Change search
Link to record
Permanent link

Direct link
Seid, Elias
Publications (10 of 18) Show all publications
Yao, X., Seid, E. & Blix, F. (2026). Securing Critical Electric Vehicle Charging Infrastructure: Risk Assessment and Mitigation Using MITRE TARA. In: Roberto Di Pietro; Karen Renaud; Paolo Mori (Ed.), 12th International Conference on Information Systems Security and Privacy (ICISSP 2026) - (Volume 1): . Paper presented at 12th International Conference on Information Systems Security and Privacy (ICISSP 2026), March 4-6, 2026, Marbella, Spain. (pp. 375-382). SciTePress
Open this publication in new window or tab >>Securing Critical Electric Vehicle Charging Infrastructure: Risk Assessment and Mitigation Using MITRE TARA
2026 (English)In: 12th International Conference on Information Systems Security and Privacy (ICISSP 2026) - (Volume 1) / [ed] Roberto Di Pietro; Karen Renaud; Paolo Mori, SciTePress , 2026, p. 375-382Conference paper, Published paper (Refereed)
Abstract [en]

The rapid global adoption of electric vehicles (EVs) has heightened the need for secure and resilient EV charging infrastructure. This paper presents a comprehensive threat analysis and risk assessment of EV charging systems using the MITRE Threat Assessment and Remediation Analysis (TARA) framework. Ten primary assets—spanning charge points (CP), charge point management systems (CPMS), and eMobility service providers (eMSPs)—are identified, and 41 threat scenarios are evaluated against key security properties: authentication, integrity, availability, confidentiality, non-repudiation, and authorization. Using structured methodologies such as risk cubes and weighted scoring models, each threat is quantified and visualized in a risk matrix to support prioritization. Findings highlight user credentials and CPMS authentication systems as highly vulnerable to attacks including MAC spoofing, SQL injection, and session hijacking. A countermeasure ranking model is then developed using CRRA, balancing effectiveness and cost to propose feasible mitigation strategies. This application of TARA not only demonstrates a methodical approach to cybersecurity assessment but also offers actionable insights for improving the cyber resilience of critical EV charging infrastructure.

Place, publisher, year, edition, pages
SciTePress, 2026
Series
ICISSP, E-ISSN 2184-4356
Keywords
Electric Vehicle Charging Infrastructure, Cybersecurity, MITRE TARA, Threat Analysis, Risk Assessment, Critical Infrastructure, Cyber Risk Mitigation, CPMS.
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-253601 (URN)10.5220/0014648200004061 (DOI)978-989-758-800-6 (ISBN)
Conference
12th International Conference on Information Systems Security and Privacy (ICISSP 2026), March 4-6, 2026, Marbella, Spain.
Available from: 2026-03-19 Created: 2026-03-19 Last updated: 2026-03-23Bibliographically approved
Seid, E. (2025). Adaptive Framework for Security Attack Monitoring in Cyber-Physical Systems. (Doctoral dissertation). Stockholm: Department of Computer and Systems Sciences, Stockholm University
Open this publication in new window or tab >>Adaptive Framework for Security Attack Monitoring in Cyber-Physical Systems
2025 (English)Doctoral thesis, comprehensive summary (Other academic)
Abstract [en]

The dissertation presents an adaptive security framework for cyber-physicalsystems (CPSs) to address the growing challenges posed by evolving cyberattacks. CPSs rely on seamless integration between computational and physical components, making security breaches potentially catastrophic. Traditional methods often fail to keep pace with rapidly advancing threats. The proposed framework leverages real-time monitoring and adaptive model predictive control to dynamically adjust defences based on the threat type, frequency, and severity. By forecasting the impact of various strategies, the system identifies optimal responses to enhance resilience and mitigate risks. The approach strengthens CPS security by adapting to the continuously evolving threat landscape and safeguarding system integrity and functionality.

Place, publisher, year, edition, pages
Stockholm: Department of Computer and Systems Sciences, Stockholm University, 2025. p. 118
Series
Report Series / Department of Computer & Systems Sciences, ISSN 1101-8526 ; 25-007
Keywords
Cyber-Physical Systems, Adaptive Security, Cybersecurity, Cyber Threat Intelligence, Critical Infrastructure Protection, Resilience Engineering
National Category
Computer Sciences Software Engineering Security, Privacy and Cryptography
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-245872 (URN)978-91-8107-364-5 (ISBN)978-91-8107-365-2 (ISBN)
Public defence
2025-09-30, L30, NOD-huset, Borgarfjordsgatan 12 and online via Zoom, public link is available at the department website, Kista, 14:00 (English)
Opponent
Supervisors
Available from: 2025-09-05 Created: 2025-08-22 Last updated: 2025-08-29Bibliographically approved
Seid, E., Busheva, R., Blix, F. & Popov, O. (2025). Advancing Cybersecurity: Semi-Automated Penetration Testing for Enhanced Vulnerability Detection. Procedia Computer Science, 263, 350-358
Open this publication in new window or tab >>Advancing Cybersecurity: Semi-Automated Penetration Testing for Enhanced Vulnerability Detection
2025 (English)In: Procedia Computer Science, E-ISSN 1877-0509, Vol. 263, p. 350-358Article in journal (Refereed) Published
Abstract [en]

