Circular Image

M.J.G. van Eeten

info

Please Note

24 records found

A sociomaterial study of a GenAI chatbot in product-to-sales knowledge communication

Master thesis (2026) - G.S. Hiremath, M.J.G. van Eeten, F.S. Gürses, N. Pachos-Fokialis, Silvia Longo
This thesis examines how an internal generative AI assistant reshapes the communication of product knowledge between Product teams and customer-facing functions. It studies a sales-enablement chatbot used inside a European location-technology company and built on a retrieval-augmented generation platform. The research uses an embedded qualitative case study based on fifteen semi-structured interviews across five role groups and twelve months of chatbot activity.

The findings show that the chatbot reorganises rather than simply replaces the existing knowledge channel. First, product documentation increasingly becomes a machine-readable organisational resource, although this transition is uneven and constrained by fragmented and outdated source material. Second, accountability for AI-generated answers becomes distributed across customer-facing users, documentation owners, the platform team and the vendor. Third, routine factual questions increasingly move to the chatbot, while judgement, customer-specific interpretation and commercial nuance continue to depend on people.

The central finding is a broken correction circuit: problems are often encountered on the customer-facing side, while the actor able to address them may sit elsewhere, yet no consistently used process connects detection to correction. The study concludes that reliable AI-mediated knowledge exchange depends not only on producing answers at scale, but also on maintaining source knowledge, preserving human escalation paths and building mechanisms through which errors, feedback and field signals can travel back to the people able to act on them. ...

A comparative study of how GDPR, NIS2, DORA and the AI Act are operationalized into compliance practices

European digital legislation such as the GDPR, NIS2, DORA and the AI Act is principles-based: it specifies what regulated entities must achieve rather than how, which keeps it flexible but relocates the task of deciding what compliance requires onto those who apply it. In practice, much of that task falls to external IT auditors and cybersecurity consultants, an intermediary layer that is rarely studied even though its choices help settle what counts as compliant and secure. This research examines how external IT auditors and cybersecurity consultants in the Netherlands operationalize principles in EU digital legislation to demonstrate compliance, and, because compliance under principles-based regulation is produced through defensibility rather than delivered by the legal text, how that process shapes what they treat as sufficiently secure. The study draws on thirteen semi-structured interviews and a focus group with consultants, auditors and framework developers, analysing the interviews thematically and the focus group sequentially, and compares four instruments at different stages of regulatory maturity. Operationalization is found to follow a structured but iterative twelve-step process across four phases, in which the decisive interpretive work concentrates in a few steps and the process may end not by resolving risk but by the client accepting it. Although the process is structured, its key decisions rest on professional judgment bounded by four incentives: enforcement risk, reputational exposure, the firm's review hierarchy and negotiation with the paying client. The first three shape what is recommended and tend toward caution, while client negotiation shapes what is implemented. Compliance and security frequently align, but their alignment is conditional rather than guaranteed, and a feedback asymmetry makes any divergence hard to see. The thesis makes this largely hidden practice visible, contributes a twelve-step process model and a revised Layered Operationalization Map, and reframes the intermediary layer as multidirectional rather than purely downstream. ...
As cybercrimes rise, companies increasingly invest in security awareness training to protect themselves, but the effectiveness of the training is being called into question by researchers. Vendors sell one-size-fits-all training, yet these programmes fail to take the routines and needs of employees into account. This results in low engagement, wasted resources and, most importantly, little change in actual behaviour. Research has explored the relation between training and behaviour, identifying several factors that influence behaviour change. The resulting advice however often remains highly abstract. As such, this research explores how security awareness training can be made more effective by involving employees and designing or modifying it to align with their primary work tasks. It offers a structured approach and practical examples for practitioners to learn from.

The research was conducted as a case study in a large engineering company spread across Europe, focussing on the offices in the Netherlands. The pseudonym IECC was given to the company, as it was an International Engineering and Consultancy Company. Qualitative research methods were used, which included semi-structured interviews with employees from three departments and external experts, brainstorming sessions with employees and an expert validation session with IECC's CISO and change manager. The main research question was: "How can security awareness training be designed or modified to align with employees’ existing work routines and needs?".

Co-design was used to answer this research question, as each step in the approach used employee input. First, employees were involved in defining their needs and routines from their primary work tasks to answer SQ1, the first sub-question. Three departments of IECC participated in the research, which included the finance department, the Business Unit Living Environment (BULE) and the fieldworkers from Field Lab Consultancy (FLC). The next step in the approach was to evaluate the current training for SQ2, in which employees were also involved. This helped determine which parts of training aligned with their needs and routines and which parts did not. For the last step, employee and expert input was combined to address the misalignments found, thus answering SQ3. This led to practical and example supported advice, targeting the factors that influence the effectiveness of security awareness training on secure behaviour.

