- Research Article
30
- 10.1016/j.elerap.2011.11.004
Word sense disambiguation for spam filtering
- Dec 28, 2011
- Electronic Commerce Research and Applications
- Carlos Laorden + 4 more +4
Word sense disambiguation for spam filtering
Computer security issues are now commonplace in the business community. Incidents such as computer viruses, Web vandalism, computer theft, etc. are regularly highlighted by the media. Indeed, the drive towards E-Business has raised the profile of security incidents. Many stakeholders play an important part in counteracting these security breaches, including law enforcement, the business community, hardware and software vendors, and researchers. The purpose of this paper is to highlight the role of universities in the battle against computer security breaches and to show, through a case study, how one university used the Soft Systems Methodology (SSM) to develop a computer security module for its undergraduate students.Key wordsComputer SecurityComputer CrimeSoft Systems MethodologyRequirements Engineering
Word sense disambiguation for spam filtering
Word sense disambiguation for spam filtering
The ‘Soft Information Systems and Technologies Methodology’ (SISTeM): an actor network contingency approach to integrated development
This paper describes the Soft Information Systems and Technologies Methodology (SISTeM), and demonstrates its utility in integrating informational and organisational development. The methodology and its stages are illustrated with examples from recent information systems and technology (IS&T) based projects, mainly in the health sector. Its antecedents in soft systems methodology are identified. The use of the approaches underpinning concept of the human/machine activity system is described. The nature of SISTeM as a social, political and technological form of contingency methodology, working with other approaches and disciplines, is demonstrated. SISTeM, it will be argued has capacity for orchestrating the emergence, consolidation and continual development of real world actor networks.
Read moreReport on the computer security foundations workshop VI
The Computer Security Foundations Workshop VI was held during June 15-17, 1993 in Franconia, New Hampshire. This is an annual workshop with the purpose of "bring[ing] together researchers to explore fundamental issues in computer security" [13]. Every year since its inception, the workshop has been limited to forty participants, the majority of whom present papers or speak on panels. The setting is informal with plenty of time for technical discussion.
Read moreProblems and Issues in Using Computer- Based Support Tools to Enhance 'Soft' Systems Methodologies
This paper explores the issue of whether computer-based support tools can enhance the use of 'soft' systems methodologies as applied to real-world problem situations. Although work has been carried out by a number of researchers in applying computer-based technology to concepts and methodologies relating to 'soft' systems thinking such as Soft Systems Methodology (SSM), such attempts appear to be still in their infancy and have not been applied widely to real-world problem situations. This paper will highlight some of the problems that may be encountered in attempting to develop computer-based support tools for 'soft' systems methodologies. Particular attention will be paid to an attempt by the author to develop a computer-based support tool for a particular 'soft' systems method of inquiry known as the Appreciative Inquiry Method that is based upon Vickers' notion of 'appreciation' (Vickers, 196S) and Checkland's SSM (Checkland, 1981). The final part of the paper will explore some of the lessons learnt from developing and applying the computer-based support tool to a real world problem situation, as well as considering the feasibility of developing computer-based support tools for 'soft' systems methodologies. This paper will put forward the point that a mixture of manual and computer-based tools should be employed to allow a methodology to be used in an unconstrained manner, but the benefits provided by computer-based technology should be utilised in supporting and enhancing the more mundane and structured tasks.
Read moreIT Security Vulnerability and Incident Response Management
This paper summarises the results of a Dutch PhD research project on IT security vulnerability and incident response management, which is supervised by the University of Twente in the Netherlands and which is currently in its final stage. Vulnerabilities are ‘failures or weaknesses in computer (application) system design, implementation or operation which can be exploited to violate the security policy defined for that system’. Incidents are defined as ‘events that have actual or potentially adverse effects on computer or network operations resulting in fraud, waste or abuse, compromise of information or loss or damage of property of information’. Hacking, denial-of-service attacks and computer viruses are examples of such events. The research project identifies a number of shortcomings in IT service management processes which affect the speed and quality of IT security vulnerability and incident response processes in enterprises. To shorten the lifecycle of vulnerabilities organizations should implement three basic process elements: (1) filtering and analyzing of vulnerability announcements and alerts, (2) prioritizing of vulnerability response activities and (3) scanning of infrastructure components. Each of these steps can be related to specific IT service management processes and to IT security incident management in particular. Using checklists, procedures and dedicated response capabilities, IT organizations are able to faster detect and respond to incidents.
