Posts

Why can't I do that?: Explaining Adaptive Security

Image
Adaptive security demo, extracted from Collaborative Security video  produced by Amel Bennaceur Our world is increasingly being pervaded by connected digital devices that make up the Internet of Things, making it important to ensure that the security of these devices and the functionality they provide.  We are working on techniques to support adaptive information security, where the security mechanisms used to protect these pervasive computing systems can change as the value of the assets being protected and the threats that arise in the environment change.  A key challenge in any adaptive system is to ensure that users understand why the behaviour of the system is changing at runtime. This is particularly true of security adaptations because in many situations they are likely to prevent users from accessing functionality. In recent work, we have focussed on software engineering techniques that support this through traceability for explaining adaptive security de...

Online Cyber Security Discussion

Image
Ready to start my first Twitter discussion for #FutureLearnAsks As we kick off the next presentation of the Introduction to Cyber Security MOOC , I took part in an online discussion on the topic with Cory Doctorow and Andrew Smith on Twitter.  This was my first time leading one of these "Ask Me Anything" sessions, which was hosted by FutureLearn as part of a new initiative called #FutureLearnAsks.  Although at times I struggled to keep up with the speed of the conversation, it was a lot of fun to engage with a diverse group of people to talk about this important topic. The discussion was seeded by a number of questions, ranging from "Is the state justified to monitor personal digital and telecommunications in the name of security?" to "What one tip would you give to people to better protect their cyber security?"  One key lesson learned about asking open ended questions like this was that if the answer is always going to start with "It depends ...

Programming to 'Make Sparks Fly'?

Image
Tools for making sure that "Sparks will Fly" This year's Royal Institution Christmas Lectures, titled " Sparks will Fly " were all about 'hacking' everyday objects to make them part of the Internet of Everything.  Presented by Prof. Danielle George from University of Manchester, they were a great showcase of how engineers tackle challenging problems by extending the capabilities of technologies like the light bulb, the telephone and the motor. Across the three lectures, the audience got to take part in building systems that used internet connected lights to play Tetris on a London skyscraper, to holographic communications and a robotic orchestra.  Through this process, we understood how to build solutions to complex problems by: decomposing them into simpler sub-problems; identifying technologies that could help us solve the sub-problems, using techniques like abstraction and  analogical reasoning ; building prototypes to test our hypotheses...

2014 Retrospective ...

Image
Highlight from November 2014: Receiving CCT status for Introduction to Cyber Security MOOC from Chris Ensor (Deputy Director, CESG) and Richard Pharro (CEO, APMG) 2014 has been an eventful year across many spheres of my academic life, complete with research published in major conferences and journals, PhD students graduating and new courses launched.  My final post for the year is a quick review of some of the highlights: January: The year started with the news that two of the papers I co-authored and submitted to the International Conference on Software Engineering (ICSE 2014) had been accepted for publication.  Both of these papers were based on the work of my PhD students, one on privacy requirements engineering and the other on adaptive user interfaces.  It turned out to be a pretty successful year for OU research at ICSE overall . February: We got confirmation that the EPSRC would be funding our project, " MonetizeMe: Privacy and the Quantified Self in the...

Cyber security careers

I am working on wrapping up the first presentation of Introduction to Cyber Security and preparing for the next presentation, which is now open for registration and will start on 26 January 2015 .   The popularity of the first presentation demonstrates a recognition of the importance of cyber security.  Hopefully some of the 15,000+ learners who engaged with the course will be inspired to study further and perhaps even pursue a career in the field.  This is an important and exciting discipline to work in, with a variety of career paths depending on people's interests and aptitude. The Open University provides a range of modules and qualifications that can support this journey, and I recently wrote a short article about some of the career options in cyber security which has now been published on OpenLearn.

REF 2014: Picking through the results

Image
REF 2014 Computing and Informatics Results, ordered by 4*/3* outputs and scaled by staff numbers (Source: http://staff.city.ac.uk/~jwo/refviewer/ ).  For the past two years, academics in UK universities have been preparing and then waiting for the results of the Research Excellence Framework ( REF 2014 ), a quality audit of selected academic research undertaken during the period 2008-2013.  The results were finally published during the very early hours of 18 December, and there has been a flurry of activity as each university and department figures out how to interpret them in a way that reflects best on their performance. At the OU, the Centre for Research in Computing was returned under the "Computer Science & Informatics" unit of assessment (UoA).  The research was produced by academics in the Department of Computing and Communications and the Knowledge Media Institute.  The REF 2014 panel's assessment was that 75% of our research outputs were 4* (wor...

Deep Learning and Adaptive Sharing for Online Social Networking

Prompted by Facebook Research's recent announcement on using deep learning to help users avoid 'drunk posting' embarrassing information on the social networking platform, I wrote an article for The Conversation about deep learning and adaptive sharing.  This draws on our research on Adaptive Sharing for Online Social Networks , which was recognised as the Best Paper at the  13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14).  The following is a short excerpt from the article: Facebook’s initial target appears aimed at extending its face recognition capability to automatically differentiate between a user’s face when sober and drunk, and use this to get a user to think twice before hitting the post button. Of course being detected as being drunk in photographs won’t be the only factor that determines when we want to moderate our social media sharing behaviours. The nature of the links we share, li...