The findings outline an approach to better align training with the needs and routines of employees. The first step in the process is to gather employee input on their primary tasks, needs and routines. The next step is to evaluate the current training in order to determine how well it aligns with the needs and routines found, identifying what needs to be changed and what is already working. The third and final step is to modify or design training using the identified building blocks, to promote actual behaviour change. By involving employees early on in the process, organisations not only gather the input needed to make targeted training, but also build concordance with them, meaning people are committed, which is needed for lasting behaviour change. ...

A Comparative Analysis of Perceived AI Value Realization across Organizational Levels in a Construction Company

Artificial intelligence (AI) is increasingly being integrated into organizational work, yet its adoption does not necessarily translate into perceived value realization. Existing research predominantly examines adoption determinants or organizational outcomes, while offering limited insight into how AI-generated value is perceived across organizational levels. This is particularly relevant within the construction sector, where digital transformation is shaped by project-based work, labour shortages, fragmented organizational structures, and traditionally conservative professional cultures.

This study addresses the research question: How is AI value realization perceived across organizational levels within a construction company? A qualitative single-case study was conducted within a large Dutch construction and infrastructure organization through 29 semi-structured interviews with managers (n = 14) and employees (n = 15). Using a Gioia-inspired methodology, the data were analysed through both cross-group and within-group comparisons across five aggregate dimensions: adoption, AI use practices, perceptions, value realization, and enabling dynamics. The findings demonstrate that AI adoption is widespread but unevenly experienced. AI use is predominantly assistive across both organizational groups, while automation-oriented and transformational applications remain comparatively limited. Across both managers and employees, bounded use emerged as the dominant AI use pattern, reflecting deliberate restrictions on AI authority in favour of continued human judgement, accountability, and professional expertise.

The study identifies a structural asymmetry in perceived AI value realization. Managers predominantly describe realized benefits, including efficiency gains, improved decision support, and enhanced work experience. Employees also perceive positive value but report substantially more constrained value, including verification burden, operational inefficiencies, job-related concerns, and unrealized collaborative benefits. The collaboration gap emerged as the clearest illustration of this asymmetry, as employees uniquely anticipated AI-enabled collaboration and uniquely experienced its absence, whereas managers were largely absent from both sides of this discussion.

A second key finding concerns the enabling dynamics underpinning perceived AI value realization. Human capability emerged as the primary enabling dynamic, followed by organizational coordination, while technical capability, although necessary, proved comparatively less decisive. The findings indicate that the principal barriers to AI value realization are not technological limitations, but the organizational and human conditions required to translate existing AI capabilities into sustained practice.

The study makes three theoretical contributions. First, it extends socio-technical theory by demonstrating that perceived AI value is distributed asymmetrically across organizational levels rather than uniformly across organizations. Second, it introduces bounded use and bounded acceptance as complementary concepts explaining how professionals simultaneously adopt AI while deliberately limiting its authority. Third, it develops a dynamic perspective on AI value realization by conceptualizing human, organizational, and technical factors as interacting enabling dynamics rather than static conditions.

To support practice, two complementary frameworks were developed. Framework 1 provides a comparative diagnosis of managers' and employees' current AI experiences, while Framework 2 translates these findings into a differentiated managerial pathway for strengthening human capability, organizational coordination, and technical support. Together, the findings suggest that improving AI value realization depends less on acquiring more advanced technologies than on creating the organizational conditions through which AI-generated value can be more evenly perceived and realized across organizational levels.
...
While Artificial Intelligence (AI) offers major opportunities, a critical gap exists between emerging AI risk management frameworks and the practical needs of businesses. This problem threatens to hinder innovation and socio-technical risks. Regulations like the EU AI Act and standards such as the NIST AI Management Framework (RMF) are often seen by practitioners as abstract and impractical. This creates a significant challenge for organisations navigating the complex AI landscape. This research investigates the perspectives of professionals on the practical ability of current AI risk management frameworks. It looks at how these frameworks balance risk management and innovation. The primary objective is to analyse these perspectives, identify the primary challenges organisations face, and provide actionable recommendations for both businesses and regulators. This research is guided by the central research question: "What are the current perspectives on the ability of AI risk management frameworks to address core business needs regarding the balance of risks and innovation?" The study uses a descriptive, qualitative methodology, beginning with a literature review to better understand the AI governance landscape and to identify the critical gaps between frameworks and practical business needs. Following this, semi-structured interviews were conducted with eleven professionals from diverse sectors, including finance, healthcare, and technology consulting. The collected data is analysed using a thematic analysis. The findings of the interviews are interpreted through a lens of socio-technical systems theory by applying principles from System-Theoretic Process Analysis (STPA) to find problems across the AI governance system. The findings of this study pointed out systemic disconnection between regulatory frameworks and actual business conditions. The main results have identified that the governance adoption comes first and foremost due to the pressure from external authorities, rather than being a real motivator for genuinely responsible innovation. Further, organisations are most concerned with socio-technical risk, such as the lack of AI literacy among decision-makers and staff resisting change. Besides, these risks are often missed by frameworks focusing solely on the technical aspect. Finally, the ambiguity of rules and the delay in the development of harmonised standards create uncertainty and force organisations to comply with inadequate tools. Currently, AI risk management frameworks are mostly viewed as inefficient in balancing risk management and innovation. Therefore, they are more perceived as a liability than a vital tool. This research concludes that this is a systemic failure. The study classifies AI governance as a "wicked problem" and a "dysfunctional system" struggling with it. The study suggests that businesses should be proactive and incorporate AI risk management into their basic structure. Additionally, it recommends that regulators should form partnerships, offer specific guidance to sectors, and revise the risk classifications in a manner that would reflect the actual complexities of the real world. ...

