Primary tabs
2022
van Vuuren, J. J., Leenen, L., & van Vuuren, A.-M. J. (2022). Don’t be Caught Unaware: A Ransomware Primer with a Specific Focus on Africa. In Human Choice and Digital by Default: Autonomy vs Digital Determination (HCC 2022). IFIP Advances in Information and Communication Technology (Vol. 656). Springer, Cham. http://doi.org/10.1007/978-3-031-15688-5_11
Ransomware attacks have become the fastest growing and most serious type of cybercrime. A ransomware attack does not only capture victims' data, but also prevents victims from accessing their own data until a ransom has been paid. The prevention of and recovery from a ransomware attack have become a major concern for governments and organizations. This paper presents guidelines for institutions to secure their systems from ransomware attacks and to put steps in place for recovery if their systems have been attacked. The human is often the weak link in allowing an intrusion into a network. African countries are at even greater risk because their populations are often not sufficiently trained nor aware of cybersecurity risks.
@{554,
author = {Joey van Vuuren and Louise Leenen and Anna-Marie van Vuuren},
title = {Don't be Caught Unaware: A Ransomware Primer with a Specific Focus on Africa},
abstract = {Ransomware attacks have become the fastest growing and most serious type of cybercrime. A ransomware attack does not only capture victims' data, but also prevents victims from accessing their own data until a ransom has been paid. The prevention of and recovery from a ransomware attack have become a major concern for governments and organizations. This paper presents guidelines for institutions to secure their systems from ransomware attacks and to put steps in place for recovery if their systems have been attacked. The human is often the weak link in allowing an intrusion into a network. African countries are at even greater risk because their populations are often not sufficiently trained nor aware of cybersecurity risks.},
year = {2022},
journal = {Human Choice and Digital by Default: Autonomy vs Digital Determination (HCC 2022). IFIP Advances in Information and Communication Technology},
volume = {656},
pages = {115-131},
month = {2022},
publisher = {Springer, Cham},
doi = {10.1007/978-3-031-15688-5_11},
}
Kondlo, A., Leenen, L., & van Vuuren, J. J. (2022). An Ontological Model for a National Cyber-Attack Response in South Africa. In Proceedings of the 21st European Conference on Cyber Warfare and Security (ECCWS 2022) (Vol. 21). Chester, United Kingdom: Academic Conferences International. http://doi.org/10.34190/eccws.21.1.213
South Africa is increasingly targeted by cyber criminals and is often ranked under the top five countries suffering the most cyber-attacks. In an initiative to counter these attacks, the South African government has initiated various measures such as a National Cybersecurity Policy Framework Policy (NCPF) and a Cybercrimes Act. However, the structures and policies that follow from these measures have not been fully implemented yet. Although the government published the NCPF in 2015 and enacted the Cybercrimes Act in May 2021, there is still a gap in terms of interoperability and shared understanding within the environment. In addition, numerous new structures have been established and others are still being planned. One example of a new structure is the Cybersecurity Hub, the national CSIRT, which is mandated to co-ordinate attack information and provide support for cyber incidents. In addition, the Hub must also implement a national Cybersecurity Awareness program. This paper presents a model for the Cybersecurity Hub in the event of a cyber incident in South Africa. The model is based on different attack scenarios and depicts the complex interoperability problem of the various roles, responsibilities, and interactions of role players when there is a cyber incident. One of the scenarios is an attack on critical infrastructure. The model is a prototype of a semantic knowledge base (an ontology) that will help with planning and decision making. Core queries that should be answered concern the critical role players during and after a cyber event; the communication activities that have to take place; and the response actions and the skills required to handle the event.
