Publications
Peer-reviewed research exploring human factors in cybersecurity, security education, usable privacy and implications of security.
Journal papers
Australian Teen Voices on Age Verification and Age Assurance Measures
Woodley G, See HW, O'Neill B, Green L, Staksrud E, Haskell-Dowland PS
Policy & Internet, Volume 17, Issue 4
Age verification and age assurance technologies, including biometrics, facial recognition software and digital identification, have been explored as potential measures to restrict access of young people to social media and sexually explicit media (SEM), including pornography. However, there is...
Real-world continuous smartwatch-based user authentication
Al-Naffakh N, Clarke NL, Li F, Haskell-Dowland PS
The Computer Journal, Vol. 68, Iss. 1
User authentication is often regarded as the 'gatekeeper' of cyber security. It has, however, long suffered from significant usability issues that have resulted in research focussing upon frictionless and transparent biometric approaches. Activity-based user authentication—a technique...
Examination of Traditional Botnet Detection on IoT-Based Bots
Woodiss-Field A, Johnstone M, Haskell-Dowland PS
Sensors, Vol. 24, Iss. 3, pp1027
A botnet is a collection of Internet-connected computers that have been suborned and are controlled externally for malicious purposes. Concomitant with the growth of the Internet of Things (IoT), botnets have been expanding to use IoT devices as their attack vectors. IoT devices utilise specific...
Energy-Efficient Covert Wireless Communication Through Probabilistic Jamming
Lu X, Huang Y, Yan S, Yang W, Haskell-Dowland PS
IEEE Wireless Communications Letters, Vol. 12, Iss. 5, pp932-936
In this work, we propose a novel energy-efficient covert wireless communication scheme through probabilistic jamming, where a jammer probabilistically transmits artificial noise (AN) with variable power against a warden’s detection. For the proposed scheme, the closed-form expressions for the...
Establishment and mapping of heterogeneous anomalies in network intrusion datasets
Riddell L, Ahmed M, Haskell-Dowland PS
Connection Science, Volume 34, Issue 1, pp2755-2783
Anomaly detection in the scope of network security aims to identify network instances for the unexpected and unique, with various security operations employing such techniques to facilitate effective threat detection. However, many systems have been designed based on the absolute mapping of attacks...
Biometric Security: A Novel Ear Recognition Approach Using a 3D Morphable Ear Model
Mursalin M, Ahmed M, Haskell-Dowland PS
Sensors, 22, 8988, DOI: 10.3390/s22228988
Biometrics is a critical component of cybersecurity that identifies persons by verifying their behavioral and physical traits. In biometric-based authentication, each individual can be correctly recognized based on their intrinsic behavioral or physical features, such as face, fingerprint, iris, and...
Anomaly Detection in Cybersecurity Datasets via Cooperative Co-evolution-based Feature Selection
Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS
ACM Transactions on Management Information Systems, Issue 3, No. 29, pp 1–39
Anomaly detection from Big Cybersecurity Datasets is very important; however, this is a very challenging and computationally expensive task. Feature selection (FS) is an approach to remove irrelevant and redundant features and select a subset of features, which can improve the machine learning...
ECU-IoHT: A dataset for analyzing cyberattacks in Internet of Health Things
Ahmed M, Byreddy S, Nutakki A, Sikos L, Haskell-Dowland PS
Ad Hoc Networks, Vol. 121, ISSN 1570-8705
In recent times, cyberattacks on the Internet of Health Things (IoHT) have continuously been growing, and so it is important to develop robust countermeasures. However, there is a lack of publicly available datasets reflecting cyberattacks on IoHT, mainly due to privacy concerns. This paper...
An Energy-Efficient and Secure Data Inference Framework for Internet of Health Things: A Pilot Study
Kang J, Dibaei M, Luo G, Yang W, Haskell-Dowland PS, Zheng X
Sensors, Vol. 21, No. 1: 312
Privacy protection in electronic healthcare applications is an important consideration, due to the sensitive nature of personal health data. Internet of Health Things (IoHT) networks that are used within a healthcare setting have unique challenges and security requirements (integrity,...
