol to Secure IEEE C37.118 Communications
Griffiths T, Ahmed M, Haskell-Dowland PS
Proceedings of the 25th European Conference on Cyber Warfare & Security (ECCWS 2026), Nottingham, UK, 29-30 June
This paper outlines the need for security on the smart grid, specifically for Phasor Measurement Units (PMUs) and Phasor Data Concentrators (PDCs). These devices are targeted due to their criticality to the smart grid and the insecure communication protocols used. Common attacks on these devices...
On Relaying Strategies in Multi-Hop Covert Wireless Communications
Yu X, Yan S, Hu J, Haskell-Dowland PS, Han Y, Ng DWK
IEEE International Conference on Communications, pp666-672, DOI: 10.1109/ICC45855.2022.9838514
Multi-hop transmissions are desirable in realizing large-scale long-distance covert wireless communications, since a single-hop transmission cannot fully satisfy the covertness requirement even with high transmit power. Against this background, this work compares amplify-and-forward (AF) and...
Towards Evaluating the Effectiveness of Botnet Detection Techniques
Woodiss-Field A, Johnstone M, Haskell-Dowland PS
International Conference on Ubiquitous Security (UBISEC 2021), pp 292-308 (published 2022), Springer, DOI: 10.1007/978-981-19-0468-4_22
Botnets are a group of compromised devices taken over and commanded by a malicious actor known as a botmaster. In recent years botnets have targeted Internet of Things (IoT) devices, significantly increasing their ability to cause disruption due to the scale of the IoT. One such IoT-based botnet was...
IoT Threat Detection Advances, Challenges and Future Directions
Karie NM, Sahri NM, Haskell-Dowland PS
2020 Workshop on Emerging Technologies for Security in IoT (ETSecIoT), 21-21 April, Sydney, Australia
It is predicted that, the number of connected Internet of Things (IoT) devices will rise to 38.6 billion by 2025 and an estimated 50 billion by 2030. The increased deployment of IoT devices into diverse areas of our life has provided us with significant benefits such as improved quality of life and...
Hybrid Routing for Man-in-the-Middle (MITM) Attack Detection in IoT Networks
Kang J, Fahd K, Venkatraman S, Trujillo-Rasua R, Haskell-Dowland PS
2019 29th International Telecommunication Networks and Applications Conference (ITNAC), ISBN: 978-1-7281-3674-5, pp. 1-6
Affordable and expandable low power networks such as 5G and Low Power Wide Area Networks (LPWAN) in the public and private network areas have improved network bandwidth capacities and processing performance. Internet of Things (IoT) technologies are increasing in popularity with numerous...
Building a Better Micro:Bit IDE – Teaching Computer Science
Ellis M, Thompson G, Haskell-Dowland PS
INTED2020 Proceedings of the 14th International Technology, Education and Development Conference, Valencia, Spain, 2-4 March, ISBN: 978-84-09-17939-8, pp8425-8433
There are a plethora of online websites and unplugged materials for people who want to learn how to code. From Scratch in the early years to the more recent (relatively) Massive Open Online Courses, there are many sources of educational and training oriented materials to assist individuals who want...
The Hop Portal Snowglobe Architecture: Making Virtual Reality Functional
Chady T, Haskell-Dowland PS
INTED2020 Proceedings of the 14th International Technology, Education and Development Conference, Valencia, Spain, 2-4 March, ISBN: 978-84-09-17939-8, pp8395-8403
Navigation in Virtual Reality is a complex experience which depends on the aesthetic, objectives and interactivity of the content. Nevertheless, one can still make distinctions with regards to how one may navigate between Virtual Reality experiences. ...
Good guidance or mistaken misdirection: Assessing the quality of password advice
Furnell SM, Haskell-Dowland PS
Proceedings of the Annual Information Institute Conference, 2020 Information Institute Las Vegas Conference
Modern websites often require users to create accounts in order to utilise services or store information. With password leaks appearing on an almost daily basis and being widely publicised, it is reasonable to assume that users should be adopting appropriate practices to secure their accounts and...
Addressing STEM Geek Culture Through Peer Learning
Vasileiou I, Haskell-Dowland PS
EDULEARN19 Proceedings, pp5289-5293, Palma, Mallorca, Spain
STEM is generally considered to be a male-dominated environment. The geek culture that often leads to social issues, and the gender imbalance that leads to fewer girls choosing a STEM subject, are becoming important topics of research. Peer learning has been widely used across the world to support...
