Entries Tagged "academic papers"

Page 76 of 87

Identifying People using Anonymous Social Networking Data

Interesting:

Computer scientists Arvind Narayanan and Dr Vitaly Shmatikov, from the University of Texas at Austin, developed the algorithm which turned the anonymous data back into names and addresses.

The data sets are usually stripped of personally identifiable information, such as names, before it is sold to marketing companies or researchers keen to plumb it for useful information.

Before now, it was thought sufficient to remove this data to make sure that the true identities of subjects could not be reconstructed.

The algorithm developed by the pair looks at relationships between all the members of a social network—not just the immediate friends that members of these sites connect to.

Social graphs from Twitter, Flickr and Live Journal were used in the research.

The pair found that one third of those who are on both Flickr and Twitter can be identified from the completely anonymous Twitter graph. This is despite the fact that the overlap of members between the two services is thought to be about 15%.

The researchers suggest that as social network sites become more heavily used, then people will find it increasingly difficult to maintain a veil of anonymity.

More details:

In “De-anonymizing social networks,” Narayanan and Shmatikov take an anonymous graph of the social relationships established through Twitter and find that they can actually identify many Twitter accounts based on an entirely different data source—in this case, Flickr.

One-third of users with accounts on both services could be identified on Twitter based on their Flickr connections, even when the Twitter social graph being used was completely anonymous. The point, say the authors, is that “anonymity is not sufficient for privacy when dealing with social networks,” since their scheme relies only on a social network’s topology to make the identification.

The issue is of more than academic interest, as social networks now routinely release such anonymous social graphs to advertisers and third-party apps, and government and academic researchers ask for such data to conduct research. But the data isn’t nearly as “anonymous” as those releasing it appear to think it is, and it can easily be cross-referenced to other data sets to expose user identities.

It’s not just about Twitter, either. Twitter was a proof of concept, but the idea extends to any sort of social network: phone call records, healthcare records, academic sociological datasets, etc.

Here’s the paper.

Posted on April 6, 2009 at 6:51 AMView Comments

Surviving a Suicide Bombing

Where you stand matters:

The two researchers have developed accurate physics-based models of a suicide bombing attack, including casualty levels and explosive composition. Their work also describes human shields available in the crowd with partial and full coverage in both two- and three-dimensional environments.

Their virtual simulation tool assesses the impact of crowd formation patterns and their densities on the magnitude of injury and number of casualties of a suicide bombing attack. For a typical attack, the writers suggest that they can reduce the number of fatalities by 12 percent and the number of injuries by 7 percent if their recommendations are followed.

Simulation results were compared and validated by real-life incidents in Iraq. Line-of-sight with the attacker, rushing toward the exit and stampede were found to be the victims’ most lethal choices both during and after the attack.

Presumably they also discovered where the attacker should stand to be as lethal as possible, but there’s no indication that they published those results.

Posted on March 26, 2009 at 8:08 AMView Comments

Research in Explosive Detection

Interesting:

Much of this research focuses on “micromechanical” devices—tiny sensors that have microscopic probes on which airborne chemical vapors deposit. When the right chemicals find the surface of the sensors, they induce tiny mechanical motions, and those motions create electronic signals that can be measured.

These devices are relatively inexpensive to make and can sensitively detect explosives, but they often have the drawback that they cannot discriminate between similar chemicals—the dangerous and the benign. They may detect a trace amount of TNT, for instance, but they may not be able to distinguish that from a trace amount of gasoline.

Seeking to make a better micromechanical sensor, Thundat and his colleagues realized they could detect explosives selectively and with extremely high sensitivity by building sensors that probed the thermal signatures of chemical vapors.

They started with standard micromechanical sensors—devices with microscopic cantilevers beams supported at one end. They modified the cantilevers so that they could be electronically heated by passing a current through them. Next they allowed air to flow over the sensors. If explosive vapors were present in the air, they could be detected when molecules in the vapor clung to the cantilevers.

Then by heating the cantilevers in a fraction of a second, they could discriminate between explosives and non-explosives. All the explosives they tested responded with unique and reproducible thermal response patterns within a split second of heating. In their paper, Thundat and his colleagues demonstrate that they could detect very small amounts of adsorbed explosives—with a limit of 600 picograms (a picogram is a trillionth of a gram). They are now improving the sensitivity and making a prototype device, which they expect to be ready for field testing later this year.

Here’s the paper, behind a paywall.

Posted on March 23, 2009 at 6:55 AMView Comments

Fingerprinting Paper

Interesting paper:

Fingerprinting Blank Paper Using Commodity Scanners

Will Clarkson, Tim Weyrich, Adam Finkelstein, Nadia Heninger, Alex Halderman, and Edward W. Felten

Abstract: This paper presents a novel technique for authenticating physical documents based on random, naturally occurring imperfections in paper texture. We introduce a new method for measuring the three-dimensional surface of a page using only a commodity scanner and without modifying the document in any way. From this physical feature, we generate a concise fingerprint that uniquely identifies the document. Our technique is secure against counterfeiting and robust to harsh handling; it can be used even before any content is printed on a page. It has a wide range of applications, including detecting forged currency and tickets, authenticating passports, and halting counterfeit goods. Document identification could also be applied maliciously to de-anonymize printed surveys and to compromise the secrecy of paper ballots.

Posted on March 19, 2009 at 6:07 AMView Comments

The "Broken Windows" Theory of Crimefighting

Evidence of its effectiveness:

Researchers, working with police, identified 34 crime hot spots. In half of them, authorities set to work—clearing trash from the sidewalks, fixing street lights, and sending loiterers scurrying. Abandoned buildings were secured, businesses forced to meet code, and more arrests made for misdemeanors. Mental health services and homeless aid referrals expanded.