Focusing on the Detection of Child Sexual Abuse Material and Terrorist Content Online

Master thesis (2025) - M.J. Rottier, S. Zannettou, M.J.G. van Eeten, M. Kroesen, Arda Gerkens, Ellen Janssen
The spread of Child Sexual Abuse Material (CSAM) and Terrorist Content Online (TCO) remains a pressing societal issue. Various organizations rely on hash databases to detect, flag, and remove harmful content. These databases function as storage of digital fingerprints of previously identified illegal material, enabling automated platform filtering. However, the effectiveness and reliability of such databases rely on the verification processes used to determine what content qualifies for inclusion.

This thesis investigates the characteristics of verification processes in CSAM and TCO hash databases, with a particular focus on triple verification. Using a multiphase mixed-methods design, the study integrates qualitative insights from stakeholder interviews, an annotation experiment, and a follow-up focus group with annotators.

The interviews with experts highlighted variations in verification workflows, ranging from single-rater decisions to triple verification models. While triple verification is seen as a standard for increasing trust and minimizing false positives, its feasibility in terms of emotional toll and volume has been questioned. Thematic insights centered around benefits (e.g., legal considerations), challenges (e.g., emotional toll, inconsistent thresholds), necessity (e.g., utility and impact), future opportunities (e.g., automation), and differences between CSAM and TCO workflows.

In the experiment, two raters from the Dutch National Police classified 2,031 real potentially illegal items under two different conditions. In the blind phase, raters voted independently, whereas in the non-blind phase, prior votes were visible. Overall inter-rater agreement rose from 89.4% in the blind condition to 97.1% in the non-blind condition. A statistically significant association was found between voting order and agreement rates, suggesting that seeing one or two prior votes can subtly influence rater alignment.

The focus group offered further insight into the found disagreements. A key theme was the importance of recognizing image series: individual images were often reclassified as illegal when identified as part of a known CSAM series. Age estimation was also a recurring source of ambiguity, particularly when visual quality was poor or when victims’ physical development and ethnicity made assessment difficult. Raters relied on indicators such as skin texture, body proportions, and dental features, though these cues were often interpreted differently.

The findings emphasize the need for verification systems that are both flexible and context-sensitive. Not all cases require the same level of scrutiny: while baseline CSAM could be classified with fewer checks, ambiguous cases require more checks. Rather than enforcing uniformity, organizations should accommodate interpretive differences while safeguarding consistency and accountability.

...
Courthouses in the Netherlands are grappling with substantial challenges stemming from escalating workloads and high burnout rates among court clerks. This strain not only compromises the well-being of essential judicial personnel but also hinders the overall efficiency and timeliness of the justice system. In response to this pressing issue, this research has delved into the potential application of Large Language Models (LLMs), a form of artificial intelligence like ChatGPT, as a means to alleviate these burdens. In order to investigate the potential of LLMs in the juridical field, the following main question has been drafted:
“How effective is an LLM in lowering the workload of the Dutch court clerks?”
The research employs a mixed research approach. The literature and desk review examines the tasks of the clerks, information about the available LLMs and prompt engineering technique. In addition to this, semi-structured interviews have been held to explore the different tasks of the clerks. Since the scope of this research is only big enough for one task, The task selection process utilized the elimination by aspects technique. After this, a targeted experiment has been conducted to analyse and evaluate the possible LLMs and select the most suitable model for this research. The effectiveness of the LLM-based prompt support have been evaluated using a mixed-methods approach, combining quantitative and qualitative data analysis, which are a within-subject experiment, semi-structured interviews, DeepEval Evaluation, expert evaluation, and a statistical analysis.
The results and the conclusion of this research are still under embargo.
...

