Posts

Showing posts with the label privacy

Dealing with the Internet of Insecure Things

Image
I was invited to deliver a presentation to the Institute of Engineering & Technology's EC3 Group on "Dealing with the Internet of Insecure Things".  My talk provided an overview of the security challenges of the Internet of Things and argued that we should adopt human-centric engineering approaches to address these challenges. Abstract:  We are in an age of the ‘Internet of Everything’ where boundaries between citizens, governments, media, and societal organisations are becoming increasingly fuzzy as interconnected digital devices enable the collection and exchange of vast amounts of information across the globe. The availability of data gathered by these devices, coupled with advances in channels of digitally mediated communication, has created a host of new systems that are embedded into a range of human activities, including agriculture, energy, transportation, healthcare, policing, and education – creating the potential for a ‘smarter planet’. However, these cy...

IET Innovation Awards Finalist! Winner!

Image
Update (16 Nov 2017):  I am very pleased to announce that the Privacy Band was chosen as the winner of the Cyber Security category of the IET Innovation Awards.  Vikram Mehta and I were presented the award which is a fantasic recognition of our invention. "Privacy Band", our novel privacy management interface device, was a finalist in the Cyber Security category of the IET Innovation Awards .  The above video shows me discussing and demonstrating the device, which embodies a metaphor of "Privacy Itch" and "Privacy Scratch" as a mechanism for privacy awareness and control. The IET Innovation Awards were announced on 15 November 2017.

Privacy Perspectives for Data Privacy Day

Image
A group of us, who are part of the EPSRC-funded, Monetize Me project , wrote an article on "Privacy perspectives: dos, don’ts, and to-dos", to mark Data Privacy Day on 28th January.   In this article, we highlight some of the challenges of understanding the privacy implications of a variety of new technologies, such as activity trackers and smart watches.  We make the point that: "... it is not individuals’ responsibility alone to protect themselves from privacy intrusions. Technology companies and developers can adopt privacy by design principles to mitigate some of these risks, and such practice should become common, to avoid us becoming disillusioned with emerging technologies. Therefore, we argue that maintaining privacy is ultimately a collective effort, shared between researchers, developers and those who ultimately use the devices and services they produce." The full article can be found on the Open University's news portal: " Privacy perspect...

Privacy-by-Design Framework for Internet of Things Systems

IOT-2016 7-9 September, 2016, Stuttgart, Germany from Charith Perera Recent DDoS attacks on key internet services, like the attack that affected the Dyn domain name service , highlighted the security challenges associated with the proliferation of insecure Internet of Things (IoT) systems.  This attack exploited common vulnerabilities like the use of default administration passwords on IoT devices such as internet-enabled CCTV cameras, internet-enabled appliances and smart home devices, to recruit over hundreds of thousands of nodes into a botnet.   This capability highlights the cyber security threats associated with the IoT and brings into sharp relief the importance of considering both security and privacy when designing these systems. In recent work, presented at the Internet of Things Conference, we describe a privacy-by-design framework for assessing the privacy capabilities of IoT applications and platforms.  Building on more general design strategies for...

Privacy Itch and Scratch

Image
Use case for on-body privacy awareness and control Ubiquitous computing technologies are being used to collect, process and share increasing amounts of personal information, from our location and physical activity levels to the things we buy and the web pages we read.  Although these developments have created a wealth of new applications that engage and entertain us, they also pose significant challenges for our privacy - particularly the challenge of maintaining awareness and control over our personal information flows as we go about our daily lives. My colleagues, Vikram Mehta, Blaine Price and Bashar Nuseibeh, and I have been exploring new interaction metaphors for enhancing our privacy awareness and control.  Our earlier work in this area used haptic interactions through the users' smartphone to enable privacy controls to be configured by physically shaking and moving the device ( PrivacyShake ).   More recently we have been exploring the role of on-body interfa...

Learning Privacy Norms for Social Software

Privacy Dynamics: Learning Privacy Norms for Social Software from Arosha Bandara The slides above are from a presentation of our work on learning privacy norms for social software at the Symposium on Engineering Adaptive and Self-Managing Systems (SEAMS) in Austin, Texas.  The paper describes an architecture for integrating privacy management capabilities into social applications that integrate sharing functionality using social media platforms like Facebook.  The following summary is extracted from the abstract of the paper that accompanies this presentation: Privacy Dynamics, is an adaptive architecture that learns privacy norms for different audience groups based on users’ sharing behaviours. Our architecture is underpinned by a formal model inspired by social identity theory, a social psychology framework for analysing group processes and intergroup relations. Our formal model comprises two main concepts, the group membership as a Social Identity (SI) map and...