Cooperative co‑evolution for feature selection in Big Data with random feature grouping
Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS
Journal of Big Data, 7, 107
A massive amount of data is generated with the evolution of modern technologies. This high throughput data generation results in Big Data, which consist of many features (attributes). However, irrelevant features may degrade the classification performance of machine learning (ML) algorithms. Feature...
No Soldiers Left Behind: An IoT-based Low-Power Military Mobile Health System Design
Kang J, Yang W, Dermody G, Ghasemian M, Adibi S, Haskell-Dowland PS
IEEE Access, ISSN: 2169-3536, Vol. 8, pp201498-201515
There has been an increasing prevalence of ad-hoc networks for various purposes and applications. These include Low Power Wide Area Networks (LPWAN) and Wireless Body Area Networks (WBAN) which have emerging applications in health monitoring as well as user location tracking in emergency settings....
A Novel Penalty-Based Wrapper Objective Function for Feature Selection in Big Data using Cooperative Co-Evolution
Rashid BANM, Ahmed M, Sikos L, Haskell-Dowland PS
IEEE Access, Vol.8, pp150113 - 150129
The rapid progress of modern technologies generates a massive amount of high-throughput data, called Big Data, which provides opportunities to find new insights using machine learning (ML) algorithms. Big Data consist of many features (also called attributes); however, not all these are necessary or...
Intelligent Building Systems: Security and Facility Professionals' Understanding of System Threats, Vulnerabilities and Mitigation Practice
Brooks D, Coole M, Haskell-Dowland PS
Security Journal, Vol. 33 No.2, pp244–265
Intelligent Buildings or Building Automation and Control Systems (BACS) are becoming common in buildings, driven by the commercial need for functionality, sharing of information, reduced costs and sustainable buildings. The facility manager often has BACS responsibility; however, their focus is...
A Survey of Distributed Certificate Authorities in MANETs
Chaudhry J, Saleem K, Haskell-Dowland PS, Miraz M
Annals of Emerging Technologies in Computing (AETiC),, vol. 2, iss. 3, pp11-18
A Certificate Authority (CA) provides the critical authentication and security services for Public Key Infrastructure (PKI) which are used for the Internet and wired networks. In MANETs (wireless and ad hoc) there is an inability to offer a centralized CA to provide these security services. Recent...
Behavioral Profiling for Transparent Verification in Cloud Storage Services
Al-Bayati B, Clarke NL, Haskell-Dowland PS, Li F
Journal of Information Warfare, pp88-105
Security is still the most sensitive issue in cloud storage services as services remain accessible to users for prolonged periods following an initial (usually simple) authentication. This issue has led to an increased vulnerability to potential attacks and sensitive customer information being...
Literature Studies on Security Warnings Development
Zaaba ZF, Furnell SM, Dowland PS
International Journal on Perceptive and Cognitive Computing, Vol 2, Iss 1, pp8-18
Security warnings are intended to alert users about the possibility of events that may compromise their protection. They encounter security warnings on daily basis in many situations when dealing with their computer. However, prior studies have shown that users often have difficulty in understanding...
A toolkit approach to information security awareness and education
Korovessis P, Furnell SM, Papadaki M, Haskell-Dowland PS
Journal of Cybersecurity Education, Research and Practice, Vol. 2017, Iss. 2, Art. 5, ISSN: 2472-2707
In today's business environment where all operations are enabled by technology, information security has become an established discipline as more and more businesses realize its value. The human component has been recognized to have an important role in information security since the only way...
A Comprehensive Evaluation of Feature Selection for Gait Recognition Using Smartwatches
Al-Naffakh N, Clarke NL, Dowland PS, Li F
International Journal for Information Security Research, Volume 6, Issue 3
Activity recognition that recognises who a user is by what they are doing at a specific point of time is attracting an enormous amount of attention. Whilst previous research in activity recognition has focused on wearable dedicated sensors (body worn sensors) or using a smartphone's sensors...
