
Benchmarking digital watermarking algorithms is not an easy task because different applications of digital watermarking often have very different sets of requirements and trade-offs between conflicting requirements. While there have been some general-purpose digital watermarking benchmarking systems available, they normally do not support complicated benchmarking tasks and cannot be easily reconfigured to work with different watermarking algorithms and testing conditions. In this paper, we propose OR-Benchmark, an open and highly reconfigurable general-purpose digital watermarking benchmarking framework, which has the following two key features: 1) all the interfaces are public and general enough to support all watermarking applications and benchmarking tasks we can think of; 2) end users can easily extend the functionalities and freely configure what watermarking algorithms are tested, what system components are used, how the benchmarking process runs, and what results should be produced. We implemented a prototype of this framework as a MATLAB software package and demonstrate how it can be used in three typical use cases. The first two use cases show how easily we can define benchmarking profiles for some robust image watermarking algorithms. The third use case shows how OR-Benchmark can be configured to benchmark some image watermarking algorithms for content authentication and self-restoration, which cannot be easily supported by other digital watermarking benchmarking systems.
Virtual asset service providers (VASPs) currently face a number of challenges, both from the technological and the regulatory perspectives. In the context of virtual asset transfers one key issue is the need for VASPs to securely exchange customer information to comply to the Travel Rule. We discuss a VASP information sharing network as one form of a trust infrastructure for VASP-to-VASP interactions. Related to this is the need for a trusted identity infrastructure for VASPs that would permit other entities to quickly ascertain the legal business status of a VASP. For customers of VASPs there is a need for seamless integration between the VASP services and the existing consumer identity management infrastructure, providing a user-friendly experience for transferring virtual assets to other users. Finally, for regulated wallets, an attestation infrastructure may provide VASPs and insurance providers with better visibility into the state of wallets based on trusted hardware.
We present a survey of toolkits employed in research workshop approaches within TIPS (Trust, Identity, Privacy and Security) domains. Our survey was developed within wider design research to develop digital service prototypes that support people in evaluating whether to trust that an online actor’s identity is not recently faked, and that a service they are registering personal information with is legitimate; and a subsequent project involving a tool that invites people to reflect on the cumulative risks of sharing apparently harmless personal information online. The radically multidisciplinary nature of both these TIPS projects has determined that we create a research space to promote exchange to, as design researchers, better understand the ‘opaque’ immediate and longer term implications of our proposed services and invite cross-disciplinary discussion towards interdisciplinary understandings. This paper is intended as an at-a-glance resource for researchers from a range of disciplinary backgrounds working on TIPS research to inform on various different material engagements, with research stakeholders, through creative workshop approaches. Our survey focused on the literature from Design (especially Participatory Design or PD, and Codesign), Human Computer Interaction (HCI) and cyber related security research. It comprises 30 papers or toolkit examples organised across: review papers; example toolkits; case studies reporting relevant toolkit use; applied toolkits for learning/knowledge exchange; research toolkits focused on demonstrating a methodological-conceptual approach (some problematising emergent or near-future technologies); and two papers that straddled the latter two categories, focusing on future practical application. We begin with an overview of our rationale and method before presenting each group of texts in a table alongside a summary discussion. We go on to discuss the various material components, affordances and terminology of the toolkits along with core concerns often left out of the reporting of research; before going on to recognise toolkits not so much as things that diagnose and fix things, but as a loose collection of readily available material and wider resources, used in particular participatory approaches, which together help account for techno-relational differences and contingencies in TIPS-related fields.
Picnic is a post-quantum digital signature scheme, where the security is based on the difficulty of inverting a symmetric block cipher and zero-knowledge proofs. Picnic is one of the alternate candidates of the third round of the standardization process. Hence, it could be standardized in case of any weakness found in the round three candidates. Based on our paper at the 23rd Euromicro Conference ([6]), we found an optimization, which reduces memory usage to make it usable on IoT devices. This paper focusses on approaches for the implementation of this optimization. As a proof-of-concept, we implemented our implementation of Picnic on a ST Nucleo-L476RG and measured the cycles of the implementation.
