kth.sePublications KTH
Change search
Link to record
Permanent link

Direct link
Kowalski, Stewart
Publications (7 of 7) Show all publications
Kowalski, S., Pavlovska, K. & Goldstein, M. (2013). Two case studies in using chatbots for security training. In: IFIP Advances in Information and Communication Technology: . Paper presented at 8th IFIP WG 11.8 World Conference on Information Security Education, WISE 8; Auckland, New Zealand, 8-10 July 2013 (pp. 265-272).
Open this publication in new window or tab >>Two case studies in using chatbots for security training
2013 (English)In: IFIP Advances in Information and Communication Technology, 2013, p. 265-272Conference paper, Published paper (Refereed)
Abstract [en]

This paper discusses the result of two case studies performed in a large international company to test the use of chatbots for internal security training. The first study targeted 26 end users in the company while the second study examined 80 security specialists. From a quantitative analytical perspective there does not appears to be any significant findings when chatbots are used for security training. However there does appear to be qualitative data that suggest that the attitudes of the respondents appear to be more positive to security when chatbots are used than with the current traditional e-learning security training courses at the company.

Series
IFIP Advances in Information and Communication Technology, ISSN 1868-4238 ; 406
Keywords
Chatbots, Security awareness training
National Category
Information Systems Computer Sciences
Identifiers
urn:nbn:se:kth:diva-139129 (URN)10.1007/978-3-642-39377-8_31 (DOI)2-s2.0-84890759586 (Scopus ID)9783642393761 (ISBN)
Conference
8th IFIP WG 11.8 World Conference on Information Security Education, WISE 8; Auckland, New Zealand, 8-10 July 2013
Note

QC 20140110

Available from: 2014-01-10 Created: 2014-01-07 Last updated: 2024-03-18Bibliographically approved
Karokola, G., Yngström, L. & Kowalski, S. (2012). Secure e-government services: A comparative analysis of e-government maturity models for the developing regions - The need for security services. International Journal of Electronic Government Research, 8(1), 1-25
Open this publication in new window or tab >>Secure e-government services: A comparative analysis of e-government maturity models for the developing regions - The need for security services
2012 (English)In: International Journal of Electronic Government Research, ISSN 1548-3886, E-ISSN 1548-3894, Vol. 8, no 1, p. 1-25Article in journal (Refereed) Published
Abstract [en]

E-Government offers many benefits to government agencies, citizens and the business community. However, e-Government services are prone to current and emerging security challenges posing potential threats to critical information assets. Securing it appears to be a major challenge facing governments globally. Based on the international security standards - the paper thoroughly investigates and analyzes eleven e-government maturity models (eGMMs) for security services. Further, it attempts to establish a common frame of reference for eGMM critical stages. The study utilizes the Soft Systems Methodology (SSM) of scientific inquiry/ learning cycle adopted from Checkland and Scholes. The findings show that security services (technical and non-technical) are lacking in eGMMs - implying that eGMMs were designed to measure more quantity of offered e-government services than the quality of security services. Therefore, as a step towards achieving secure e-government services the paper proposes a common frame of reference for eGMM with five critical stages. These stages will later be extended to include the required security services.

Keywords
Developing Regions, E-Government, E-Government Maturity Model, Information Security, Security Services
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-97723 (URN)10.4018/jegr.2012010101 (DOI)000212428500001 ()2-s2.0-84860519899 (Scopus ID)
Note

QC 20120614

Available from: 2012-06-14 Created: 2012-06-14 Last updated: 2024-03-15Bibliographically approved
Mwakalinga, J. & Kowalski, S. (2011). Architecture for Adaptive Information Security Systems as applied to Social Networks. In: The IEEE International conference on computer communications and networks.
Open this publication in new window or tab >>Architecture for Adaptive Information Security Systems as applied to Social Networks
2011 (English)In: The IEEE International conference on computer communications and networks, 2011Conference paper, Published paper (Refereed)
Abstract [en]

Users of social networks appear to want and need to share information online without necessarily thinking about the security consequences. Hackers and attackers have understood the potential vulnerabilities in social networks. This paper describes an architecture for adaptive information security systems, which could be applied to provide security services in social networks. The problem with most security architectures is that they do not provide adaptive security measures to environments and to culture of users. In addition, most security architectures provide technical security measures but fail to provide socio-technical measures. The enemies of ICT use both technical and social measures to attack ICT systems. This paper presents a security architecture that provides adaptive security measures and socio-technical measures in social networks.