The impact of security and its antecedents in behaviour intention of using e-government services
Alharbi N, Papadaki M, Haskell-Dowland PS
Journal of Behaviour and Information Technology, ISSN: 0144-929X, Vol 36, Iss 6, pp620-636
One of the main challenges associated with e-government adoption is lack of security. Thus, the aim of this research is to investigate the role of security in e-government adoption by integrating security, trust and privacy with the Unified Theory of Acceptance and Use of Technology 2 (UTAUT2). In...
Graphical One-Time Password (GOTPass): A usability evaluation
Alsaiari H, Papadaki M, Dowland PS, Furnell SM
Information Security Journal: a Global Perspective, ISSN: 1939-3547, Vol 25, Iss 1-3, pp94-108
Complying with a security policy often requires users to create long and complex passwords to protect their accounts. However, remembering such passwords is difficult for many and may lead to insecure practices, such as choosing weak passwords or writing them down. In addition, they are vulnerable...
Adaptive Behavioral Profiling for Identity Verification in Cloud Computing: A Model and Preliminary Analysis
Al-Bayati B, Clarke NL, Dowland PS
GSTF Journal on Computing (JOC), ISSN:2251-3043, Vol. 5, Iss.1, pp21-28
In the past few years, cloud computing has become a new paradigm for hosting and delivering services over the Internet. Customers can directly access the resources (hardware and software) of cloud computing services over the Internet without the need to have specific knowledge about the resources....
Secure Graphical One Time Password (GOTPass): An Empirical Study
Alsaiari H, Papadaki M, Dowland PS, Furnell SM
Information Security Journal: A Global Perspective, 24, pp207-220
The traditional text-based password has been the default security medium for years; however, the difficulty of memorizing secure strong passwords often leads to insecure practices. A possible alternative solution is graphical authentication, which is motivated by the fact that the capability of...
Security Factors Influencing End Users' Adoption of E-Government
Alharbi N, Papadaki M, Dowland PS
Journal of Internet Technology and Secured Transaction (JITST), Volume 3, Issue 4, pp320-328
The use of e-government has increased in recent years, and many countries now use it to provide high quality services to their citizens. Thus, a number of studies have investigated user acceptance of e-government via the use of adoption models, such as the Unified Theory of Acceptance and Use of...
Investigating the Viability of Multifactor Graphical Passwords for User Authentication
Jali MZ, Furnell SM, Dowland PS
Information Security Journal: A Global Perspective, 00:1–12, ISSN: 1939-3555, Published online: 18 Apr 2014
Authentication using images (i.e., graphical passwords) is claimed to be one of the alternatives for overcoming weaknesses in the traditional username and password authentication. This paper reports on the study to explore the feasibility of combining two graphical password methods for better...
Active authentication for mobile devices utilising behaviour profiling
Li F, Clarke NL, Papadaki M, Dowland PS
International Journal of Information Security, Volume 13, Issue 3, pp229-244, ISSN:1615-5262
With nearly 6 billion subscribers around the world, mobile devices have become an indispensable component in modern society. The majority of these devices rely upon passwords and personal identification numbers as a form of user authentication, and the weakness of these point-of-entry techniques is...
Misuse Detection for Mobile Devices Using Behaviour Profiling
Li F, Clarke NL, Papadaki M, Dowland PS
International Journal of Cyber Warfare & Terrorism, Volume 1, Issue 1, pp43-55, ISSN: 1947-3435
Mobile devices have become essential to modern society; however, as their popularity has grown, so has the ...
Massively Multi-Player Online Role Playing Games: What’s the Risk?
Sanders B, Dowland PS, Atkinson S, Furnell SM
Journal of Virtual Worlds Research, vol. 3, no. 3, ISSN: 1941-8477
Some may argue that the proliferation of personal computers together with the widespread use of the Internet has brought many benefits to society. The popularity of the internet and its associated online services continues to grow at an exponential rate and consequently, so does the number of...
Online Addiction: A Cultural Comparison of Privacy Risks in Online Gaming Environments
Sanders B, Dowland PS, Atkinson S, Zahra D, Furnell SM, Papadaki M
Journal of Multimedia Processing Technologies, vol. 1, no. 3, September, pp181-193, ISSN: 0976-4127
In this paper we investigated the levels of addiction and personal data disclosure within Massively Multiplayer Online Role Playing Game environments (MMORPG’s). The study made use of an online survey, a combination of a six point behavioural addiction framework, Self Determination Theory and...