Adaptive Privacy @ SET for BRITAIN

Image
SET for BRITAIN 2015 will be held at Westminster on 9 March 2015 Our research on  ' Adaptive Sharing for Online Social Networks ' has been selected for presentation at this year's SET for BRITAIN event at the Houses of Parliament.  The work will be presented by Dr. Mu Yang, one of the post-doctoral researchers on our Adaptive Security and Privacy project.  She will be presenting a model that allows social network users to balance privacy risks against social benefits by providing advice on the optimal audience for different types of information. The work has the potential to strengthen the privacy for users of online social networks such as Facebook and Twitter. This is based on our TrustCom 2014 paper, ' Adaptive Sharing for Online Social Networks: A Trade-off between Privacy Risk and Social Benefit ' which received the Best Paper Award.  For more details our participation in the SET for BRITAIN event on 9 March 2015, see " OU Research at SET for BR...

Online Cyber Security Discussion

Image
Ready to start my first Twitter discussion for #FutureLearnAsks As we kick off the next presentation of the Introduction to Cyber Security MOOC , I took part in an online discussion on the topic with Cory Doctorow and Andrew Smith on Twitter.  This was my first time leading one of these "Ask Me Anything" sessions, which was hosted by FutureLearn as part of a new initiative called #FutureLearnAsks.  Although at times I struggled to keep up with the speed of the conversation, it was a lot of fun to engage with a diverse group of people to talk about this important topic. The discussion was seeded by a number of questions, ranging from "Is the state justified to monitor personal digital and telecommunications in the name of security?" to "What one tip would you give to people to better protect their cyber security?"  One key lesson learned about asking open ended questions like this was that if the answer is always going to start with "It depends ...

Deep Learning and Adaptive Sharing for Online Social Networking

Prompted by Facebook Research's recent announcement on using deep learning to help users avoid 'drunk posting' embarrassing information on the social networking platform, I wrote an article for The Conversation about deep learning and adaptive sharing.  This draws on our research on Adaptive Sharing for Online Social Networks , which was recognised as the Best Paper at the  13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14).  The following is a short excerpt from the article: Facebook’s initial target appears aimed at extending its face recognition capability to automatically differentiate between a user’s face when sober and drunk, and use this to get a user to think twice before hitting the post button. Of course being detected as being drunk in photographs won’t be the only factor that determines when we want to moderate our social media sharing behaviours. The nature of the links we share, li...

Privacy Distillation @ Best RESG Research 2014

Image
Privacy Distilation for Mobile Applications from Arosha Bandara I had the opportunity to present our research on Privacy Distillation for Mobile Applications at the British Computer Society Requirements Engineering Specialist Group's Best of RESG Research 2014 event .  The slides above are based on those originally presented by Keerthi Thomas at ICSE 2014. Some interesting questions were discussed following my presentation, including: How does the distillation process cope with the overall mobile software eco-system? At the moment we have only considered the peer-to-peer information flows between the end users of the mobile application.  However, it should be possible to use the Privacy Facets Framework to consider the information, information flows and actors in the overall mobile software eco-system.  Of course some extensions will be required, for example to capture factors such the legal and regulatory aspects of privacy associated with the plac...

Adaptive Sharing for Online Social Networks

Image
TrustCom 2014, Beijing, China | Picture by  Peter23 We recently presented our initial work on developing quantitative models of privacy risk and social benefit at TrustCom 2014 in China.  The work was undertaken by Mu Yang, a post-doctoral researcher on the Adaptive Security and Privacy  project. The paper was recognised as the Best Paper at the conference, being judged against 73 papers presented at the conference The models presented in the paper could be used to optimise the audience for online social networking postings and we are currently developing a field experiment to evaluate the approach we are proposing.  You can find the paper at the link below: Yang, Mu; Yu, Yijun; Bandara, Arosha and Nuseibeh, Bashar (2014). Adaptive sharing for online social networks: a trade-off between privacy risk and social benefit. In: 13th IEEE International Conference on Trust, Security and Privacy in Computing and Communications (IEEE TrustCom-14), 24-26 September 201...

Cyber Security MOOC

Image
Introduction to Cyber Security Over the past few months I have been working with my colleagues at The Open University to produce a MOOC (Massive Open Online Course) that will provide learners with basic knowledge and skills relating to information security.  " Introduction to Cyber Security " is an 8-week course that will be hosted on the Futurelearn platform, with the first presentation scheduled to start on 13 October.  Learners will be guided through the content by Cory Doctorow, who is a visiting professor at the OU. The course was produced with the support of the UK government, as part of the National Cyber Security Programme, with the aim of raising general awareness and interest relating to cyber security.     It is hoped that learners who complete the course - from young people considering careers in computing, to those already in work looking to improve their knowledge and skills, or members of the public looking to protect themselves online - will ga...

Merging privacy ...