In the face of increasing cyberattacks, organizations today depend heavily on information technology resources, making regular penetration testing crucial for identifying system vulnerabilities and potential exploits. While automated vulnerability management tools are widely used, they often present challenges such as result interpretation, irrelevant findings, and overwhelming volumes of data that complicate the extraction of critical information. Manual penetration testing, on the other hand, offers greater flexibility, enabling professionals to tailor their methods to the specific characteristics of a given environment. This study focuses on semi-automated penetration testing, blending automated efficiency with manual adaptability, to identify vulnerabilities in a web application, providing insights into optimizing vulnerability detection processes.

Keywords
cybersecurity, penetration testing, manual testing, automated testing, vulnerabilities, tools, severity
National Category
Computer Sciences
Research subject
Computer and Systems Sciences; Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-245870 (URN)10.1016/j.procs.2025.07.043 (DOI)
Available from: 2025-08-22 Created: 2025-08-22 Last updated: 2025-08-28Bibliographically approved
Ferzali, A., Mengistu, N., Seid, E. & Blix, F. (2025). Cloud Security Misconfigurations and Compliance: An Empirical Model for DORA Readiness in Financial Environments. In: Alexander Lawall; Fan Wu (Ed.), SECURWARE 202: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies. Paper presented at SECURWARE 2025, The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, Barcelona, Spain, 26-30 October, 2025. (pp. 139-146). International Academy, Research and Industry Association (IARIA)
Open this publication in new window or tab >>Cloud Security Misconfigurations and Compliance: An Empirical Model for DORA Readiness in Financial Environments
2025 (English)In: SECURWARE 202: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 139-146Conference paper, Published paper (Refereed)
Abstract [en]

The increasing reliance of financial institutions on cloud infrastructures has amplified concerns surrounding regulatory compliance and cybersecurity, particularly in light of the EU’s Digital Operational Resilience Act (DORA). This paper presents an experimental, empirical model designed to assess security misconfigurations in Amazon Web Services (AWS) and evaluate their alignment with DORA compliance requirements. Leveraging a Python-based scanning script built with the AWS Boto3 SDK, the study programmatically inspects critical AWS services—S3, Elastic Compute Cloud (EC2), Identity and Access Management (IAM), and Virtual Private Cloud (VPC) —within a controlled environment configured with known vulnerabilities. Each misconfiguration is automatically mapped to relevant DORA articles (Articles 5, 9, and 10), and accompanied by actionable remediation strategies. The results, visualized through a Streamlit dashboard and exportable PDF reports, demonstrate the tool’s ability to detect compliance gaps in real-time. Unlike previous work based on theoretical models or manual audits, this research offers a replicable, data-driven approach that bridges the gap between technical vulnerabilities and regulatory mandates. By doing so, it empowers financial institutions to strengthen their operational resilience and proactively align with emerging regulatory standards in dynamic cloud ecosystems.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2025
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords
Cloud Security; DORA Compliance; Financial Institutions; AWS Misconfigurations; Operational Resilience; Regulatory Technology (RegTech); Cybersecurity Governance Identity and Access Management (IAM).
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250021 (URN)9781685583064 (ISBN)
Conference
SECURWARE 2025, The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, Barcelona, Spain, 26-30 October, 2025.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved
Adesina, A., Seid, E., Blix, F. & Popov, O. (2025). Compliance Standards and Frameworks and Its Implications on Cyber security: A NIS2 Study Within the Swedish Automotive Industries. In: Proceedings of the 11th International Conference on Information Systems Security and Privacy - Volume 1: . Paper presented at ICISSP, Porto, Portugal, 2025 (pp. 367-376). Science and Technology Publications, Lda
Open this publication in new window or tab >>Compliance Standards and Frameworks and Its Implications on Cyber security: A NIS2 Study Within the Swedish Automotive Industries
2025 (English)In: Proceedings of the 11th International Conference on Information Systems Security and Privacy - Volume 1, Science and Technology Publications, Lda , 2025, p. 367-376Conference paper, Published paper (Refereed)
Abstract [en]

