Research Publications
2026
This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors (Botha, Singh, & Leenen, 2025a), through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence. The current study focuses on a new, active case involving an elderly South African (SA) woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme. The case is presently under investigation by the Directorate for Priority Crime Investigation (DPCI), a specialised unit of the South African Police Services (SAPS) tasked with addressing serious economic crimes and commonly referred to as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness in real-world conditions. The analysis further reflects on legal, technical, and procedural challenges encountered during the investigation, offering critical insights for law enforcement, regulators, and cybersecurity professionals. It also highlights broader systemic vulnerabilities that facilitate such scams, particularly among elderly and non-technical populations. The findings underscore the need for enhanced public education, improved regulatory oversight, and international cooperation in combating cryptocurrency fraud. Ultimately, the paper contributes to the evolving discourse on financial crime in the digital age and aims to support the development of more secure and accountable crypto-investment environments.
@{537,
author = {Johnny Botha and Kreaan Singh and Louise Leenen},
title = {Evaluating an Investigative Process for Cryptocurrency-Related Crimes},
abstract = {This paper evaluates a previously proposed investigative process for cryptocurrency-related crimes, originally introduced by the authors (Botha, Singh, & Leenen, 2025a), through the application of a real-world case study. The process covers crime reporting and case registration, on-chain analysis, off-chain analysis, and the transformation of investigative intelligence into court-admissible evidence. The current study focuses on a new, active case involving an elderly South African (SA) woman who was defrauded of a substantial portion of her pension through a fraudulent investment scheme. The case is presently under investigation by the Directorate for Priority Crime Investigation (DPCI), a specialised unit of the South African Police Services (SAPS) tasked with addressing serious economic crimes and commonly referred to as the Hawks. By systematically applying the proposed investigative process to this case, the study assesses the framework's practical utility, adaptability, and effectiveness in real-world conditions. The analysis further reflects on legal, technical, and procedural challenges encountered during the investigation, offering critical insights for law enforcement, regulators, and cybersecurity professionals. It also highlights broader systemic vulnerabilities that facilitate such scams, particularly among elderly and non-technical populations. The findings underscore the need for enhanced public education, improved regulatory oversight, and international cooperation in combating cryptocurrency fraud. Ultimately, the paper contributes to the evolving discourse on financial crime in the digital age and aims to support the development of more secure and accountable crypto-investment environments.},
year = {2026},
journal = {Proceedings of the 21st International Conference on Cyber Warfare and Security (ICCWS 2026)},
volume = {21},
pages = {45-56},
month = {2026},
issue = {1},
publisher = {Academic Conferences International},
address = {North Carolina, United States of America},
doi = {10.34190/iccws.21.1.4538},
}
This paper presents a follow-up study to earlier research on cryptocurrency crime, again drawing on the case of an elderly woman defrauded by an online platform known as RSI-Platform. Whereas the initial study focused mainly on on-chain analysis within the blockchain environment, the present work shifts attention to off-chain approaches, applying open-source intelligence (OSINT) techniques to deepen investigations into crypto-related fraud. By systematically examining diverse input data, such as names, phone numbers, email addresses, and URLs, this study conducts link analysis and aims to build detailed profiles of potential suspects, thereby advancing understanding of the strategies and methods used in cryptocurrency scams. The analysis aims not only to trace the scammers' digital footprints but also to reveal networks and connections to other fraudulent platforms that support these activities. Moreover, this research seeks to raise public awareness about the scale and operation of fake online investment schemes in the crypto sector. By exposing the vulnerabilities exploited by offenders and illustrating how OSINT can be used to detect and disrupt such scams, the paper adds to ongoing discussions on cybersecurity and consumer protection in the fast-changing field of digital finance. Additionally, the findings are intended to offer practical insights for law enforcement agencies, policymakers, and the wider public, encouraging a more informed and proactive response to the threats posed by crypto-related fraud.
@{536,
author = {Johnny Botha and Abraha Berkman and Louise Leenen},
title = {Leveraging Open-Source Intelligence to Combat Cryptocurrency Investment Scams},
abstract = {This paper presents a follow-up study to earlier research on cryptocurrency crime, again drawing on the case of an elderly woman defrauded by an online platform known as RSI-Platform. Whereas the initial study focused mainly on on-chain analysis within the blockchain environment, the present work shifts attention to off-chain approaches, applying open-source intelligence (OSINT) techniques to deepen investigations into crypto-related fraud. By systematically examining diverse input data, such as names, phone numbers, email addresses, and URLs, this study conducts link analysis and aims to build detailed profiles of potential suspects, thereby advancing understanding of the strategies and methods used in cryptocurrency scams. The analysis aims not only to trace the scammers' digital footprints but also to reveal networks and connections to other fraudulent platforms that support these activities. Moreover, this research seeks to raise public awareness about the scale and operation of fake online investment schemes in the crypto sector. By exposing the vulnerabilities exploited by offenders and illustrating how OSINT can be used to detect and disrupt such scams, the paper adds to ongoing discussions on cybersecurity and consumer protection in the fast-changing field of digital finance. Additionally, the findings are intended to offer practical insights for law enforcement agencies, policymakers, and the wider public, encouraging a more informed and proactive response to the threats posed by crypto-related fraud.},
year = {2026},
journal = {Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026)},
volume = {25},
pages = {96-106},
month = {June 2026},
issue = {1},
publisher = {Academic Conferences International},
address = {Nottingham, United Kingdom},
doi = {10.34190/eccws.25.1.4883},
}
Cryptocurrency exchanges act as critical intermediaries within the digital asset ecosystem, yet users currently rely on largely opaque, platform-defined trust scores to assess their reliability and risk. Existing industry frameworks, notably those produced by CoinGecko and CoinMarketCap, provide useful signals related to liquidity and volume integrity but suffer from limited transparency, fixed weighting schemes, and the absence of sentiment-based assessment. This paper presents HTREx (Hybrid Trust and Risk Evaluation framework for exchanges), a semi-automated, modular trust and risk assessment framework for cryptocurrency exchanges that addresses these limitations. The framework integrates five dimensions of exchange integrity: user sentiment, regulatory compliance, technical security, transparency, and incident history. Sentiment is quantified using transformer-based natural language processing applied to user-generated content from mobile application reviews and online forums. Compliance is assessed through structured extraction of regulatory and operational disclosures from Terms of Service documents using large language models. Security, transparency, and incident history are evaluated through a combination of publicly verifiable indicators, third-party assessments, and a recency-weighted incident scoring model. All components are normalised and aggregated into a composite score using user-adjustable weights, enabling personalised risk prioritisation while retaining a defensible default configuration for comparative analysis. The framework is demonstrated using four prominent exchanges, Kraken, Coinbase, Binance, and Uniswap, highlighting clear differences between centralised and decentralised platforms and illustrating how sentiment, compliance, and historical incidents materially influence overall trust assessments. The results suggest that transparent, extensible, and user-configurable scoring models can provide a more interpretable and context-sensitive evaluation of exchange risk than existing monolithic trust scores, with direct relevance for both retail and institutional participants.