From Model B To Micro:Bit – Teaching Computer Science
Ellis M, Thompson G, Haskell-Dowland PS
Proceedings of EDULEARN19 Conference, pp2725-2731, Palma, Mallorca, Spain
In the early 1980’s, the UK British Broadcasting Company (BBC), in partnership with the Acorn Computer company designed and released the BBC Micro computer. With a specific focus on the educational sector and accompanying television series, the BBC/Acorn introduced a (relatively) cost-effective...
Design Principles and Guidelines for Targeted Security Awareness
Mahmoud N, Furnell SM, Haskell-Dowland PS
Proceedings of the Annual Information Institute Conference, March 26-28, Las Vegas, USA, ISBN: 978-1-935160-19-9
Key aspects that weaken users’ ability to use security are often related to the difficulty of comprehending the features/notifications within the interfaces of applications, inconsistency in the interfaces, and not receiving appropriate guidance or adequate security information. This often leads...
Misuse Detection in a Simulated IaaS Environment
Al-Bayati B, Clarke NL, Haskell-Dowland PS, Li F
1st International Workshop on Emerging Technologies for Authorization and Authentication, ISBN: 978-3-030-04371-1, pp103-115
Cloud computing is an emerging technology paradigm by offering elastic computing resources for individuals and organisations with low cost. However, security is still the most sensitive issue in cloud computing services as the service remains accessible to anyone after initial simple authentication...
Continuous identity verification in cloud storage services using behavioural profiling
Al-Bayati B, Clarke NL, Haskell-Dowland PS, Li F
17th European Conference on Cyber Warfare and Security ECCWS 2018, 28-29 June, ISBN: 978-1-911218-85-2, pp1-10
Cloud storage services have become immensely popular because they enable users to remotely store their data over the Internet. However, this has led to a lack of physical control to protect their information with an increasing vulnerability to potential attacks. Well-known service providers...
Transparent Authentication: Utilising Heart Rate for User Authentication
Enamamu T, Clarke NL, Haskell-Dowland PS, Li F
International Conference for Internet Technology and Secured Transactions (ICITST-2017) , pp283-289, ISBN:978-1-9083-207-97
There has been exponential growth in the use of wearable technologies in the last decade with smart watches having a large share of the market. Smart watches were primarily used for health and fitness purposes but recent years have seen a rise in their deployment in other areas. Recent smart watches...
Body Temperature Authentication for Secure Smartwatch to Smart Device Communication
Enamamu T, Clarke NL, Haskell-Dowland PS, Li F
Proceedings of the IEEE International Conference on Computing, Networking and Informatics (ICCNI 2017) , ISBN: 978-1-5090-4643-0, pp1-7
The advancement of smart devices has led to a steep rise in wearable devices of which smart watches are increasingly gaining popularity in the wearable technology market. Most smart watches have evolved from their first generation to their present generation with increased functionality and...
Unobtrusive Gait Recognition Using Smartwatches
Al-Naffakh N, Clarke NL, Li F, Haskell-Dowland PS
International Conference of the Biometrics Special Interest Group (BIOSIG), 20-22 September, Darmstadt, Germany, pp211-218, ISBN 978-3-88579-664-0, 10.23919/BIOSIG.2017.8053523
Gait recognition is a technique that identifies or verifies people based upon their walking patterns. Smartwatches, which contain an accelerometer and gyroscope have recently been used to implement gait-based biometrics. However, this prior work relied upon data from single sessions for both...
Towards Targeted Security Awareness Raising
Mahmoud N, Furnell SM, Haskell-Dowland PS
Proceedings of the Annual Information Institute Conference, 18-20 April, Las Vegas, USA, ISBN: 978-1-935160-18-2
Users are frequently cited as being the weakest link in the information security chain. However, in many cases they are ill-positioned to follow good practice and make the necessary decisions. Part of the reason here is that, even if security awareness, training and/or education have been provided,...
Teleoperation of mobile robots over wireless internet
Dorigo M, Harriehausen-Mühlbauer B, Stengel I, Dowland PS
Proceedings of the 4th International Conference on Internet Technologies and Applications, ITA 11; Wrexham, Wales; United Kingdom, ISBN:978-094688168-0, pp145-151
There are thousands of applications where a mobile robot has to be manually teleoperated over wireless internet connections. This paper presents a concept on how mobile robots can be controlled remotely over the Internet from anywhere in the world and feedback such as full HD resolution video and...