Read moreCyber Warfare and National Security: Analyzing the Evolving US-China Cyber Rivalry through the Lens of Realism and Its Implications for Global Cyber security Governance
The growing use and innovation in information technology and communication in all domains of life has made the world richer but also fragile and it has led to breach of privacy and increased dependence on the internet. Thus cyber security has become one of the major global concerns a growing nontraditional security issue. We can observe that the cyber security discourse of today emphasizes the increasing set of threats ranging from cybercrime, computer viruses, and cyber espionage. Globally cyber terrorism and cyber war are also becoming major issues that are discussed on global platforms. The complexity of the digital world and increased security risk have led to overemphasis that may violate equality, freedom of speech, and fairness. The study aims to highlight the growing paranoia that comes with the growth of cyberspace through the lens of the theory of realism, understanding that the concept of security dilemma also exists in the cyber domain. Just like traditional conflicts, states are engaged in constant power struggles in cyberspace. The study highlights the major concerns related to cyber security and cyber-warfare with its relationship to foreign policy implications for China and the U.S. The methodology applied in this study includes a comprehensive exploration of the landscape of cyber-security and cyber-warfare in China and the U.S. The chapter seeks to analyze the growing landscape of cyber security and cyber warfare and the changing nature of threats with a focus on the foreign policy implications of China and the U.S. about cyber security and warfare. A detailed comparative analysis of China and the U.S. with an understanding of differences and potentials of collaboration and conflict concerning cyber policies. The chapter will contribute to the promotion of international cooperation in addressing this new emerging global challenge of cyber security and warfare. With deep insights to understand this global threat, this research aspires to have a lasting influence on national security considerations with evidence-based suggestions and recommendations. By identifying potential areas for collaboration and examining diplomatic responses to cyber incidents. This chapter seeks to foster a more collaborative approach to secure cyber security and the implication of the phenomenon on the Foreign Policies of China and the U.S. Recognizing that Cybersecurity is entwined with international relations, the research argues that findings extend beyond the specific context of China and the U.S. The chapter aims to contribute to the vast field of international relations by shedding light on the complex between national interest, diplomatic relations, and Cybersecurity. The key argument in this study is to underscore the rapidly evolving nature of cyber warfare tactics and Cybersecurity threats and emphasize the need for an adaptive policy response to effectively counter emerging challenges in both China and the U.S.
Read moreEvaluation of the awareness and effectiveness of IT security programs in a large publicly funded health care system.
Electronic health records are becoming increasingly common in the health care industry. Although information technology (IT) poses many benefits to improving health care and ease of access to information, there are also security and privacy risks. Educating health care providers is necessary to ensure proper use of health information systems and IT and reduce undesirable outcomes. This study evaluated employees' awareness and perceptions of the effectiveness of two IT educational training modules within a large publicly funded health care system in Canada. Semi-structured interviews and focus groups included a variety of professional roles within the organisation. Participants also completed a brief demographic data sheet. With the consent of participants, all interviews and focus groups were audio recorded. Thematic analysis and descriptive statistics were used to evaluate the effectiveness of the IT security training modules. Five main themes emerged: (i) awareness of the IT training modules, (ii) the content of modules, (iii) staff perceptions about differences between IT security and privacy issues, (iv) common breaches of IT security and privacy, and (v) challenges and barriers to completing the training program. Overall, nonclinical staff were more likely to be aware of the training modules than were clinical staff. We found e-learning was a feasible way to educate a large number of employees. However, health care providers required a module on IT security and privacy that was relatable and applicable to their specific roles. Strategies to improve staff education and mitigate against IT security and privacy risks are discussed. Future research should focus on integrating health IT competencies into the educational programs for health care professionals.