Nowadays, almost anyone can take pictures at any time. Simultaneously, services such as social networks make it easy to share and redistribute these images. Users who do not want pictures of them to be recorded and distributed can hardly defend themselves against this. With the introduction of the GDPR in the European Union, users can now at least demand the deletion of such unsolicited uploaded data from web platforms. To find such images, however, the user must first upload comparative images to such a web service so that this service can compare them with its database to show the user whether unwanted images exist or not. This means that the user must involuntarily pass on his biometric data to a web service where he does not actually want his data to be saved. Thus, in this paper, we present our privacy-friendly face recognition approach based on Local Binary Patterns and Error Correction Codes, that allows users to query web services for the presence of unwanted images without revealing biometric information. We evaluated each step of our approach with the "FERET database of facial images" and the "Yale Face Database".
In this talk, I will present our recent work on verifiable e-auction [1], which is done in collaboration with Samiran Bag, Siamak Shahandashti and Indranil Ray. Vickrey auction is a second-price sealed-bid auction scheme, named after William Vickrey who among many other contributions first developed the theory for this scheme and won a Nobel prize in 1996. However, despite the extreme importance in the auction theory, Vickrey auction has rarely been used in practice. One key obstacle concerns the trustworthiness of the auctioneer. The auctioneer can trivially learn all bid inputs which may contain trade secrets. Furthermore, a dishonest auctioneer may secretly modify the second-highest price in order to increase the auction revenue without bidders noticing it. In this talk, we resolve this fundamental trust problem by designing a publicly verifiable e-auction scheme that completely removes the need for auctioneers. This represents a paradigm change from previous schemes. Our solution is called Self-Enforcing Auction Lot (SEAL). It does not require any secret channels between bidders; all communication is public and everyone including the third party observers can verify the integrity of the auction outcome; the system allows bidders to jointly compute the winning bid while preserving the privacy of losing bids, as well as effectively resolving any tie in the contest if it exists; it supports both first-price and second-price sealed-bid auctions; most importantly, it occurs only a linear computation and communication complexity with respect to the bit length of the bid price, which is probably the best one may hope for. All these make SEAL a practical solution to deploy in a real-world application, e.g., as a smart contract on a blockchain platform.
Written security policies are an important part of the complex set of measures to protect organizations from adverse events. However, research detailing these policies and their effectiveness is comparatively sparse. We tackle this research gap by conducting an analysis of a specific user-oriented sub-component of a full information security policy, the Minimum Security Standard. Specifically, we conduct an analysis of 29 publicly accessible minimum security standard documents from U.S. academic institutions. We study the prevalence of an extensive set of user-oriented provisions across these statements such as who is being addressed, whether the standard is considered binding and how it is being enforced, and which specific procedures and practices for users are introduced. We demonstrate significant diversity in focus, style and comprehensiveness in this sample of minimum security standards and discuss their significance within the overall security landscape of organizations.
Ubiquitous computing has fundamentally redefined many existing business models. The collected sensor data has great potential, which is being recognized by more and more industries, including car insurance companies with Usage-Based Insurance (UBI). However, most of these business models are very privacy-invasive and must be constructed with care. For a data processor, the integrity of the data is particularly important. With kUBI, we present a framework that takes into account the interests of the providers as well as the privacy of the users, using the example of Android. It is fully integrated into the Android system architecture. It uses hybrid data processing in both stakeholder domains. Protected enclaves, whose function can be transparently traced by a user at any time, protect company secrets in the hostile environment, i.e. a user’s smartphone. The framework is theoretically outlined and its integration into Android is shown. An evaluation shows that the user in the exemplary use case UBI can be protected by kUBI.