@{553,
author = {Aphile Kondlo and Louise Leenen and Joey van Vuuren},
title = {An Ontological Model for a National Cyber-Attack Response in South Africa},
abstract = {South Africa is increasingly targeted by cyber criminals and is often ranked under the top five countries suffering the most cyber-attacks. In an initiative to counter these attacks, the South African government has initiated various measures such as a National Cybersecurity Policy Framework Policy (NCPF) and a Cybercrimes Act. However, the structures and policies that follow from these measures have not been fully implemented yet. Although the government published the NCPF in 2015 and enacted the Cybercrimes Act in May 2021, there is still a gap in terms of interoperability and shared understanding within the environment. In addition, numerous new structures have been established and others are still being planned. One example of a new structure is the Cybersecurity Hub, the national CSIRT, which is mandated to co-ordinate attack information and provide support for cyber incidents. In addition, the Hub must also implement a national Cybersecurity Awareness program. This paper presents a model for the Cybersecurity Hub in the event of a cyber incident in South Africa. The model is based on different attack scenarios and depicts the complex interoperability problem of the various roles, responsibilities, and interactions of role players when there is a cyber incident. One of the scenarios is an attack on critical infrastructure. The model is a prototype of a semantic knowledge base (an ontology) that will help with planning and decision making. Core queries that should be answered concern the critical role players during and after a cyber event; the communication activities that have to take place; and the response actions and the skills required to handle the event.},
year = {2022},
journal = {Proceedings of the 21st European Conference on Cyber Warfare and Security (ECCWS 2022)},
volume = {21},
pages = {130-139},
month = {24-25 June 2022},
issue = {1},
publisher = {Academic Conferences International},
address = {Chester, United Kingdom},
doi = {10.34190/eccws.21.1.213},
}
2021
Leenen, L., Ramluckan, T., & van Niekerk, B. (2021). Impact of AI Regulations on Cybersecurity Practitioners. In Proceedings of the 20th European Conference on Cyber Warfare and Security (ECCWS 2021) (Vol. 20). Chester, United Kingdom: Academic Conferences International.
@{558,
author = {Louise Leenen and Trishana Ramluckan and Brett van Niekerk},
title = {Impact of AI Regulations on Cybersecurity Practitioners},
abstract = {},
year = {2021},
journal = {Proceedings of the 20th European Conference on Cyber Warfare and Security (ECCWS 2021)},
volume = {20},
month = {24-25 June 2021},
publisher = {Academic Conferences International},
address = {Chester, United Kingdom},
}
Mbabe, W., Ajayi, O., Bagula, A., Leenen, L., & Schoeman, N. (2021). A Workflow System for Managing Ethical Clearance in Research Work. In 2021 IST-Africa Conference (IST-Africa). IEEE.
Ethical clearances are mandatory for most research work involving or impacting humans, animals or the environment. The approvals ensure that research is conducted in an acceptable manner, do not affect other people, animals or the environment negatively and is done within expected boundaries. Though important, it takes a long time to obtain Ethical Clearances approvals; inevitably slowing down research work(s), demoralizing researcher(s) and rendering the research obsolete before commencement. Major causes of delay in Ethical Clearance approval processes, especially in Universities, have been attributed to the manual paper-based approach in use and the lack of effective tracking and feedback processes. In a bid to address these issues and speed up Ethical Clearance approvals, this work proposes an Ethical Clearance workflow system. The main functions of the system were developed, tested by stakeholders and was found acceptable and useful.
@{555,
author = {Wanga Mbabe and Olasupo Ajayi and Antoine Bagula and Louise Leenen and Natasha Schoeman},
title = {A Workflow System for Managing Ethical Clearance in Research Work},
abstract = {Ethical clearances are mandatory for most research work involving or impacting humans, animals or the environment. The approvals ensure that research is conducted in an acceptable manner, do not affect other people, animals or the environment negatively and is done within expected boundaries. Though important, it takes a long time to obtain Ethical Clearances approvals; inevitably slowing down research work(s), demoralizing researcher(s) and rendering the research obsolete before commencement. Major causes of delay in Ethical Clearance approval processes, especially in Universities, have been attributed to the manual paper-based approach in use and the lack of effective tracking and feedback processes. In a bid to address these issues and speed up Ethical Clearance approvals, this work proposes an Ethical Clearance workflow system. The main functions of the system were developed, tested by stakeholders and was found acceptable and useful.},
year = {2021},
journal = {2021 IST-Africa Conference (IST-Africa)},
pages = {1-9},
month = {10-14 May 2021},
publisher = {IEEE},
}
van Heerden, R., Leenen, L., & Irwin, B. (2021). Description of a Network Attack Ontology Presented Formally. In Artificial Intelligence for Cyber Security: Methods, Issues and Possible Horizons or Opportunities (1st ed., Vol. 1–972, p. X, 467). Springer, Cham. http://doi.org/https://doi.org/10.1007/978-3-030-72236-4_14
The identification of network attacks in real-time is becoming increasingly important. Most Artificial Intelligence (AI) applications use machine learning to do the classification of attack types but the advantage of an ontological approach is that automated reasoning is the underpinning theory rather than automated learning. Automated reasoners allow automated classification and this powerful feature is the basis for the developing of an early warning system for active network attacks. In this paper, the authors describe how to employ Semantic Technologies by building an ontology to identify network attack types in order to support the automated classification of current network attacks by recognising relevant properties which are then mapped to relevant attack scenarios depicted in the ontology. The classes and relationships of the ontology are described formally and implemented in Protégé, an ontology editor. The Attack Scenario class, a core class of the ontology, represents types of network attacks, for example, a Denial of Service attack. The ontology is evaluated by showing three examples of real attacks that are correctly classified by the presented ontology.
