
The increase in the number of mobile devices that use the Android operating system has attracted the attention of cybercriminals who want to disrupt or gain unauthorized access to them through malware infections. To prevent such malware, cybersecurity experts and researchers require datasets of malware samples that most available antivirus software programs cannot detect. However, researchers have infrequently discussed how to identify evolving Android malware characteristics from different sources. In this paper, we analyze a wide variety of Android malware datasets to determine more discriminative features such as permissions and intents. We then apply machine-learning techniques on collected samples of different datasets based on the acquired features' similarity. We perform random sampling on each cluster of collected datasets to check the antivirus software's capability to detect the sample. We also discuss some common pitfalls in selecting datasets. Our findings benefit firms by acting as an exhaustive source of information about leading Android malware datasets.
: This report outlines the key insights gained at the “Hello Diversity! Conference” held in June 2019 at the Freie Universität Berlin (Germany). The two-day event featured 14 talks from experts in academia and practice who shared their perspectives on how entrepreneurial diversity affects the exploration and exploitation of digital innovation potentials. Their insights highlighted the lack of holistic knowledge on the topic, especially concerning the role of digital technologies in fostering entrepreneurial diversity. The shortcomings of related discourses were debated in several panel discussions with the 170 participants involved in research or in fostering entrepreneurial diversity through management practices, policies, and special interest groups. The conference culminated in a “Paperthon”, which kick-started interdisciplinary research projects aimed at increasing our understanding of entrepreneurial diversity in the digital age.
The Association for Information Systems (AIS) is the premier professional association for individuals and organizations that lead the research, teaching, practice, and study of information systems. It serves society through advancing knowledge and promoting excellence in the practice and study of information systems. To that end, the AIS hosts seven academic journals: Journal of the Association for Information Systems (JAIS), Communications of the Association for Information Systems (CAIS), AIS Transactions on Human-Computer Interactions (THCI), AIS Transactions on Replication Research (TRR), Pacific Asia Journal of the Association for Information Systems (PAJAIS), Revista Latinoamericana y del Caribe de la Asociacion de Sistemas de Informacion (RELCASI), and Scandinavian Journal of Information Systems (SJIS). In this editorial statement, we summarize the different mission statements for each journal; describe their different audiences, goals, and markets; and identify their shared values, requirements, and resources. We do so to assist AIS members to identify the most suitable journal outlet for their research.
Younger scholars often receive advice to submit work to conferences for feedback and polishing in anticipation that they will later submit it to a journal for publication. But is this a normal practice? What do the IS scholars really think or do about the linkage between conferences and journals? What are IS journals' policies and their editors-in-chiefs' views on that linkage? This paper explores aspects of the relationship between conference presentation and journal publication, which include motivations for participating in conferences, potential for subsequent publication, preferred journal targets, and progress of paper development following conference presentation. We obtained data that form the basis for our findings and recommendations from two main sources: 1) a panel study with two sequential surveys of IS scholars who presented papers at three consecutive International Conference on Information Systems (ICIS) meetings (in St. Louis 2010, Shanghai 2011, and Orlando 2012) and 2) an email interview with the editors-in-chief of 21 major IS journals in regard to their respective journals' policies and their personal views. The paper provides recommendations for various stakeholders including scholars, journal editors, conference organizers, leaders in the field, and anyone outside the IS field who wants to understand its norms and culture.
Analysts have estimated that more than 80 percent of today's data is stored in unstructured form (e.g., text, audio, image, video)-much of it expressed in rich and ambiguous natural language. Traditionally, to analyze natural language, one has used qualitative data-analysis approaches, such as manual coding. Yet, the size of text data sets obtained from the Internet makes manual analysis virtually impossible. In this tutorial, we discuss the challenges encountered when applying automated text-mining techniques in information systems research. In particular, we showcase how to use probabilistic topic modeling via Latent Dirichlet allocation, an unsupervised text-mining technique, with a LASSO multinomial logistic regression to explain user satisfaction with an IT artifact by automatically analyzing more than 12,000 online customer reviews. For fellow information systems researchers, this tutorial provides guidance for conducting text-mining studies on their own and for evaluating the quality of others.