A User Study of Developers’ Practices and Perception in VS Code Extension Ecosystem

Visual Studio Code (VS Code) has become the dominant development environment worldwide, used by the majority of software professionals. Its success largely stems from its highly extensible architecture, supported by an extensive marketplace hosting more than 100,000 extensions that allow developers to tailor their workflows. However, recent research and industry investigations have revealed that these extensions can be exploited to execute arbitrary code, exfiltrate data, or compromise build environments.

Despite growing attention to these technical threats, little is known about how such risks are perceived and managed within organizational settings, where developer autonomy intersects with organizational governance and policy. Using a qualitative approach, interviews were conducted with 21 professionals from 19 companies across five countries to explore how developers perceive and manage the security of VS Code extensions in organizational contexts.

The findings reveal that extension management practices are largely convenience-driven, with developers relying on surface-level Marketplace signals, such as publisher verification, ratings, and download counts, that can easily be manipulated, as shown in prior research. These cues provide reassurance but not assurance, leading developers to conflate popularity or verified status with safety. In most organizations, extension governance is minimal or informal, resulting in fragmented practices where developers must independently assess security risks despite operating in managed environments.

The study concludes that secure extension use in VS Code is not merely a technical issue but a socio-technical and governance challenge that requires coordination across multiple levels. At the marketplace level, clearer communication of verification criteria, greater visibility of permissions or a modified permission model, and stronger mechanisms for signaling risk are needed. At the organizational level, structured allowlist policies, internal vetting workflows, and targeted awareness programs can bridge the gap between platform safeguards and developer behavior. At the developer level, improved understanding and interpretation of trust cues should be supported, not assumed, through organizational policy and education. Together, these measures align platform design, organizational governance, and developer practice toward a shared framework of accountability and safer extension use within professional environments.
...

Bridging the Gap Between Innovation and Application

Master thesis (2024) - S.I. Slavova, Y. Zhauniarovich, Sepinoud Azimi , M.J.G. van Eeten, E. Bárbaro
As digitalization advances, cybersecurity departments are increasingly overwhelmed by alerts and potential threats, leading to decision fatigue among security analysts. In response, many are adopting Artificial Intelligence (AI) to automate routine tasks, prioritize alerts, and accelerate incident response. However, the pace of AI adoption in cybersecurity lags behind that of threat actors, revealing underlying challenges. This thesis explores these challenges through a case study of a large European bank's cybersecurity department, using a sociotechnical systems (STS) approach. Semi-structured interviews with security analysts, data scientists, and leadership revealed four key themes: (1) mixed perceptions of AI, (2) the influence of organizational factors on AI adoption, (3) the importance of interdisciplinary collaboration, and (4) the critical role of trust in AI systems. While AI offers potential benefits like improved threat detection and reduced decision fatigue, challenges such as data quality issues and lack of transparency persist. Organizational readiness, leadership support, and effective change management are crucial for successful AI integration. Building trust through transparency and active user involvement is essential for adoption. The thesis proposes a conceptual model that addresses these challenges by integrating technical and social factors, offering practical recommendations for enhancing AI adoption in cybersecurity. Future research should expand on these findings through diverse case studies, human-centered AI frameworks, and longitudinal studies to better understand AI’s impact on trust and collaboration in cybersecurity. ...
Master thesis (2023) - H.D. Yeşilli, Y. Zhauniarovich, M.J.G. van Eeten, J. Ubacht, Lukas Willinge, Ruurd Boomsma
Increasing digitalization of systems bring about the grand challenge of keeping these systems secure from malicious prying eyes, and thus highlighting the need for increased Cybersecurity practices. Ransomware is among the most prevalent cybersecurity threats in our current digital era. The attacks are mainly done by advanced persistent threats (ATPs) to increase the impact done to organizations worldwide. Ransomware encrypt data using advanced cryptographic measures and lock users out of their systems to ask for a ransom that is typically paid through bitcoins. ATPs also exfiltrate sensitive data and utilize double and triple extortion methods where they either blackmail the organization with the public release or selling of their data, or they go to the customers to blackmail them, so they pressure the organization into paying the ransom. Defense against Ransomware is possible but in many cases, by the time, ransomware is detected the malicious actors already have strong access into the systems and data. All is not lost however as organizations can bring back their systems and data if there are backup & recovery policies that have been established prior. This thesis systematically explores the ransomware topic scoped on backups & recovery to identify how ransomware attack backups, what are the best practices for backups & recovery, and the corresponding challenges for organizations to produce policy recommendations. To this end, three methods are used. The methods are: semi-systematic literature review, qualitative content analysis, and semi-structured interviews. A triangulation of these methods over cybersecurity frameworks, expert knowledge and backup software provider reports establish essential insights. The main recommendations made are that organizations must ensure that they regularly must create redundant, airgapped, offline, and offsite backups that are stored in multiple storage media. Furthermore organizations must establish proper cyber hygiene practices in order to protect their backups. Lastly, organizations must ensure that they can test and maintain resilient backup & recovery policies through establishing responsibility and accountability of different stakeholders, streamlining their IT environments, and having a cybersecurity-enabling approach to organizational IT governance. The research is a rigorous and comprehensive overview of the backup & recovery topic against ransomware and is academically relevant as it fills research gaps on: how ransomware attacks target backups & recovery specifically, what the best practices offered by the most credible cybersecurity frameworks are, and why organizations still fail in setting up proper backup & recovery practices. The EPA relevance is characterized through navigating a branch of the grand challenge of cybersecurity, namely ransomware. This is a grand challenge as there are a plethora of stakeholders on an organizational level who have different opinions and views on the topic at hand where organizations are comprised of teams in different countries, subject to different regulations, etc. Therefore it is essential in this complex environment to see what could be made as policy recommendations for organizations of all levels against the treat of ransomware with respect to backup & recovery practices. ...
In recent years, more and more emphasis has been put on the importance of good preventative cyber security and vulnerability management techniques such as "Patch Tuesday".
Despite the increased importance, not all organisations have the same resources and knowledge when it comes to securing their networks against cyber adversaries.

