Service security and privacy as a socio-technical problem

Interdisciplinary Research Group in Socio-technical Cybersecurity

Service security and privacy as a socio-technical problem

Bella Giampaolo, Curzon Paul, Lenzini Gabriele
Abstract:
The security and privacy of the data that users transmit, more or less deliberately, to modern services is an open problem. It is not solely limited to the actual Internet traversal, a sub-problem vastly tackled by consolidated research in security protocol design and analysis. By contrast, it entails much broader dimensions pertaining to how users approach technology and understand the risks for the data they enter. For example, users may express cautious or distracted personas depending on the service and the point in time; further, pre-established paths of practice may lead them to neglect the intrusive privacy policy offered by a service, or the outdated protections adopted by another. The approach that sees the service security and privacy problem as a socio-technical one needs consolidation. With this motivation, the article makes a threefold contribution. It reviews the existing literature on service security and privacy, especially from the socio-technical standpoint. Further, it outlines a general research methodology aimed at layering the problem appropriately, at suggesting how to position existing findings, and ultimately at indicating where a transdisciplinary task force may fit in. The article concludes with the description of the three challenge domains of services whose security and privacy we deem open socio-technical problems, not only due to their inherent facets but also to their huge number of users.
Authors:
Bella Giampaolo, Curzon Paul, Lenzini Gabriele
Publication date:
2015
Published in:
Journal of Computer Security
Reference:
Bella, G., Curzon, P., & Lenzini, G. (2015). Service security and privacy as a socio-technical problem. Journal of Computer Security, 23(5), 563-585.

Get in touch with us

SnT – Interdisciplinary Centre for Security, Reliability and Trust
Maison du Nombre, 6, avenue de la Fonte L-4364 Esch-sur-Alzette
info-irisc-lab@uni.lu