With this paper, we hope to foster debate about the place of open access (OA) in scholarly publishing. After providing a background to OA's development and current state, we examine some of the accusations leveled against it: that OA publishers are predatory, that OA is too expensive, and that self-depositing papers in OA repositories will bring about the end of scholarly publishing. After contextualizing each accusation, we show that they arise from problems with not only access, open or otherwise, but also the scholarly publishing system more broadly. Accordingly, we instead propose the discussions we believe the scholarly community should be having about scholarly publishing to take advantage of social and technological innovations and move it into the 21st century.
Due to several recent highly publicized information breaches, information security has gained a higher profile. Hence, it is reasonable to expect that information security would receive an equally significant emphasis in the education of future systems professionals. A variety of security standards that various entities (e.g., NIST, COSO, ISACA-COBIT, ISO) have put forth emphasize the importance of information security from the very beginning of the system development lifecycle (SDLC) to avoid significant redesign in later phases. To determine the emphasis on security in typical systems analysis and design (SA&D) courses, we examine (1) to what extent security is emphasized in the core SA&D courses and (2) at what phase in the SDLC do most SA&D courses begin to emphasize security. In order to address these questions, we reviewed SA&D textbooks currently on the market to identify how extensively they cover security-related issues. Given the fairly high awareness of information security in practice, we expected to see an equally high emphasis on such matters in the textbooks. However, our review suggests that this is not the case, which suggests a gap in our preparation. To address this gap, we offer a proposal for modifying a portion of the SA&D curricula.
With in-memory technology, all data and applications are kept in the computer's main memory to avoid expensive mechanical hard-drive I/O access, reduce latency times, and increase the ability to process large volumes of data or complex data. In this "innovation and novel concepts" article, we discuss how in-memory technology may create business value. Based on our experiences in collaborating with the Hilti Corporation, one of the first adopters of SAP's in-memory technology appliance (SAP HANA), we describe and discuss illustrative application scenarios that are made possible through the increased computing power offered by in-memory technology. Based on these scenarios, we identify principles of value creation through in-memory technology: the first-order effects of reduced latency times and increased ability to process large volumes of complex data (big data processing) that lead to the second-order effects of advanced business analytics and the convergence of OLTP and OLAP that themselves lead to business value through improved organizational performance.
This study outlines the findings of a qualitative study designed to develop an understanding of nurses' experiences using an electronic medical record system (EMR) in a mandatory usage context. Drawing upon the Unified Theory of Acceptance and Use of Technology, a combined deductive/inductive research approach was adopted to study nurses working in an urban hospital system. This approach allowed for an in-depth study of the nature and structure of mandated information systems (IS) use in a healthcare context. We found that understanding the relationship between key technology acceptance constructs and system use required a multidimensional conceptualization of usage - something not commonly found in the IS literature. We identified three facets important to gaining a holistic understanding of nurses' use of EMR technology: time spent using the system, timing of use, and mode of use. We empirically demonstrate that the dimensions of IS use can be mandated and internalized to varying degrees even within the same organization, and that the predictors of use can be differentially associated with the dimensions of use given the degree of the mandate.
The growing trend in offshore software development has imposed new skills requirements on collaborating global partners. In the U. S. this has translated into skill sets that include communications, project management, business analysis, and team management. In a virtual setting, these skills take on a complex proportion. This paper describes an educational initiative in offshore software development between undergraduate students enrolled in a project management course at Marquette University, USA and graduate business students enrolled in an Information Systems Analysis and Design course at Management Development Institute, India. The course replicated an offshore client/vendor relationship in a virtual setting. For faculty considering such initiatives, this paper describes the setting and factors critical to success of this initiative and cautions against others that can be detrimental to such an effort.