Nonvisual Presentation, Navigation and Manipulation of Structured Documents on Mobile and Wearable Devices
Dorigo M, Harriehausen-Mühlbauer B, Stengel I, Dowland PS
International Conference on Computers for Handicapped Persons, ISBN: 978-3-319-08595-1, pp383-390
There are a large number of highly structured documents, for example: newspaper articles, scientific, mathematical or technical literature. As a result of inductive research with 200 blind and visually impaired participants, a multi-modal user interface for non-visual presentation, navigation and...
Activity Recognition using wearable computing
Al-Naffakh N, Clarke NL, Dowland PS, Li F
11th International Conference for Internet Technology and Secured Transactions (ICITST), pp. 189-195, Barcelona, Spain
A secure, user-convenient approach to authenticate users on their mobile devices is required as current approaches (e.g., PIN or Password) suffer from security and usability issues. Transparent Authentication Systems (TAS) have been introduced to improve the level of security as well as offer...
Increasing eLearning Engagement Using Mobile Technologies
Triantafyllidis A, Clarke NL, Dowland PS, Vranopoulos G
9th annual International Conference of Education, Research and Innovation (ICERI2016), 14-16 November, Seville, Spain, pp8644-8653, ISBN: 978-84-617-5895-1, ISSN: 2350-1095
Web-based Learning Management Systems (LMS) have their way into the methods that students, lecturers and generally the education community communicates, stores, shares and collaborates. Although technically they seem to provide an ideal environment for deploying constructive eLearning activities,...
The Value of the Biometrics in Invigilated E-Assessments
Ketab S, Clarke NL, Dowland PS
Proceedings of the the 8th Annual International Conference on Education and New Learning Technologies, Barcelona, Spain, 4-6 July, ISBN: 978-84-608-8860-4, ISSN: 2340-1117
Over the last decade, e-learning has played an important role in education. The growing number of users (70 million students and 1.2 million teachers across 7.5 million courses) has given rise to a major concern over protecting them from misuse; the most significant of the potential misuse is the...
A Review of Graphical Authentication Utilising a Keypad Input Method
Alsaiari H, Papadaki M, Dowland PS, Furnell SM
Proceedings of The 8th Saudi Students Conference, January 31 - February 1, pp359-374
The traditional password has long been the most widely used authentication mechanism in spite of its well-known flaws. In order to address these flaws, researchers have utilised images or drawings as a potential alternative. In this paper, we consider the attributes of several graphic-based...
E-Invigilation of E-Assessments
Ketab S, Clarke NL, Dowland PS
Proceedings of INTED2015 Conference 2nd-4th March 2015, Madrid, Spain, ISBN: 978-84-606-5763-7
Over the last ten years, e-learning has played a vital role in education. A leading Virtual Learning Environment (VLE) reports a user base of 70 million students and 1.2 million teachers across 7.5 million courses. Whilst e-learning has introduced flexibility and remote/distance-based learning,...
Security challenges of e-government adoption based on end users' perspective
Alharbi N, Papadaki M, Dowland PS
Proceedings of the 9th International Conference for Internet Technology and Secured Transactions (ICITST 2014), London, UK, pp78-82, ISBN: 978-1-908320-39-1
In recent years, many countries have used e-government to provide high quality services to their citizens. Thus, a number of studies have investigated user acceptance of e-government through the use of adoption models, such as the Unified Theory of Acceptance and Use of Technology (UTAUT) model....
Alternative Graphical Authentication for Online Banking Environments
Alsaiari H, Papadaki M, Dowland PS, Furnell SM
Proceedings of the Eighth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2014), Plymouth, UK, July 8-9, pp122-136, ISBN: 978-1-84102-375-5
Many financial institutes tend to implement a secure authentication mechanism through the utilization of the One-Time-Password (OTP) technique. The use of a hardware security token to generate the required OTP has been widespread. Despite the fact that this method provides a fairly high level of...
