PALANTIR : An NFV-Based Security-as-a-Service Approach for Automating Threat Mitigation
Maxime Compastié, Antonio López Martínez, Carolina Fernandez, Manuel Gil Pérez, Stylianos Tsarsitalidis, George Xylouris, Izidor Mlakar, Michail Alexandros Kourtis, Valentino Šafran, 2023, izvirni znanstveni članek

Opis: Small and medium enterprises are significantly hampered by cyber-threats as they have inherently limited skills and financial capacities to anticipate, prevent, and handle security incidents. The EU-funded PALANTIR project aims at facilitating the outsourcing of the security supervision to external providers to relieve SMEs/MEs from this burden. However, good practices for the operation of SME/ME assets involve avoiding their exposure to external parties, which requires a tightly defined and timely enforced security policy when resources span across the cloud continuum and need interactions. This paper proposes an innovative architecture extending Network Function Virtualisation to externalise and automate threat mitigation and remediation in cloud, edge, and on-premises environments. Our contributions include an ontology for the decision-making process, a Fault-and-Breach-Management-based remediation policy model, a framework conducting remediation actions, and a set of deployment models adapted to the constraints of cloud, edge, and on-premises environment(s). Finally, we also detail an implementation prototype of the framework serving as evaluation material.
Ključne besede: Security-as-a-Service, security orchestration, policy-driven management, virtual network functions, finite state machines, constraints programming
.pdf Celotno besedilo (963,42 KB)
Visiting nuclear reactors : safety and security aspects
Barbara Pavlakovič, 2022, izvirni znanstveni članek

Opis: Visiting nuclear reactors is a niche tourism offer within energy (industrial) tourism, which leads tourists through areas that are not primarily meant for them. Hence, safety and security issues are even more critical in this case. This study aims to highlight different aspects of safety and security issues in nuclear power plant tours and to present measures taken to address these concerns. In addition, we studied the connection between plant visits and the public image of nuclear energy. Information was gathered through participant observation (personal visits of factory tours) and an online survey. There, we identified safety and security nuclear power plant visit protocols and a positive correlation between the visit variable and the two variables of the public image of nuclear energy, which suggests energy (industrial) tourism as a suitable tool to enhance awareness and knowledge about nuclear energy.
Ključne besede: Nuclear power plants, Energy (industrial) tourism, Safety, Security, Risk, Participant observation
.pdf Celotno besedilo (508,34 KB)
Home gardening and food security concerns during the COVID-19 pandemic
Maja Turnšek, S. L. Gangenes Skar, Marit Piirman, Ragnheidur Thorarinsdottir, Martina Bavec, Ranka Junge-Berberovic, 2022, izvirni znanstveni članek

Opis: At times of crisis, home gardening has often been sought out as a potential solution for threats to food security and as a measure to increase socio-psychological effects, such as public sense of self-efficacy, trust in the government and care for one’s wellbeing. The objective of this study was to investigate if home gardening increased during the COVID-19 pandemic in the spring/summer of 2020 and to provide socio-psychological insights into the explanatory factors of such an increase. An explanatory theoretical model of home gardening was proposed and tested to analyse whether home gardening is correlated to food security concerns, and if so, to what extent. A nonrepresentative survey was conducted in five European countries (Slovenia, Norway, Estonia, Switzerland, and Iceland) using snowball sampling via social media networks, reaching 1144 participants. The results showed the pandemic did prove to be an important psychological push towards home gardening prompted by food security concerns. Measured as loose as introducing at least one new gardening activity during COVID-19, this study found an approximately 10% increase in home gardening during the first wave of COVID-19 in the sample population, which was skewed towards educated, female, middle-class Europeans.
Ključne besede: food security, home gardening, COVID-19, food security concerns, wellbeing, behavioural change, protection motivation theory
.pdf Celotno besedilo (2,27 MB)
Work of Ljubljana’s Municipal Warden Service – from repression to prevention and collaboration
Tinkara Bulovec, Roman Fortuna, 2023, izvirni znanstveni članek