@{535,
author = {Bongani Mawhayi and Johnny Botha and Louise Leenen},
title = {A Hybrid, Transparent Trust and Risk Assessment Framework for Cryptocurrency Exchanges},
abstract = {Cryptocurrency exchanges act as critical intermediaries within the digital asset ecosystem, yet users currently rely on largely opaque, platform-defined trust scores to assess their reliability and risk. Existing industry frameworks, notably those produced by CoinGecko and CoinMarketCap, provide useful signals related to liquidity and volume integrity but suffer from limited transparency, fixed weighting schemes, and the absence of sentiment-based assessment. This paper presents HTREx (Hybrid Trust and Risk Evaluation framework for exchanges), a semi-automated, modular trust and risk assessment framework for cryptocurrency exchanges that addresses these limitations. The framework integrates five dimensions of exchange integrity: user sentiment, regulatory compliance, technical security, transparency, and incident history. Sentiment is quantified using transformer-based natural language processing applied to user-generated content from mobile application reviews and online forums. Compliance is assessed through structured extraction of regulatory and operational disclosures from Terms of Service documents using large language models. Security, transparency, and incident history are evaluated through a combination of publicly verifiable indicators, third-party assessments, and a recency-weighted incident scoring model. All components are normalised and aggregated into a composite score using user-adjustable weights, enabling personalised risk prioritisation while retaining a defensible default configuration for comparative analysis. The framework is demonstrated using four prominent exchanges, Kraken, Coinbase, Binance, and Uniswap, highlighting clear differences between centralised and decentralised platforms and illustrating how sentiment, compliance, and historical incidents materially influence overall trust assessments. The results suggest that transparent, extensible, and user-configurable scoring models can provide a more interpretable and context-sensitive evaluation of exchange risk than existing monolithic trust scores, with direct relevance for both retail and institutional participants.},
year = {2026},
journal = {Proceedings of the 25th European Conference on Cyber Warfare and Security (ECCWS 2026)},
volume = {25},
month = {June 2026},
issue = {1},
publisher = {Academic Conferences International},
address = {Nottingham, United Kingdom},
doi = {10.34190/eccws.25.1.4840},
}
This paper models consensus formation processes using multi-agents simulations. The use of artefacts in the formation of consensus is investigated. This approach allows the study of complex team dynamics. We found that through the consensus process there are phases characterised by the efficiency of team meetings and the productivity of team members. We show that artefacts can play a significant role to improve the time to reach consensus. Furthermore, teams that use artefacts can significantly reduce the effects of bad team structure. Different team structures are investigated and characterized based on how well it supports the consensus formation process.
@inbook{534,
author = {Johannes Vorster and Louise Leenen},
title = {The effect of Artifacts on Consensus formation: An Agent-based Simulation Approach},
abstract = {This paper models consensus formation processes using multi-agents simulations. The use of artefacts in the formation of consensus is investigated. This approach allows the study of complex team dynamics. We found that through the consensus process there are phases characterised by the efficiency of team meetings and the productivity of team members. We show that artefacts can play a significant role to improve the time to reach consensus. Furthermore, teams that use artefacts can significantly reduce the effects of bad team structure. Different team structures are investigated and characterized based on how well it supports the consensus formation process.},
year = {2026},
journal = {Simulation and Modeling Methodologies, Technologies and Applications. SIMULTECH 2024. Lecture Notes in Networks and Systems},
volume = {1620},
pages = {114-136},
publisher = {Springer},
address = {Cham, Switzerland},
doi = {10.1007/978-3-032-04777-9_7},
}
2025
Many real-world decisions follow rules that hold in general but allow exceptions, such as "birds usually fly, unless they are penguins." Most interpretable classifiers struggle to capture this pattern, leading to explanations that feel less aligned with human reasoning. This paper introduces the Defeasible Horn Classifier with Exceptions (DHCE), a symbolic model that makes this reasoning structure explicit. Each rule combines a default with its linked exceptions, so predictions can be explained step by step without relying on post-hoc tools. DHCE is learned using Answer Set Programming, which searches for globally optimal rule sets while balancing accuracy and simplicity. The resulting models consist of ranked Horn rules that provide full traceability: users can see both why a decision applies and why it may be overridden. We evaluate DHCE on standard classification benchmarks and find that it matches or outperforms leading interpretable models, a performance level that prior work shows to be competitive with classical machine learning classifiers. By making prediction decisions inherently retractable, DHCE delivers accuracy alongside explanations that mirror how people reason, making it suited for domains where understanding why a rule no longer applies is as important as the prediction itself.
@{552,
author = {Ruvarashe Madzime and Tommie Meyer and Louise Leenen},
title = {An Override-aware Classifier for Transparent AI},
abstract = {Many real-world decisions follow rules that hold in general but allow exceptions, such as "birds usually fly, unless they are penguins." Most interpretable classifiers struggle to capture this pattern, leading to explanations that feel less aligned with human reasoning. This paper introduces the Defeasible Horn Classifier with Exceptions (DHCE), a symbolic model that makes this reasoning structure explicit. Each rule combines a default with its linked exceptions, so predictions can be explained step by step without relying on post-hoc tools. DHCE is learned using Answer Set Programming, which searches for globally optimal rule sets while balancing accuracy and simplicity. The resulting models consist of ranked Horn rules that provide full traceability: users can see both why a decision applies and why it may be overridden. We evaluate DHCE on standard classification benchmarks and find that it matches or outperforms leading interpretable models, a performance level that prior work shows to be competitive with classical machine learning classifiers. By making prediction decisions inherently retractable, DHCE delivers accuracy alongside explanations that mirror how people reason, making it suited for domains where understanding why a rule no longer applies is as important as the prediction itself.},
year = {2025},
journal = {Proceedings of the Southern African Conference for Artificial Intelligence Research (SACAIR 2025), Volume II},
volume = {II},
pages = {349-360},
month = {2025},
address = {Cape Town, South Africa},
url = {https://2025.sacair.org.za/online-proceedings/Papers/paper_17.pdf},
}
This study analyses the most prominent cryptocurrency scams from 2022 to 2024, highlighting certain trends and common manipulation tactics used by fraudsters during this period. The paper builds upon a previous study that examined the most prominent scams, during the COVID-19 pandemic, between 2020 and 2022, a period characterised by substantial market volatility and heightened investor interest. In contrast, the period from 2022 to 2024 was marked by a bear market, during which investor interest in cryptocurrency declined. Despite this downturn, several significant scams emerged, which are analysed. The findings reveal a significant reported financial loss, highlighting investors' vulnerabilities. The paper does a comparison analysis per year on the type of scams, monetary losses, the founding country of the scams, the number of users affected, and arrests made. By examining the financial impact of these scams, the study aims to provide insight into the scale and severity of fraud in the cryptocurrency market during this period. The paper highlights the dire need for enhanced public awareness and regulatory entities to combat the evolving landscape of cryptocurrency fraud. Lastly, the study aims to inform policymakers, industry stakeholders, and researchers about the pressing challenges in securing the cryptocurrency ecosystem.
