Primary tabs
2024
Nkambule, M., van Vuuren, J. J., & Leenen, L. (2024). Integrating Enterprise Architecture into Cybersecurity Risk Management in Higher Education. In Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024) (Vol. 19). Johannesburg, South Africa: Academic Conferences International. http://doi.org/10.34190/iccws.19.1.2189
Cybercriminals constantly seek new methods to infiltrate a company's defences, making cybersecurity investments essential. Enterprise architecture (EA) provides a systematic risk detection and mitigation process by emphasising the interdependencies between systems, data, processes, people, and other factors. This paper provides a comprehensive approach, also referred to as a process, based on EA to assist African universities in developing a comprehensive cybersecurity plan. The EA process comprises four pillars: business architecture, data architecture, application architecture, and technology architecture. African universities can develop a comprehensive cybersecurity strategy using an EA approach in cybersecurity to achieve institutional goals and objectives. The potential attack surface comprises isolated EA components and their interconnections. This article comprehensively examines various EA processes such as business, information, application, and technology architecture. These processes are carefully analysed to evaluate the organisational structures and uncover opportunities to enhance security protocols. Additionally, we delve deep into abstract security patterns, seeking to cultivate an environment of trustworthiness within complex systems. Our research findings underscore the significant potential within African higher education institutions. By embracing a model-based approach to risk analysis and mitigation, these institutions can fortify their cybersecurity defences to ensure uninterrupted business operations and enhance overall resilience in the face of evolving security challenges. When we combine EA and information security (ICS), we uncover many vulnerabilities malicious actors might exploit. By embracing a holistic EA-based methodology, institutions can craft and implement robust security protocols to safeguard their components and connections. Leveraging EA, our proposed integrated approach aims to forge a comprehensive cybersecurity risk management strategy tailored to the African higher education sector. This strategy seeks to facilitate the identification of critical elements and their intricate interrelationships, thus formulating an effective defence strategy against potential cyber threats. The synergy promises to elevate cybersecurity practices, ensure uninterrupted business operations, and fortify the continent's resilience.
@{549,
author = {Mafika Nkambule and Joey van Vuuren and Louise Leenen},
title = {Integrating Enterprise Architecture into Cybersecurity Risk Management in Higher Education},
abstract = {Cybercriminals constantly seek new methods to infiltrate a company's defences, making cybersecurity investments essential. Enterprise architecture (EA) provides a systematic risk detection and mitigation process by emphasising the interdependencies between systems, data, processes, people, and other factors. This paper provides a comprehensive approach, also referred to as a process, based on EA to assist African universities in developing a comprehensive cybersecurity plan. The EA process comprises four pillars: business architecture, data architecture, application architecture, and technology architecture. African universities can develop a comprehensive cybersecurity strategy using an EA approach in cybersecurity to achieve institutional goals and objectives. The potential attack surface comprises isolated EA components and their interconnections. This article comprehensively examines various EA processes such as business, information, application, and technology architecture. These processes are carefully analysed to evaluate the organisational structures and uncover opportunities to enhance security protocols. Additionally, we delve deep into abstract security patterns, seeking to cultivate an environment of trustworthiness within complex systems. Our research findings underscore the significant potential within African higher education institutions. By embracing a model-based approach to risk analysis and mitigation, these institutions can fortify their cybersecurity defences to ensure uninterrupted business operations and enhance overall resilience in the face of evolving security challenges. When we combine EA and information security (ICS), we uncover many vulnerabilities malicious actors might exploit. By embracing a holistic EA-based methodology, institutions can craft and implement robust security protocols to safeguard their components and connections. Leveraging EA, our proposed integrated approach aims to forge a comprehensive cybersecurity risk management strategy tailored to the African higher education sector. This strategy seeks to facilitate the identification of critical elements and their intricate interrelationships, thus formulating an effective defence strategy against potential cyber threats. The synergy promises to elevate cybersecurity practices, ensure uninterrupted business operations, and fortify the continent's resilience.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {501-510},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2189},
}
Coetzer, C., & Leenen, L. (2024). Managing Cyber Security Debt: Strategies for Identification, Prioritisation, and Mitigation. In Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024) (Vol. 19). Johannesburg, South Africa: Academic Conferences International. http://doi.org/10.34190/iccws.19.1.2178
This paper explores cyber security debt, a technical debt arising from unaddressed security vulnerabilities in an organisation's IT systems. These vulnerabilities accumulate due to resource limitations, time constraints, and expertise gaps, potentially leading to security breaches and data compromises. The paper outlines the cyber security debt management process involving identification, prioritisation, and mitigation strategies. Drawing parallels to financial debt, the authors emphasise the escalating risks of delaying cyber security debt repayment. The paper underscores the significance of diligent debt management in maintaining digital resilience and mitigating cyber threats. The increasing interconnectedness of systems and rapid software development has given rise to a hidden challenge known as cyber security debt. Cyber security debt is posed as a subset of technical debt, encompassing the accumulation of security vulnerabilities within an organisation's IT infrastructure and applications. Drawing a parallel between cyber security debt and its financial counterpart, the authors underscore the grave risks of deferring debt repayment. Just as financial debt accrues interest, unresolved security vulnerabilities compound over time, elevating the likelihood of breaches and data exposure. A poignant case study of the Equifax breach exemplifies the real-world consequences of neglecting security debt management. The failure to patch a well-known vulnerability led to a colossal data breach, highlighting the urgency of addressing security weaknesses promptly. Complex in nature, cyber security debt materialises when organisations fail to address vulnerabilities during various operational life cycles. These vulnerabilities might remain concealed within IT architecture, legacy code, or third-party libraries, posing a formidable challenge to detection and resolution. By understanding the parallels between financial and cyber security debt and proactively managing the latter, organisations can enhance their ability to safeguard against evolving cyber threats and maintain a robust security posture.