Assessing image-based authentication techniques in a web-based environment
Jali MZ, Furnell SM, Dowland PS
Information Management & Computer Security, Vol.18, Iss.1, pp43-53
The purpose of this paper is to assess the usability of two image-based authentication methods when used in the web-based environment. The evaluated approaches involve clicking secret points within a single image (click-based) and remembering a set of images in the correct sequence (choice-based).
An automated framework for managing security vulnerabilities
Alayed A, Furnell SM, Zhao D, Dowland PS
Information Management & Computer Security, vol. 13, no. 2, pp156-166
This paper aims to look at unpatched software which represents a significant problem for internet-based systems, with a myriad malware incidents and hacker exploits taking advantage of vulnerable targets. Unfortunately, vulnerability management is a non-trivial task, and is complicated by an...
A long-term trial of alternative user authentication technologies
Furnell SM, Papadopoulos I, Dowland PS
Information Management and Computer Security, Vol. 12, No. 2, pp178-190
Modern IT systems have a continued requirement for reliable user authentication at login. However, the majority of systems are still using username/password combinations, in spite of a variety of recognised weaknesses. Identifies the need for improved login authentication, and investigates the...
A prototype tool for information security awareness and training
Furnell SM, Gennatou M, Dowland PS
International Journal of Logisitics Information Management, vol. 15, no. 5, pp352-357
Information systems security is a critical issue for all organisations with a significant dependence upon information technology. However, it is a requirement that is often difficult to address, particularly within small organisations, as a result of a lack of resources and expertise. This paper...
An experimental comparison of secret-based user authentication technologies
Irakleous I, Furnell SM, Dowland PS, Papadaki M
Information Management and Computer Security, vol. 10, no. 3, pp100-108
Information systems security is a critical issue for all organisations with a significant dependence upon information technology. However, it is a requirement that is often difficult to address, particularly within small organisations, as a result of a lack of resources and expertise. This paper...
Security analysers: Administrator Assistants or Hacker Helpers?
Furnell SM, Chiliarchaki P, Dowland PS
Information Management and Computer Security, vol. 9, no.2, pp93-101
Security analyser tools provide a means of automatically identifying, and potentially exploiting, vulnerabilities within computer systems and networks. Although such tools are useful to system administrators, in order to highlight and overcome weaknesses in protection, they are also of assistance...
Authentication and Supervision: A survey of user attitudes
Furnell SM, Dowland PS, Illingworth HM, Reynolds PL
Computers & Security, vol. 19, no. 6, pp529-539
User authentication is a vital element in ensuring the secure operation of IT systems. In the vast majority of cases, this role is fulfilled by the password, but evidence suggests that this approach is easily compromised. Whilst many alternatives exist, particularly in the form of biometric...
A conceptual architecture for real-time intrusion monitoring
Furnell SM, Dowland PS
Information Management and Computer Security, vol. 8, no. 2, pp65-74
The detection and prevention of authorised activities, by both external parties and internal personnel, is an important issue within IT systems. Traditional methods of user authentication and access control do not provide comprehensive protection and offer opportunities for compromise by various...
Computer Crime and Abuse: A Survey of Public Attitudes and Awareness
Dowland PS, Furnell SM, Illingworth HM, Reynolds PL
Computers & Security, vol. 18, no. 8, pp715-726
In recent years, a number of surveys have indicated a significant escalation in reported incidents of computer crime and abuse. This rise is coupled with increasing attention to the issue in the mass media, which has the effect of heightening public perceptions of problems with IT and may represent...
Dissecting the 'Hacker Manifesto'
Furnell SM, Dowland PS, Sanders P
Information Management and Computer Security, vol.7, no.2 pp69-75
Twelve years ago, a text was written within the hacking community which is widely referred to as the 'Hacker Manifesto'. This text, and the opinions that it offers, have since been widely embraced by the hacker community and the document is referenced from numerous sites on the Internet. ...