Publications

Peer-reviewed research exploring human factors in cybersecurity, security education, usable privacy and implications of security.

Journal papers

JOURNAL 2025

Australian Teen Voices on Age Verification and Age Assurance Measures

Woodley G, See HW, O'Neill B, Green L, Staksrud E, Haskell-Dowland PS

Policy & Internet, Volume 17, Issue 4

Age verification and age assurance technologies, including biometrics, facial recognition software and digital identification, have been explored as potential measures to restrict access of young people to social media and sexually explicit media (SEM), including pornography. However, there is...

JOURNAL 2025

Real-world continuous smartwatch-based user authentication

Al-Naffakh N, Clarke NL, Li F, Haskell-Dowland PS

The Computer Journal, Vol. 68, Iss. 1

User authentication is often regarded as the 'gatekeeper' of cyber security. It has, however, long suffered from significant usability issues that have resulted in research focussing upon frictionless and transparent biometric approaches. Activity-based user authentication—a technique...

JOURNAL 2024

Examination of Traditional Botnet Detection on IoT-Based Bots

Woodiss-Field A, Johnstone M, Haskell-Dowland PS

Sensors, Vol. 24, Iss. 3, pp1027

A botnet is a collection of Internet-connected computers that have been suborned and are controlled externally for malicious purposes. Concomitant with the growth of the Internet of Things (IoT), botnets have been expanding to use IoT devices as their attack vectors. IoT devices utilise specific...

JOURNAL 2023

Energy-Efficient Covert Wireless Communication Through Probabilistic Jamming

Lu X, Huang Y, Yan S, Yang W, Haskell-Dowland PS

IEEE Wireless Communications Letters, Vol. 12, Iss. 5, pp932-936

In this work, we propose a novel energy-efficient covert wireless communication scheme through probabilistic jamming, where a jammer probabilistically transmits artificial noise (AN) with variable power against a warden’s detection. For the proposed scheme, the closed-form expressions for the...

JOURNAL 2022

Establishment and mapping of heterogeneous anomalies in network intrusion datasets

Riddell L, Ahmed M, Haskell-Dowland PS

Connection Science, Volume 34, Issue 1, pp2755-2783

Anomaly detection in the scope of network security aims to identify network instances for the unexpected and unique, with various security operations employing such techniques to facilitate effective threat detection. However, many systems have been designed based on the absolute mapping of attacks...

JOURNAL 2022

Biometric Security: A Novel Ear Recognition Approach Using a 3D Morphable Ear Model

Mursalin M, Ahmed M, Haskell-Dowland PS

Sensors, 22, 8988, DOI: 10.3390/s22228988

Biometrics is a critical component of cybersecurity that identifies persons by verifying their behavioral and physical traits. In biometric-based authentication, each individual can be correctly recognized based on their intrinsic behavioral or physical features, such as face, fingerprint, iris, and...

JOURNAL 2022

Anomaly Detection in Cybersecurity Datasets via Cooperative Co-evolution-based Feature Selection

Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS

ACM Transactions on Management Information Systems, Issue 3, No. 29, pp 1–39

Anomaly detection from Big Cybersecurity Datasets is very important; however, this is a very challenging and computationally expensive task. Feature selection (FS) is an approach to remove irrelevant and redundant features and select a subset of features, which can improve the machine learning...

JOURNAL 2021

ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things

Ahmed M, Byreddy S, Nutakki A, Sikos L, Haskell-Dowland PS

Ad Hoc Networks, Vol. 121, ISSN 1570-8705

In recent times, cyberattacks on the Internet of Health Things (IoHT) have continuously been growing, and so it is important to develop robust countermeasures. However, there is a lack of publicly available datasets reflecting cyberattacks on IoHT, mainly due to privacy concerns. This paper...

JOURNAL 2021

An Energy-Efficient and Secure Data Inference Framework for Internet of Health Things: A Pilot Study

Kang J, Dibaei M, Luo G, Yang W, Haskell-Dowland PS, Zheng X

Sensors, Vol. 21, No. 1: 312

Privacy protection in electronic healthcare applications is an important consideration, due to the sensitive nature of personal health data. Internet of Health Things (IoHT) networks that are used within a healthcare setting have unique challenges and security requirements (integrity,...