@{548,
author = {Christo Coetzer and Louise Leenen},
title = {Managing Cyber Security Debt: Strategies for Identification, Prioritisation, and Mitigation},
abstract = {This paper explores cyber security debt, a technical debt arising from unaddressed security vulnerabilities in an organisation's IT systems. These vulnerabilities accumulate due to resource limitations, time constraints, and expertise gaps, potentially leading to security breaches and data compromises. The paper outlines the cyber security debt management process involving identification, prioritisation, and mitigation strategies. Drawing parallels to financial debt, the authors emphasise the escalating risks of delaying cyber security debt repayment. The paper underscores the significance of diligent debt management in maintaining digital resilience and mitigating cyber threats. The increasing interconnectedness of systems and rapid software development has given rise to a hidden challenge known as cyber security debt. Cyber security debt is posed as a subset of technical debt, encompassing the accumulation of security vulnerabilities within an organisation's IT infrastructure and applications. Drawing a parallel between cyber security debt and its financial counterpart, the authors underscore the grave risks of deferring debt repayment. Just as financial debt accrues interest, unresolved security vulnerabilities compound over time, elevating the likelihood of breaches and data exposure. A poignant case study of the Equifax breach exemplifies the real-world consequences of neglecting security debt management. The failure to patch a well-known vulnerability led to a colossal data breach, highlighting the urgency of addressing security weaknesses promptly. Complex in nature, cyber security debt materialises when organisations fail to address vulnerabilities during various operational life cycles. These vulnerabilities might remain concealed within IT architecture, legacy code, or third-party libraries, posing a formidable challenge to detection and resolution. By understanding the parallels between financial and cyber security debt and proactively managing the latter, organisations can enhance their ability to safeguard against evolving cyber threats and maintain a robust security posture.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {439-446},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2178},
}
Vorster, J., & Leenen, L. (2024). Covert Subversive Agents and Consensus Disruption on Large Projects. In Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024) (Vol. 19). Johannesburg, South Africa: Academic Conferences International. http://doi.org/10.34190/iccws.19.1.2174
Is it possible to dramatically affect and influence military and other projects through social engineering of the consensus processes? In this paper we explore the impact that subversive agents can have on the ability of projects to move forward by disrupting the social cohesion and decision-making abilities of the processes designed to reach consensus. A consensus simulator is used to model group social cohesion behaviour in the context of project deliverables and show what the effect can be on the effort to reach consensus (number of meetings) as well as the time to reach consensus (calendar time) when subversive agents attempt to influence the groups making up the project team in such a way that it delays the ability of the team to reach consensus on key decisions. Many military options are available to delay enemy projects, including the assassination of enemy scientists, sanctions aimed at denying key project components, or even direct military action such as bombing the enemy facilities. However, this paper focusses on aspects of soft-force projection through covert disruption of project timelines. A social simulator was constructed that models individual agent's beliefs about various key topics within the context of a project. The effect that a small number of subversive agents can have on the time- and effort of a project is shown. In their covert actions, these subversive agents need to stay hidden, and thus their covert actions are limited, yet they can exert significant damage to the project in terms of delays. In this paper we present results showing the effects that such a small group can have, as well as pointing out that there seem to be a critical group size over which the subversive agents can not only have significant impact on project-delays but can also steer and direct certain key decisions.