Opis: Purpose: This article highlights the work of Ljubljana’s Municipal Warden Service (MWS), emphasizing the application of criminological knowledge in both preventive and repressive efforts. Design/Methods/Approach: We performed both qualitative and quantitative analyses using data from the SUDMR and PowerBI apps, employed by municipal wardens to track preventive actions and map repressive measures. Findings: In recent years, there has been a significant increase in both repressive and preventive actions of municipal wardens, with 115,453 measures implemented and 2,752 hours allocated to preventive work in 2022. The majority of repressive measures targeted road-related offenses. Community-oriented work and engagement were prioritized, especially in the densely populated city centre, focusing on road traffic and vulnerable road users. Integrating the apps used by MWS with criminological knowledge supports future planning, implementation, and justification of measures, as well as urban planning. Besides, mutual cooperation and exchange of information between MWS and other stakeholders are key to comprehensive security provision in the local environment. Research Limitations/Implications: A key limitation is that we only analysed repressive and preventive measures conducted by the MWS Ljubljana in 2022. Practical Implications: Applying criminological findings to municipal warden work is effective. Utilizing hot spot displays supports informed decision-making and preventive strategies. In instances where general prevention methods and misdemeanour procedures prove ineffective in ensuring public safety and preventing violations, particularly findings from the field of prevention, community policing and plural policing, can be useful. Originality/Value: This study is pioneering with a unique approach, utilizing new methodologies and perspectives to explain and validate the work of municipal wardens.
Ključne besede: Municipal Warden Service, City of Ljubljana, criminological findings, prevention, repression, local safety and security
URL Povezava na datoteko
Role of corporate security in healthcare institutions during the COVID-19 epidemic
Dejan Pavlović, 2023, izvirni znanstveni članek

Opis: Purpose: This study examines the vital role of corporate security in healthcare institutions during the epidemic and underscores its significance. It also presents the perspectives of healthcare employees on corporate security. The aim is to provide insights into the current state of corporate security in Slovenia and offer recommendations for enhancement. Design/Methods/Approach: Procedures employed encompass a descriptive approach and a synthesis of existing knowledge. We focused on corporate activity within organizations, particularly emphasizing effective corporate security. A review of domestic and foreign literature provided context, while a quantitative survey questionnaire gathered empirical data. The questionnaire included 18 closed questions on a 5-point Likert scale, along with socio-demographic data. Data analysis utilized IBM SPSS version 23.0. Findings: The main goal of corporate security is to ensure the safety of people in each organisation (in our case, healthcare institutions). Healthcare institutions, especially hospitals, are critical infrastructures are in constant operation; therefore, an institution must be protected 24 hours a day. According to health facility staff, on average security during the epidemic was adequate, and the organisation of security was well planned. Research Limitations/Implications: The results of the study provide a starting point for further research in the area of the topic addressed, while also serving to inform professionals and the general public about the topic. Originality/Value: The study a starting point for empirical studies that will address corporate security in relation to healthcare institutions.
Ključne besede: corporate security, COVID-19, sense of security, healthcare institutions, security risks
URL Povezava na datoteko
Identifying key activities, artifacts and roles in agile engineering of secure software with hierarchical clustering
Anže Mihelič, Tomaž Hovelja, Simon Vrhovec, 2023, izvirni znanstveni članek

Opis: Different activities, artifacts, and roles can be found in the literature on the agile engineering of secure software (AESS). The purpose of this paper is to consolidate them and thus identify key activities, artifacts, and roles that can be employed in AESS. To gain initial sets of activities, artifacts, and roles, the literature was first extensively reviewed. Activities, artifacts, and roles were then cross-evaluated with similarity matrices. Finally, similarity matrices were converted into distance matrices, enabling the use of Ward’s hierarchical clustering method for consolidating activities, artifacts, and roles into clusters. Clusters of activities, artifacts, and roles were then named as key activities, artifacts, and roles. We identified seven key activities (i.e., security auditing, security analysis and testing, security training, security prioritization and monitoring, risk management, security planning and threat modeling; and security requirements engineering), five key artifacts (i.e., security requirement artifacts, security repositories, security reports, security tags, and security policies), and four key roles (i.e., security guru, security developer, penetration tester, and security team) in AESS. The identified key activities, artifacts, and roles can be used by software development teams to improve their software engineering processes in terms of software security.
Ključne besede: secure software development, security engineering, agile methods, agile development, software development, software engineering, software security, application security, cybersecurity, cyber resilience
.pdf Celotno besedilo (557,17 KB)
Agile development of secure software for small and medium-sized enterprises
Anže Mihelič, Simon Vrhovec, Tomaž Hovelja, 2023, izvirni znanstveni članek