Connected In-Car Multimedia: Qualities Affecting Composability of Dynamic Functionality
Knirsch A, Wietzke J, Moore R, Dowland PS
Proceedings of the Tenth International Network Conference (INC 2014), Plymouth, UK, July 8-9, pp81-93, ISBN: 978-1-84102-373-1
In-Car Multimedia systems have become a fundamental part of a car's human-machine interface. Recent developments within the domain of mobile consumer electronics create demands for flexible functionality by use of after-market applications, also within the automotive sector. Further, current...
Nonvisual Presentation and Navigation within the Structure of Digital Text-Documents on Mobile Devices
Dorigo M, Harriehausen-Mühlbauer B, Stengel I, Dowland PS
7th International Conference, UAHCI 2013, Las Vegas, NV, USA, July 21-26, ISBN: 978-3-642-39193-4, pp311-320
This paper introduces a novel concept for an assistive technology in support of blind and visually impaired persons for nonvisual presentation and navigation within the structure of digital text-documents on mobile devices (smart phones, internet tablets, etc.) which enables them to get a fast...
Learning management systems in higher education: a faculty perspective
Triantafyllidis A, Clarke NL, Dowland PS
6th International Conference of Education, Research and Innovation (ICERI2013), Madrid, Spain, ISBN: 978-84-616-3847-5, pp5120-5130
The use of the Internet and the Web have gradually made their way into the methods that students, lecturers and generally the education community communicates, stores, shares and collaborates. Indeed, it has arguably become the norm rather than the alternative. As an alternative to traditional...
Learning management systems in higher education: a student perspective
Triantafyllidis A, Clarke NL, Dowland PS
5th International Conference of Education, Research and Innovation (ICERI2012), Madrid, Spain, ISBN: 978-84-616-0763-1, pp4046-4055
The Internet and especially the Web have effectively become the default mechanism for information dissemination, collaboration, communication and storage. Higher education institutions have started to make use of these technologies by implementing web based Learning Management Systems (LMS). Their...
E-Invigilator: A Biometric-Based Supervision System for e-Assessments
Clarke NL, Dowland PS, Furnell SM
The International Conference on Information Society (i-Society 2013), Toronto, Canada, 24-26 June
The creation of Virtual Learning Environments (VLEs) have revolutionized the online delivery of learning materials, from traditional lectures slides through to podcasts, blogs and wikis. However, such advances in how we assess such learning have not evolved – with physical attendance at proctored...
Survey: improving document accessibility from the blind and visually impaired user's point of view
Dorigo M, Harriehausen-Mühlbauer B, Stengel I, Dowland PS
Proceedings of the 6th International Conference on Universal Access in Human-Computer Interaction. Applications and Services, pp129-135, 978-3-642-21656-5
There are thousands of digital documents available on the internet, but many of them are not accessible for blind and visually impaired people. To find out what is of importance as to the reading of text and the navigation within documents from the user’s point of view, a survey has been conducted...
Assessing the usability of application level security warnings
Zaaba ZF, Furnell SM, Dowland PS, Stengel I
Eleventh Annual Security Conference, Las Vegas, Nevada, US, 11-13 April
This paper investigates users’ understanding of security messages that can be encountered on a daily basis whilst using their computer. An experimental study was conducted that made use of a custom-built program designed to capture security messages and examine users’ views regarding the...
Multifactor Graphical Passwords: An Assessment of End-User Performance
Jali MZ, Furnell SM, Dowland PS
Proceedings of the 7th International Conference of Information Assurance & Security (IAS2011), Melaka, Malaysia, 5-8 December 2011. IEEE 978-1-4577-2153-3
This paper reports on the usability study carried out to assess the feasibility of combining two graphical password methods for better security. The methods involved clicking on the image (i.e. click-based) and selecting a series of images (i.e. choice-based). A graphical password prototype was...
Quantifying the effect of graphical password guidelines for better security
Jali MZ, Furnell SM, Dowland PS
Future Challenges in Security and Privacy for Academia and Industry (SEC 2011), Lucerne, Switzerland, 7-9 June 2011. Volume 354/2011, Springer-Verlag, pp80-91
Authentication using images or graphical passwords is one of the possible alternatives for traditional authentication based upon passwords. This study aims to investigate the practicality of giving guidelines or advice to users before they start choosing their image passwords, the effectiveness of...