JOURNAL 2020

Cooperative co‑evolution for feature selection in Big Data with random feature grouping

Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS

Journal of Big Data, 7, 107

A massive amount of data is generated with the evolution of modern technologies. This high throughput data generation results in Big Data, which consist of many features (attributes). However, irrelevant features may degrade the classification performance of machine learning (ML) algorithms. Feature...

JOURNAL 2020

No Soldiers Left Behind: An IoT-based Low-Power Military Mobile Health System Design

Kang J, Yang W, Dermody G, Ghasemian M, Adibi S, Haskell-Dowland PS

IEEE Access, ISSN: 2169-3536, Vol. 8, pp201498-201515

There has been an increasing prevalence of ad-hoc networks for various purposes and applications. These include Low Power Wide Area Networks (LPWAN) and Wireless Body Area Networks (WBAN) which have emerging applications in health monitoring as well as user location tracking in emergency settings....

JOURNAL 2020

A Novel Penalty-Based Wrapper Objective Function for Feature Selection in Big Data using Cooperative Co-Evolution

Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS

IEEE Access, Vol.8, pp150113 - 150129

The rapid progress of modern technologies generates a massive amount of high-throughput data, called Big Data, which provides opportunities to find new insights using machine learning (ML) algorithms. Big Data consist of many features (also called attributes); however, not all these are necessary or...

JOURNAL 2019

Intelligent Building Systems: Security and Facility Professionals' Understanding of System Threats, Vulnerabilities and Mitigation Practice

Brooks D, Coole M, Haskell-Dowland PS

Security Journal, Vol. 33 No.2, pp244–265

Intelligent Buildings or Building Automation and Control Systems (BACS) are becoming common in buildings, driven by the commercial need for functionality, sharing of information, reduced costs and sustainable buildings. The facility manager often has BACS responsibility; however, their focus is...

JOURNAL 2018

A Survey of Distributed Certificate Authorities in MANETs

Chaudhry J, Saleem K, Haskell-Dowland PS, Miraz M

Annals of Emerging Technologies in Computing (AETiC),, vol. 2, iss. 3, pp11-18

A Certificate Authority (CA) provides the critical authentication and security services for Public Key Infrastructure (PKI) which are used for the Internet and wired networks. In MANETs (wireless and ad hoc) there is an inability to offer a centralized CA to provide these security services. Recent...

JOURNAL 2019

Behavioral Profiling for Transparent Verification in Cloud Storage Services

Al-Bayati B, Clarke NL, Haskell-Dowland PS, Li F

Journal of Information Warfare, pp88-105

Security is still the most sensitive issue in cloud storage services as services remain accessible to users for prolonged periods following an initial (usually simple) authentication. This issue has led to an increased vulnerability to potential attacks and sensitive customer information being...

JOURNAL 2016

Literature Studies on Security Warnings Development

Zaaba ZF, Furnell SM, Dowland PS

International Journal on Perceptive and Cognitive Computing, Vol 2, Iss 1, pp8-18

Security warnings are intended to alert users about the possibility of events that may compromise their protection. They encounter security warnings on daily basis in many situations when dealing with their computer. However, prior studies have shown that users often have difficulty in understanding...

JOURNAL 2017

A toolkit approach to information security awareness and education

Korovessis P, Furnell SM, Papadaki M, Haskell-Dowland PS

Journal of Cybersecurity Education, Research and Practice, Vol. 2017, Iss. 2, Art. 5, ISSN: 2472-2707

In today's business environment where all operations are enabled by technology, information security has become an established discipline as more and more businesses realize its value. The human component has been recognized to have an important role in information security since the only way...

JOURNAL 2016

A Comprehensive Evaluation of Feature Selection for Gait Recognition Using Smartwatches

Al-Naffakh N, Clarke NL, Dowland PS, Li F

International Journal for Information Security Research, Volume 6, Issue 3

Activity recognition that recognises who a user is by what they are doing at a specific point of time is attracting an enormous amount of attention. Whilst previous research in activity recognition has focused on wearable dedicated sensors (body worn sensors) or using a smartphone's sensors...

JOURNAL 2017

The impact of security and its antecedents in behaviour intention of using e-government services

Alharbi N, Papadaki M, Haskell-Dowland PS

Journal of Behaviour and Information Technology, ISSN: 0144-929X, Vol 36, Iss 6, pp620-636

One of the main challenges associated with e-government adoption is lack of security. Thus, the aim of this research is to investigate the role of security in e-government adoption by integrating security, trust and privacy with the Unified Theory of Acceptance and Use of Technology 2 (UTAUT2). In...