@{544,
author = {Johnny Botha and Vilma Luoma-Aho and Louise Leenen},
title = {Top Crypto Scams in 2022-2024: Analysing Trends, Tactics, and Regulatory Responses},
abstract = {This study analyses the most prominent cryptocurrency scams from 2022 to 2024, highlighting certain trends and common manipulation tactics used by fraudsters during this period. The paper builds upon a previous study that examined the most prominent scams, during the COVID-19 pandemic, between 2020 and 2022, a period characterised by substantial market volatility and heightened investor interest. In contrast, the period from 2022 to 2024 was marked by a bear market, during which investor interest in cryptocurrency declined. Despite this downturn, several significant scams emerged, which are analysed. The findings reveal a significant reported financial loss, highlighting investors' vulnerabilities. The paper does a comparison analysis per year on the type of scams, monetary losses, the founding country of the scams, the number of users affected, and arrests made. By examining the financial impact of these scams, the study aims to provide insight into the scale and severity of fraud in the cryptocurrency market during this period. The paper highlights the dire need for enhanced public awareness and regulatory entities to combat the evolving landscape of cryptocurrency fraud. Lastly, the study aims to inform policymakers, industry stakeholders, and researchers about the pressing challenges in securing the cryptocurrency ecosystem.},
year = {2025},
journal = {2025 IST-Africa Conference (IST-Africa)},
pages = {1-9},
month = {28-30 May 2025},
publisher = {IEEE},
address = {Nairobi, Kenya},
doi = {10.23919/IST-Africa67297.2025.11060494},
}
In the rapidly evolving landscape of organizational structures and project management, achieving timely consensus among team members is crucial for maintaining agility and responsiveness. During the consensus formation process, team members has the choice of who to talk to in an attempt to consolidate views on a topic. In this paper we ask the question, to what extent do strategies for selecting team members affect the speed of consensus formation? Similarly, once two team members engage in conversations on a specific set of topics, the question we ask is, to what extent do different strategies for selecting the topics for discussion affect the time to reach consensus within multi-agent systems. By simulating various strategies, we identify methods that optimize consensus speed, specifically highlighting the benefits of prioritizing unaligned agents and addressing contentious topics early in the process. Our findings reveal that these strategies significantly enhance consensus efficiency, while approaches focusing on aligning with similar views tend to prolong the process. Additionally, we observe that the initial distribution of agent views, provided the standard deviation is constant, has negligible effects on consensus time, suggesting that diversity of opinion is more critical than specific distribution patterns. These insights offer practical implications for improving decision-making processes in organizational and project contexts.
@{543,
author = {Johannes Vorster and Louise Leenen},
title = {Optimizing Social Consensus: The Impact of Agent Selection and Topic Strategy on Time to Reach Agreement},
abstract = {In the rapidly evolving landscape of organizational structures and project management, achieving timely consensus among team members is crucial for maintaining agility and responsiveness. During the consensus formation process, team members has the choice of who to talk to in an attempt to consolidate views on a topic. In this paper we ask the question, to what extent do strategies for selecting team members affect the speed of consensus formation? Similarly, once two team members engage in conversations on a specific set of topics, the question we ask is, to what extent do different strategies for selecting the topics for discussion affect the time to reach consensus within multi-agent systems. By simulating various strategies, we identify methods that optimize consensus speed, specifically highlighting the benefits of prioritizing unaligned agents and addressing contentious topics early in the process. Our findings reveal that these strategies significantly enhance consensus efficiency, while approaches focusing on aligning with similar views tend to prolong the process. Additionally, we observe that the initial distribution of agent views, provided the standard deviation is constant, has negligible effects on consensus time, suggesting that diversity of opinion is more critical than specific distribution patterns. These insights offer practical implications for improving decision-making processes in organizational and project contexts.},
year = {2025},
journal = {Proceedings of the 15th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH},
volume = {1},
pages = {135-144},
month = {2025},
publisher = {SCITEPRESS - Science and Technology Publications},
address = {Spain},
doi = {10.5220/0013650900003970},
}
The increasing cybersecurity threats to higher education institutions in Africa necessitate risk management frameworks that are resilient and sensitive to regional needs. This paper applies Modified General Morphological Analysis (MGMA) to identify essential elements for an adaptable cybersecurity framework, focusing on the African higher education context. African institutions face many challenges, like limited funding, underdeveloped digital infrastructures, and rising cyberattacks. Our proposed MGMA is a structured methodology to examine key cybersecurity dimensions: governance, policy, technical controls, capacity building, and resource allocation. This approach allows for assessing complex interrelations among these elements, aimed at practical solutions suitable for African institutions. This study focuses on risk management approaches to address the specific vulnerabilities of African higher education institutions (HEIs), such as restricted budgets, inadequate cybersecurity teams, and increasing reliance on digital systems. The study promotes collaborative efforts by creating institutional networks, sharing resources, and enhancing cybersecurity expertise across Africa. The findings will guide decision-makers in aligning cybersecurity investments with strategic institutional goals, providing a framework for protecting critical educational assets, strengthening resilience, and advancing digital infrastructure development across African higher education.
@{542,
author = {Mafika Nkambule and Joey van Vuuren and Louise Leenen},
title = {Creating a Cybersecurity Culture Framework in Higher Education},
abstract = {The increasing cybersecurity threats to higher education institutions in Africa necessitate risk management frameworks that are resilient and sensitive to regional needs. This paper applies Modified General Morphological Analysis (MGMA) to identify essential elements for an adaptable cybersecurity framework, focusing on the African higher education context. African institutions face many challenges, like limited funding, underdeveloped digital infrastructures, and rising cyberattacks. Our proposed MGMA is a structured methodology to examine key cybersecurity dimensions: governance, policy, technical controls, capacity building, and resource allocation. This approach allows for assessing complex interrelations among these elements, aimed at practical solutions suitable for African institutions. This study focuses on risk management approaches to address the specific vulnerabilities of African higher education institutions (HEIs), such as restricted budgets, inadequate cybersecurity teams, and increasing reliance on digital systems. The study promotes collaborative efforts by creating institutional networks, sharing resources, and enhancing cybersecurity expertise across Africa. The findings will guide decision-makers in aligning cybersecurity investments with strategic institutional goals, providing a framework for protecting critical educational assets, strengthening resilience, and advancing digital infrastructure development across African higher education.},
year = {2025},
journal = {Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025)},
volume = {20},
pages = {304-312},
month = {28-29 March 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Virginia, United States of America},
doi = {10.34190/iccws.20.1.3268},
}
This paper introduces a novel Interest Rate Calculation Model for cyber security risk quantification, addressing the challenges of cyber security debt management. Unlike traditional qualitative risk assessments, this model applies financial principles to quantify risk impact dynamically, integrating seamlessly with industry frameworks. By framing cyber security risks in financial terms, the model enhances decision-making, promotes strategic resource allocation, and fosters stakeholder engagement. Through a structured methodology, it empowers organisations to assess, prioritise, and mitigate cyber security debt efficiently, ensuring long-term resilience in an evolving threat landscape.
@{541,
author = {Christo Coetzer and Louise Leenen},
title = {Quantifying Cyber Security Risk through Interest Rate Calculation in Debt Management},
abstract = {This paper introduces a novel Interest Rate Calculation Model for cyber security risk quantification, addressing the challenges of cyber security debt management. Unlike traditional qualitative risk assessments, this model applies financial principles to quantify risk impact dynamically, integrating seamlessly with industry frameworks. By framing cyber security risks in financial terms, the model enhances decision-making, promotes strategic resource allocation, and fosters stakeholder engagement. Through a structured methodology, it empowers organisations to assess, prioritise, and mitigate cyber security debt efficiently, ensuring long-term resilience in an evolving threat landscape.},
year = {2025},
journal = {Proceedings of the 20th International Conference on Cyber Warfare and Security (ICCWS 2025)},
volume = {20},
pages = {37-44},
month = {28-29 March 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Virginia, United States of America},
doi = {10.34190/iccws.20.1.3357},
}
The investigation of cryptocurrency crimes is still in its infancy with no standardised process or methodology to follow. This paper describes research that forms part of a broader project led by the second author (Botha, et al., 2025). The broader project's aim is to develop a methodology to follow when conducting cryptocurrency crime investigations. One of the steps in the proposed methodology is web scraping. The authors of this paper present a detailed exploration of web scraping techniques within the broader context of the proposed investigation methodology. In this paper, the focus is on developing a well-structured methodology for scraping social media platforms and online forums to gather data related to fraudulent activities; the goal is to find posts that include references to the wallet address of interest. This exploration uses an iterative approach; for every new cryptocurrency wallet address discovered or revealed through on-chain analysis, a parallel path is followed by scraping the Internet. If a mention of the cryptocurrency address should be discovered it is considered to be a key finding, creating a pivot point in the investigation. From a pivot point, further open-source intelligence (OSINT) techniques will be applied, though this aspect falls beyond the scope of this paper. If no relevant information or link is found, the scraping path will not be pursued, and the investigation proceeds with on-chain analysis to identify additional wallet addresses. Additionally, challenges encountered in web scraping, such as handling platform restrictions, ensuring data accuracy, and managing large volumes of data, are addressed. The goal of the proposed methodology is to enhance data extraction and analysis efficiency contributing to the proposed methodology for investigating cryptocurrency scams.