Facebook vs. Whatsapp The acquisition of WhatsApp by Facebook has raised a number of interesting privacy debates, with the latest being a legal challenge to the deal on the grounds that WhatsApp's existing user privacy agreement will be violated if Facebook starts using the data to deliver targeted advertising.  It raises the question of whether the difference in the privacy agreements between WhatsApp and Facebook was part of the analysis when the acquisition was planned. Questions that could (arguably should) have been part of the decision to value WhatsApp at ~£11bn (~US$16bn) include: if isolating WhatsApp from Facebook (as proposed in the above article) would limit the possibility of creating new revenue streams (e.g., through advertising), from WhatsApp users? would users leave WhatsApp in droves if Facebook changed the privacy policy to allows user data to be used for advertising? whether hardly any users will care about the potential use of personal informatio...

ICSE 2014 Success ...

Image
ICSE 2014 I am really pleased to have two research papers being presented at the 36th International Conference on Software Engineering, which will take place in Hyderabad, India in 31 May - 7 June 2014.  The papers are: Thomas, Keerthi; Bandara, Arosha K.; Price, Blaine A. and Nuseibeh, Bashar (2014). Distilling Privacy Requirements for Mobile Applications . In: 36th International Conference on Software Engineering (ICSE 2014), 31 May-7 June, 2014, Hyderabad, India (Forthcoming), ACM. Akiki, Pierre A.; Bandara, Arosha K. and Yu, Yijun (2014). Integrating adaptive user interface capabilities in enterprise applications . In: 36th International Conference on Software Engineering (ICSE 2014), 31 May-7 June, 2014, Hyderabad, India (Forthcoming), ACM. The first of these papers presents a novel approach, called Requirements Distillation, for eliciting privacy requirements from qualitative data, such as user interviews or experience reports.  This was developed by my stude...

Unmissable blogs ...

Image
I don't always have a lot of time to keep up with what is going on in the 'Blog-o-sphere', but there are a a few blogs that I try to read whenever possible.  In an effort to increase the frequency of my own blogging I thought it would be a good idea to write a post about my 'unmissable blogs': Prof.so - written by Anthony Finkelstein, provides some excellent insights into software engineering research and academia in general, with some great humour thrown in. Check out some of the excellent '10 Top ...' lists! Geek Prof - written by Ian Sommerville, is a blog I've only recently been introduced to but found to be a really good read.  Wise words about the state of academia and research, as well as insights on a range of topics that range from cybersecurity to software and systems engineering. Crypto-gram - written by Bruce Schneier, the content of which can be accessed in multiple forms, including a podcast and a email newsletter.  This is one ...

Calming those Angry Birds ...

Image
Screenshot of article on The Conversation site The latest revelations from the Snowden files includes evidence that NSA and GCHQ were tapping into some of the application analytics data being gathered by popular mobile applications like Angry Birds.  I was invited by The Conversation platform to contribute to a short article titled, " Angry Birds will have angry users until privacy rules are clear " that discusses this issue and where the responsibility for privacy and security in mobile applications lies.

Engineering Adaptive Software Systems (EASSy) Workshop

Image
My introduction video for the EASSy workshop I am headed to Japan next week to participate in the NII-Shonan Workshop on Engineering Adaptive Software Systems .  This event will bring together an international group of software engineering researchers who are working on the challenges of realising adaptive systems.  I am looking forward to attending this year, having missed out on the first edition which I helped organise last year !

Adaptive Security and Privacy

Image
My colleague, Prof. Bashar Nuseibeh, has been recently awarded a prestigious ERC Advanced Research grant, as well as a Royal Society-Wolfson Merit Award, to support research in the area of adaptive privacy and security.  As a co-Investigator on some of the previous projects in this area ( PRiMMA and Microsoft Research SEIF ), I am pleased to be part of the research team that will work on this research with Bashar and others.  To find out more about the research agenda, visit the Adaptive Security and Privacy project website .  On a related note, we are also starting a project on Adaptive Information Security for Cloud Computing , funded by the Qatar National Research Fund, which will involve collaborating with a research team based at Qatar University. As result of all this activity, we are soon going to be starting the recruitment process for both post-doctoral researchers and PhD students who have an interest in working in the area of adaptive systems for privacy ...

Mobile East 2012 - See it, Shake it, Set it

I presented the above talk about research done as part of the PRiMMA project on studying privacy management for mobile applications at the Mobile East 2012 conference .  The following is the abstract of this talk: As a result of advances in ubiquitous computing areas, and the widespread use of related technology in various applications, it is now possible to capture an unprecedented amount of information about people’s daily lives and use this information in various ways. Proponents of these developments argue that they will allow computer technologies to inform, entertain and assist us in ways that are more comfortable, intuitive and unobtrusive. On the other hand, it is argued that such pervasive data gathering is likely to cause serious invasions of individual privacy, potentially culminating in harm to individuals and society at large.  This talk reports on research that has been investigating users' experience of managing their privacy when using mobile applicatio...