@inbook{527,
author = {Renier van Heerden and Louise Leenen and Barry Irwin},
title = {Description of a Network Attack Ontology Presented Formally},
abstract = {The identification of network attacks in real-time is becoming increasingly important. Most Artificial Intelligence (AI) applications use machine learning to do the classification of attack types but the advantage of an ontological approach is that automated reasoning is the underpinning theory rather than automated learning. Automated reasoners allow automated classification and this powerful feature is the basis for the developing of an early warning system for active network attacks. In this paper, the authors describe how to employ Semantic Technologies by building an ontology to identify network attack types in order to support the automated classification of current network attacks by recognising relevant properties which are then mapped to relevant attack scenarios depicted in the ontology. The classes and relationships of the ontology are described formally and implemented in Protégé, an ontology editor. The Attack Scenario class, a core class of the ontology, represents types of network attacks, for example, a Denial of Service attack. The ontology is evaluated by showing three examples of real attacks that are correctly classified by the presented ontology.},
year = {2021},
journal = {Artificial Intelligence for Cyber Security: Methods, Issues and Possible Horizons or Opportunities},
edition = {1},
pages = {343–368},
month = {01 June 2021},
publisher = {Springer, Cham},
isbn = {978-3-030-72236-4},
doi = {https://doi.org/10.1007/978-3-030-72236-4_14},
}
2020
Leenen, L., van Vuuren, J. J., & van Vuuren, A.-M. J. (2020). Cybersecurity and Cybercrime Combatting Culture for African Police Services. In Proceedings of the 14th IFIP Human Choice and Computers Conference (HCC 2020).
@{560,
author = {Louise Leenen and Joey van Vuuren and Anna-Marie van Vuuren},
title = {Cybersecurity and Cybercrime Combatting Culture for African Police Services},
abstract = {},
year = {2020},
journal = {Proceedings of the 14th IFIP Human Choice and Computers Conference (HCC 2020)},
month = {2020},
}
Ajayi, O., Odun-Ayo, I., & Leenen, L. (2020). On the Performance of Off-Peak Workload Allocation Models in Cloud Computing. In Proceedings of the South African Conference for Artificial Intelligence Research (SACAIR 2020). South Africa.
@{559,
author = {Olasupo Ajayi and Isaac Odun-Ayo and Louise Leenen},
title = {On the Performance of Off-Peak Workload Allocation Models in Cloud Computing},
abstract = {},
year = {2020},
journal = {Proceedings of the South African Conference for Artificial Intelligence Research (SACAIR 2020)},
month = {2020},
address = {South Africa},
}
Roodt, J., Leenen, L., & van Vuuren, J. (2020). Modelling Of The Complex Societal Problem Of Establishing A National Energy Sufficiency Competence . In 23rd International Conference on Information Fusion.
