Tuesday, November 27, 2012

CyLab Researchers Make Major Advances In Audit Technology For Privacy Protection



A team of researchers at Carnegie Mellon University led by Dr. Anupam Datta, Assistant Research Professor at CyLab and Electrical & Computer Engineering, has developed algorithms that can help protect individual privacy by checking that organizations such as hospitals and banks are disclosing personal information about their customers to third parties in compliance with privacy regulations. They have produced the first complete formal specification of disclosure clauses in two important US privacy laws -- the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and the Gramm-Leach-Bliley Act (GLBA).

They also built an algorithm that can help investigators detect violations of these laws and similar privacy policies. The research team included Henry DeYoung (a graduate student in the Computer Science Department) and three postdoctoral researchers in Dr. Datta's research group: Dr. Deepak Garg (now faculty at MPI-SWS), Dr. Limin Jia (now faculty at CMU CyLab), and Dr. Dilsun Kaynar (now faculty at CMU Computer Science Department).

Privacy has become a significant concern in modern society as personal information about individuals is increasingly collected, used, and shared, often using digital technologies, by a wide range of organizations. To mitigate privacy concerns, organizations are required to respect privacy laws in regulated sectors (e.g., HIPAA in healthcare, GLBA in financial sector) and to adhere to self-declared privacy policies in self-regulated sectors (e.g., privacy policies of companies such as Google and Facebook in Web services). Enforcing these kinds of privacy policies in organizations is difficult because privacy laws and enterprise policies typically identify a complex set of conditions governing the disclosure of personal information. For example, the HIPAA Privacy Rule includes over 80 clauses that permit, deny, and even require the disclosure of personal health information, making it difficult to manually ensure that all disclosures are compliant with the law. 

The research team at Carnegie Mellon University created a formal language for specifying a rich class of privacy policies. They then used this language to produce the first complete formal specification of disclosure clauses in two important US privacy laws -- the Health InsurancePortability and Accountability Act (HIPAA) Privacy Rule and theGramm-Leach-Bliley Act (GLBA). Recognizing that certain portions of complex privacy policies such as HIPAA are subjective and might require input from human auditors for compliance determination, the specification clearly separates out the subjective and the objective portions of a given policy.

The team then developed an algorithm that checks audit logs for compliance with privacy policies expressed in their language.  The algorithm has two distinct characteristics. First, it automatically checks the objective portion of the privacy policy for compliance and outputs the subjective portion for inspection by human auditors. Second, recognizing that audit logs are often incomplete in practice (i.e., they may not contain sufficient information to determine whether a policy is violated or not), the algorithm proceeds iteratively: in each iteration it checks as much of the policy it possibly can over the current log and outputs a residual policy that can only be checked when the log is extended with additional information. Initial experiments with a prototype implementation checking compliance of simulated audit logs with the HIPAA Privacy Rule indicates that the algorithm is fast enough to be used in practice. 

Additional information about this work can be found on the project web page:http://www.andrew.cmu.edu/user/danupam/privacy.html

Carnegie Mellon CyLab Awarded DHS Contract For Research Into Understanding And Disrupting The Economics Of Cybercrime



Carnegie Mellon University CyLab has been awarded a multi-million dollar contract for research into Understanding and Disrupting the Economics of Cybercrime. Nicolas Christin, CyLab Senior Systems Scientist and Associate Director of the Information Networking Institute (INI), is Principle Investigator (PI). His co-PIs are fellow CyLab researcher Alessandro Acquisti, along with Tyler Moore of Southern Methodist University, Ross Anderson of Cambridge University, and Ryan Williams of NFCTA. Richard Clayton of Cambridge University will also participate as instrumental senior personnel.

Based on the realization that focusing on a particular attack, or a specific set of attacks, is unlikely to provide the detailed level of understanding necessary to design meaningful intervention policies against cybercrime, the methodology developed by Christin and his colleagues holistically combines network measurements with behavioral and economic analysis. The project will consist of four research tasks: designing cybercrime indicators, designing data interchange formats and standards, modeling online-crime supply chains and modeling attackers' behavioral psychology The contract is one of thirty four, totaling $40 million that the U.S. Department of Homeland Security (DHS) Science and Technology Directorate (DHS S&T) has awarded to twenty-nine academic and research organizations. This funding is for research and development of cyber security solutions.

In January 2011, the DHS S&T Cyber Security Division (CSD) issued a Cyber Security R&D Broad Agency Announcement (BAA 11-02) that solicited proposals for 14 Technical Topic Areas (TTAs) aimed at improving security in federal networks and across the Internet while developing new and enhanced technologies for detecting, preventing and responding to cyber attacks on the nation's critical information infrastructure. BAA 11-02 elicited white paper responses from more than 1,000 offerors.

Following extensive review and down-select process, more than 200 offerors were invited to submit full proposals for final review. And of those, new awards were made to the twenty-nine organizations that were announced on October 26, 2012.