@{547,
author = {Johannes Vorster and Louise Leenen},
title = {Covert Subversive Agents and Consensus Disruption on Large Projects},
abstract = {Is it possible to dramatically affect and influence military and other projects through social engineering of the consensus processes? In this paper we explore the impact that subversive agents can have on the ability of projects to move forward by disrupting the social cohesion and decision-making abilities of the processes designed to reach consensus. A consensus simulator is used to model group social cohesion behaviour in the context of project deliverables and show what the effect can be on the effort to reach consensus (number of meetings) as well as the time to reach consensus (calendar time) when subversive agents attempt to influence the groups making up the project team in such a way that it delays the ability of the team to reach consensus on key decisions. Many military options are available to delay enemy projects, including the assassination of enemy scientists, sanctions aimed at denying key project components, or even direct military action such as bombing the enemy facilities. However, this paper focusses on aspects of soft-force projection through covert disruption of project timelines. A social simulator was constructed that models individual agent's beliefs about various key topics within the context of a project. The effect that a small number of subversive agents can have on the time- and effort of a project is shown. In their covert actions, these subversive agents need to stay hidden, and thus their covert actions are limited, yet they can exert significant damage to the project in terms of delays. In this paper we present results showing the effects that such a small group can have, as well as pointing out that there seem to be a critical group size over which the subversive agents can not only have significant impact on project-delays but can also steer and direct certain key decisions.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {421-429},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2174},
}
Gertenbach, W., Botha, J., & Leenen, L. (2024). A Proposed High-Level Methodology on How OSINT is applied in Blockchain Investigations. In Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024) (Vol. 19). Johannesburg, South Africa: Academic Conferences International. http://doi.org/10.34190/iccws.19.1.2172
The characteristics of blockchain established a desirable platform for entities to innovate and operate in a secure, transparent, and decentralised manner. However, cybercriminals have increasingly found refuge in the decentralised environment of blockchain technology. Cryptocurrencies are increasingly misused in malicious activities that encompass the trade of illicit goods, money laundering, various types of scams and ransomware attacks. The total cryptocurrency value received by illicit addresses reached an all-time high of $20.6 billion in 2022 according to Chainalysis. The inherent privacy and anonymity features of many blockchain networks make it challenging for law enforcement and regulatory agencies to track and apprehend wrongdoers. Consequently, a pressing need arises not only to initiate investigations on the blockchain to identify unlawful activities, but also to discover connections between these activities and the identities of the responsible individuals. Due to blockchain data being publicly available, the application of Open-Source Intelligence (OSINT) techniques is proposed to facilitate these types of investigations. In the context of blockchain, OSINT, together with investigation tools hold the promise of unearthing valuable information that could aid in attributing malicious activities to the individuals responsible for those actions. By analysing and synthesizing data from publicly accessible sources, such as data from blockchain explorers and link analysis tools such Chainalysis, Maltego or Spiderfoot, investigators could potentially unveil valuable clues that assist in building a comprehensive picture of blockchain-related criminal activities. Ultimately, with sufficient information and actionable intelligence collected, the main goal is to link it to Know Your Customer (KYC) data, that could be obtained from cryptocurrency exchanges via a subpoena from law enforcement agencies. This paper delves into the mechanisms of various OSINT tools and techniques, to determine their adaptability to the specific demands of blockchain investigations. This study provides a methodology and recommendations with insights into how these tools can be wielded to bridge the gap between blockchain's pseudonymity and real-world identities.
@{546,
author = {W.P. Gertenbach and Johnny Botha and Louise Leenen},
title = {A Proposed High-Level Methodology on How OSINT is applied in Blockchain Investigations},
abstract = {The characteristics of blockchain established a desirable platform for entities to innovate and operate in a secure, transparent, and decentralised manner. However, cybercriminals have increasingly found refuge in the decentralised environment of blockchain technology. Cryptocurrencies are increasingly misused in malicious activities that encompass the trade of illicit goods, money laundering, various types of scams and ransomware attacks. The total cryptocurrency value received by illicit addresses reached an all-time high of $20.6 billion in 2022 according to Chainalysis. The inherent privacy and anonymity features of many blockchain networks make it challenging for law enforcement and regulatory agencies to track and apprehend wrongdoers. Consequently, a pressing need arises not only to initiate investigations on the blockchain to identify unlawful activities, but also to discover connections between these activities and the identities of the responsible individuals. Due to blockchain data being publicly available, the application of Open-Source Intelligence (OSINT) techniques is proposed to facilitate these types of investigations. In the context of blockchain, OSINT, together with investigation tools hold the promise of unearthing valuable information that could aid in attributing malicious activities to the individuals responsible for those actions. By analysing and synthesizing data from publicly accessible sources, such as data from blockchain explorers and link analysis tools such Chainalysis, Maltego or Spiderfoot, investigators could potentially unveil valuable clues that assist in building a comprehensive picture of blockchain-related criminal activities. Ultimately, with sufficient information and actionable intelligence collected, the main goal is to link it to Know Your Customer (KYC) data, that could be obtained from cryptocurrency exchanges via a subpoena from law enforcement agencies. This paper delves into the mechanisms of various OSINT tools and techniques, to determine their adaptability to the specific demands of blockchain investigations. This study provides a methodology and recommendations with insights into how these tools can be wielded to bridge the gap between blockchain's pseudonymity and real-world identities.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {75-83},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2172},
}
Botha, J., & Leenen, L. (2024). Cryptocurrency-crime Investigation: Fraudulent use of Bitcoin in a Divorce Case. In Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024) (Vol. 19). Johannesburg, South Africa: Academic Conferences International. http://doi.org/10.34190/iccws.19.1.2050
Bitcoin and cryptocurrency adoption has increased significantly over the past few years. The significant growth in the industry has been matched by growth of crimes in this domain; not only in scams and dark-web illegal trading, but also in white-collar crimes with fraud and perjury occurring increasingly. With blockchain technology, the world of financial infidelity has become increasingly sophisticated. There is a common belief that blockchain and cryptocurrency provide means of hiding funds from the public or close associates who may not be familiar with the technology. The rise of cryptocurrency has also led to spouses hiding digital assets during divorce settlements. This study presents a use case of a couple in the midst of a divorce where one of the spouses was accused of perjury for failure to declare bitcoin holdings, obtained via Bitcoin mining, and possibly other forms of cryptocurrency and digital assets to the court. The plaintiff is entitled to fifty percent of all assets. While property, stocks, bonds, and bank accounts can easily be traced, cryptocurrency assets are more complex to trace but it is not impossible. This paper illustrates how such a case can be investigated by following the flow of funds on the blockchain, using tools such as Maltego and QLUE. The paper thus presents an investigative process that can be followed for a new category of forensic investigation.