Read moreCase Study & Lessons Learned: Creation and Pilot of a Regional Small Business Accelerator and Cybersecurity Assessment Program
Startup companies and originated small businesses are an essential aspect of our nation’s economy, contributing to many organizations that aim, in some cases, to become larger enterprises. As a small business is in the mode of sustaining and growth, minimizing cybersecurity and business resilience threats may not be front and center on the minds of these entities. This paper will provide a case study background about a project and effort – the New Jersey Cybersecurity Regional Cluster (NJCRC) - that has contributed significant outreach to New Jersey small businesses to provide free cybersecurity risk assessments to help small businesses prepare their organizations against technical, operational, and cyber and information security resilience threats. In addition to the background of this outreach activity, the process and procedures followed, along with the selected cybersecurity risk assessment framework, a theoretical model followed, challenges, and learned lessons are demonstrated.
Read moreThe Effect of Internet Security Breach Announcements on Market Value: Capital Market Reactions for Breached Firms and Internet Security Developers
Assessing the value of information technology (IT) security is challenging because of the difficulty of measuring the cost of security breaches. An event-study analysis, using market valuations, was used to assess the impact of security breaches on the market value of breached firms. The information-transfer effect of security breaches (i.e., their effect on the market value of firms that develop security technology) was also studied. The results show that announcing an Internet security breach is negatively associated with the market value of the announcing firm. The breached firms in the sample lost, on average, 2.1 percent of their market value within two days of the announcement--an average loss in market capitalization of $1.65 billion per breach. Firm type, firm size, and the year the breach occurred help explain the cross-sectional variations in abnormal returns produced by security breaches. The effects of security breaches are not restricted to the breached firms. The market value of security developers is positively associated with the disclosure of security breaches by other firms. The security developers in the sample realized an average abnormal return of 1.36 percent during the two-day period after the announcement--an average gain of $1.06 billion in two days. The study suggests that the cost of poor security is very high for investors. rity, information technology security management, Internet security, security breach an-
Read moreA Reflection on SSM as a Critical Social Action Research Method: Towards Improvement of Project Governance
Academic research is often regarded as less than helpful for practice, while knowledge practitioners are accused of failing to apply relevant research in their industries. This study successfully bridged the theory‑practice gap in that it resolved a real‑world problem and added to the body of knowledge, i.e. it aided to: identify underlying social root causes of a flawed project governance process and associated decision support software; define actions for improvement; and realise generalisable theoretical and applied knowledge to improve both theory and practice. It illustrates that collaborative academic research adds value to both academia and industry. This paper discusses an empirical study where soft systems methodology (SSM) was applied as an interventionist action research (AR) method, positioned in the critical systems thinking (CST) and critical social research (CSR) paradigm. SSM is defined as a learning system that facilitates the identification of actions for improvement of problematical social contexts—it gives epistemological guidance to systematically explore perspectives of individuals involved in and affected by social (e.g. organisational) settings, to identify actions for improvement. However, SSM is found to be most often applied interpretively by academia, i.e., to understand a problem context, rather than to improve it, and by practitioners as a consulting tool. SSM successfully facilitates exploring of problematical social contexts, but, according to users of it, fail to effect real and lasting change. It is also quite difficult to extract generalisable learning from its output. In this study, the researcher argues that SSM have the potential to live up to its original intent. So, she positioned SSM in the CST/CSR paradigm by applying an enriched version of it. She guided participants to reflect on inherent flaws in the scrutinised project governance business process and associated decision support software. Hence, by applying methodological pluralism, she also guided them to reflect on actions for change in light of the organisation’s socially constructed structures and their effects on involved and affected stakeholders of the process. SSM was enriched by also reflecting on the output of facilitated workshops, which aimed to identify required transformation to improve upon deficient project governance, from the perspectives of: the role of the participant(s) in the organisation; the effects that identified organisational decisions and changes may have on them; and by asking probing questions about the crux of statements made, e.g. if it is presumed to be true, what would the effect be, or vice versa. The outcome was emancipation, as key underlying social and structural causes for the organisational deficiencies surfaced.