This research tries to examine the vulnerability posture of Dutch municipal ICT networks.
To accomplish this a network ranges dataset was curated using open source intelligence techniques.
These networks, related to current and previous Dutch municipalities, have been used to collect network data scans and observe the changes in software products and versions.
Based on the data collected we can observe the software update moments for different organisations and analyse how often software products are kept up to date.
Using this network scan data and a subset of open-source products, we were able to construct a case study analysis about the general trends of vulnerability management and the influencing factors thereof.
This was done through timeline analysis, involving also software update releases, security advisories, and publicly disclosed vulnerability exploits.
Our findings show uncoordinated strategies within the different organisations and rare proactive security behaviour.

Another contribution of this study is in the sphere of reconnaissance and open source intelligence gathering, showing that publicly available information alone is a time-consuming procedure that renders very few useful data points.
These later findings have implications for both adversaries as well as security organisations, as reliable data could only be obtained through direct contact with the underlying municipality.
...
Master thesis (2022) - R. LIU, C.W.M. Naastepad, M.J.G. van Eeten
In this thesis I investigate possibilities for expanding freedom of choice in the development and use of digital education technologies. This thesis may be of interest to university policy-makers, students, professors, software-developers, or anyone interested in expanding freedom of choice in the development and use of digital education technologies.
This research aims to investigate possibilities for the creation of a free space in the cultural sphere for digital education technology to protect from intervention by intellectual (near-) monopolies. Intellectual monopolies are companies that build their wealth by excessive monopolising access to knowledge and converting it into intellectual rents, a type of intangible assets.
The thesis are examined against the background of an overarching perspective on society as consisting of three spheres. Legal-political sphere is to develop laws and regulations; Economic sphere is about production, distribution (trading) and consumption of goods; Cultural sphere is to generate idea and knowledge. In each sphere, there also are three aspects belonging to legal-politics, economics, and culture.
The thesis consists of two parts and adopts a macro-to-micro research framework. In the first part, the research focuses on the macro-socialistic level first and then zooms in to business level (education technology) by analysing existing literature. This part investigates how intellectual monopolies emerge, first in general and then more specifically in digital education technology, and how they reduce freedom of education. More specifically, the thesis identifies economic, legal-political and cultural factors that promote intellectual monopoly in the digital industry, and explains how intellectual (near-)monopoly in digital education (e.g. in online-learning platforms, LMSs or video-conferencing software) arises as a consequence of particular relationships between the economic, legal-political and cultural sphere, where governments and international organisations give laws and regulation (e.g. IP law, education laws and regulation, the standardisation of education) that support the concentration of R&D in a few giant digital high-tech companies and the growth of (near-)monopoly positions in the digital education technology market, enabling high-tech giants to extract what in this study is called ‘learning-related rent’ (tangible and intangible assets formed by controlling learning tools and learning content), and reducing freedom of education (the core component of the cultural sphere).
In the second part, the thesis zoom in further to the university level and examines the possibilities decision-makers at universities have to expand freedom of choice in digital education technology for professors and students through a case study of a Dutch university. An interview is conducted as the main method of the case study to collect data. From the interview results, legal-political, economic and cultural hurdles in establishing free space in choosing education technology in the cultural sphere have been identified. ...