In an attempt to stop phishing attacks, an increasing number of organisations run Simulated Phishing Campaigns to train their staff not to click on suspicious links. Organisations can buy toolkits to craft and run their own campaigns, or hire a specialist company to provide such campaigns as a service. To what extent this activity reduces the vulnerability of an organisation to such attacks is debated in both the research and practitioner communities, but an increasing number of organisations do it because it seems common practice, and are convinced by vendors’ claims about the reduction in clickrates that can be achieved. But most are not aware that effective security is not just about reducing clickrates for simulated phishing messages, that there are many different ways of running such campaigns, and that there are security, legal, and trust issues associated with those choices. The goal of this paper is to equip organisational decision makers with tools for making those decisions. A closer examination of costs and benefits of the choice reveals that it may be possible to run a legally compliant campaign, but that it is costly and time-consuming. Additionally, the impact of Simulated Phishing Campaigns on employees’ self-efficacy and trust in the organisation may negatively affect other organisational goals. We conclude that for many organisations, a joined-up approach of (1) improving technical security measures, (2) introducing and establishing adequate security incident reporting, and (3) increasing staff awareness through other means may deliver better protection at lower cost.
We investigate the combined use of eIDAS-based electronic identity and Verifiable Credentials for remote onboarding and contracting, and provide a proof-of-concept implementation based on SAML authentication. The main non-trivial value derived from this proposal is a higher degree of assurance in the contract offering phase for the Contracting Service Provider.
While social engineering is still a recent threat, many organisations only address it by using traditional trainings, penetration tests, standardized security awareness campaigns or serious games. Existing research has shown that methods for raising employees’ awareness are more effective if adjusted to their target audience. For that purpose, we propose the creation of specific scenarios for serious games by considering specifics of the respective organisation. Based on the work of Faily and Flechais [11], who created personas utilizing grounded theory, we demonstrate how to develop a specific scenario for HATCH [4], a serious game on social engineering. Our method for adapting a scenario of a serious game on social engineering resulted in a realistic scenario and thus was effective. Since the method is also very time-consuming, we propose future work to investigate if the effort can be reduced.
This paper presents a comprehensive classification of identity management approaches. The classification makes use of three axes: topology, type of user, and type of environment. The analysis of existing approaches using the resulting identity management cube (IMC) highlights the trade-off between user control and trust in attributes. A comparative analysis of IMC and established models identifies missing links between the approaches. The IMC is extended by a morphology of identity management, describing characteristics of cooperation. The morphology is then mapped to the life cycle of users and identity management in a further step. These classifications are practically underlined with current approaches. Both methods combined provide a comprehensive characterization of identity management approaches. The methods help to choose suited approaches and implement needed tools.
Software development has passed from being rigid and not very flexible, to be automated with constant changes. This happens due to the creation of continuous integration and delivery environments. Nevertheless, developers often rely on such environments due to the large number of amenities they offer. They focus on authentication only, without taking into consideration other aspects of security such as the integrity of the source code and of the compiled binaries. The source code of a software project must not be maliciously modified. Notwithstanding, there is no safe method to verify that its integrity has not been violated. Trusted computing technology, in particular, the Trusted Platform Module (TPM) can be used to implement that secure method.
While the rapid evolution of container-based virtualization technologies, emerging as an integral part of cloud-based environments, brings forth several new opportunities for enabling the provision of distributed, mixed-criticality services, it also raises significant concerns for their security, resilience, and configuration correctness. In this paper, we present CloudVaults for coping with these challenges: a multi-level security verification framework that supports trust aware service graph chains with verifiable evidence on the integrity assurance and correctness of the comprised containers. It is a first step towards a new frontier of security mechanisms to enable the provision of Configuration Integrity Verification (CIV), during both load- and run-time, by providing fine-grained measurements in supporting container trust decisions, thus, allowing for a much more effective verification towards building a global picture of the entire service graph integrity. We additionally provide and benchmark an open-source implementation of the enhanced attestation schemes.
Public key cryptosystems play a crucial role in the security of widely used communication protocols and in the protection of data. However, the foreseen emergence of quantum computers will break the security of most of the asymmetric cryptographic techniques used today, including those used to verify the authenticity of electronic travel documents. The security of international borders would thus be jeopardised in a quantum scenario. To overcome the threat to current asymmetric cryptography, post-quantum cryptography aims to provide practical mechanisms which are resilient to attacks using quantum computers. In this paper, we investigate the practicality of employing post-quantum digital signatures to ensure the authenticity of an electronic travel document. We created a special-purpose public key infrastructure based on these techniques, and give performance results for both creation and verification of certificates. This is the first important step towards specifying the next generation of electronic travel documents, as well as providing a valuable test use case for post-quantum techniques.