Read moreImplementing Corporate Sustainable Development: A Case of an SME from India
Studies have repeatedly illustrated how institutions struggle to implement sustainable development models, even when their formal claims indicate strict adoption of principles of sustainable development ( Sean Markey, 2010 ). Relevance of innovative and feasible projects for sustainable development is escalating rapidly among the business community ( Brower, 2011 ). The efforts of many organizations to recognize sustainable development principles as an important community vision is encouraging, but only very few of them have proved themselves in successfully translating their goals into actionable strategies ( Sean Markey, 2010 ). Extra Weave Pvt. Ltd, a small and medium enterprise (SME) in Allapuzha district of the state of Kerala, India, stands out from the crowd in its remarkable achievements in sustainability, overcoming initial challenges and issues in implementation of a sound sustainability development model. This article is a case study of the implementation issues of sustainable development practices at Extra Weave Pvt. Ltd. The study focuses on how communication plays a role in the implementation of sustainable development practices in Extra Weave. The study also discusses how soft system methodology (SSM) was used to identify the issues in implementation and facilitate for appropriate solutions.
Read moreMuch more than old wine in new bottles
This chapter explores the potential of Soft Systems Methodology (SSM) for making improvements in healthcare practices. SSM is an approach designed for tackling real world problems and is described as a learning process that engages relevant stakeholders in a process of inquiry into a problematic situation with the aim of improving the situation. SSM has potential to contribute to the way we manage change in healthcare by acknowledging the complexities of the real world rather than trying to provide simplified or idealized solutions that all-too-often do not work in reality. Although SSM has not been extensively used in healthcare it has been applied in a variety of healthcare settings and for different types of problematic situations and improvements, indicating the versatility of the methodology. We provide examples of how SSM has been applied and based on our analysis discuss some main principles for how SSM can bring about more responsive, sustainable change in healthcare, including: a participatory approach that involves relevant stakeholders with expertise about the local context; a systems approach to assess and address the problematic situation; and approaching improvements in an iterative learning cycle.
Read moreHidden identification for operators of information-processing systems by heart rate variability in the course of professional activity
The number of cyber crimes is constantly increasing nowadays and the prevention of unauthorized access has become a key issue in computer security. Much of the research in cyber crimes focus on users' identification but little research has been carried out in hidden identification. This paper reveals the results of the experiment on hidden identification by heart rate variability (HRV).
Read moreModeling and Controlling Downgrading Operations in Information Systems
In existing systems, information are protected by security models that control the accesses to the information, depending on their security level. In such systems, allowing accesses that were previously denied by diminishing the security level of the information is called downgrading. Controlling this downgrade of sensitive information is an important issue in computer security, as it requires the definition of formal security models able to express contextual authorisations for some information flows. In traditional security models, information downgrading is however most of the time not taken into account and must be managed by external systems. In some recent security models, information downgrading is defined, but for specific security policies, which limits the downgrading controls. In order to be able to express a generic information downgrading control, we present in this article a formalization of the different concepts of downgrading and we propose a model to specify and control downgrade operations. Contrary to existing downgrading models, our model relies on an abstract security policy in order to define downgrading controls that are not restricted to specific scenarios.
Read moreAnalysis of the Expressive Power of DIFC Model Based on Temporal Logic
Comparing the expressive power of access control models is a fundamental issue in computer security. A better solution to this problem is helpful for understanding the limitations and potential capabilities of models, improving models and selecting appropriate security models for different applications. The existing comparison theories either do not consider the security properties when comparing, or the semantics of the security properties considered are too weak, or the comparison methods are vague and difficult to operate. In this paper, we define a mapping between models whose security properties are preserved based on temporal logic, and propose a more scientific and standard comparison method of expressive power with operability based on the mapping. On this basis, we demonstrate that the DIFC has better expressive power than the BLP model.
Read more