A Recommendation to Policy Makers

Master thesis (2022) - A.A. Mukhamedov, J. Ubacht, M.J.G. van Eeten, Y. Zhauniarovich, S.H. van Engelenburg, VANESSA SIMÕES DE AZEVEDO
In the past several years, financial applications of the blockchain technology experienced significant growth, development and adoption among the public and institutional investors. With the rise of stablecoins and major events such as the announcement of Facebook’s own cryptocurency Libra in 2019, the EU regulators felt the urgent need to address the digital currencies that may pose financial and security risks if left unsupervised. In 2020, the European Commission introduced the Markets in Crypto-Assets (MiCA) framework to regulate the crypto-asset issuers and service providers located in the EU or serving EU clients from abroad. One of the regulation’s objectives is to address the risks of the crypto-markets while leveraging its benefits, yet there has been no evaluation of the proposed regulation besides the Commission’s own impact assessment.

Thus, this research offers an evaluation of the MiCA framework by adopting World Economic Forum’s DeFi white paper risk framework and interviews with the industry experts to generate both qualitative and quantitative data that is used to construct policy considerations for future amendments. By conducting interviews with 8 legal experts, the study provides insights into the strengths and weaknesses of the MiCA framework, while the interviews with 2 respondents from crypto-asset issuer entities, 6 from crypto-asset service providers entities and 3 from institutional investors entities provided further insights into the perceptions of the industry participants on the EU crypto regulation. Moreover, the study presents the risk perceptions of each respondent groups as during the interview rounds the participants were presented 18 risks of DeFi and were asked to select the most 5 critical risks perceived by them. This information is used to reveal what risks are perceived by each group. Lastly, the study presents a content analysis to assess the extent to which the 18 risks ranked by the interviewees are addressed in the MiCA framework. In summary, the results of the study suggest many points of improvement to the MiCA framework with respect to definitions, scoping, classifications and the regulatory approach. Moreover, the results suggest that the policy makers should focus on the unaddressed risks in the future amendments and policies, most importantly on technical and operational risks that have been left out from the framework. ...

Using a Mixed Methods Approach to investigate IT-practitioners’ decision-making and patch activity

In the current digitalised society keeping assets secure is one of the most prominent challenges organisations face. In the ongoing arms race between attackers and defenders, software security patching is a well-recognised and effective strategy to mitigate vulnerabilities in software products. However, organisations struggle with the best practice to “patch early and often”, resulting in vulnerabilities in software being exposed for much longer than desired. Prior research indicates the socio-technical nature of this practice forms the core of delays in software patch management. Developing a deeper understanding of the decision-making of IT practitioners and what socio-technical factors play a role in this process allows organisations to address the ineffectiveness of their security patch process. The main research question in this explorative research is: What socio-technical factors influence the effectiveness and timeliness of the security patching process in organisations? This Mixed Methods research combines qualitative data from interviews with IT practitioners, with a quantitative data exploration of the meaningfulness of organisational measurements. Findings show that IT practitioners go through a funnel of decision-making that influences the decision of what to patch, and when to patch. The presence and interplay of different socio-technical factors related to four main aspects of this decision (i.e., security, applicability, operability, and availability) result in tensions and trade-offs influencing the decision space of IT. Furthermore, this study indicates the interrelations between the significance of socio-technical factors, which is reduced by certain coping strategies applied by IT practitioners. This research reveals that having some measurement in place helps to understand the existence of challenges and the working of coping strategies, therefore contributing to an understanding of socio-technical challenges. However, it also reveals several limitations to the quality of existing data and difficulties in coming to measurements that provide meaningful information, due to socio-technical factors. The main contribution of this research is a better understanding of how socio-technical factors influence the decision-making process of IT practitioners. This research is limited in the way it uses quantitative data to understand patching activity. Future research is recommended to compare the potential discrepancy between what IT practitioners state influences the effectiveness of their security patch process and what the actual patching activity of IT practitioners reveals about the effectiveness of patching. This research furthermore hypothesises that not all socio-technical factors have the same level of significance. It is recommended to investigate the possibilities of quantification of the importance of each of the socio-technical challenges identified in this explorative study. ...