@{545,
author = {Johnny Botha and Louise Leenen},
title = {Cryptocurrency-crime Investigation: Fraudulent use of Bitcoin in a Divorce Case},
abstract = {Bitcoin and cryptocurrency adoption has increased significantly over the past few years. The significant growth in the industry has been matched by growth of crimes in this domain; not only in scams and dark-web illegal trading, but also in white-collar crimes with fraud and perjury occurring increasingly. With blockchain technology, the world of financial infidelity has become increasingly sophisticated. There is a common belief that blockchain and cryptocurrency provide means of hiding funds from the public or close associates who may not be familiar with the technology. The rise of cryptocurrency has also led to spouses hiding digital assets during divorce settlements. This study presents a use case of a couple in the midst of a divorce where one of the spouses was accused of perjury for failure to declare bitcoin holdings, obtained via Bitcoin mining, and possibly other forms of cryptocurrency and digital assets to the court. The plaintiff is entitled to fifty percent of all assets. While property, stocks, bonds, and bank accounts can easily be traced, cryptocurrency assets are more complex to trace but it is not impossible. This paper illustrates how such a case can be investigated by following the flow of funds on the blockchain, using tools such as Maltego and QLUE. The paper thus presents an investigative process that can be followed for a new category of forensic investigation.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {34-42},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2050},
}
Vorster, J. S., & Leenen, L. (2024). Stochastic Consensus Simulation for Organizational Cooperation. In Simulation and Modeling Methodologies, Technologies and Applications (1st ed., Vol. 1211, p. 215). Springer, Cham. http://doi.org/https://doi.org/10.1007/978-3-031-77603-8_8
This paper delves into the intricacies of consensus processes within project teams, shedding light on determinants such as group size and the role of artefacts. By deploying both a simulation and a mathematical model, the study unfolds insights into the temporal and resource dynamics essential for consensus formation. Notably, for smaller teams, the quadratic dependence on team size underscores the complexities inherent in achieving consensus. In contrast, larger teams exhibit a linear relationship, hinting at a more scalable consensus process. The investigation introduces the influence of artefacts, emphasizing the significance it plays in streamlining consensus efforts. A noteworthy revelation is the substantial reduction, over 30%, in consensus time with the use of artefacts, underscoring their impact on communication and collaboration within teams. This finding underscores the pragmatic importance of well-structured documentation and artefacts in expediting consensus-building processes. Historic project failures often attributed to prolonged and intricate consensus processes. This research contributes valuable insights for project managers. By elucidating the interplay between team size, artefacts, and consensus, the study provides a nuanced understanding of project dynamics. This understanding, grounded in both simulation and mathematical models, offers practical guidance for project management strategies, enabling tailored approaches based on team size and organizational structure. Ultimately, this research advances the discourse on effective project management by unraveling the complexities of consensus processes and illuminating the transformative impact of artefacts.
@inbook{525,
author = {Johannes Vorster and Louise Leenen},
title = {Stochastic Consensus Simulation for Organizational Cooperation},
abstract = {This paper delves into the intricacies of consensus processes within project teams, shedding light on determinants such as group size and the role of artefacts. By deploying both a simulation and a mathematical model, the study unfolds insights into the temporal and resource dynamics essential for consensus formation. Notably, for smaller teams, the quadratic dependence on team size underscores the complexities inherent in achieving consensus. In contrast, larger teams exhibit a linear relationship, hinting at a more scalable consensus process. The investigation introduces the influence of artefacts, emphasizing the significance it plays in streamlining consensus efforts. A noteworthy revelation is the substantial reduction, over 30%, in consensus time with the use of artefacts, underscoring their impact on communication and collaboration within teams. This finding underscores the pragmatic importance of well-structured documentation and artefacts in expediting consensus-building processes. Historic project failures often attributed to prolonged and intricate consensus processes. This research contributes valuable insights for project managers. By elucidating the interplay between team size, artefacts, and consensus, the study provides a nuanced understanding of project dynamics. This understanding, grounded in both simulation and mathematical models, offers practical guidance for project management strategies, enabling tailored approaches based on team size and organizational structure. Ultimately, this research advances the discourse on effective project management by unraveling the complexities of consensus processes and illuminating the transformative impact of artefacts.},
year = {2024},
journal = {Simulation and Modeling Methodologies, Technologies and Applications},
volume = {1211},
edition = {1},
pages = {139-173},
month = {December 2024},
publisher = {Springer, Cham},
isbn = {978-3-031-77603-8},
doi = {https://doi.org/10.1007/978-3-031-77603-8_8},
}
Vorster, J. S., & Leenen, L. (2024). Exploring the Impact of Subversive Agents on Consensus Processes in Project Teams: Multi-agent Simulations. . In Simulation and Modeling Methodologies, Technologies and Applications (1st ed., Vol. 1211, p. 215). Springer, Cham. http://doi.org/https://doi.org/10.1007/978-3-031-77603-8_3
This theoretical study investigates the influence of subversive agents on consensus-seeking processes within project teams. Departing from traditional cooperative team dynamics, the research introduces agents strategically working to influence views and decisions. Key findings reveal that yes-agents, actively advocating for specific views, can enhance consensus times but carry the risk of swaying decisions toward potentially incorrect outcomes. In contrast, subversive agents, by widening the range of options or polarizing the group, substantially delay consensus processes. Notably, the level of cooperation among subversive agents does not significantly impact consensus times, yet coordinated actions profoundly shape decision outcomes. Under specific conditions, even a small minority of subversive agents can significantly extend the time to reach consensus, showcasing their potent influence. This research contributes to understanding the interplay between cooperation, subversion, and decision-making, offering valuable insights for future exploration and empirical research.