Deploying the appropriate digital environment for conducting cybersecurity exercises can be challenging and typically requires a lot of effort and system resources. Usually, for deploying vulnerable webservices and setting up labs for hands-on cybersecurity exercises to take place, more configuration is required along with technical expertise. Containerization techniques and solutions provide less overhead and can be used instead of virtualization techniques to revise the existing approaches. Furthermore, it is important to sandbox or replicate existing systems or services for the cybersecurity exercises to be realistic. To address such challenges, we conducted a performance evaluation of some of the existing deployment techniques to analyze their benefits and drawbacks. We tested techniques relevant to containerization or MicroVMs that include less overhead instead of the regular virtualization techniques to provide meaningful and comparable results from the deployment of scalable solutions, demonstrating their benefits and drawbacks. Towards this direction, we present a use case for deploying cybersecurity exercises that requires less effort and moderate system resources. By using the deployed components, we provide a baseline proposal for monitoring the progress of the participants using a host-based intrusion system.
Sharing Cyber Threat Intelligence (CTI) is advocated to get better defence against new sophisticated cyber-attacks. CTI may contain critical information about the victim infrastructure, existing vulnerabilities and business processes so sharing CTI may carry a risk. However, evaluating the risk of sharing CTI datasets is challenging due to the nature of the CTI context which is associated with the evolution of the threat landscape and new cyber attacks that are difficult to evaluate. In this paper, we present a quantitative risk model to assess the risk of sharing CTI datasets enabled by sharing with different entities in various situations. The model enables the identification of the threats and evaluation of the impacts of disclosing this information. We present two use cases that help to determine the risk level of sharing a CTI dataset and consequently the mitigation techniques to enable responsible sharing. Risk identification and evaluation have been validated using experts’ opinions.
While there is substantial interest in ethical practice relating to Artificial Intelligence (AI), to date there has been limited consideration of what this means in the banking sector. This study aimed to address this gap in the literature through a qualitative study of public attitudes and perceptions of current and potential future uses of AI in banking. A series of focus groups were conducted with diverse members of the public. Focus group participants were largely positive about the role of AI in speeding up financial processes and increasing efficiency. Yet, they also expressed a number of concerns around potential negative impacts on society and consistently emphasized the importance of human judgement or oversight. The findings suggest a potential cognitive dissonance where people use new services due to perceived convenience or immediate benefits, while disliking or distrusting those services or holding concerns about their impacts on society. The findings illustrate that participants' concerns did not typically relate to private or individual interests but more often to wider ethical and social concerns. The focus groups demonstrated the value of qualitative, deliberative methods to explore the nuances of public responses and highlighted the importance of taking account of conditions for public acceptability - rather than just customer uptake - in order to develop ethical practice and establish a social licence for uses of AI in banking.
This paper describes Twizzle Benchmarking, a framework originally developed for evaluating and comparing the performance of perceptual image hashing algorithms. There are numerous perceptual hashing approaches with different characteristics in terms of robustness and sensitivity, which also use different techniques for feature extraction and distance measurements, making comparison difficult. For this reason, we have developed Twizzle Benchmarking, which enables comparison and evaluation regardless of the algorithm, distance calculation, data set or type of data. Furthermore, Twizzle is not limited to perceptual hashing approaches, but can be used for a variety of purposes and classification problems, such as multimedia forensics, face recognition or biometric authentication.
As the complexity of applications and software frameworks increases, cybersecurity becomes more challenging.The potential attack surface keeps expanding while each product has its own peculiarities and requirements leading to tailor-made solutions per case.These are the primary reasons which render security solutions expensive, highly complex and with significant deployment delay. This technical survey intends to reveal the pillars of today’s cybersecurity market, as well as identify emerging trends,key players and functional aspects. Such an insight will allow all interested parties to optimize the design process of a contemporary and future-proof cybersecurity framework for end-to-end protection.