Complex societal problems require a multi-disciplinary and multi-method approach to develop models that can support the development of solutions. General morphological analysis is a qualitative method to extract information from experts through facilitation and the use of customized software. Ontologies provide semantic representation of knowledge bases together with automated reasoning capabilities. These two approaches, combined with the use of concept maps, provide an integrated approach which can be used to understand complex and ill-structured problem domains and to aid in business modelling, strategy and scenario development and finally, decision-making. The resulting models are subjective constructs reflecting the knowledge and understanding of the analysts. Subsequent synthesis of new understanding and decisions rely on the robust validation and verification of the underlying logic and assumptions of the conceptual models. Morphological Analysis and ontological constructs are applied in terms of an integrated Morphological Ontology Design Engineering methodology (MODE), which is based on Design Science. The paper is developed around the opportunity of scoping the applied research competence required to support a nation’s progress toward energy sufficiency. This paper presents a complex fused model for national energy sufficiency in New Zealand. The approach can be used to address other ill- structured complex societal problems.
@{375,
author = {JH Roodt and Louise Leenen and Jansen van Vuuren},
title = {Modelling Of The Complex Societal Problem Of Establishing A National Energy Sufficiency Competence},
abstract = {Complex societal problems require a multi-disciplinary and multi-method approach to develop models that can support the development of solutions. General morphological analysis is a qualitative method to extract information from experts through facilitation and the use of customized software. Ontologies provide semantic representation of knowledge bases together with automated reasoning capabilities. These two approaches, combined with the use of concept maps, provide an integrated approach which can be used to understand complex and ill-structured problem domains and to aid in business modelling, strategy and scenario development and finally, decision-making. The resulting models are subjective constructs reflecting the knowledge and understanding of the analysts. Subsequent synthesis of new understanding and decisions rely on the robust validation and verification of the underlying logic and assumptions of the conceptual models.
Morphological Analysis and ontological constructs are applied in terms of an integrated Morphological Ontology Design Engineering methodology (MODE), which is based on Design Science. The paper is developed around the opportunity of scoping the applied research competence required to support a nation’s progress toward energy sufficiency. This paper presents a complex fused model for national energy sufficiency in New Zealand. The approach can be used to address other ill- structured complex societal problems.},
year = {2020},
journal = {23rd International Conference on Information Fusion},
pages = {880 - 887},
month = {06/07-09/07},
isbn = {978-0-578-64709-8},
}
Jafta, Y., Leenen, L., & Chan, P. (2020). An Ontology for the South African Protection of Personal Information Act. In The 19th European Conference on Cyber Warfare and Security. UK: Academic Conferences and Publishing International Limited.
The protection and management of data, and especially personal information, is becoming an issue of critical importance in both the business environment and in general society. Various institutions have justifiable reasons to gather the personal information of individuals but they are required to comply with any legislation involving the processing of such data. Organisations thus face legal and other repercussions should personal information be breached or treated negligently. Most countries have adopted privacy and data protection laws or are in the process of enacting such laws. In South Africa, the Protection of Privacy Information Act (POPIA) was formally adopted in 2013 but it is yet to be implemented. When the implementation of the Act is announced, role players (responsible parties and data subjects) affected by POPIA will have a grace period of a year to become compliant and/or understand how the Act will affect them. One example of a mandate that follows from POPIA is data breach notification. This paper presents the development of a prototype ontology on POPIA to promote transparency and education of affected data subjects and organisations including government departments. The ontology provides a semantic representation of a knowledge base for the regulations in the POPIA and how it affects these role players. The POPIA is closely aligned with the European Union’s General Data Protection Regulation (GDPR), and the POPIA ontology is inspired by similar ontologies developed for the GDPR.
@{374,
author = {Y Jafta and Louise Leenen and P Chan},
title = {An Ontology for the South African Protection of Personal Information Act},
abstract = {The protection and management of data, and especially personal information, is becoming an issue of critical importance in both the business environment and in general society. Various institutions have justifiable reasons to gather the personal information of individuals but they are required to comply with any legislation involving the processing of such data. Organisations thus face legal and other repercussions should personal information be breached or treated negligently. Most countries have adopted privacy and data protection laws or are in the process of enacting such laws. In South Africa, the Protection of Privacy Information Act (POPIA) was formally adopted in 2013 but it is yet to be implemented. When the implementation of the Act is announced, role players (responsible parties and data subjects) affected by POPIA will have a grace period of a year to become compliant and/or understand how the Act will affect them. One example of a mandate that follows from POPIA is data breach notification. This paper presents the development of a prototype ontology on POPIA to promote transparency and education of affected data subjects and organisations including government departments. The ontology provides a semantic representation of a knowledge base for the regulations in the POPIA and how it affects these role players. The POPIA is closely aligned with the European Union’s General Data Protection Regulation (GDPR), and the POPIA ontology is inspired by similar ontologies developed for the GDPR.},
year = {2020},
journal = {The 19th European Conference on Cyber Warfare and Security},
pages = {158 - 176},
month = {25/06 - 26/06},
publisher = {Academic Conferences and Publishing International Limited},
address = {UK},
isbn = {978-1-912764-61-7},
}
van Vuuren, J., & Leenen, L. (2020). Proving It Is the Data That Is Biased, Not the Algorithm Through a Recent South African Online Case Study. Journal of Information Warfare, 19(3).