Cyber security standards and regulations are pivotal in guiding organizations toward mitigating cyber risks and enhancing their overall security posture. The European Union’s NIS2 Directive, which introduces stringent and comprehensive security requirements, exemplifies a Current regulatory framework designed to address evolving cyber threats. This study critically examines the regulatory, governance, cyber security, and compliance challenges introduced by NIS2 within the Swedish automotive industry. It further explores the strategic integration of NIS2 with existing regulatory frameworks to streamline compliance approaches and foster long term resilience. The findings reveal the increasing complexity and financial implications of compliance, while also identifying significant opportunities to bolster cyber security resilience. This paper underscores the necessity for organizations to adopt proactive and adaptive strategies in response to the dynamic European regulatory landscape. While the focus is on the Swedish automotive sector, the study provides valuable insights that may inform future research into the broader implications of NIS2 across diverse industries and regions within the European Union.

Place, publisher, year, edition, pages
Science and Technology Publications, Lda, 2025
Series
International Conference on Information Systems Security and Privacy, E-ISSN 2184-4356 ; 1
Keywords
Automotive Industry, Complexities, Compliance, Cyber security, Cyber security Frameworks, EU Regulations, NIS2 Directive, Organisational Preparedness, Standards
National Category
Computer Sciences Law
Identifiers
urn:nbn:se:su:diva-243126 (URN)10.5220/0013321200003899 (DOI)2-s2.0-105001818679 (Scopus ID)
Conference
ICISSP, Porto, Portugal, 2025
Available from: 2025-05-12 Created: 2025-05-12 Last updated: 2025-05-12Bibliographically approved
Seid, E., Blix, F. & Popov, O. (2025). Cyber Resilience Using ASFA: DORA-Compliant Threat-Led Penetration Testing. In: Gabriele Oliva, Stefano Panzieri, Bernhard Hämmerli, Federica Pascucci, Luca Faramondi (Ed.), Critical Information Infrastructures Security: 19th International Conference, CRITIS 2024, Rome, Italy, September 18–20, 2024, Revised Selected Papers. Paper presented at The 19th International Conference on Critical Information Infrastructures Security (CRITIS 2024), September 18–20, 2024, Rome, Italy. (pp. 269-288). Springer Nature
Open this publication in new window or tab >>Cyber Resilience Using ASFA: DORA-Compliant Threat-Led Penetration Testing
2025 (English)In: Critical Information Infrastructures Security: 19th International Conference, CRITIS 2024, Rome, Italy, September 18–20, 2024, Revised Selected Papers / [ed] Gabriele Oliva, Stefano Panzieri, Bernhard Hämmerli, Federica Pascucci, Luca Faramondi, Springer Nature , 2025, p. 269-288Conference paper, Published paper (Refereed)
Abstract [en]

The financial sector is experiencing an increase in cyber incidents, prompting numerous firms to outsource IT infrastructure management. A primary factor contributing to these breaches is that the impacted systems are socio-technical systems (STSs), which include not only technical components such as software and hardware but also physical elements (e.g., robotics, mobility) and social components (e.g., human actors, business processes, and organizational units). Evaluating STS security breaches requires a holistic approach, considering human, organizational, software, and infrastructural elements. The study involves combining strategic factors, including social and organizational dynamics, with technical components such as software and physical infrastructure.

In our previous work, we developed a security attack-monitoring system to tackle these challenges. This framework was developed to monitor, analyze, and model security incidents across the social, cyber, and physical dimensions of cyber-physical systems (CPS). This paper employs the framework to conduct threat-led penetration testing in accordance with the Digital Operational Resilience Act (DORA), thus improving the financial sector’s capacity to address information and communication crises. This study provides important insights into cyberattacks and their impact on the financial sector by examining security breaches reported to the Swedish Civil Contingencies Agency (MSB) by critical service providers. The experiment was performed in collaboration with a prominent Swedish financial institution.