"The work to be accomplished through these contracts will significantly advance cyber security and support the mission of the DHS Science and Technology Directorate's Cyber Security Division to create a safe, secure and resilient cyber environment," Dr. Douglas Maughan, director of DHS' S&T Cyber Security Division told Homeland Security Today. "Our goal," said Maughan, "is to transform the cyber-infrastructure to be resistant to attack so that critical national interests are protected from catastrophic damage and our society can confidently adopt new technological advances." (See Homeland Security Today, 10-26-12)


Monday, November 5, 2012

Glimpses into the 9th Annual CyLab Partners Conference

CyLab Researchers Nicolas Christin, Rahul Telang, Alessandro Acquisti
9th Annual Cylab Partners Conference (October 2012)
Glimpses into the 9th Annual CyLab Partners Conference

[NOTE: This CyBlog post is also cross-posted as a CyLab Chronicles on the main CyLab web site.]

The 9th Annual CyLab Partners Conference was held at the main campus of Carnegie Mellon University (Pittsburgh, Pa.), on October 2nd and 3rd, 2012.

The Partners Confernce is an exclusive benefit of membership in the CyLab Partners program, and like the recruitment opportunities, reputational boost and Seminar webcasts, it is one of several benefits that is available to all Partners, whether at $25,000 level, the $100,000 level or the $350,000 level.

For two days, representatives from CyLab's corporate Partners recieve research updates from our work across a broad range of areas, e.g., Next Generation Internet, Trustworthy Computing, Mobility, Software Security, Usable Privacy and Security, Businss Risks and Economic Implications, and more. Perhaps even more important is the time to interact one on one with faculty researchers during breaks and meals, and to interact with CyLab's graduate students at the poster session.

Annual Partners Conference content is archived on the CyLab Partners Portal (another exclusive benefit of membership), including videos of the research presentations, along with .pdfs of the slides for each presentation, as well as electronic files of the student posters, documenting current projects.

To entice you to consider taking advantage of the benefits of CyLab partnership, and to contribute to the general dialogue on the vital issues of cyber security and privacy, we have posted a CyLab Partners Conference video sampler and some other content to both the CyLab YouTube Channel and the CyLab iTunesU Store.

The sampler, 9th Annual Partners Conferenece Excerpts, includes two or three minute snippets from each of the following six presentations:
  • Virgil Gligor - "On Foundations of Trust in Networksof Humans and Computers"
  • David Brumley - "Automatically Finding Exploitable Bugs in Off-The-Shelf Executables"
  • Mike Farb - "SafeSlinger: Applied Ad-Hoc Smartpone Trust Establishment"
  • Lorrie Cranor - "Measuring the Success of Web-based Spoofing Attacks on OS Password-Entry Dialogs" 
  • Collin Jackson - "Web Security" 
  • Rahul Telang - "Competition and Data Breaches"
  • Norman Sadeh - "Mobile Privacy"


Four full faculty researcher presentations have also been made available publicly:
Related Posts

Tuesday, October 30, 2012

An Update on My "Secrets Stolen/Fortunes Lost" Co-Author Christopher Burgess



In case you missed it, my Secrets Stolen, Fortunes Lost co-author, Christopher Burgess was featured in a recent Forbes Magazine article on What Do Former CIA Spies Do When They Quit the Spy Game?

Upon retirement after thirty years with the Central Intelligence Agency, in various position including Station Chief, Burgess, was awarded the Career Distinguished Intelligence Medal, the highest level of career recognition. After retirement, he took on important roles in the private sector, first as Senior Advisor to Cisco Chief Security Office (CSO) John Stewart, and then as CSO himself at Atigeo. In the Forbes piece, Christopher shares some insights on his transition:

One [skill] that served me well was my ability to collaborate. That’s a huge skill for a field officer. Everybody on a team has something to contribute and you have to truly recognize and believe that. Another skill is a technique common to planning intelligence operations: building in ‘fall back positions’ and alternate routes while mapping out how to attain a goal. In Agency operations, things go wrong and you have to have backup plans. Also in the corporate world, whether you are selling a widget or consulting, competitors will surprise you. Dealing with that surprise, keeping your cool when all about you are losing theirs, definitely came from Agency training. Another key skill I developed in the Agency was creating loyal workforces, which yield outstanding results. A big part of that is knowing exactly what you are asking someone to do. If you don’t know from personal experience, you cannot be shy about asking them to give you feedback on their probability of success in a risky operation. Art Keller, What Do Former CIA Spies Do When They Quit the Spy Game? Forbes, 10-12-12

As I have mentioned in previous posts, this year, in CSO Magazine, I have been focusing on interviews with C-level executives, who also happened to be thought-leaders. (Surely, you have noticed that "C-level executives" and "thought leaders" are not straightforward synonyms?)