@inbook{524,
author = {Johannes Vorster and Louise Leenen},
title = {Exploring the Impact of Subversive Agents on Consensus Processes in Project Teams: Multi-agent Simulations.},
abstract = {This theoretical study investigates the influence of subversive agents on consensus-seeking processes within project teams. Departing from traditional cooperative team dynamics, the research introduces agents strategically working to influence views and decisions. Key findings reveal that yes-agents, actively advocating for specific views, can enhance consensus times but carry the risk of swaying decisions toward potentially incorrect outcomes. In contrast, subversive agents, by widening the range of options or polarizing the group, substantially delay consensus processes. Notably, the level of cooperation among subversive agents does not significantly impact consensus times, yet coordinated actions profoundly shape decision outcomes. Under specific conditions, even a small minority of subversive agents can significantly extend the time to reach consensus, showcasing their potent influence. This research contributes to understanding the interplay between cooperation, subversion, and decision-making, offering valuable insights for future exploration and empirical research.},
year = {2024},
journal = {Simulation and Modeling Methodologies, Technologies and Applications},
volume = {1211},
edition = {1},
pages = {29-60},
month = {Dec 2024},
publisher = {Springer, Cham},
isbn = {978-3-031-77603-8},
doi = {https://doi.org/10.1007/978-3-031-77603-8_3},
}
2023
Hou, J.-C., Leenen, L., & van Heerden, R. (2023). STIX2 Cyber Attack Report Tool for Higher Education. In Southern Africa Telecommunication Networks and Applications Conference (SATNAC 2023). South Africa.
@{557,
author = {J-C. Hou and Louise Leenen and Renier van Heerden},
title = {STIX2 Cyber Attack Report Tool for Higher Education},
abstract = {},
year = {2023},
journal = {Southern Africa Telecommunication Networks and Applications Conference (SATNAC 2023)},
month = {28-30 August 2023},
address = {South Africa},
}
Olaifa, M., van Vuuren, J. J., Plessis, D. du, & Leenen, L. (2023). Security Issues in Cyber Threat Intelligence Exchange: A Review. In Computing Conference (Vol. Lecture Notes in Networks and Systems 739).
The cost and time required by individual organizations to build an effective cyber defence can become overwhelming with the growing number of cyber attacks. Hence, the introduction of platforms that encourage collaborative effort in the fight against cyber attacks is considered advantageous. However, the acceptability and efficiency of the CTI exchange platforms is massively challenged by lack of trust caused by security issues encountered in such communities. This review examines the security and participation cost issues revolving around the willingness of participants to either join or actively participate in CTI exchange communities and proposed solutions to the security issues from the research perspective.
@{499,
author = {Moses Olaifa and Joey van Vuuren and Deon Plessis and Louise Leenen},
title = {Security Issues in Cyber Threat Intelligence Exchange: A Review},
abstract = {The cost and time required by individual organizations to
build an effective cyber defence can become overwhelming with the growing
number of cyber attacks. Hence, the introduction of platforms that
encourage collaborative effort in the fight against cyber attacks is considered
advantageous. However, the acceptability and efficiency of the CTI
exchange platforms is massively challenged by lack of trust caused by
security issues encountered in such communities. This review examines
the security and participation cost issues revolving around the willingness
of participants to either join or actively participate in CTI exchange communities
and proposed solutions to the security issues from the research
perspective.},
year = {2023},
journal = {Computing Conference},
volume = {Lecture Notes in Networks and Systems 739},
pages = {1308-1319},
month = {20-21 October 2023},
}
Botha, J., Pederson, T., & Leenen, L. (2023). An Analysis of the MTI Crypto Investment Scam: User Case . In Proceedings of the 22-nd European Conference on Cyber Warfare and Security (ECCWS).