In the recent past, some Internet users questioned the reliability of online news, but not necessarily the role of search engines in programming public discourse. In 2018, South African Twitter users accused Google of peddling misinformation when Google Image searches for the phrase “squatter camps in South Africa” displayed images of white squatter camps. Many ana-lysts blamed Google’s algorithm for displaying bias. In this article, the authors use this example in comparing the findings of six different search engines to counter this argument. Search engines that are diverse in their scope and origin are used to prove that is it not the algorithm, but rather the data that is biased.
@article{373,
author = {Jansen van Vuuren and Louise Leenen},
title = {Proving It Is the Data That Is Biased, Not the Algorithm Through a Recent South African Online Case Study},
abstract = {In the recent past, some Internet users questioned the reliability of online news, but not necessarily the role of search engines in programming public discourse. In 2018, South African Twitter users accused Google of peddling misinformation when Google Image searches for the phrase “squatter camps in South Africa” displayed images of white squatter camps. Many ana-lysts blamed Google’s algorithm for displaying bias. In this article, the authors use this example in comparing the findings of six different search engines to counter this argument. Search engines that are diverse in their scope and origin are used to prove that is it not the algorithm, but rather the data that is biased.},
year = {2020},
journal = {Journal of Information Warfare},
volume = {19},
pages = {118-129},
issue = {3},
publisher = {Peregrine Technical Solutions},
address = {Virginia, USA},
isbn = {1445-3312},
}
van Vuuren, J., Leenen, L., & Pieterse, P. (2020). Development and Implementation of Cybercrime Strategies in Africa with Specific Reference to South Africa. Journal of Information Warfare, 19(3).
Cybercrime is increasing at a rate few individuals would have predicted. IBM estimated in 2016 that, in 2019, the cost of cybercrime would reach $2 trillion, a threefold increase from the 2015 estimate of $500 billion. The growth of the Internet and the rapid development of technology provide enormous economic and social benefits but at the same time provide platforms for cybercriminals to exploit. Organised crime is using more sophisticated techniques, which require highly skilled and specialised law enforcement responses. One example is the use of cryptocurrencies, which makes it easier for cybercriminals to hide their proceeds. Regulatory measures often lag behind. In this paper, the authors give an overview of the growing threat of cybercrime with a specific focus on high levels of cybercrime in Africa. The focus then turns to the development of national cybercrime strategies and implementation. Results from literature and the authors’ analyses of two cyber indices to measure the capabilities and capacities of countries are combined to present a framework for the development of a cybercrime strategy, and in particular, a strategy customised for African countries.
@article{372,
author = {Jansen van Vuuren and Louise Leenen and P Pieterse},
title = {Development and Implementation of Cybercrime Strategies in Africa with Specific Reference to South Africa},
abstract = {Cybercrime is increasing at a rate few individuals would have predicted. IBM estimated in 2016 that, in 2019, the cost of cybercrime would reach $2 trillion, a threefold increase from the 2015 estimate of $500 billion. The growth of the Internet and the rapid development of technology provide enormous economic and social benefits but at the same time provide platforms for cybercriminals to exploit. Organised crime is using more sophisticated techniques, which require highly skilled and specialised law enforcement responses. One example is the use of cryptocurrencies, which makes it easier for cybercriminals to hide their proceeds. Regulatory measures often lag behind.