Keywords
Deterrence, socio-technical security measures, value–based chain, social networks
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-34525 (URN)
Note
QC 20110609Available from: 2011-06-09 Created: 2011-06-09 Last updated: 2024-03-18Bibliographically approved
Mwakalinga, J. & Kowalski, S. (2011). ICT Crime Cases Autopsy: Using the Adaptive Information Security Systems Model to Improve ICT Security. In: IJCSNS International Journal of Computer Science and Network Security.
Open this publication in new window or tab >>ICT Crime Cases Autopsy: Using the Adaptive Information Security Systems Model to Improve ICT Security
2011 (English)In: IJCSNS International Journal of Computer Science and Network Security, 2011Conference paper, Published paper (Refereed)
Abstract [en]

This paper presents an analysis of ICTcrimes using the adaptive informationsecurity systems model. There is a desire ofbeing able to identify potential ICT victimsso that measures could be taken to protectthem. We briefly describe the crime theories,the top ten crimes, and the desire to havecrime proofing products. We then describethe adaptive model for information securitysystems, and the architecture and the sociotechnicalsystem for analyzing ICT crimes.The analysis of the ICT crimes is presented.Finally, we present recommendations onhow to improve on how to improve ICTsecurity.

Keywords
Socio-technical, deterrence, prevention, detection, response
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-34524 (URN)
Note
QC 20110609Available from: 2011-06-09 Created: 2011-06-09 Last updated: 2024-03-18Bibliographically approved
Mwakalinga, J. & Kowalski, S. (2011). Modeling the Enemies of an IT Security System: A Socio-Technical System Security Model. In: The 12th International Symposium on Models and Modeling Methodologies in Science and Engineering, in the context of the 2nd International Conference on Complexity, Informatics, and Cybernetics.
Open this publication in new window or tab >>Modeling the Enemies of an IT Security System: A Socio-Technical System Security Model
2011 (English)In: The 12th International Symposium on Models and Modeling Methodologies in Science and Engineering, in the context of the 2nd International Conference on Complexity, Informatics, and Cybernetics, 2011Conference paper, Published paper (Refereed)
Abstract [sv]

This paper presents a socio-technical security model for security systems that include both the system being defended and the attacking system. We first model security as a ratio or function of the states that an attacker can produce over the states that defend can control. We then sub divided the control states of a defending systems using the security value chain and socio technical system security model. The paper then presents two attempts to validate the acceptance of the defense model using cross culture surveys of individuals from over 20 different countries indicate culture variation in security modeling. An example of how an attacker can model an attack strategy is given at the end of the paper. The paper concludes with a discussion of how the modeling can be new research in modeling criminal organization using effective based operations methodology.

Keywords
Enemy of IT, deterrence, prevention, detection, response, and socio-technical model, center of gravity
National Category
Control Engineering
Identifiers
urn:nbn:se:kth:diva-34522 (URN)
Note
QC 20110609Available from: 2011-06-09 Created: 2011-06-09 Last updated: 2024-03-18Bibliographically approved
Karokola, G., Kowalski, S. & Yngström, L. (2011). Secure e-government services: Towards a framework for integrating IT security services into e-government maturity models. In: 2011 Information Security for South Africa - Proceedings of the ISSA 2011 Conference: . Paper presented at 2011 Conference on Information Security for South Africa, ISSA 2011, 15 August 2011 through 17 August 2011, Rosebank, Johannesburg.
Open this publication in new window or tab >>Secure e-government services: Towards a framework for integrating IT security services into e-government maturity models
2011 (English)In: 2011 Information Security for South Africa - Proceedings of the ISSA 2011 Conference, 2011Conference paper, Published paper (Refereed)
Abstract [en]