Since the start of the Covid-19 pandemic, blockchain and cryptocurrency adoption has increased significantly. The adoption rate of blockchain-based technologies has surpassed the Internet adoption rate in the 90s and early 2000s. As this industry has grown significantly, so too has the instances of crypto scams. Numerous cryptocurrency scams exist to exploit users. The generally limited understanding of how cryptocurrencies operate has increased the possible number of scams, relying on people’s misplaced sense of trust and desire for making money quickly and easily. As such, investment scams have also been growing in popularity. Mirror Trading International (MTI) has been named South Africa’s biggest crypto scam in 2020, resulting in losses of $1.7 billion. It is also one of the largest reported international crypto investment scams. This paper focuses on a specific aspect of the MTI scam; an analysis on the fund movements on the blockchain from the perpetrators and members who benefited the most from the scam. The authors used various Open-Source Intelligence (OSINT) tools, alongside QLUE, as well as news articles and blockchain explorers. These tools and techniques are used to follow the money-trial on the blockchain, in search of possible mistakes made by the perpetrator. This could include instances where some personal information might have been leaked. With such disclosed personal information, OSINT tools and investigative techniques can be used to identify the criminals. Due to the CEO of MTI having been arrested, and the case currently being dealt with in the court of law in South Africa, this paper also presents investigative processes that could be followed. Thus, the focus of this paper is to follow the money and consequently propose a process for an investigator to investigate crypto crimes and scams on the blockchain. As the adoption of blockchain technologies continues to increase at unprecedented rates, it is imperative to produce investigative toolkits and use cases to help reduce time spent trying to catch bad actors within the generally anonymous realm of cryptocurrencies
@{498,
author = {Johnny Botha and Thor Pederson and Louise Leenen},
title = {An Analysis of the MTI Crypto Investment Scam: User Case},
abstract = {Since the start of the Covid-19 pandemic, blockchain and cryptocurrency adoption has increased significantly. The adoption rate of blockchain-based technologies has surpassed the Internet adoption rate in the 90s and early 2000s. As this industry has grown significantly, so too has the instances of crypto scams. Numerous cryptocurrency scams exist to exploit users. The generally limited understanding of how cryptocurrencies operate has increased the possible number of scams, relying on people’s misplaced sense of trust and desire for making money quickly and easily. As such, investment scams have also been growing in popularity. Mirror Trading International (MTI) has been named South Africa’s biggest crypto scam in 2020, resulting in losses of $1.7 billion. It is also one of the largest reported international crypto investment scams. This paper focuses on a specific aspect of the MTI scam; an analysis on the fund movements on the blockchain from the perpetrators and members who benefited the most from the scam. The authors used various Open-Source Intelligence (OSINT) tools, alongside QLUE, as well as news articles and blockchain explorers. These tools and techniques are used to follow the money-trial on the blockchain, in search of possible mistakes made by the perpetrator. This could include instances where some personal information might have been leaked. With such disclosed personal information, OSINT tools and investigative techniques can be used to identify the criminals. Due to the CEO of MTI having been arrested, and the case currently being dealt with in the court of law in South Africa, this paper also presents investigative processes that could be followed. Thus, the focus of this paper is to follow the money and consequently propose a process for an investigator to investigate crypto crimes and scams on the blockchain. As the adoption of blockchain technologies continues to increase at unprecedented rates, it is imperative to produce investigative toolkits and use cases to help reduce time spent trying to catch bad actors within the generally anonymous realm of cryptocurrencies},
year = {2023},
journal = {Proceedings of the 22-nd European Conference on Cyber Warfare and Security (ECCWS)},
pages = {36-48},
month = {June 2023},
}
Vorster, J., & Leenen, L. (2023). Consensus Simulator for Organisational Structures. In the 13th International Conference on Simulation and Modelling Methodologies, Technologies and Applications (SimulTech).. Rome, Italy.
In this paper we present a new simulator to investigate consensus within organisations, based on organisational structure, team dynamics, and artefacts. We model agents who can interact with each other and with artefacts, as well as the mathematical models that govern agent behaviour. We show that for a fixed problem size, there is a maximum time within which all agents will reach consensus, independent of number of agents. We present the results from simulating wide ranges of problem sizes and agent group sizes and report on two significant statistics; the time to reach consensus and the effort to reach consensus. The time to reach consensus has implications for project delivery timelines, and the effort relates to project economics.
@{497,
author = {Johannes Vorster and Louise Leenen},
title = {Consensus Simulator for Organisational Structures},
abstract = {In this paper we present a new simulator to investigate consensus within organisations, based on organisational
structure, team dynamics, and artefacts. We model agents who can interact with each other and with artefacts,
as well as the mathematical models that govern agent behaviour. We show that for a fixed problem size, there
is a maximum time within which all agents will reach consensus, independent of number of agents. We present
the results from simulating wide ranges of problem sizes and agent group sizes and report on two significant
statistics; the time to reach consensus and the effort to reach consensus. The time to reach consensus has
implications for project delivery timelines, and the effort relates to project economics.},
year = {2023},
journal = {the 13th International Conference on Simulation and Modelling Methodologies, Technologies and Applications (SimulTech).},
month = {12- 14 2023},
address = {Rome, Italy},
}
Vorster, J., & Leenen, L. (2023). Exploring the Effects of Subversive Agents on Consensus-Seeking Processes Using a Multi-Agent Simulator . In Proceedings of the 13th International Conference on Simulation and Modelling Methodologies, Technologies and Applications (SimulTech 2023). Portugal: SCITEPRESS - Science and Technology Publications, Lda.