Evaluating Avalanche's security controls using a reconstruction of its anatomy from forensic evidence

How did Avalanche, a botnet with an active lifetime of 8 years while serving 20+ malware families, ensure a smooth operation of business? Avalanche had the attention of security researchers and law enforcement, yet it managed to persevere for a long period of time.
In this work, we answer this question by analyzing Avalanche’s security controls and its business model based on longitudinal ground truth data from its criminal investigation by German law enforcement. We first analyzed previous botnet research and identified five research challenges: (1) the botnet phenomenon keeps evolving, so continuous research is required, (2) there is not yet a framework to categorize or interpret botnet evasion techniques, (3) botnet research is challenging due to the lack of large real-world datasets, (4) botnet takedowns are challenging and costly, so other avenues for intervening in botnets should be explored, and (5) more research is being done into botnet economics, but it is mostly based on case studies methodologies without access to ground truth data.
We defined the adversarial context of botnets and showed how their responses – evasion techniques – can be interpreted as security controls according to deviant security theory. We created a framework for categorizing these security controls, based on security control types and the type of threat. Turning to our data, we performed an exploratory analysis in which we processed, validated and interpreted the available data based on their different types: server images, network data and databases. Based on the insights from this analysis, we applied the business model canvas and described Avalanche’s business model. We describe how Avalanche provides it customers with proxying and domain registration services, generating on aver- age $7,500 of revenue per month from 59 customers. We identified seven security controls, three technical controls and four administrative controls, that were applied to evade detection, to increase resilience against takedowns and to conceal the ownership by the botnet operators.
Our findings show that Avalanche configured itself to adequately respond to the threats in its adversarial context. Its business model – through using different key partners and many replaceable resources – and its application of security controls – such as backups, bot monitoring and proxy architecture – created redun- dancy in Avalanche’s operation, allowing it to detect and resolve threats quickly. ...

Understanding the impact of security training on the security behaviour of employees within an organisational context

Master thesis (2021) - B.A.P. van den Kieboom, S.E. Parkin, M.J.G. van Eeten, F.W. Guldenmund
Research shows that most of the security issues arise through human shortcomings, instead of technical issues (Abawajy, 2014). Therefore, users of information systems have to become more security aware. The reasonable solution to these human shortcomings was to provide users with policies that tell them what to do and have the technical systems behind them for support. However, within an organisational environment, information technology is increasingly needed for the completion of work activities. This creates problems for users to follow policies that require an excessive amount of effort and introduces human errors. Mainly caused by employees feeling like the amount of effort is unreasonable and not fitting into their daily work activities (Kirlappos, Parkin, & Sasse, 2014). Subsequently, cyber attacks are mostly caused by liabilities created due to the human error and social engineering (Schneier, 2015). Therefore, it is of importance for organisations to find a way to manage security in an effective manner, by taking into account the interactions between the social and physical environment. Accordingly, there is a possibility that employees find complying to security rules and procedures to have higher costs than benefits to their company. Finally, it is fundamental to find aspects where the business and security processes clash, in order to improve the security and productivity of the organisation (Beautement, Becker, Parkin, Krol, & Sasse, 2016). ...

Solving IoT vulnerabilities through governance

Master thesis (2021) - T. de Roon, S.E. Parkin, M.J.G. van Eeten, J. Ubacht, R. Krenn
Connecting ‘things’ like a doorbell, webcam, lamp, or other objects to the web to provide a service or control is called the Internet of Things (IoT). These devices contain vulnerabilities that form risks for the device user and possibly the network owner through their heterogeneity. The identified knowledge gap is the need for more IoT governance but no specification on governance options and means to reach specific stakeholders. Using a dataset of network scan data of The Hague as the empirical context for the defined knowledge gap, this research aims to look into the vulnerabilities IoT devices carry, and then look into relevant stakeholders to see what they can do through governance and why they are not doing this. To answer the main research question: How can the municipality of The Hague use governance instruments to decrease cyber vulnerabilities in IoT devices?
Using a literature study to define IoT concepts and the governance of IoT and current governance examples, background information is provided for the rest of this research. The database of 1649 IP addresses of network scan data from the area of The Hague is then used to find what vulnerabilities are present and what stakeholders are identifiable from this data. Exploring this network scan data showed only 191 devices are fully identifiable from the total number of IP addresses. These devices all carry vulnerabilities for the user of these devices, and being visible is by itself a vulnerability. No device owners could be directly identified, only the providers of the networks these devices are found in. This results in the identifiable stakeholders from the dataset: ISPs and device manufacturers.
Governance options are defined for these stakeholders (e.g. security-by-design, informing users etc.). These options are assessed on viability and validity through semi-structured interviews with three ISPs and the municipality.
The conclusion found is that the most viable action to take is informing device users since secure configuration and usage of a device would take away vulnerabilities while waiting for European legislation to be implemented. This legislation will force more security-by-design. The recommendation for the municipality is to take the role of leading actor, provide a better problematization with the data available, and use this to generate more urgency with other stakeholders. Starting public-private partnerships (with ISPs, device vendors, universities, other municipalities: different perspectives to progress the problem) and starting information campaigns and therefore try to reach as many people as possible. Even though ISPs can not provide in reaching vulnerable users directly, they can help in general information campaigns. Increasing security practices on the user side while waiting for legislation on the manufacturer's side.
...