JOURNAL 2016

Graphical One-Time Password (GOTPass): A usability evaluation

Alsaiari H, Papadaki M, Dowland PS, Furnell SM

Information Security Journal: a Global Perspective, ISSN: 1939-3547, Vol 25, Iss 1-3, pp94-108

Complying with a security policy often requires users to create long and complex passwords to protect their accounts. However, remembering such passwords is difficult for many and may lead to insecure practices, such as choosing weak passwords or writing them down. In addition, they are vulnerable...

JOURNAL 2016

Adaptive Behavioral Profiling for Identity Verification in Cloud Computing: A Model and Preliminary Analysis

Al-Bayati B, Clarke NL, Dowland PS

GSTF Journal on Computing (JOC), ISSN:2251-3043, Vol. 5, Iss.1, pp21-28

In the past few years, cloud computing has become a new paradigm for hosting and delivering services over the Internet. Customers can directly access the resources (hardware and software) of cloud computing services over the Internet without the need to have specific knowledge about the resources....

JOURNAL 2015

Secure Graphical One Time Password (GOTPass): An Empirical Study

Alsaiari H, Papadaki M, Dowland PS, Furnell SM

Information Security Journal: A Global Perspective, 24, pp207-220

The traditional text-based password has been the default security medium for years; however, the difficulty of memorizing secure strong passwords often leads to insecure practices. A possible alternative solution is graphical authentication, which is motivated by the fact that the capability of...

JOURNAL 2014

Security Factors Influencing End Users' Adoption of E-Government

Alharbi N, Papadaki M, Dowland PS

Journal of Internet Technology and Secured Transaction (JITST), Volume 3, Issue 4, pp320-328

The use of e-government has increased in recent years, and many countries now use it to provide high quality services to their citizens. Thus, a number of studies have investigated user acceptance of e-government via the use of adoption models, such as the Unified Theory of Acceptance and Use of...

JOURNAL 2014

Investigating the Viability of Multifactor Graphical Passwords for User Authentication

Jali MZ, Furnell SM, Dowland PS

Information Security Journal: A Global Perspective, 00:1–12, ISSN: 1939-3555, Published online: 18 Apr 2014

Authentication using images (i.e., graphical passwords) is claimed to be one of the alternatives for overcoming weaknesses in the traditional username and password authentication. This paper reports on the study to explore the feasibility of combining two graphical password methods for better...

JOURNAL 2014

Active authentication for mobile devices utilising behaviour profiling

Li F, Clarke NL, Papadaki M, Dowland PS

International Journal of Information Security, Volume 13, Issue 3, pp229-244, ISSN:1615-5262

With nearly 6 billion subscribers around the world, mobile devices have become an indispensable component in modern society. The majority of these devices rely upon passwords and personal identification numbers as a form of user authentication, and the weakness of these point-of-entry techniques is...

JOURNAL 2011

Misuse Detection for Mobile Devices Using Behaviour Profiling

Li F, Clarke NL, Papadaki M, Dowland PS

International Journal of Cyber Warfare & Terrorism, Volume 1, Issue 1, pp43-55, ISSN: 1947-3435

Mobile devices have become essential to modern society; however, as their popularity has grown, so has the ...

JOURNAL 2011

Massively Multi-Player Online Role Playing Games: What’s the Risk?

Sanders B, Dowland PS, Atkinson S, Furnell SM

Journal of Virtual Worlds Research, vol. 3, no. 3, ISSN: 1941-8477

Some may argue that the proliferation of personal computers together with the widespread use of the Internet has brought many benefits to society. The popularity of the internet and its associated online services continues to grow at an exponential rate and consequently, so does the number of...

JOURNAL 2010

Online Addiction: A Cultural Comparison of Privacy Risks in Online Gaming Environments

Sanders B, Dowland PS, Atkinson S, Zahra D, Furnell SM, Papadaki M

Journal of Multimedia Processing Technologies, vol. 1, no. 3, September, pp181-193, ISSN: 0976-4127

In this paper we investigated the levels of addiction and personal data disclosure within Massively Multiplayer Online Role Playing Game environments (MMORPG’s). The study made use of an online survey, a combination of a six point behavioural addiction framework, Self Determination Theory and...