In this paper we explore the effects of subversive agents on the effectiveness of consensus-seeking processes. A subversive agent can try and commit industrial espionage, or, could be a disgruntled employee. The ability of an organisation to effectively execute projects, especially projects within large and complex organisation such as those found in large corporates, governments and military institutions, depend on team members reaching consensus on everything from the project vision through various design phases and eventually project implementation and realisation. What could the effect be of agents trying to subvert such a process in a way that does not raise suspicions? Such an agent cannot openly sabotage the project, but rather tries to influence others in a way that increases the time it takes to reach consensus, thus delaying projects in subtle ways. Here we explore the effect such agents could have on the time and effort to reach consensus though the use of a stochastic Multi-Agent-Simulation (MAS).
@inbook{495,
author = {Johannes Vorster and Louise Leenen},
title = {Exploring the Effects of Subversive Agents on Consensus-Seeking Processes Using a Multi-Agent Simulator},
abstract = {In this paper we explore the effects of subversive agents on the effectiveness of consensus-seeking processes.
A subversive agent can try and commit industrial espionage, or, could be a disgruntled employee. The ability
of an organisation to effectively execute projects, especially projects within large and complex organisation
such as those found in large corporates, governments and military institutions, depend on team members
reaching consensus on everything from the project vision through various design phases and eventually project
implementation and realisation. What could the effect be of agents trying to subvert such a process in a way
that does not raise suspicions? Such an agent cannot openly sabotage the project, but rather tries to influence
others in a way that increases the time it takes to reach consensus, thus delaying projects in subtle ways. Here
we explore the effect such agents could have on the time and effort to reach consensus though the use of a
stochastic Multi-Agent-Simulation (MAS).},
year = {2023},
journal = {Proceedings of the 13th International Conference on Simulation and Modelling Methodologies, Technologies and Applications (SimulTech 2023)},
month = {07/2023},
publisher = {SCITEPRESS - Science and Technology Publications, Lda},
address = {Portugal},
}
Botha, J., Botha, D., & Leenen, L. (2023). An Analysis of Crypto Scams during the Covid-19 Pandemic: 2020-2022. In Proceedings of the 18th International Conference on Cyber Warfare and Security (ICCWS). Maryland USA, 9-10 March 2023. Academic Publishers.
Blockchain and cryptocurrency adoption has increased significantly since the start of the Covid-19 pandemic. This adoption rate has overtaken the Internet adoption rate in the 90s and early 2000s, but as a result, the instances of crypto scams have also increased. The types of crypto scams reported are typically giveaway scams, rug pulls, phishing scams, impersonation scams, Ponzi schemes as well as pump and dumps. The US Federal Trade Commission (FTC) reported that in May 2021 the number of crypto scams were twelve times higher than in 2020, and the total loss increased by almost 1000%. The FTC also reported that Americans have lost more than $80 million due to cryptocurrency investment scams from October 2019 to October 2020, with victims between the ages of 20 and 39 represented 44% of the reported cases. Social Media has become the go-to place for scammers where attackers hack pre-existing profiles and ask targets’ contacts for payments in cryptocurrency. In 2020, both Joe Biden and Bill Gates’ Twitter accounts were hacked where the hacker posted tweets promising that for all payments sent to a specified address, double the amount will be returned, and this case of fraud was responsible for $100,000 in losses. A similar scheme using Elon Musk’s Twitter account resulted in losses of nearly $2 million. This paper analyses the most significant blockchain and cryptocurrency scams since the start of the Covid-19 pandemic, with the aim of raising awareness and contributing to protection against attacks. Even though the blockchain is a revolutionary technology with numerous benefits, it also poses an international crisis that cannot be ignored.
@inbook{494,
author = {Johnny Botha and D.P. Botha and Louise Leenen},
title = {An Analysis of Crypto Scams during the Covid-19 Pandemic: 2020-2022},
abstract = {Blockchain and cryptocurrency adoption has increased significantly since the start of the Covid-19 pandemic. This adoption rate has overtaken the Internet adoption rate in the 90s and early 2000s, but as a result, the instances of crypto scams have also increased. The types of crypto scams reported are typically giveaway scams, rug pulls, phishing scams, impersonation scams, Ponzi schemes as well as pump and dumps. The US Federal Trade Commission (FTC) reported that in May 2021 the number of crypto scams were twelve times higher than in 2020, and the total loss increased by almost 1000%. The FTC also reported that Americans have lost more than $80 million due to cryptocurrency investment scams from October 2019 to October 2020, with victims between the ages of 20 and 39 represented 44% of the reported cases. Social Media has become the go-to place for scammers where attackers hack pre-existing profiles and ask targets’ contacts for payments in cryptocurrency. In 2020, both Joe Biden and Bill Gates’ Twitter accounts were hacked where the hacker posted tweets promising that for all payments sent to a specified address, double the amount will be returned, and this case of fraud was responsible for $100,000 in losses. A similar scheme using Elon Musk’s Twitter account resulted in losses of nearly $2 million. This paper analyses the most significant blockchain and cryptocurrency scams since the start of the Covid-19 pandemic, with the aim of raising awareness and contributing to protection against attacks. Even though the blockchain is a revolutionary technology with numerous benefits, it also poses an international crisis that cannot be ignored.},
year = {2023},
journal = {Proceedings of the 18th International Conference on Cyber Warfare and Security (ICCWS). Maryland USA, 9-10 March 2023},
month = {2023},
publisher = {Academic Publishers},
}
Jafta, Y., Leenen, L., & Meyer, T. (2023). Investigating Ontology-based Data Access with GitHub. In Lecture Notes in Computer Science 13870 (Proceedings of the 20th Extended Semantic Web Conference) (Vol. 13870). Springer.