Resource Management for Multicore Aware Software Architectures of In-Car Multimedia Systems
Knirsch A, Wietzke J, Moore R, Dowland PS
Lecture Notes in Informatics (LNI) - Proceedings, Series of the Gesellschaft für Informatik (GI), Volume P-192, 9th Workshop Automotive Software Engineering, INFORMATIK 2011: Informatik schafft Communities, 4.–7. October 2011, Berlin, p216, ISBN: 978-3-88579-286-4, (full text is available online)
With increasing hardware capabilities the demands on the functionality of user centric systems continuously expand. The next generation of automotive embed- ded systems is going to make use of multicore hardware architectures, which strongly enhances the computational power. This means a movement...
Emerging risks in massively multiplayer online role playing games
Sanders B, Atkinson S, Dowland PS, Furnell SM, Papadaki M
EU Kids Online Conference, Friday 23 September, New Academic Building LSE
Massively Multiplayer Online Role Playing Games (MMORPG’s) are highly ...
Behaviour Profiling for Transparent Authentication for Mobile Devices
Li F, Clarke NL, Papadaki M, Dowland PS
Proceedings of the 10th European Conference on Information Warfare and Security (ECIW), Tallinn, Estonia 7-8 July, pp307-314
Since the first handheld cellular phone was introduced in 1970s, the mobile phone has changed significantly both in terms of popularity and functionality. With more than 4.6 billion subscribers around the world, it has become a ubiquitous device in our daily life. Apart from the traditional...
End-User Perception and Usability of Information Security
Zaaba ZF, Furnell SM, Dowland PS
Proceedings of the Fifth International Symposium on Human Aspects of Information Security & Assurance (HAISA 2011), London, UK, ISBN: 978-1-84102-284-0, pp97-107
This paper investigates users’ understanding of security features and application and examines ...
Online Addiction: Privacy Risks in Online Gaming Environments
Sanders B, Chen V, Zahra D, Dowland PS, Atkinson S, Papadaki M, Furnell SM
Proceedings of the International Conference on Management of Emergent Digital EcoSystems (MEDES), October 26-29, Bangkok, Thailand
In this paper we investigated the levels of addiction and personal data disclosure within Massively Multiplayer Online Role Playing Game environments (MMORPG's). The study made use of an online survey which embraced a combination of a six point behavioural addiction framework, Self...
Behaviour Profiling on Mobile Devices
Li F, Clarke NL, Papadaki M, Dowland PS
International Conference on Emerging Security Technologies, 6-8 September, Canterbury, UK, pp77-82
Over the last decade, the mobile device has become a ubiquitous tool within everyday life. Unfortunately, whilst the popularity of mobile devices has increased, a corresponding increase can also be identified in the threats being targeted towards these devices. Security countermeasures such as AV...
Implications and Risks of MMORPG Addiction: Motivations, Emotional Investment, Problematic Usage and Personal Privacy
Sanders B, Dowland PS, Furnell SM
Proceedings of the South African Information Security Multi-Conference (SAISMC 2010), Port Elizabeth, South Africa, 17-18 May, ISBN: 978-1-84102-256-7, pp61-73
The omnipresence of technology combined with the widespread embrace of online communication has undoubtedly created a subculture of ‘always on’. Indeed, experts have revealed that online interaction and information invokes a ‘dopamine squirt’ similar in effect to that of narcotics abuse. ...
A Critical Evaluation of an Online Peer Assessment System (OPAS)
Clarke NL, Dowland PS
Proceedings of the International Conference of Education, Research and Innovation (ICERI 2009), 16-18th November, Madrid, Spain
The method of assessing knowledge and understanding can vary, with new approaches being developed periodically. Although traditional methods such as exams, essays and oral presentations still form the backbone to many undergraduate assessment programmes, much focus is being given to newer techniques...
Evaluating Web-Based User Authentication using Graphical Techniques
Jali MZ, Furnell SM, Dowland PS
Proceedings of the Third International Symposium on Human Aspects of Information Security & Assurance (HAISA 2009), Athens, Greece, ISBN: 978-1-84102-231-4, pp108-118
Graphical techniques are one of the many alternatives proposed to address the weaknesses in the conventional authentication based upon username and passwords. In this paper, two methods of graphical technique, namely ‘click-based’ and ‘choice-based’ are studied in term of their usability for...