JOURNAL 2010

Assessing image-based authentication techniques in a web-based environment

Jali MZ, Furnell SM, Dowland PS

Information Management & Computer Security, Vol.18, Iss.1, pp43-53

The purpose of this paper is to assess the usability of two image-based authentication methods when used in the web-based environment. The evaluated approaches involve clicking secret points within a single image (click-based) and remembering a set of images in the correct sequence (choice-based).

JOURNAL 2005

An automated framework for managing security vulnerabilities

Alayed A, Furnell SM, Zhao D, Dowland PS

Information Management & Computer Security, vol. 13, no. 2, pp156-166

This paper aims to look at unpatched software which represents a significant problem for internet-based systems, with a myriad malware incidents and hacker exploits taking advantage of vulnerable targets. Unfortunately, vulnerability management is a non-trivial task, and is complicated by an...

JOURNAL 2004

A long-term trial of alternative user authentication technologies

Furnell SM, Papadopoulos I, Dowland PS

Information Management and Computer Security, Vol. 12, No. 2, pp178-190

Modern IT systems have a continued requirement for reliable user authentication at login. However, the majority of systems are still using username/password combinations, in spite of a variety of recognised weaknesses. Identifies the need for improved login authentication, and investigates the...

JOURNAL 2002

A prototype tool for information security awareness and training

Furnell SM, Gennatou M, Dowland PS

International Journal of Logisitics Information Management, vol. 15, no. 5, pp352-357

Information systems security is a critical issue for all organisations with a significant dependence upon information technology. However, it is a requirement that is often difficult to address, particularly within small organisations, as a result of a lack of resources and expertise. This paper...

JOURNAL 2002

An experimental comparison of secret-based user authentication technologies

Irakleous I, Furnell SM, Dowland PS, Papadaki M

Information Management and Computer Security, vol. 10, no. 3, pp100-108

Information systems security is a critical issue for all organisations with a significant dependence upon information technology. However, it is a requirement that is often difficult to address, particularly within small organisations, as a result of a lack of resources and expertise. This paper...

JOURNAL 2001

Security analysers: Administrator Assistants or Hacker Helpers?

Furnell SM, Chiliarchaki P, Dowland PS

Information Management and Computer Security, vol. 9, no.2, pp93-101

Security analyser tools provide a means of automatically identifying, and potentially exploiting, vulnerabilities within computer systems and networks. Although such tools are useful to system administrators, in order to highlight and overcome weaknesses in protection, they are also of assistance...

JOURNAL 2000

Authentication and Supervision: A survey of user attitudes

Furnell SM, Dowland PS, Illingworth HM, Reynolds PL

Computers & Security, vol. 19, no. 6, pp529-539

User authentication is a vital element in ensuring the secure operation of IT systems. In the vast majority of cases, this role is fulfilled by the password, but evidence suggests that this approach is easily compromised. Whilst many alternatives exist, particularly in the form of biometric...

JOURNAL 2000

A conceptual architecture for real-time intrusion monitoring

Furnell SM, Dowland PS

Information Management and Computer Security, vol. 8, no. 2, pp65-74

The detection and prevention of authorised activities, by both external parties and internal personnel, is an important issue within IT systems. Traditional methods of user authentication and access control do not provide comprehensive protection and offer opportunities for compromise by various...

JOURNAL 1999

Computer Crime and Abuse: A Survey of Public Attitudes and Awareness

Dowland PS, Furnell SM, Illingworth HM, Reynolds PL

Computers & Security, vol. 18, no. 8, pp715-726

In recent years, a number of surveys have indicated a significant escalation in reported incidents of computer crime and abuse. This rise is coupled with increasing attention to the issue in the mass media, which has the effect of heightening public perceptions of problems with IT and may represent...

JOURNAL 1999

Dissecting the 'Hacker Manifesto'

Furnell SM, Dowland PS, Sanders P

Information Management and Computer Security, vol.7, no.2 pp69-75

Twelve years ago, a text was written within the hacking community which is widely referred to as the 'Hacker Manifesto'. This text, and the opinions that it offers, have since been widely embraced by the hacker community and the document is referenced from numerous sites on the Internet. ...

38 journal articles