Data analysis-based decision-making is performed daily by domain experts. As data grows, getting access to relevant data becomes a challenge. In an approach known as Ontology-based data access (OBDA), AQ1 ontologies are advocated as a suitable formal tool to address complex data access. This technique combines a domain ontology with a data source by using a declarative mapping specification to enable data access using a domain vocabulary.We investigate this approach by studying the theoretical background; conducting a literature review on the implementation of OBDA in production systems; implementing OBDA on a relational dataset using an OBDA tool and; providing results and analysis of query answering.We selected Ontop (https://ontop-vkg.org) to illustrate how this technique enhances the data usage of the GitHub community. AQ2 Ontop is an open-source OBDA tool applied in the domain of relational databases. The implementation consists of the GHTorrent dataset and an extended SemanGit ontology. We perform a set of queries to highlight a subset of the features of this data access approach. The results look positive and can assist various use cases related to GitHub data with a semantic approach. OBDA does provide benefits in practice, such as querying in domain vocabulary and making use of reasoning over the axioms in the ontology. However, the practical impediments we observe are in the “manual” development of a domain ontology and the creation of a mapping specification which requires deep knowledge of a domain and the data. Also, implementing OBDA within the practical context of an information system requires careful consideration for a suitable user interface to facilitate the query construction from ontology vocabulary. Finally, we conclude with a summary of the paper and direction for future research.
@inbook{493,
author = {Yahlieel Jafta and Louise Leenen and Thomas Meyer},
title = {Investigating Ontology-based Data Access with GitHub},
abstract = {Data analysis-based decision-making is performed daily by
domain experts. As data grows, getting access to relevant data becomes a
challenge. In an approach known as Ontology-based data access (OBDA), AQ1
ontologies are advocated as a suitable formal tool to address complex
data access. This technique combines a domain ontology with a data
source by using a declarative mapping specification to enable data access
using a domain vocabulary.We investigate this approach by studying the
theoretical background; conducting a literature review on the implementation
of OBDA in production systems; implementing OBDA on a relational
dataset using an OBDA tool and; providing results and analysis of
query answering.We selected Ontop (https://ontop-vkg.org) to illustrate
how this technique enhances the data usage of the GitHub community. AQ2
Ontop is an open-source OBDA tool applied in the domain of relational
databases. The implementation consists of the GHTorrent dataset and
an extended SemanGit ontology. We perform a set of queries to highlight
a subset of the features of this data access approach. The results look
positive and can assist various use cases related to GitHub data with
a semantic approach. OBDA does provide benefits in practice, such as
querying in domain vocabulary and making use of reasoning over the
axioms in the ontology. However, the practical impediments we observe
are in the “manual” development of a domain ontology and the creation
of a mapping specification which requires deep knowledge of a domain
and the data. Also, implementing OBDA within the practical context
of an information system requires careful consideration for a suitable
user interface to facilitate the query construction from ontology vocabulary.
Finally, we conclude with a summary of the paper and direction
for future research.},
year = {2023},
journal = {Lecture Notes in Computer Science 13870 (Proceedings of the 20th Extended Semantic Web Conference)},
volume = {13870},
month = {2023},
publisher = {Springer},
}
2022
Borchjes, L., Nyirenda, C., & Leenen, L. (2022). Model-Free Deep Reinforcement Learning in Software-Defined Networks. In Southern Africa Telecommunication Networks and Applications Conference (SATNAC 2022). South Africa. Retrieved from https://arxiv.org/abs/2209.01490
This paper compares two deep reinforcement learning approaches for cyber security in software defined networking. Neural Episodic Control to Deep Q-Network has been implemented and compared with that of Double Deep Q-Networks. The two algorithms are implemented in a format similar to that of a zero-sum game. A two-tailed T-test analysis is done on the two game results containing the amount of turns taken for the defender to win. Another comparison is done on the game scores of the agents in the respective games. The analysis is done to determine which algorithm is the best in game performer and whether there is a significant difference between them, demonstrating if one would have greater preference over the other. It was found that there is no significant statistical difference between the two approaches.
@{556,
author = {Luke Borchjes and Clement Nyirenda and Louise Leenen},
title = {Model-Free Deep Reinforcement Learning in Software-Defined Networks},
abstract = {This paper compares two deep reinforcement learning approaches for cyber security in software defined networking. Neural Episodic Control to Deep Q-Network has been implemented and compared with that of Double Deep Q-Networks. The two algorithms are implemented in a format similar to that of a zero-sum game. A two-tailed T-test analysis is done on the two game results containing the amount of turns taken for the defender to win. Another comparison is done on the game scores of the agents in the respective games. The analysis is done to determine which algorithm is the best in game performer and whether there is a significant difference between them, demonstrating if one would have greater preference over the other. It was found that there is no significant statistical difference between the two approaches.},
year = {2022},
journal = {Southern Africa Telecommunication Networks and Applications Conference (SATNAC 2022)},
month = {28-30 August 2022},
address = {South Africa},
url = {https://arxiv.org/abs/2209.01490},
}