In this paper, the authors give an overview of the growing threat of cybercrime with a specific focus on high levels of cybercrime in Africa. The focus then turns to the development of national cybercrime strategies and implementation. Results from literature and the authors’ analyses of two cyber indices to measure the capabilities and capacities of countries are combined to present a framework for the development of a cybercrime strategy, and in particular, a strategy customised for African countries.},
year = {2020},
journal = {Journal of Information Warfare},
volume = {19},
pages = {83 - 101},
issue = {3},
publisher = {Peregrine Technical Solutions},
address = {Virginia, USA},
isbn = {1445-3312},
}
Ramluckan, T., van Niekerk, B., & Leenen, L. (2020). Cybersecurity and Information Warfare Research in South Africa: Challenges and Proposed Solutions. Journal of Information Warfare, 19(1).
Cybersecurity is often incorrectly assumed to be a purely technical field; however, there are numerous multidisciplinary aspects, such as, for example, human factors, legal, and governance issues. The broad scope, combined with other historical or bureaucratic factors, can provide challenges to researchers and students where appropriate methodologies do not necessarily conform to traditional disciplinary norms; prejudice against research approaches can occur as a result of ‘old school thought’. This paper aims to investigate the South African national and institutional perspectives for higher education and research, identify challenges, and propose solutions to facilitate multidisciplinary research into cybersecurity and Information Warfare (IW) in South Africa.
@article{371,
author = {T Ramluckan and B van Niekerk and Louise Leenen},
title = {Cybersecurity and Information Warfare Research in South Africa: Challenges and Proposed Solutions},
abstract = {Cybersecurity is often incorrectly assumed to be a purely technical field; however, there are numerous multidisciplinary aspects, such as, for example, human factors, legal, and governance issues. The broad scope, combined with other historical or bureaucratic factors, can provide challenges to researchers and students where appropriate methodologies do not necessarily conform to traditional disciplinary norms; prejudice against research approaches can occur as a result of ‘old school thought’. This paper aims to investigate the South African national and institutional perspectives for higher education and research, identify challenges, and propose solutions to facilitate multidisciplinary research into cybersecurity and Information Warfare (IW) in South Africa.},
year = {2020},
journal = {Journal of Information Warfare},
volume = {19},
pages = {80-95},
issue = {1},
publisher = {Peregrine Technical Solutions},
address = {Virginia, USA},
isbn = {ISSN 1445-3312},
}
2019
Botha, J., Wout, van’t, & Leenen, L. (2019). A Comparison of Chat Applications in Terms of Security and Privacy. In Proceedings of the 18th European Conference on Cyber Warfare and Security (ECCWS 2019). Coimbra, Portugal: Academic Conferences International.
@{562,
author = {Johnny Botha and van't Wout and Louise Leenen},
title = {A Comparison of Chat Applications in Terms of Security and Privacy},
abstract = {},
year = {2019},
journal = {Proceedings of the 18th European Conference on Cyber Warfare and Security (ECCWS 2019)},
month = {4-5 July 2019},
publisher = {Academic Conferences International},
address = {Coimbra, Portugal},
}
van Vuuren, J. J., & Leenen, L. (2019). Building Blocks and Measurement of National Cyberpower. In Developments in Information Security and Cybernetic Wars. Hershey, Pennsylvania, United States of America: IGI Global.
@inbook{561,
author = {Joey van Vuuren and Louise Leenen},
title = {Building Blocks and Measurement of National Cyberpower},
abstract = {},
year = {2019},
journal = {Developments in Information Security and Cybernetic Wars},
publisher = {IGI Global},
address = {Hershey, Pennsylvania, United States of America},
}
2018
van Vuuren, J. J., & Leenen, L. (2018). A Model for Measuring Perceived Cyberpower. In Proceedings of the 13th International Conference on Cyber Warfare and Security (ICCWS 2018). Washington D.C., United States of America: Academic Conferences International.
@{567,
author = {Joey van Vuuren and Louise Leenen},
title = {A Model for Measuring Perceived Cyberpower},
abstract = {},
year = {2018},
journal = {Proceedings of the 13th International Conference on Cyber Warfare and Security (ICCWS 2018)},
month = {March 2018},
publisher = {Academic Conferences International},
address = {Washington D.C., United States of America},
}