An Assessment of People’s Vulnerabilities in Relation to Personal and Sensitive Data
Sanders B, Dowland PS, Furnell SM
Proceedings of the Third International Symposium on Human Aspects of Information Security & Assurance (HAISA 2009), Athens, Greece, ISBN: 978-1-84102-231-4, pp50-60
Social engineering refers to a number of techniques that are used to exploit human vulnerabilities and manipulate people into breaking normal security procedures. Evidence suggests that this problem is rapidly increasing and cyber criminals are using a magnitude of different avenues to reach their...
Service-Oriented Architecture: Performance Issues and Approaches
Swientek M, Bleimann U, Dowland PS
Proceedings of the Seventh International Network Conference (INC2008), Plymouth, UK, 8-10 July, pp261-269
The introduction of a Service-Oriented Architecture (SOA) can affect performance in a negative way. This exacerbates the application of SOA to systems for bulk data processing. This paper describes specific aspects of Service-Oriented Architectures that impact performance particularly. It discusses...
A practical usability evaluation of security features in end-user applications
Furnell SM, Katsabas D, Dowland PS, Reid F
Proceedings of the 22nd IFIP International Information Security Conference (IFIP SEC 2007), Sandton, South Africa, 14-16 May, pp. 205-216
The presentation and usability of security features can represent a significant impediment to effective protection for end-user systems. In order to investigate the nature and level of problems that can be encountered during attempts to use security within standard end-user applications, this paper...
Considering the Usability of End-User Security Software
Furnell SM, Jusoh A, Katsabas D, Dowland PS
Proceedings of 21st IFIP International Information Security Conference (IFIP SEC 2006), Karlstad, Sweden, 22-24 May, pp307-316
Security features can now be found in a variety of end-user applications. However, the extent to which such features can actually be understood and used by the target audience is often undermined by poor attention to human-computer interaction factors. This paper considers the problem, and...
Using Human Computer Interaction principles to promote usable security
Katsabas D, Furnell SM, Dowland PS
Proceedings of Fifth International Network Conference (INC 2005), July 5-7, Samos, Greece, pp235-242
Faced with an increasing range of attacks, the appropriate use of available security features in computer systems and applications is becoming ever more necessary. However, although many applications provide ways in which users can protect themselves against threats, the design and implementation of...
Identifying the security requirements for virtual university environments
Ruiz VC, Furnell SM, Phippen AD, Dowland PS, Stengel I, Bleimann U
Proceedings of the Fourth Security Conference 2005, Las Vegas, USA, 30-31 March
Virtual universities (VUs) are meant to provide a new learning model for students and a way to study away from traditional facilities. Security is now regarded as a high priority within computer systems, and has been increasingly introduced to the public over the years. Many new technologies have...
Survey of Wireless Access Point Security
Voisin M, Ghita BV, Dowland PS
Proceedings of the Fourth Security Conference 2005, Las Vegas, USA, 30-31 March
The development of wireless networks has introduced a number of security issues inherent to the communication medium and to the different security approaches available. While WEP encryption is widely accepted as insecure, it remains one of the easiest to use and most widespread wireless security...
PassImages : an alternative method of user authentication
Charruau D, Furnell SM, Dowland PS
Proceedings of the ISOneWorld 2005, Las Vegas, USA, 30 March - 1 April,
This paper presents an assessment of an alternative to the predominant password and ...
A Long-term Trial of Keystroke Profiling using Digraph, Trigraph and Keyword Latencies
Dowland PS, Furnell SM
Proceedings of IFIP/SEC 2004 - 19th International Conference on Information Security, Toulouse, France, 23-26 August, pp275-289
A number of previous studies have investigated the use of keystroke analysis as a means of authenticating users' identities at the point of initial login. By contrast, relatively little research has focused upon the potential of applying the technique for identity verification during the...
A Correlation Framework for Continuous User Authentication Using Data Mining
Singh H, Furnell SM, Dowland PS, Lines BL, Kaur S
Proceedings of the Fourth International Network Conference (INC 2004), Plymouth, UK, 6-9 July 2004, pp237-245
The ever-increasing security breaches by both external and internal intruders highlight the lack of security measures in many current systems. Extensive work has been carried out to address this problem, for example by enhancing the initial login stage in order to overcome the security flaws of...
Improving Security Awareness And Training Through Computer-Based Training
Furnell SM, Warren A, Dowland PS
Proceedings of the WISE Conference, Monterey, USA, July, pp287-301
Security awareness is a critical issue for all organisations that depend upon information technology. However, significant survey evidence suggests that the issue is often given inadequate attention in modern organisations, leading to problems through security incidents. This paper considers...