While the important role of family carers has been increasingly recognized in healthcare service provision, particularly for patients with acute or chronic illnesses, the family carer’s information needs have not been well understood or adequately supported by health information systems. In this study, we explore the information needs of a family carer by analyzing the extensive online diary of a Vietnamese family carer supporting his wife, who was a lung cancer patient. The study provides a deep understanding of the information needs of the family carer and suggests a four-stage information journey model including identification, searching, interpretation and information sharing, and collaboration. A number of themes emerge from the study including the key role of the carer, information filtering by the carer, information sharing and collaboration, and the influence of Vietnamese culture. The paper concludes with a discussion of the requirements for health information systems that meet the needs of family carers.
In recent years the Swedish Police Force (SPF) have encountered greater demands on availability and 24/7 services when dealing with errands that are regarded as low priority compared to regular police work, e.g.collecting tips from the public.One attempt to meet these increasing demands was the development of a mobile communications platform that allowed the public to communicate easily with the SPF using their own mobile phones by sending SMS and MMS.The focus of this paper is on the early phases of development of this m-service, in particular, on the specific technical issues such as interoperability and standards used by the actors on the scene affecting the development of mobile information systems.The learning experiences are as follows: First, mobile communication platforms have a large potential for contributing to the field of emergency management information systems since they can be based on open and nationally accepted standards.Second, global and national standards for sending multimedia messages are not always truly standardized.Operators and mobile phone manufacturers make minor alterations and interpretations of the standard and thereby some of the benefits found in standards disappear.Third, when developing mobile information systems we suggest and recommend that the analysis phase should be enhanced compared to traditional system development, and it should address the interoperability between mobile phones on one hand and operators on the other hand.
The emerging research area of eParticipation can be characterized as the study of technologyfacilitated citizen participation in (democratic) deliberation and decision- making. Using conventional literature study techniques, we identify 105 articles that are considered to be highly relevant to eParticipation. We develop a definitional schema that suggests different ways of understanding an emerging socio- technical research area and use this schema to map the research contributions identified. This allows us make an initial sketch of the scientific character of the area and its central concerns, theories, and methods. We extend the analysis to define four central research challenges for the field: understanding technology and participation; the strategic challenge; the design challenge; and the evaluation challenge. This article thus contributes to a developing account of eParticipation, which will help future researchers both to navigate the research area and to focus their research agendas.
Every year, the Dutch Minister of Health promises that by the following year, all citizens in the Netherlands will have an Electronic Health Record (EHR). Until now this promise has not been met. One of the main requirements for realizing a national EHR is an interoperability framework, agreeable to the government, vendors and users. This paper first studies the demand side using the results of twenty two interviews with physicians, asking them about their core processes and their expected value of an EHR. This provides us with the adoption perspective on the EHR market. Next we look at the current EHR market, investigating the suppliers and their achievements and market share. Finally we take a look at the government side with an overview of the interoperability requirements dictated by the national IT-agenda for healthcare. The contribution of this paper is twofold: o First, our main conclusion is that success in the EHR market in the Netherlands is not yet motivated by interoperability requirements. o Second, from a detailed analysis on micro level the following result stands out: A majority of the end users (demand side) do not get support in their relevant working processes.
The shrinking student numbers in IS programs in developed countries have created a crisis for the IS profession. In this paper, we explore how offshoring is affecting the IS discipline both directly and indirectly and show some of the major causes behind the relocation of IS work. Our primary message is that while offshoring has impacted the location of some IS tasks, this has not led to the demise of the field. Indeed, in contrast to the public conception, the statistics show there are more IS jobs now than ever before in developed countries.We explore what can be done to better prepare the field for the offshoring challenge and to align the rather negative public perception of the future of the IS field with reality. While simple IS tasks such as coding can be commoditized and are therefore vulnerable to offshoring, other significant pieces of IS work (e.g., business modeling/IS business analysis) are "customer-facing" with high levels of complexity. The latter are less vulnerable to commoditization and consequently less likely to be offshored. We recommend that the academic IS community focuses more on producing these customer-facing IS personnel that organizations will increasingly look for. We offer some suggestions for stakeholder groups in the field to address the key challenges they face.