Place, publisher, year, edition, pages
Springer Nature, 2025
Series
Lecture Notes in Computer Science (LNCS), ISSN 0302-9743, E-ISSN 1611-3349
Keywords
Incident Reporting, DORA, Cybersecurity, Cyber-Resilience, Risk Management, Penetration Testing
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-240585 (URN)10.1007/978-3-031-84260-3_16 (DOI)2-s2.0-105000827523 (Scopus ID)978-3-031-84260-3 (ISBN)978-3-031-84259-7 (ISBN)
Conference
The 19th International Conference on Critical Information Infrastructures Security (CRITIS 2024), September 18–20, 2024, Rome, Italy.
Available from: 2025-03-10 Created: 2025-03-10 Last updated: 2025-08-22Bibliographically approved
Seid, E., Deniz, I., Blix, F. & Popov, O. (2025). Cyber Supply Chain Resilience: Analyzing ISO, NIST, and NIS2 Frameworks for Mitigating Third-Party Risks. Procedia Computer Science, 263, 591-599
Open this publication in new window or tab >>Cyber Supply Chain Resilience: Analyzing ISO, NIST, and NIS2 Frameworks for Mitigating Third-Party Risks
2025 (English)In: Procedia Computer Science, E-ISSN 1877-0509, Vol. 263, p. 591-599Article in journal (Refereed) Published
Abstract [en]

The growing frequency of cyber-attacks on supply chains has jeopardized organizational integrity and data security, underscoring the need to strengthen Cyber Supply Chain Risk Management (CSCRM) frameworks. This paper explores the application, effectiveness, and challenges of three key frameworks—ISO, NIST, and NIS2—in mitigating third-party risks within the cyber supply chain. Using an empirical research approach, data was collected from domain experts in the field of information security. The analysis focuses on how effectively these frameworks enhance organizational data security and the practices surrounding their adoption and implementation. This study contributes valuable insights to CSCRM practices, offering actionable findings for organizations seeking to bolster their cyber defenses. The results also provide policymakers with a deeper understanding of the challenges that need to be addressed for future improvements in CSCRM frameworks.

Keywords
Cyber Supply Chain Risk Management (CSCRM), Third-party cyber risks, Cybersecurity frameworks, ISO, NIST, NIS2
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-245871 (URN)10.1016/j.procs.2025.07.071 (DOI)2-s2.0-105013959898 (Scopus ID)
Available from: 2025-08-22 Created: 2025-08-22 Last updated: 2025-09-09Bibliographically approved
Guo, H., Seid, E., Li, Y. & Blix, F. (2025). Evaluating User Perceptions of Privacy Protection in Smart Healthcare Services. In: Alexander Lawall; Fan Wu (Ed.), SECURWARE 2025: The 19th International Conference on Emerging Security Information, Systems and Technologies. Paper presented at SECURWARE 2025,The 19th International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain. (pp. 132-138). International Academy, Research and Industry Association (IARIA)
Open this publication in new window or tab >>Evaluating User Perceptions of Privacy Protection in Smart Healthcare Services
2025 (English)In: SECURWARE 2025: The 19th International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 132-138Conference paper, Published paper (Refereed)
Abstract [en]

As smart healthcare services rapidly evolve, ensuring user privacy has become a critical concern. While prior research has focused extensively on technical solutions, the user perspective on privacy protection remains underexplored. This study addresses that gap by examining how users perceive both technical and organizational privacy protection measures across four smart healthcare service types: wearable devices, mobile health apps, telehealth platforms, and medicine delivery systems. Through qualitative survey, the study uncovers a duality in user perceptions. Positive perceptions relate to multi-layer technical safeguards, regulatory oversight (e.g., General Data Protection Regulation (GDPR), Health Insurance Portability and Accountability Act (HIPAA), and proactive provider practices, such as transparent privacy policies and breach responses. On the other hand, negative perceptions center on lack of transparency, limited user control, forced consent to privacy terms, and both cognitive and operational barriers to engaging with privacy features. These findings reveal a critical imbalance in user-provider power dynamics and call for user-centric privacy strategies that balance protection with usability. The study contributes to theoretical advancements in privacy calculus, Technology Acceptance Model (TAM), and Unified Theory of Acceptance and Use of Technology (UTAUT) by refining constructs, such as perceived control, facilitating conditions, and transparency. Practical recommendations are offered to guide more inclusive, adaptable, and empowering privacy solutions in smart healthcare contexts.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2025
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords
Privacy protection measures, privacy-preserving techniques, smart healthcare, users’ perception.
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250023 (URN)9781685583064 (ISBN)
Conference
SECURWARE 2025,The 19th International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved
Seid, E., Popov, O. & Blix, F. (2025). Security Engineering in Cyber-Physical Systems: A Systematic Review of Methodological Approaches. In: Mike Mannion, Tomi Mannisto, Leszek Maciaszek (Ed.), Proceedings of the 20th International Conference on Evaluation of Novel Approaches to Software Engineering ENASE: Volume 1. Paper presented at 20th International Conference on Evaluation of Novel Approaches to Software Engineering, ENASE2025, 4-6 April 2025, Proto, Portugal. (pp. 822-834). SciTePress
Open this publication in new window or tab >>Security Engineering in Cyber-Physical Systems: A Systematic Review of Methodological Approaches
2025 (English)In: Proceedings of the 20th International Conference on Evaluation of Novel Approaches to Software Engineering ENASE: Volume 1 / [ed] Mike Mannion, Tomi Mannisto, Leszek Maciaszek, SciTePress , 2025, p. 822-834Conference paper, Published paper (Refereed)
Abstract [en]