Assessing IT Security Culture: System Administrator and End-User
Finch J, Furnell SM, Dowland PS
Proceedings of ISOneWorld Conference 2003, Las Vegas, USA, April 23-25, CD Only
Appropriate understanding and acceptance of IT security should now be regarded as an essential requirement within any modern business. Although a number of previous studies have been published that assess organizational attitudes, the respondents have typically been IT administrators or top-level...
Critical awareness ? The problem of monitoring security vulnerabilities
Furnell SM, Alayed A, Barlow I, Dowland PS
Proceedings of European Conference on Information Warfare and Security, 8-9 July 2002, Brunel, UK, pp85-92
Security vulnerabilities are known problems that frequently affect operating systems, Internet servers and application programs from numerous vendors. The paper examines the scale of the problem, referencing advisory sources such as CERT/CC, BugTraq and CVE. Although it is relatively easy to...
Keystroke Analysis as a Method of Advanced User Authentication and Response
Dowland PS, Furnell SM, Papadaki M
Proceedings of IFIP/SEC 2002 - 17th International Conference on Information Security, Cairo, Egypt, 7-9 May, pp215-226
There has been significant interest in the area of keystroke analysis to support the authentication of users, and previous research has identified three discrete methods of application; static, periodic dynamic and continuous dynamic analysis. This paper summarises the approaches and metrics arising...
A Preliminary Investigation of User Authentication Using Continuous Keystroke Analysis
Dowland PS, Singh H, Furnell SM
Proceedings of the IFIP 8th Annual Working Conference on Information Security Management & Small Systems Security, Las Vegas, 27-28 September
There has been significant research in to the provision of reliable initial-login user authentication, however there is still a need for continuous authentication during a user session. This paper presents a series of results from the preliminary statistical analysis of multi-application keystroke...
Investigating and Evaluating Behavioural Profiling and Intrusion Detection Using Data Mining
Singh H, Furnell SM, Lines BL, Dowland PS
Proceedings of International Workshop on Mathematical Methods, Models and Architectures for Computer Networks Security, St. Petersburg, Russia, 21-23 May
The continuous growth of computer networks, coupled with the increasing number of people relying upon information technology, has inevitably attracted both mischievous and malicious abusers. Such abuse may originate from both outside an organisation and from within, and will not necessarily be...
A Generic Taxonomy for Intrusion Specification and Response
Furnell SM, Magklaras GB, Papadaki M, Dowland PS
Proceedings of Euromedia 2001, Valencia, Spain, 18-20 April
The paper presents a preliminary description of an intrusion taxonomy to aid the development of a generic intrusion specification and response platform. Existing intrusion taxonomies are assessed in order to derive a suitable classification of incidents that would be both detectable and addressable...
Promoting security awareness and training within small organisations
Furnell SM, Gennatou M, Dowland PS
Proceedings of the First Australian Information Security Management (AISM) Workshop, Geelong, Australia, 7 November
Information systems security is a critical issue for all organisations with a significant dependence upon information technology. However, it is a requirement that is often difficult to address, particularly within small organisations, as a result of a lack of resources and expertise. This paper...
A conceptual intrusion monitoring architecture and thoughts on practical implementation
Dowland PS, Furnell SM
Proceedings of the World Computer Congress 2000, 21-25 August
The paper presents a conceptual description of the Intrusion Monitoring System (IMS) architecture, which is designed to facilitate detection of system penetration and other anomalous activity in a networked environment. The architecture is based upon eight functional elements, distributed between a...
Enhancing Operating System Authentication Techniques
Dowland PS, Furnell SM
Proceedings of the Second International Network Conference (INC 2000), Plymouth, UK, pp253-261, 3-6 July
The need for enhanced user authentication has been evident for some time; but has not been addressed at the operating system level to any degree. Whilst all mainstream operating systems offer some level of user identification and authentication, this is generally based on the username/password...
Developing tools to support online distance learning
Furnell SM, Evans MP, Dowland PS
Proceedings of EUROMEDIA 2000, Antwerp, Belgium, 8-10 May
This paper considers the emerging concept of Online Distance Learning (ODL), which utilises Internet and the World Wide Web technologies to deliver educational courses to remote students. Many authors have conjectured that ODL has the potential to revolutionise educational provision, facilitating,...