@{540,
author = {Bongani Mawhayi and Johnny Botha and Louise Leenen},
title = {A Web Scraping Approach Towards Cryptocurrency Investigations},
abstract = {The investigation of cryptocurrency crimes is still in its infancy with no standardised process or methodology to follow. This paper describes research that forms part of a broader project led by the second author (Botha, et al., 2025). The broader project's aim is to develop a methodology to follow when conducting cryptocurrency crime investigations. One of the steps in the proposed methodology is web scraping. The authors of this paper present a detailed exploration of web scraping techniques within the broader context of the proposed investigation methodology. In this paper, the focus is on developing a well-structured methodology for scraping social media platforms and online forums to gather data related to fraudulent activities; the goal is to find posts that include references to the wallet address of interest. This exploration uses an iterative approach; for every new cryptocurrency wallet address discovered or revealed through on-chain analysis, a parallel path is followed by scraping the Internet. If a mention of the cryptocurrency address should be discovered it is considered to be a key finding, creating a pivot point in the investigation. From a pivot point, further open-source intelligence (OSINT) techniques will be applied, though this aspect falls beyond the scope of this paper. If no relevant information or link is found, the scraping path will not be pursued, and the investigation proceeds with on-chain analysis to identify additional wallet addresses. Additionally, challenges encountered in web scraping, such as handling platform restrictions, ensuring data accuracy, and managing large volumes of data, are addressed. The goal of the proposed methodology is to enhance data extraction and analysis efficiency contributing to the proposed methodology for investigating cryptocurrency scams.},
year = {2025},
journal = {Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025)},
volume = {24},
pages = {445-454},
month = {25 June 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Germany},
doi = {10.34190/eccws.24.1.3557},
}
Managing cybersecurity risks within financial technology organisations is increasingly complex, with traditional qualitative assessments falling short in quantifying the financial implications of cyber threats. This paper presents an approach to implementing a Cybersecurity Debt Management Model, which integrates cybersecurity with financial risk management methodologies, demonstrating a structured method for operationalising the model within a FinTech IT environment. The model quantifies the financial impact of unresolved cybersecurity vulnerabilities, facilitating decision making, targeted resource allocation, and regulatory compliance. The proposed approach provides organisations with insights into managing cybersecurity debt, thereby promoting resilience and alignment of technical measures with strategic objectives.
@article{539,
author = {Christo Coetzer and Louise Leenen},
title = {Managing Cybersecurity Debt in FinTech: A Practical Approach for Financial Risk Quantification and Strategic Decision Making},
abstract = {Managing cybersecurity risks within financial technology organisations is increasingly complex, with traditional qualitative assessments falling short in quantifying the financial implications of cyber threats. This paper presents an approach to implementing a Cybersecurity Debt Management Model, which integrates cybersecurity with financial risk management methodologies, demonstrating a structured method for operationalising the model within a FinTech IT environment. The model quantifies the financial impact of unresolved cybersecurity vulnerabilities, facilitating decision making, targeted resource allocation, and regulatory compliance. The proposed approach provides organisations with insights into managing cybersecurity debt, thereby promoting resilience and alignment of technical measures with strategic objectives.},
year = {2025},
journal = {Journal of Information Warfare},
volume = {24},
pages = {62-66},
issue = {4},
publisher = {ArmisteadTEC},
}
This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a facade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss. After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss. These manipulative tactics are referred to as pig butchering. The paper utilises qualitative data from interviews and correspondence with the victim, along with an examination of platform behaviours to highlight common patterns in cryptocurrency scams. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim. To contextualise the collected information, a link analysis was done, utilising the tool Maltego. The link analysis visually maps the entities associated with the suspect within a network of nodes and connections. By situating the Elite-Bit case within the broader context of cryptocurrency regulation and consumer protection, this paper underscores the urgent need for enhanced regulatory frameworks and public awareness initiatives. This study aims to contribute to the ongoing discourse on financial fraud in the cryptocurrency sector, providing insights that may assist in the prevention of future scams and the promotion of more secure investment and trading practices.
@{538,
author = {Johnny Botha and Kreaan Singh and Louise Leenen},
title = {Analysis of a Cryptocurrency Investment Scam: Pig Butchering},
abstract = {This paper analyses and investigates a cryptocurrency investment scam involving the suspicious and fraudulent cryptocurrency trading platform, Elite-Bit, through a detailed case study of a victim's experience. With the rapid rise of cryptocurrency, deceptive platforms like Elite-Bit exploit unsuspecting investors by presenting a facade of legitimacy. This case study chronicles the victim's journey, beginning with a seemingly romantic connection through a dating platform, to an introduction to an investment opportunity, and subsequently a financial loss. After investing a substantial amount, the victim faced unexpected barriers when attempting to withdraw funds, including exorbitant transaction fees and other fabricated costs. The analysis reveals how Elite-Bit employs manipulative tactics such as social engineering and false urgency to maintain control over investors, ultimately leading to significant financial loss. These manipulative tactics are referred to as pig butchering. The paper utilises qualitative data from interviews and correspondence with the victim, along with an examination of platform behaviours to highlight common patterns in cryptocurrency scams. An on-chain and off-chain analysis was conducted using the limited input data provided by the victim. To contextualise the collected information, a link analysis was done, utilising the tool Maltego. The link analysis visually maps the entities associated with the suspect within a network of nodes and connections. By situating the Elite-Bit case within the broader context of cryptocurrency regulation and consumer protection, this paper underscores the urgent need for enhanced regulatory frameworks and public awareness initiatives. This study aims to contribute to the ongoing discourse on financial fraud in the cryptocurrency sector, providing insights that may assist in the prevention of future scams and the promotion of more secure investment and trading practices.},
year = {2025},
journal = {Proceedings of the 24th European Conference on Cyber Warfare and Security (ECCWS 2025)},
volume = {24},
pages = {61-70},
month = {25 June 2025},
issue = {1},
publisher = {Academic Conferences International},
address = {Germany},
doi = {10.34190/eccws.24.1.3558},
}
KnowIt (Knowledge discovery in time series data) is a flexible framework for building deep time series models and interpreting them. It is implemented as a Python toolkit, with source code and documentation available from this https URL. It imposes minimal assumptions about task specifications and decouples the definition of dataset, deep neural network architecture, and interpretability technique through well defined interfaces. This ensures the ease of importing new datasets, custom architectures, and the definition of different interpretability paradigms while maintaining on-the-fly modeling and interpretation of different aspects of a user's own time series data. KnowIt aims to provide an environment where users can perform knowledge discovery on their own complex time series data through building powerful deep learning models and explaining their behavior. With ongoing development, collaboration and application our goal is to make this a platform to progress this underexplored field and produce a trusted tool for deep time series modeling.