Opis: Although agile methods gained popularity and became globally widespread, developing secure software with agile methods remains a challenge. Method elements (i.e., roles, activities, and artifacts) that aim to increase software security on one hand can reduce the characteristic agility of agile methods on the other. The overall aim of this paper is to provide small- and medium-sized enterprises (SMEs) with the means to improve the sustainability of their software development process in terms of software security despite their limitations, such as low capacity and/or financial resources. Although software engineering literature offers various security elements, there is one key research gap that hinders the ability to provide such means. It remains unclear not only how much individual security elements contribute to software security but also how they impact the agility and costs of software development. To address the gap, we identified security elements found in the literature and evaluated them for their impact on software security, agility, and costs in an international study among practitioners. Finally, we developed a novel lightweight approach for evaluating agile methods from a security perspective. The developed approach can help SMEs to adapt their software development to their needs.
Ključne besede: secure software development, security engineering, agile, small and medium sized enterprises, software development management, security
.pdf Celotno besedilo (2,58 MB)
Criminal Justice and Security in Central and Eastern Europe : the United Nations sustainable development goals - rural and urban safety ans security perspectives

Opis: The fourteenth international biennial conference Criminal Justice and Security in Central and Eastern Europe, organised by the Faculty of Criminal Justice and Security, University of Maribor (UM FCJS) on 12–14 September 2023, is subtitled The United Nations Sustainable Development Goals – Rural and Urban Safety and Security Perspectives and addresses current challenges related to the UN SDGs and the provision of security in local communities. Topics of the conference are related to a research project of the UM FCJS on local safety and security – rural and urban perspectives (2019-20124) based on the UN SDGs that aim at the development of democratic societies trying to achieve seventeen ambitious goals globally. The conference is also a milestone that signifies thirteen years of membership of the UM FCJS in the United Nation’s Academic Impact Network (UNAI). The book of abstracts includes more than sixty abstracts of papers presented at the conference. The main topics of this year’s conference are rural criminology, criminal justice, policing, covid-19, crime, criminality, crime prevention, perception of crime, crime analysis, safety, security, community (oriented) policing, victimology and penology. Thanks for this great academic event go to the programme and organising committees, authors, participants and conference supporters nationally and internationally.
Ključne besede: Criminal justice, criminology, UN SDGs, local, security, local, urban, rural
.pdf Celotno besedilo (9,05 MB)
Layered battleship game changer password system
Boštjan Brumen, Darko Crepulja, Leon Bošnjak, 2022, izvirni znanstveni članek

Opis: The paper presents a secure and usable variant of the Game Changer Password System, first proposed by McLennan, Manning, and Tuft. Unlike the initial proposal based on inadequately secure Monopoly and Chess, we propose an improved version based on a layered “Battleship” game resilient against brute force and dictionary attacks. Since the initially proposed scheme did not check for the memorability and usability of a layered version, we conducted an experiment on the usability and memorability aspects. Surprisingly, layered passwords are just as memorable as single ones and, with an 80% recall rate, comparable to other graphical password systems. The claim that memorability is the most vital aspect of game-based password systems cannot be disproved. However, the experiment revealed that the usability decreased to such a low level that users felt less inclined to use such a system daily or recommend it to others. Our study has once again shown that optimizing the password security–memorability–usability triangle is hard to achieve without compromising one of its cornerstones. However, the layered Game Changer Password System can be used in specific applications where usability is of secondary importance, while security and memorability augmented by its graphical interface are at the forefront.
Ključne besede: security, authentication, passwords, graphical passwords, cryptanalysis, games, memory, memorability, usability
.pdf Celotno besedilo (820,86 KB)
Cyber Security- Training Students and Scholars for the Challenges of Information and Communication Technologies in Research and Studies for Internationalisation : handbook

Opis: This handbook is a product of the Erasmus+ Strategic Partnership between the partners Université Polytéchnique Hauts-de-France, Politechnika Poznanska, Brandenburgische Technische Universität Cottbus-Senftenberg and the coordinator University of Maribor. Contentuous contribution were made by staff of University of Maribor and Politechnika Poznanska, evaluations by staff of the other two partners. The handbooks handles virtual learning environments in the international education and research area and exposure of the systems to cybercrime. Besides introductory contributions on legal aspects of challenges in the fields of human rights, European regulations of data security, civil law and criminal law aspects of caber security of virtual learning environments and methodologies of their introduction w8ithin organisations, the handbook also gives useful instructions for elaboration of virtual courses within virtual learning environments relevant for the internationalised research and education not only since the Covid-19 pandemic. The handbook is dedicated to use on the internet within the Moodle system.
Ključne besede: cyber security, virtual learning environment, data security, cyber crime, systems
.pdf Celotno besedilo (5,72 MB)
