Evidence-Driven Security Analysis
Examining security mechanisms, interfaces, attacks, and user behavior to identify where risks appear and where designs can be improved.
About
Digital Identity Security · Usability · Human-Centered Cybersecurity
I am an Assistant Professor of Computer Science and a cybersecurity researcher working on digital identity, authentication security, security usability, and the interaction between people and security systems.
I study how security mechanisms behave in real-world use, where technical design, human decisions, interface choices, and attacker behavior all come together.
What I Do
My work focuses on the intersection of cybersecurity, privacy, usability, and user interaction. I am particularly interested in security mechanisms that require people to interpret information, recognize risk, and make decisions during authentication.
I study security systems as people actually use them, not only as they are expected to operate in ideal conditions. That means looking beyond whether a protocol is technically sound and asking what happens when the system is deployed, the interface becomes part of the decision, and the user is distracted, under pressure, or facing a convincing attack.
My goal is to contribute to systems that provide strong technical protection while also making security decisions clearer and more manageable for the people who depend on them.
A technically strong security mechanism can still become vulnerable when its interface is confusing, its warnings are easy to ignore, or its protection depends too heavily on constant user attention.
I therefore treat usability as part of security design rather than something added after the security mechanism has already been built.
Areas of Expertise
My work spans authentication technologies, password security, phishing-resistant systems, and the human decisions that influence whether security mechanisms succeed in practice.
Problems I Work On
I focus on security problems that emerge when technical protection, attacker behavior, system design, and human decision-making interact.
I study how authentication requests can provide enough context for users to distinguish a legitimate action from an unexpected or fraudulent request.
I examine how authentication mechanisms can provide strong protection while keeping security decisions clear, understandable, and manageable for users.
I explore designs that make the system itself more resistant to phishing and misuse instead of relying entirely on users to recognize every threat.
Focus Areas
These areas bring together security research, system design, authentication technology, and the way people interact with security decisions.
I study how authentication prompts, contextual information, and interface design influence a user's ability to recognize legitimate and fraudulent requests.
I investigate approaches for generating strong, site-specific credentials without relying on a traditional vault that stores every password.
I examine technologies and system designs that reduce the opportunity for phishing attacks to succeed, including cases where an attacker can present a convincing interface to the user.
I study how strong security controls can remain understandable and practical without creating unnecessary complexity for the user.
I examine how interface design, repeated prompts, context, time pressure, and user attention can influence security decisions.
I am interested in systems that protect digital identity while balancing strong authentication, access control, security, and user experience.
What I Bring
I approach cybersecurity problems by combining technical analysis with an understanding of how systems behave when people use them in real environments.
Examining security mechanisms, interfaces, attacks, and user behavior to identify where risks appear and where designs can be improved.
Translating technical security problems and research findings into clear explanations that can support researchers, technical teams, and decision-makers.
Treating technical protection and usability as parts of the same security system rather than competing objectives.
Academic Background
My academic background provides the foundation for my work in computer science, cybersecurity, authentication, and human-centered security.
Doctoral research focused on the security and usability of emerging web authentication paradigms.
Dissertation: “On the Security and Usability of New Authentication Paradigms for Web Authentication.”
Advisor: Dr. Nitesh Saxena
Graduate education in Computer Science.
Academic foundation in Computer Science.
Experience
Experience spanning cybersecurity research, higher education, and work on security systems involving authentication and user interaction.
Jazan University, Saudi Arabia
SPIES Lab, University of Alabama at Birmingham
Professional Service
Let's Work Together
I welcome conversations with researchers, organizations, technical teams, and professionals working on digital identity, authentication, phishing-resistant systems, password security, and human-centered cybersecurity.
I am also open to research collaboration, technical discussions, invited talks, educational initiatives, and projects that connect cybersecurity research with practical problems.
Connect
For collaboration, professional enquiries, academic discussions, or research-related conversations, you can contact me through my institutional email or professional profiles.
Email: mjabour [at] jazanu.edu.sa