@article{531,
author = {Marthinus Theunissen and Randle Rabe and Marelie Davel},
title = {KnowIt: Deep Time Series Modeling and Interpretation},
abstract = {KnowIt (Knowledge discovery in time series data) is a flexible framework for building deep time series models and interpreting them. It is implemented as a Python toolkit, with source code and documentation available from this https URL. It imposes minimal assumptions about task specifications and decouples the definition of dataset, deep neural network architecture, and interpretability technique through well defined interfaces. This ensures the ease of importing new datasets, custom architectures, and the definition of different interpretability paradigms while maintaining on-the-fly modeling and interpretation of different aspects of a user's own time series data. KnowIt aims to provide an environment where users can perform knowledge discovery on their own complex time series data through building powerful deep learning models and explaining their behavior. With ongoing development, collaboration and application our goal is to make this a platform to progress this underexplored field and produce a trusted tool for deep time series modeling.},
year = {2025},
journal = {arXiv},
}
In ensembles, improved generalization is frequently attributed to \emph{diversity} among members of the ensemble. By viewing a single neural network as an \emph{implicit ensemble}, we perform an exploratory investigation that applies well-known ensemble diversity measures to a neural network in order to study the relationship between diversity and generalization in the over-parameterized regime. Our results show that i) deeper layers of the network generally have higher levels of diversity—particularly for MLPs—and ii) layer-wise accuracy positively correlates with diversity. Additionally, we study the effects of well-known regularizers such as Dropout, DropConnect and batch size, on diversity and generalization. We generally find that increasing the strength of the regularizer increases the diversity in the neural network and this increase in diversity is positively correlated with model accuracy. We show that these results hold for several benchmark datasets (such as Fashion-MNIST and CIFAR-10) and architectures (MLPs and CNNs). Our findings suggest new avenues of research into the generalization ability of deep neural networks.
@article{530,
author = {Ruan Van der Spoel and Randle Rabe},
title = {Investigating the relationship between diversity and generalization in deep neural networks},
abstract = {In ensembles, improved generalization is frequently attributed to \emph{diversity} among members of the ensemble. By viewing a single neural network as an \emph{implicit ensemble}, we perform an exploratory investigation that applies well-known ensemble diversity measures to a neural network in order to study the relationship between diversity and generalization in the over-parameterized regime. Our results show that i) deeper layers of the network generally have higher levels of diversity—particularly for MLPs—and ii) layer-wise accuracy positively correlates with diversity. Additionally, we study the effects of well-known regularizers such as Dropout, DropConnect and batch size, on diversity and generalization. We generally find that increasing the strength of the regularizer increases the diversity in the neural network and this increase in diversity is positively correlated with model accuracy. We show that these results hold for several benchmark datasets (such as Fashion-MNIST and CIFAR-10) and architectures (MLPs and CNNs). Our findings suggest new avenues of research into the generalization ability of deep neural networks.},
year = {2025},
journal = {Proceedings of the 7th Northern Lights Deep Learning Conference (NLDL)},
volume = {307},
pages = {375 - 387},
}
The performance of deep learning models is affected by not only data quantity but also data quality. Data pruning is a process by which practitioners can reduce the size of a dataset by only keeping the most important training data points, thereby achieving similar test set performance. We empirically investigate two popular data pruning methods under noisy and noiseless conditions and show that these methods fail in the presence of significant label noise. We highlight that the success of data pruning is distinctly affected by three factors: redundancy in the dataset, the presence of problematic samples, and interdependence between samples. We perform a detailed investigation on commonly used benchmark classification datasets and neural network architectures. We find that our observations are consistent across data distributions and training protocols.
@article{529,
author = {Leon Freese and Marthinus Theunissen},
title = {Data Pruning: Redundant, Problematic, and Interdependent Samples},
abstract = {The performance of deep learning models is affected by not only data quantity but also data quality. Data pruning is a process by which practitioners can reduce the size of a dataset by only keeping the most important training data points, thereby achieving similar test set performance. We empirically investigate two popular data pruning methods under noisy and noiseless conditions and show that these methods fail in the presence of significant label noise. We highlight that the success of data pruning is distinctly affected by three factors: redundancy in the dataset, the presence of problematic samples, and interdependence between samples. We perform a detailed investigation on commonly used benchmark classification datasets and neural network architectures. We find that our observations are consistent across data distributions and training protocols.},
year = {2025},
journal = {Artificial Intelligence Research. SACAIR 2025. Communications in Computer and Information Science},
volume = {vol 2784},
month = {25 November 2025},
doi = {https://doi.org/10.1007/978-3-032-11733-5_12},
}
Precision agriculture requires the estimation of plant growth stages in real-time. When the plant growth stage is known, the wastage of resources in cultivation, such as nutrients and water, is reduced as only the required resources need to be supplied. Plants at different growth stages, however, have similar morphological features, which can make autonomous growth stage estimation difficult. This paper presents two feature extraction methods for growth stage estimation: one that uses a bank of Gabor filters and morphological operations, and the other that uses pre-trained convolutional neural networks (CNNs) and transfer learning. We test these methods on a publicly available plant growth stage dataset (“bccr-segset“) for two species, canola and radish, grown and captured under indoor conditions. The two proposed feature extraction methods are compared, using support vector machines and boosted trees as classifiers. We find that both methods are suitable for real-time applications, and that CNN features outperform the hand-crafted features, both with regard to speed and accuracy. The best system (VGG-19 features, classified with a radial basis function support vector machine) obtained an accuracy of 98.4% for both species, processing an image in 0.08 seconds.
@article{528,
author = {Aldrin Ngorima and Albert Helberg and Marelie Davel},
title = {Feature extraction for plant growth estimation},
abstract = {Precision agriculture requires the estimation of plant growth stages in real-time. When the plant growth stage is known, the wastage of resources in cultivation, such as nutrients and water, is reduced as only the required resources need to be supplied. Plants at different growth stages, however, have similar morphological features, which can make autonomous growth stage estimation difficult. This paper presents two feature extraction methods for growth stage estimation: one that uses a bank of Gabor filters and morphological operations, and the other that uses pre-trained convolutional neural networks (CNNs) and transfer learning. We test these methods on a publicly available plant growth stage dataset (“bccr-segset“) for two species, canola and radish, grown and captured under indoor conditions. The two proposed feature extraction methods are compared, using support vector machines and boosted trees as classifiers. We find that both methods are suitable for real-time applications, and that CNN features outperform the hand-crafted features, both with regard to speed and accuracy. The best system (VGG-19 features, classified with a radial basis function support vector machine) obtained an accuracy of 98.4% for both species, processing an image in 0.08 seconds.},
year = {2025},
journal = {Artificial Intelligence Research. SACAIR 2025. Communications in Computer and Information Science},
volume = {vol 2784},
month = {25 November 2025},
doi = {https://doi.org/10.1007/978-3-032-11733-5_5},
}
Criminal investigations involving cryptocurrencies are still premature with no standard investigative process to follow. This paper proposes a high-level methodology using open-source and analysed data to perform such investigations. It focuses on situations where Bitcoin is involved, but where other similar blockchains are concerned, the technical investigator should apply this methodology only after careful consideration. A case study approach is used to illustrate a cryptocurrency scamming platform, a giveaway scam, and divorce fraud. In all the cases, one needs to follow or trace the funds on the blockchain, referred to as on-chain analysis. The end goal of on-chain analysis is to find a destination address linked to identifiable information obtained from open-source data platforms-such as websites, social media, or a cryptocurrency exchange. Law enforcement can then be engaged to instruct the exchange to reveal all personal and transactional information linked to the address through a subpoena. A successful investigation will result in criminal prosecution and a potential recovery of funds. To maintain familiar investigation processes, the researchers looked at traditional (or non-technical) as well as technical investigation techniques.