In the remaining hot spots, normal policing and services continued.

Then researchers from Harvard and Suffolk University sat back and watched, meticulously recording criminal incidents in each of the hot spots.

The results, just now circulating in law enforcement circles, are striking: A 20 percent plunge in calls to police from the parts of town that received extra attention. It is seen as strong scientific evidence that the long-debated “broken windows” theory really works—that disorderly conditions breed bad behavior, and that fixing them can help prevent crime.

[…]

Many police departments across the country already use elements of the broken windows theory, or focus on crime hot spots. The Lowell experiment offers guidance on what seems to work best. Cleaning up the physical environment was very effective; misdemeanor arrests less so, and boosting social services had no apparent impact.

EDITED TO ADD (3/13): The paper.

Posted on February 20, 2009 at 12:03 PMView Comments

Computer Virus Epidemiology

WiFi networks and malware epidemiology,” by Hao Hu, Steven Myers, Vittoria Colizza, and Alessandro Vespignani.

Abstract

In densely populated urban areas WiFi routers form a tightly interconnected proximity network that can be exploited as a substrate for the spreading of malware able to launch massive fraudulent attacks. In this article, we consider several scenarios for the deployment of malware that spreads over the wireless channel of major urban areas in the US. We develop an epidemiological model that takes into consideration prevalent security flaws on these routers. The spread of such a contagion is simulated on real-world data for georeferenced wireless routers. We uncover a major weakness of WiFi networks in that most of the simulated scenarios show tens of thousands of routers infected in as little as 2 weeks, with the majority of the infections occurring in the first 24–48 h. We indicate possible containment and prevention measures and provide computational estimates for the rate of encrypted routers that would stop the spreading of the epidemics by placing the system below the percolation threshold.

Honestly, I’m not sure I understood most of the article. And I don’t think that their model is all that great. But I like to see these sorts of methods applied to malware and infection rates.

EDITED TO ADD (3/13): Earlier—but free—version of the paper.

Posted on February 18, 2009 at 5:53 AMView Comments

Difficult-to-Pronounce Things are Judged to Be More Risky

Do I have any readers left who think humans are rational about risks?

Abstract

Low processing fluency fosters the impression that a stimulus is unfamiliar, which in turn results in perceptions of higher risk, independent of whether the risk is desirable or undesirable. In Studies 1 and 2, ostensible food additives were rated as more harmful when their names were difficult to pronounce than when their names were easy to pronounce; mediation analyses indicated that this effect was mediated by the perceived novelty of the substance. In Study 3, amusement-park rides were rated as more likely to make one sick (an undesirable risk) and also as more exciting and adventurous (a desirable risk) when their names were difficult to pronounce than when their names were easy to pronounce.

Posted on February 17, 2009 at 1:56 PMView Comments

Worldwide Browser Patch Rates

Interesting research:

Abstract:

Although there is an increasing trend for attacks against popular Web browsers, only little is known about the actual patch level of daily used Web browsers on a global scale. We conjecture that users in large part do not actually patch their Web browsers based on recommendations, perceived threats, or any security warnings. Based on HTTP useragent header information stored in anonymized logs from Google’s web servers, we measured the patch dynamics of about 75% of the world’s Internet users for over a year. Our focus was on the Web browsers Firefox and Opera. We found that the patch level achieved is mainly determined by the ergonomics and default settings of built-in auto-update mechanisms. Firefox’ auto-update is very effective: most users installed a new version within three days. However, the maximum share of the latest, most secure version never exceeded 80% for Firefox users and 46% for Opera users at any day in 2007. This makes about 50 million Firefox users with outdated browsers an easy target for attacks. Our study is the result of the first global scale measurement of the patch dynamics of a popular browser.

Posted on February 13, 2009 at 6:27 AMView Comments

Confessions Corrupt Eyewitnesses

People confess to crimes they don’t commit. They do it a lot. What’s interesting about this research is that confessions—whether false or true—corrupt other eyewitnesses:

Abstract

A confession is potent evidence, persuasive to judges and juries. Is it possible that a confession can also affect other evidence? The present study tested the hypothesis that a confession will alter eyewitnesses’ identification decisions. Two days after witnessing a staged theft and making an identification decision from a lineup that did not include the thief, participants were told that certain lineup members had confessed or denied guilt during a subsequent interrogation. Among those participants who had made a selection but were told that another lineup member confessed, 61% changed their identifications. Among those participants who had not made an identification, 50% went on to select the confessor when his identity was known. These findings challenge the presumption in law that different forms of evidence are independent and suggest an important overlooked mechanism by which innocent confessors are wrongfully convicted: Potentially exculpatory evidence is corrupted by a confession itself.

More:

When asked to explain their change, subjects revealed they were actually convinced by the confessor, and not simply complying with it, saying, “His face now looks more familiar than the one I chose before.”

Posted on February 4, 2009 at 6:35 AMView Comments

Cost of the U.S. No-Fly List

Someone did the analysis:

As will be analyzed below, it is estimated that the costs of the no-fly list, since 2002, range from approximately $300 million (a conservative estimate) to $966 million (an estimate on the high end). Using those figures as low and high potentials, a reasonable estimate is that the U.S. government has spent over $500 million on the project since the September 11, 2001 terrorist attacks. Using annual data, this article suggests that the list costs taxpayers somewhere between $50 million and $161 million a year, with a reasonable compromise of those figures at approximately $100 million.

Posted on February 3, 2009 at 1:01 PMView Comments

1 74 75 76 77 78 87

Sidebar photo of Bruce Schneier by Joe MacInnis.