Evaluating Cyber Threat Intelligence Feeds Using Quantitative Metrics and User Appreciation Scores

Master thesis (2021) - Jelle Egbers, M.J.G. van Eeten, M.E. Warnier, A.J. Klievink, X.B. Bouwman
In the battle against ever-changing cyber threats, a new ally has joined in: Cyber Threat Intelligence. Evolved from historical blacklists and anti-virus, Threat Intelligence aims to protect and inform its clients against both nation state actors, as well as cyber criminals. Threat Intelligence comes in many shapes and sizes, and for a wide range of prices. For the average consumer of Threat Intelligence, it is unknown which form will fit their needs, nor which price range is suitable for them.

This mystery surrounding Threat Intelligence, caused by its prohibitively high pricing, shows in the limited amount of research that has been conducted on the topic. Bouwman et al. lifted a tip of the veil, interviewing professionals regarding their use of Threat Intelligence and presenting descriptive statistics of its contents. They found very limited overlap between Threat Intelligence sources and that acquisition is largely based on gut-feeling. However, it is still largely unknown if these findings generalize to the whole field of Threat Intelligence and if these findings on macro level translate to more granular levels, it is our goal to find this out. ...
Master thesis (2019) - Bas Stinenbosch, Pieter Hartel, Michel van Eeten, Rolf van Wegberg, Gert Jan van Hardeveld
Background: A lot of scientists have tried to shed light on dark web markets. They did this by scraping these marketplaces over a period of time and describe what they were seeing. However, the methods used to measure these markets were never validated before. Research goal: This research will identify and validate the methods that are used in the literature to measure darknet marketplaces. Methods: To validate these methods, a novel dataset is used, namely the confiscated backend of a market. This dataset is cleaned and used to analyze the accuracy of these proxies on. Results: It is found that the number of transactions, revenue, and market share can be estimated with a high amount of explained variance. The predictions are precise enough to find prominent vendors on the market. The designed method of calculating the illegally obtained profits of a darknet vendor is easy to understand and could be used by law enforcement agencies. Finally, it is found that some vendors register to a market early as a strategy to ensure their business continuity. ...
Malicious software such as botnets are a threat to society and increasingly so through Internet of Things (IoT) devices. The large volume, pervasiveness and high vulnerability of IoT devices make them low hanging fruit for malicious actors. Currently, the biggest threat for insecure IoT devices is Mirai, a botnet which is deployed for DDoS attacks. Home users often fail to detect and resolve Mirai on their IoT devices. For this reason, Internet Service Providers (ISP) increasingly take efforts to increase remediation. Sending their infected customers a notifications containing cleanup instructions is currently the most feasible measure on a large scale. However, previous studies point out that it is not clear how people process these notifications, if they comply with it and how this effects the remediation rate and speed. The central research question of this study is ‘What is the role of IoT device end users in Mirailike bot remediation?’. We have conducted an eight-week experiment at the KPN Abuse Desk that notifies customers about abuse incidents. 177 Mirai-infected consumers have been randomly assigned to a walled garden notification (i.e., a quarantined environment), an e-mail notification, or control group. All subjects within the experiment have been tracked for two weeks to estimate the infection time and are contacted afterward for interview purposes. Male consumers and consumers younger than 54 years possess relatively more often a Miraiinfected device compared to other consumers. Both e-mail and walled garden notifications are effective in reaching consumers, informing them and encouraging them to take action. The majority of consumers do not follow the recommendations provided by the notification. In contrast, the number of actions that are performed while not mentioned in the notifications is remarkably high. Since many consumers asked for additional help, we conclude that consumers appear don’t have a full understanding of how to tackle the problem. In the control group, several consumers remediated Mirai unintentionally. However, these cases do not explain all observed remediation. Using two survival analysis modeling techniques, we find that consumers placed in a walled garden have a 29% to 85% shorter infection time than other consumers. We conclude that there is a discrepancy between stated behavior and the actual behavior of consumers. Although we cannot observe all cleanup efforts of consumers, we observed that awareness of the Mirai-infection and the intention to comply with the recommended actions influence that unobserved behavior. Gender also influences the unobserved behavior. Women clean up their device quicker than men while their statements during the interviews contradict this. One explanation is that women may unintentionally clean up their device. We conclude that age, consumer market, device type and customer satisfaction have no significant influence on remediation. We believe that it is unlikely that all unexplained remediation can be attributed to the unobserved behavior. We thus cannot explain all observed remediation from the user perspective. Therefore, we argue that future work must also focus on the attacker perspective. Since we only observed Mirai-infections, we cannot exclude the possibility that competing malware confiscated infected devices within our experiment. In addition, novel Mirai variants may have evolved scanning behavior which obstructed proper detection of infected bots. ...