@{523,
author = {JG Botha and Kreaan Singh and Louise Leenen},
title = {A Proposed Bitcoin Blockchain Investigation Methodology: Based on a Case Study Approach},
abstract = {Criminal investigations involving cryptocurrencies are still premature with no standard investigative process to follow. This paper proposes a high-level methodology using open-source and analysed data to perform such investigations. It focuses on situations where Bitcoin is involved, but where other similar blockchains are concerned, the technical investigator should apply this methodology only after careful consideration. A case study approach is used to illustrate a cryptocurrency scamming platform, a giveaway scam, and divorce fraud. In all the cases, one needs to follow or trace the funds on the blockchain, referred to as on-chain analysis. The end goal of on-chain analysis is to find a destination address linked to identifiable information obtained from open-source data platforms-such as websites, social media, or a cryptocurrency exchange. Law enforcement can then be engaged to instruct the exchange to reveal all personal and transactional information linked to the address through a subpoena. A successful investigation will result in criminal prosecution and a potential recovery of funds. To maintain familiar investigation processes, the researchers looked at traditional (or non-technical) as well as technical investigation techniques.},
year = {2025},
journal = {Journal of Information Warfare},
volume = {24},
pages = {1-18},
issue = {1},
address = {ArmisteadTEC, LLC Virginia Beach, Virginia, USA},
}
The ocean plays a vital role in our society and represents a constantly changing landscape that is not well understood and therefore needs continuous monitoring and research. Sustainable monitoring is essential to assess both the current and future state of our oceans. However, conventional monitoring faces significant challenges, including issues of accessibility, and spatial and temporal constraints. The development of digital twins of the ocean (DTO) offers an emerging technology that could revolutionise our understanding of marine and coastal environments. Current DTO have shown effectiveness in monitoring marine and coastal environments in the European context. However, there is a need for a DTO for the Southern African and Western Indian Ocean regions that addresses specific concerns that are relevant to these regions. Successful development of a DTO depends on the availability of high-quality data. Therefore, various data inputs are necessary to build an accurate digital twin. This paper explores the data that can be utilised in a DTO, detailing how different ocean variables are collected and integrated into the digital twin. As a first step towards the development of a DTO in these regions, the paper proposes a data management plan and its implementation in the development of DTO. The data management plan is based on the phases of data in a geospatial data life cycle. Challenges regarding the management of data in this DTO and possible solutions are presented in the conclusion.
@article{522,
author = {Shelley Haupt and Bolelang Sibolla and Raymond Molapo and Lizwe Mdakane and Nicolene Fourie},
title = {Exploring the Use of Data in a Digital Twin for the Marine and Coastal Environment},
abstract = {The ocean plays a vital role in our society and represents a constantly changing landscape that is not well understood and therefore needs continuous monitoring and research. Sustainable monitoring is essential to assess both the current and future state of our oceans. However, conventional monitoring faces significant challenges, including issues of accessibility, and spatial and temporal constraints. The development of digital twins of the ocean (DTO) offers an emerging technology that could revolutionise our understanding of marine and coastal environments. Current DTO have shown effectiveness in monitoring marine and coastal environments in the European context. However, there is a need for a DTO for the Southern African and Western Indian Ocean regions that addresses specific concerns that are relevant to these regions. Successful development of a DTO depends on the availability of high-quality data. Therefore, various data inputs are necessary to build an accurate digital twin. This paper explores the data that can be utilised in a DTO, detailing how different ocean variables are collected and integrated into the digital twin. As a first step towards the development of a DTO in these regions, the paper proposes a data management plan and its implementation in the development of DTO. The data management plan is based on the phases of data in a geospatial data life cycle. Challenges regarding the management of data in this DTO and possible solutions are presented in the conclusion.},
year = {2025},
journal = {International Jornal of Geo-Information},
volume = {14},
month = {03/2025},
issue = {4},
doi = {https://doi.org/10.3390/ijgi14040140},
}
@article{521,
author = {Aldrin Ngorima and Albert Helberg and Marelie Davel},
title = {Simplified Temporal Convolutional-Based Channel Estimation for a WiFi Vehicular Communication Channel},
abstract = {},
year = {2025},
journal = {IEEE 3rd Wireless Africa Conference (WAC)},
pages = {1 - 5},
month = {02/2025},
publisher = {IEEE},
address = {Pretoria, South Africa},
isbn = {979-8-3315-1758-8},
doi = {10.1109/WAC63911.2025.10992609},
}
2024
A giveaway scam is a type of fraud leveraging social media platforms and phishing campaigns. These scams have become increasingly common and are now also prevalent in the crypto community where attackers attempt to gain crypto-enthusiasts' trust with the promise of high-yield giveaways. Giveaway scams target individuals who lack technical familiarity with the blockchain. They take on various forms, often presenting as genuine cryptocurrency giveaways endorsed by prominent figures or organizations within the blockchain community. Scammers entice victims by promising substantial returns on a nominal investment. Victims are manipulated into sending cryptocurrency under the pretext of paying for verification or processing fees. However, once the funds have been sent, the scammers disappear and leave victims empty-handed. This study employs essential blockchain tools and techniques to explore the mechanics of giveaway scams. A crucial aspect of an investigation is to meticulously trace the movement of funds within the blockchain so that illicit gains resulting from these scams can be tracked. At some point a scammer wants to cash-out by transferring the funds to an off-ramp, for example, an exchange. If the investigator can establish a link to such an exchange, the identity of the owner of cryptocurrency address could be revealed. However, in organised scams, criminals make use of mules and do not use their own identities. The authors of this paper select a use case and then illustrate a comprehensive approach to investigate the selected scam. This paper contributes to the understanding and mitigation of giveaway scams in the cryptocurrency realm. By leveraging the mechanics of blockchain technology, dissecting scammer tactics, and utilizing investigative techniques and tools, the paper aims to contribute to the protection of investors, the industry, and the overall integrity of the blockchain ecosystem. This research sheds light on the intricate workings of giveaway scams and proposes effective strategies to counteract them.
@{550,
author = {Johnny Botha and Louise Leenen},
title = {An Analysis of a Cryptocurrency Giveaway Scam: Use Case},
abstract = {A giveaway scam is a type of fraud leveraging social media platforms and phishing campaigns. These scams have become increasingly common and are now also prevalent in the crypto community where attackers attempt to gain crypto-enthusiasts' trust with the promise of high-yield giveaways. Giveaway scams target individuals who lack technical familiarity with the blockchain. They take on various forms, often presenting as genuine cryptocurrency giveaways endorsed by prominent figures or organizations within the blockchain community. Scammers entice victims by promising substantial returns on a nominal investment. Victims are manipulated into sending cryptocurrency under the pretext of paying for verification or processing fees. However, once the funds have been sent, the scammers disappear and leave victims empty-handed. This study employs essential blockchain tools and techniques to explore the mechanics of giveaway scams. A crucial aspect of an investigation is to meticulously trace the movement of funds within the blockchain so that illicit gains resulting from these scams can be tracked. At some point a scammer wants to cash-out by transferring the funds to an off-ramp, for example, an exchange. If the investigator can establish a link to such an exchange, the identity of the owner of cryptocurrency address could be revealed. However, in organised scams, criminals make use of mules and do not use their own identities. The authors of this paper select a use case and then illustrate a comprehensive approach to investigate the selected scam. This paper contributes to the understanding and mitigation of giveaway scams in the cryptocurrency realm. By leveraging the mechanics of blockchain technology, dissecting scammer tactics, and utilizing investigative techniques and tools, the paper aims to contribute to the protection of investors, the industry, and the overall integrity of the blockchain ecosystem. This research sheds light on the intricate workings of giveaway scams and proposes effective strategies to counteract them.},
year = {2024},
journal = {Proceedings of the 23rd European Conference on Cyber Warfare and Security (ECCWS 2024)},
volume = {23},
pages = {74-85},
month = {27-28 June 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Jyvaskyla, Finland},
doi = {10.34190/eccws.23.1.2524},
}
Documentation and artefact generation is an essential part of business processes. This paper explores the use of artefacts as a means of reaching consensus through the use of Multi-Agent Simulations. In particular we investigate the time to reach consensus with and without the use of artefacts and show the efficiency of artefacts as a means of facilitating consensus, perhaps more importantly, to create efficient consensus processes in the face of difficult organizational communications channels. We found that polyarchies are highly efficient at consensus formation, but are not realistic for larger organizations. For these organisations a small team that facilitate consensus formation is nearly as efficient. The introduction of artefacts significantly improve consensus formation in situations where intra-team communications causes delays in consensus formation.
