• DocumentCode
    568494
  • Title

    A Data-Reachability Model for Elucidating Privacy and Security Risks Related to the Use of Online Social Networks

  • Author

    Creese, Sadie ; Goldsmith, Michael ; Nurse, Jason R C ; Phillips, Elizabeth

  • Author_Institution
    Dept. of Comput. Sci., Univ. of Oxford, Oxford, UK
  • fYear
    2012
  • fDate
    25-27 June 2012
  • Firstpage
    1124
  • Lastpage
    1131
  • Abstract
    Privacy and security within Online Social Networks (OSNs) has become a major concern over recent years. As individuals continue to actively use and engage with these mediums, one of the key questions that arises pertains to what unknown risks users face as a result of unchecked publishing and sharing of content and information in this space. There are numerous tools and methods under development that claim to facilitate the extraction of specific classes of personal data from online sources, either directly or through correlation across a range of inputs. In this paper we present a model which specifically aims to understand the potential risks faced should all of these tools and methods be accessible to a malicious entity. The model enables easy and direct capture of the data extraction methods through the encoding of a data-reachability matrix for which each row represents an inference or data-derivation step. Specifically, the model elucidates potential linkages between data typically exposed on social-media and networking sites, and other potentially sensitive data which may prove to be damaging in the hands of malicious parties, i.e., fraudsters, stalkers and other online and offline criminals. In essence, we view this work as a key method by which we might make cyber risk more tangible to users of OSNs.
  • Keywords
    data privacy; reachability analysis; security of data; social networking (online); data extraction methods; data-derivation step; data-reachability matrix; data-reachability model; malicious entity; online social networks; online sources; privacy risk; security risk; Accuracy; Data mining; Data models; Electronic mail; Privacy; Security; Social network services; Social-network risks; data-reachability model; information leakage; online social networks; privacy; security;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2012 IEEE 11th International Conference on
  • Conference_Location
    Liverpool
  • Print_ISBN
    978-1-4673-2172-3
  • Type

    conf

  • DOI
    10.1109/TrustCom.2012.22
  • Filename
    6296102