Ensuring strong security in Cyber-Physical Systems (CPS) is increasingly essential as these systems become integral to contemporary industrial and societal infrastructures. The increasing prevalence of security risks requires the advancement of conventional security engineering approaches to tackle the distinct problems presented by CPS. This study offers a thorough assessment of the research methodologies, approaches, and strategies used in security engineering for cyber-physical systems over the last fifteen years. The review analyses the design and execution of security solutions, including empirical and conceptual investigations, along with the integration and enhancement of existing methodologies. This study seeks to offer a systematic overview of contemporary developments and pinpoint methodological concerns essential for future research in adaptive and security engineering -driven for CPS through an analysis of diverse literature. This study enhances the current discussion by providing a thorough analysis of the research environment, demonstrating the requirement for new and contextually relevant security engineering methodologies.

Place, publisher, year, edition, pages
SciTePress, 2025
Series
Proceedings of the International Conference on Evaluation of Novel Approaches to Software Engineering (ENASE), E-ISSN 2184-4895
Keywords
Cyber-Physical Systems Security, Cybersecurity Frameworks, Security Model, Quantitative Research, Qualitative Research, Cyber-Physical System, Security Engineering, Threat Modeling, Cyber Risk.
National Category
Software Engineering
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-243644 (URN)10.5220/0013478100003928 (DOI)978-989-758-742-9 (ISBN)
Conference
20th International Conference on Evaluation of Novel Approaches to Software Engineering, ENASE2025, 4-6 April 2025, Proto, Portugal.
Available from: 2025-05-27 Created: 2025-05-27 Last updated: 2025-05-28Bibliographically approved
Song, D., Li, Y., Berzinji, A. & Seid, E. (2025). Towards Automated Penetration Testing Using Inverse Soft-Q Learning. In: Alexander Lawall; Fan Wu (Ed.), SECURWARE 2025: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies. Paper presented at SECURWARE 2025 : The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain. (pp. 62-68). International Academy, Research and Industry Association (IARIA)
Open this publication in new window or tab >>Towards Automated Penetration Testing Using Inverse Soft-Q Learning
2025 (English)In: SECURWARE 2025: The Nineteenth International Conference on Emerging Security Information, Systems and Technologies / [ed] Alexander Lawall; Fan Wu, International Academy, Research and Industry Association (IARIA) , 2025, p. 62-68Conference paper, Published paper (Refereed)
Abstract [en]

Penetration testing (pentesting), a proactive defensive practice for identifying vulnerabilities and supporting cybersecurity management, has traditionally been conducted manually due to its heavy reliance on specialized knowledge of human experts. In this paper, we propose PT-ISQL, an automated PenTesting approach based on Inverse Soft-Q Learning (ISQL), an imitation learning algorithm that enables efficient policy learning from expert demonstrations. PT-ISQL trains an agent to take optimal actions when interacting with the pentesting environment by effectively mimicking expert behavior. Our evaluation shows that PT-ISQL achieves high performance using significantly fewer expert demonstrations compared with generative adversarial imitation learning approaches. Furthermore, it demonstrates faster convergence, improved stability, and reduced training overhead. These results suggest that PT-ISQL is a promising and practical solution for scalable, automated penetration testing.

Place, publisher, year, edition, pages
International Academy, Research and Industry Association (IARIA), 2025
Series
International Conference on Emerging Security Information, Systems and Technologies, E-ISSN 2162-2116
Keywords
penetration testing, deep reinforcement learning, imitation learning, inverse soft-Q learning, PT-ISQL
National Category
Computer Sciences
Research subject
Computer and Systems Sciences
Identifiers
urn:nbn:se:su:diva-250029 (URN)9781685583064 (ISBN)
Conference
SECURWARE 2025 : The Nineteenth International Conference on Emerging Security Information, Systems and Technologies, 26-30 October, 2025, Barcelona, Spain.
Available from: 2025-11-27 Created: 2025-11-27 Last updated: 2025-12-03Bibliographically approved
Organisations

Search in DiVA

Show all publications