@{551,
author = {Johannes Vorster and Louise Leenen},
title = {The Unreasonable Effectiveness of Artefacts and Documentation: An Exploration of Consensus Using Multi-Agent Simulations in a Two-Team Configuration},
abstract = {Documentation and artefact generation is an essential part of business processes. This paper explores the use of artefacts as a means of reaching consensus through the use of Multi-Agent Simulations. In particular we investigate the time to reach consensus with and without the use of artefacts and show the efficiency of artefacts as a means of facilitating consensus, perhaps more importantly, to create efficient consensus processes in the face of difficult organizational communications channels. We found that polyarchies are highly efficient at consensus formation, but are not realistic for larger organizations. For these organisations a small team that facilitate consensus formation is nearly as efficient. The introduction of artefacts significantly improve consensus formation in situations where intra-team communications causes delays in consensus formation.},
year = {2024},
journal = {Proceedings of the 14th International Conference on Simulation and Modeling Methodologies, Technologies and Applications - Volume 1: SIMULTECH},
volume = {1},
pages = {313-323},
month = {2024},
publisher = {SCITEPRESS - Science and Technology Publications},
address = {France},
doi = {10.5220/0012785300003758},
}
Cybercriminals constantly seek new methods to infiltrate a company's defences, making cybersecurity investments essential. Enterprise architecture (EA) provides a systematic risk detection and mitigation process by emphasising the interdependencies between systems, data, processes, people, and other factors. This paper provides a comprehensive approach, also referred to as a process, based on EA to assist African universities in developing a comprehensive cybersecurity plan. The EA process comprises four pillars: business architecture, data architecture, application architecture, and technology architecture. African universities can develop a comprehensive cybersecurity strategy using an EA approach in cybersecurity to achieve institutional goals and objectives. The potential attack surface comprises isolated EA components and their interconnections. This article comprehensively examines various EA processes such as business, information, application, and technology architecture. These processes are carefully analysed to evaluate the organisational structures and uncover opportunities to enhance security protocols. Additionally, we delve deep into abstract security patterns, seeking to cultivate an environment of trustworthiness within complex systems. Our research findings underscore the significant potential within African higher education institutions. By embracing a model-based approach to risk analysis and mitigation, these institutions can fortify their cybersecurity defences to ensure uninterrupted business operations and enhance overall resilience in the face of evolving security challenges. When we combine EA and information security (ICS), we uncover many vulnerabilities malicious actors might exploit. By embracing a holistic EA-based methodology, institutions can craft and implement robust security protocols to safeguard their components and connections. Leveraging EA, our proposed integrated approach aims to forge a comprehensive cybersecurity risk management strategy tailored to the African higher education sector. This strategy seeks to facilitate the identification of critical elements and their intricate interrelationships, thus formulating an effective defence strategy against potential cyber threats. The synergy promises to elevate cybersecurity practices, ensure uninterrupted business operations, and fortify the continent's resilience.
@{549,
author = {Mafika Nkambule and Joey van Vuuren and Louise Leenen},
title = {Integrating Enterprise Architecture into Cybersecurity Risk Management in Higher Education},
abstract = {Cybercriminals constantly seek new methods to infiltrate a company's defences, making cybersecurity investments essential. Enterprise architecture (EA) provides a systematic risk detection and mitigation process by emphasising the interdependencies between systems, data, processes, people, and other factors. This paper provides a comprehensive approach, also referred to as a process, based on EA to assist African universities in developing a comprehensive cybersecurity plan. The EA process comprises four pillars: business architecture, data architecture, application architecture, and technology architecture. African universities can develop a comprehensive cybersecurity strategy using an EA approach in cybersecurity to achieve institutional goals and objectives. The potential attack surface comprises isolated EA components and their interconnections. This article comprehensively examines various EA processes such as business, information, application, and technology architecture. These processes are carefully analysed to evaluate the organisational structures and uncover opportunities to enhance security protocols. Additionally, we delve deep into abstract security patterns, seeking to cultivate an environment of trustworthiness within complex systems. Our research findings underscore the significant potential within African higher education institutions. By embracing a model-based approach to risk analysis and mitigation, these institutions can fortify their cybersecurity defences to ensure uninterrupted business operations and enhance overall resilience in the face of evolving security challenges. When we combine EA and information security (ICS), we uncover many vulnerabilities malicious actors might exploit. By embracing a holistic EA-based methodology, institutions can craft and implement robust security protocols to safeguard their components and connections. Leveraging EA, our proposed integrated approach aims to forge a comprehensive cybersecurity risk management strategy tailored to the African higher education sector. This strategy seeks to facilitate the identification of critical elements and their intricate interrelationships, thus formulating an effective defence strategy against potential cyber threats. The synergy promises to elevate cybersecurity practices, ensure uninterrupted business operations, and fortify the continent's resilience.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {501-510},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2189},
}
This paper explores cyber security debt, a technical debt arising from unaddressed security vulnerabilities in an organisation's IT systems. These vulnerabilities accumulate due to resource limitations, time constraints, and expertise gaps, potentially leading to security breaches and data compromises. The paper outlines the cyber security debt management process involving identification, prioritisation, and mitigation strategies. Drawing parallels to financial debt, the authors emphasise the escalating risks of delaying cyber security debt repayment. The paper underscores the significance of diligent debt management in maintaining digital resilience and mitigating cyber threats. The increasing interconnectedness of systems and rapid software development has given rise to a hidden challenge known as cyber security debt. Cyber security debt is posed as a subset of technical debt, encompassing the accumulation of security vulnerabilities within an organisation's IT infrastructure and applications. Drawing a parallel between cyber security debt and its financial counterpart, the authors underscore the grave risks of deferring debt repayment. Just as financial debt accrues interest, unresolved security vulnerabilities compound over time, elevating the likelihood of breaches and data exposure. A poignant case study of the Equifax breach exemplifies the real-world consequences of neglecting security debt management. The failure to patch a well-known vulnerability led to a colossal data breach, highlighting the urgency of addressing security weaknesses promptly. Complex in nature, cyber security debt materialises when organisations fail to address vulnerabilities during various operational life cycles. These vulnerabilities might remain concealed within IT architecture, legacy code, or third-party libraries, posing a formidable challenge to detection and resolution. By understanding the parallels between financial and cyber security debt and proactively managing the latter, organisations can enhance their ability to safeguard against evolving cyber threats and maintain a robust security posture.