e-Government maturity models (eGMMs) lack security services (technical and socio/non-technical) in its critical maturity stages. The paper proposes a comprehensive framework for integrating IT security services into eGMM critical stages. The proposed framework is a result of integrating information security maturity model (ISMM) critical levels into e-government maturity model (eGMM) critical stages. The research utilizes Soft Systems Methodology (SSM) of scientific inquiry adopted from Checkland and Scholes. The paper contributes to the theoretical and empirical knowledge in the following ways: firstly, it introduces a new approach that shows how government's can progressively secure their e-government services; secondly, it outlines the security requirements (technical and non-technical) for critical maturity stages of eGMM; and thirdly, it enhances awareness and understanding to the governments and stakeholders such as practitioners, experts and citizens on the importance of security requirements being clearly defined within eGMM critical stages.

Series
2011 Information Security for South Africa - Proceedings of the ISSA 2011 Conference
Keywords
e-Government, Information Security, Maturity Model, Security Requirements, Technical and Non-technical Security aspects, Critical level, E-government services, Empirical knowledge, Integrating information, IT security, Maturity stages, Scientific inquiry, Security services, Soft systems methodology, Government data processing, Information services, Information technology, Security systems, Security of data
National Category
Computer Sciences
Identifiers
urn:nbn:se:kth:diva-150723 (URN)10.1109/ISSA.2011.6027525 (DOI)2-s2.0-80053932311 (Scopus ID)9781457714832 (ISBN)
Conference
2011 Conference on Information Security for South Africa, ISSA 2011, 15 August 2011 through 17 August 2011, Rosebank, Johannesburg
Note

QC 20140910

Available from: 2014-09-10 Created: 2014-09-09 Last updated: 2024-03-15Bibliographically approved
Karokola, G., Kowalski, S. & Yngström, L. (2011). Towards an information security maturity model for secure e-Government services: A stakeholders view. In: Proceedings of the 5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011: . Paper presented at 5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011, London, United Kingdom, July 7-8, 2011 (pp. 58-73).
Open this publication in new window or tab >>Towards an information security maturity model for secure e-Government services: A stakeholders view
2011 (English)In: Proceedings of the 5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011, 2011, p. 58-73Conference paper, Published paper (Refereed)
Abstract [en]

The paper proposes a comprehensive information security maturity model (ISMM) that addresses both technical and socio/non-technical security aspects. The model is intended for securing e-government services (implementation and service delivery) in an emerging and increasing security risk environment. The paper utilizes extensive literature review and survey study approaches. A total of eight existing ISMMs were selected and critically analyzed. Models were then categorized into security awareness, evaluation and management orientations. Based on the model's strengths-three models were selected to undergo further analyses and then synthesized. Each of the three selected models was either from the security awareness, evaluation or management orientations category. To affirm the findings-a survey study was conducted into six government organizations located in Tanzania. The study was structured to a large extent by the security controls adopted from the Security By Consensus (SBC) model. Finally, an ISMM with five critical maturity levels was proposed. The maturity levels were: undefined, defined, managed, controlled and optimized. The papers main contribution is the proposed model that addresses both technical and non-technical security services within the critical maturity levels. Additionally, the paper enhances awareness and understanding on the needs for security in e-government services to stakeholders.

Keywords
e-Government, Information Security, Maturity Model, Security services, Technical and Non-technical security, Government data processing, Information services, Mobile security, Surveys, Comprehensive information, E-government services, E-governments, Government organizations, Literature reviews, Technical security, Security of data
National Category
Information Systems
Identifiers
urn:nbn:se:kth:diva-308784 (URN)2-s2.0-84875546106 (Scopus ID)
Conference
5th International Symposium on Human Aspects of Information Security and Assurance, HAISA 2011, London, United Kingdom, July 7-8, 2011
Note

QC 20220212

Available from: 2022-02-12 Created: 2022-02-12 Last updated: 2022-06-25Bibliographically approved
Organisations

Search in DiVA

Show all publications