@{548,
author = {Christo Coetzer and Louise Leenen},
title = {Managing Cyber Security Debt: Strategies for Identification, Prioritisation, and Mitigation},
abstract = {This paper explores cyber security debt, a technical debt arising from unaddressed security vulnerabilities in an organisation's IT systems. These vulnerabilities accumulate due to resource limitations, time constraints, and expertise gaps, potentially leading to security breaches and data compromises. The paper outlines the cyber security debt management process involving identification, prioritisation, and mitigation strategies. Drawing parallels to financial debt, the authors emphasise the escalating risks of delaying cyber security debt repayment. The paper underscores the significance of diligent debt management in maintaining digital resilience and mitigating cyber threats. The increasing interconnectedness of systems and rapid software development has given rise to a hidden challenge known as cyber security debt. Cyber security debt is posed as a subset of technical debt, encompassing the accumulation of security vulnerabilities within an organisation's IT infrastructure and applications. Drawing a parallel between cyber security debt and its financial counterpart, the authors underscore the grave risks of deferring debt repayment. Just as financial debt accrues interest, unresolved security vulnerabilities compound over time, elevating the likelihood of breaches and data exposure. A poignant case study of the Equifax breach exemplifies the real-world consequences of neglecting security debt management. The failure to patch a well-known vulnerability led to a colossal data breach, highlighting the urgency of addressing security weaknesses promptly. Complex in nature, cyber security debt materialises when organisations fail to address vulnerabilities during various operational life cycles. These vulnerabilities might remain concealed within IT architecture, legacy code, or third-party libraries, posing a formidable challenge to detection and resolution. By understanding the parallels between financial and cyber security debt and proactively managing the latter, organisations can enhance their ability to safeguard against evolving cyber threats and maintain a robust security posture.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {439-446},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2178},
}
Is it possible to dramatically affect and influence military and other projects through social engineering of the consensus processes? In this paper we explore the impact that subversive agents can have on the ability of projects to move forward by disrupting the social cohesion and decision-making abilities of the processes designed to reach consensus. A consensus simulator is used to model group social cohesion behaviour in the context of project deliverables and show what the effect can be on the effort to reach consensus (number of meetings) as well as the time to reach consensus (calendar time) when subversive agents attempt to influence the groups making up the project team in such a way that it delays the ability of the team to reach consensus on key decisions. Many military options are available to delay enemy projects, including the assassination of enemy scientists, sanctions aimed at denying key project components, or even direct military action such as bombing the enemy facilities. However, this paper focusses on aspects of soft-force projection through covert disruption of project timelines. A social simulator was constructed that models individual agent's beliefs about various key topics within the context of a project. The effect that a small number of subversive agents can have on the time- and effort of a project is shown. In their covert actions, these subversive agents need to stay hidden, and thus their covert actions are limited, yet they can exert significant damage to the project in terms of delays. In this paper we present results showing the effects that such a small group can have, as well as pointing out that there seem to be a critical group size over which the subversive agents can not only have significant impact on project-delays but can also steer and direct certain key decisions.
@{547,
author = {Johannes Vorster and Louise Leenen},
title = {Covert Subversive Agents and Consensus Disruption on Large Projects},
abstract = {Is it possible to dramatically affect and influence military and other projects through social engineering of the consensus processes? In this paper we explore the impact that subversive agents can have on the ability of projects to move forward by disrupting the social cohesion and decision-making abilities of the processes designed to reach consensus. A consensus simulator is used to model group social cohesion behaviour in the context of project deliverables and show what the effect can be on the effort to reach consensus (number of meetings) as well as the time to reach consensus (calendar time) when subversive agents attempt to influence the groups making up the project team in such a way that it delays the ability of the team to reach consensus on key decisions. Many military options are available to delay enemy projects, including the assassination of enemy scientists, sanctions aimed at denying key project components, or even direct military action such as bombing the enemy facilities. However, this paper focusses on aspects of soft-force projection through covert disruption of project timelines. A social simulator was constructed that models individual agent's beliefs about various key topics within the context of a project. The effect that a small number of subversive agents can have on the time- and effort of a project is shown. In their covert actions, these subversive agents need to stay hidden, and thus their covert actions are limited, yet they can exert significant damage to the project in terms of delays. In this paper we present results showing the effects that such a small group can have, as well as pointing out that there seem to be a critical group size over which the subversive agents can not only have significant impact on project-delays but can also steer and direct certain key decisions.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {421-429},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2174},
}
The characteristics of blockchain established a desirable platform for entities to innovate and operate in a secure, transparent, and decentralised manner. However, cybercriminals have increasingly found refuge in the decentralised environment of blockchain technology. Cryptocurrencies are increasingly misused in malicious activities that encompass the trade of illicit goods, money laundering, various types of scams and ransomware attacks. The total cryptocurrency value received by illicit addresses reached an all-time high of $20.6 billion in 2022 according to Chainalysis. The inherent privacy and anonymity features of many blockchain networks make it challenging for law enforcement and regulatory agencies to track and apprehend wrongdoers. Consequently, a pressing need arises not only to initiate investigations on the blockchain to identify unlawful activities, but also to discover connections between these activities and the identities of the responsible individuals. Due to blockchain data being publicly available, the application of Open-Source Intelligence (OSINT) techniques is proposed to facilitate these types of investigations. In the context of blockchain, OSINT, together with investigation tools hold the promise of unearthing valuable information that could aid in attributing malicious activities to the individuals responsible for those actions. By analysing and synthesizing data from publicly accessible sources, such as data from blockchain explorers and link analysis tools such Chainalysis, Maltego or Spiderfoot, investigators could potentially unveil valuable clues that assist in building a comprehensive picture of blockchain-related criminal activities. Ultimately, with sufficient information and actionable intelligence collected, the main goal is to link it to Know Your Customer (KYC) data, that could be obtained from cryptocurrency exchanges via a subpoena from law enforcement agencies. This paper delves into the mechanisms of various OSINT tools and techniques, to determine their adaptability to the specific demands of blockchain investigations. This study provides a methodology and recommendations with insights into how these tools can be wielded to bridge the gap between blockchain's pseudonymity and real-world identities.
@{546,
author = {W.P. Gertenbach and Johnny Botha and Louise Leenen},
title = {A Proposed High-Level Methodology on How OSINT is applied in Blockchain Investigations},
abstract = {The characteristics of blockchain established a desirable platform for entities to innovate and operate in a secure, transparent, and decentralised manner. However, cybercriminals have increasingly found refuge in the decentralised environment of blockchain technology. Cryptocurrencies are increasingly misused in malicious activities that encompass the trade of illicit goods, money laundering, various types of scams and ransomware attacks. The total cryptocurrency value received by illicit addresses reached an all-time high of $20.6 billion in 2022 according to Chainalysis. The inherent privacy and anonymity features of many blockchain networks make it challenging for law enforcement and regulatory agencies to track and apprehend wrongdoers. Consequently, a pressing need arises not only to initiate investigations on the blockchain to identify unlawful activities, but also to discover connections between these activities and the identities of the responsible individuals. Due to blockchain data being publicly available, the application of Open-Source Intelligence (OSINT) techniques is proposed to facilitate these types of investigations. In the context of blockchain, OSINT, together with investigation tools hold the promise of unearthing valuable information that could aid in attributing malicious activities to the individuals responsible for those actions. By analysing and synthesizing data from publicly accessible sources, such as data from blockchain explorers and link analysis tools such Chainalysis, Maltego or Spiderfoot, investigators could potentially unveil valuable clues that assist in building a comprehensive picture of blockchain-related criminal activities. Ultimately, with sufficient information and actionable intelligence collected, the main goal is to link it to Know Your Customer (KYC) data, that could be obtained from cryptocurrency exchanges via a subpoena from law enforcement agencies. This paper delves into the mechanisms of various OSINT tools and techniques, to determine their adaptability to the specific demands of blockchain investigations. This study provides a methodology and recommendations with insights into how these tools can be wielded to bridge the gap between blockchain's pseudonymity and real-world identities.},
year = {2024},
journal = {Proceedings of the 19th International Conference on Cyber Warfare and Security (ICCWS 2024)},
volume = {19},
pages = {75-83},
month = {26-27 March 2024},
issue = {1},
publisher = {Academic Conferences International},
address = {Johannesburg, South Africa},
doi = {10.34190/iccws.19.1.2172},
}