In the first of these interviews (fourth one coming soon), Christopher and I discussed a range of vital issues, but of course we started with a look back at our collaboration on Secrets Stolen/Fortunes Lost:

My 30,000-foot perspective has not changed since we co-authored Secrets Stolen, Fortune Lost — every company (emphasis intended) regardless of locale has the potential to fall into the sights of an entity or individual who has designs on their assets. The company can choose to educate or not educate their workforce to this reality. Sadly, I continue to see far too many companies operating as if they are immune from falling into the cross-hairs of someone's targeting scheme because they aren't engaged in national security work — they equate economic espionage and IP theft to only those in the national security vertical. While I don t disagree the nation state vector is one about which we, collectively, must pay attention; the individual, the competitor and the criminal vectors also warrant every company's attention. How to meet the challenges of 21st century security and privacy, CSO Magazine, 4-18-12

NOTE: You can find links to all my CSO Magazine articles in the CyBlog sidebar.

Christopher Burgess is also one of those experts from business and government (in this instance, it's a twofer!) who have delivered CyLab Seminars in the context of my Business Risks Forum. He has given two Seminars, one in 2010 and one this year.

Access to the webcast and online archive of the CyLab Seminar series is an exclusive benefit available only to CyLab Partners. But from time to time, we release select seminars, and excerpts from seminars, via You Tube and iTunes to both promote our program and contribute to the public dialogue on the vital issues of cyber security and privacy.

Here are embedded videos of both of Burgess' CyLab Seminars. Enjoy.

CyLab Business Risks Forum: Christopher Burgess - Collaborative Distributed Inferencing (2012)



CyLab Business Risks Forum: Christoper Burgess - Common Sense Approach to Social Media (2010)

Monday, October 29, 2012

CyLab Researchers Discuss Code 2600, Award-Winning Cyber Crime Documentary with Filmaker Jeremy Zerechak


Lorrie Cranor, Jeremy Zerechak, Nicholas Christin, Norman Sadeh, CyLab, October 2012

CyLab Researchers Discuss Code 2600, Award-Winning Cyber Crime Documentary
 with Filmaker Jeremy Zerechak

Carnegie Mellon University CyLab recently hosted two screenings of CODE 2600, an award-winning full-length documentary on the societal implications of cyber security and cyber risk.

These evening screenings were preceded by a special CyLab Seminar Series event: a panel discussion in which
 three CyLab researchers, Lorrie CranorNicolas Christin and Norman Sadeh, joined filmmaker  Jeremy Zerechak
 for a discussion of the film and the important issues it highlights.  

Dr. Cranor, who moderated the panel, was among numerous cyber security and privacy experts interviewed in the documentary, others included: world-class cryptographer and security commentator Bruce Schneier
BlackHat and DEFCON founder Jeff Moss, leading security iconoclast Marcus Ranum and Jennifer Granick,
Director of Civil Liberties at Stanford University's Center for Internet and Society

Here is the full video of the panel discussion, beginning with a clip from the film:


For more compelling videos on cybersecurity and privacy, visit the CyLab You Tube Channel and
CyLab iTunes StoreThe content is free!

Thursday, October 18, 2012

Sample Some Fruits of CyLab Mobility Research Safeslinger for Secure Smartphone Communications. It's FREE!



Sample Some Fruits of CyLab Mobility Research, e.g., Safeslinger for Mobile App for Secure Smartphone Communications. It's FREE!

By Richard Power


CyLab has seven major research thrusts (as seven cross-cutting research thrusts); Mobility is one of those seven major research thrusts. And CyLab research isn't locked away in some ivory tower of abstraction; no, it is impacting security in the here and now.

Safeslinger, developed by Mike Farb, Adrian Perrig, Jonathan McCune and other CyLab team members is an excellent example.

This video, available via the CyLab You Tube Channel illustrates the how and why.



More on Safeslinger from CyLab Online

CyLab Chronicles: Mike Farb Offers Insights Into SafeSlinger, CyLab's Powerful New Smartphone App

CyLab's New Smartphone App, SafeSlinger, Empowers Users' to Strengthen Their Own Security and Privacy

SafeSlinger App for Mobile Devices

SafeSlinger: An Easy-to-use and Secure Approach for Human Trust Establishment

CyLab Chronicles: Q&A with Mike Farb (2011)

CyLab Researchers Release KeySlinger, Security App for iPhone and Android

Tuesday, September 25, 2012

BSIMM4 Released; If You Are Not Part of the Solution, Well Then ...



BSIMM4 Released; If You Are Not Part of the Solution, Well then ...

By Richard Power


My perspective on cyber security goes back to the mid-1990s, and well, yes, my view on its current state (and its likely future) is rather cynical. Why? I was among those who spent the 1990s warning of what was to come, and having those warnings discounted by those entranced by that mass of false memes known as "the conventional wisdom." For the next ten years, I watched the nascent trends I had detected become dominant themes in the field. And in recent years, since the retrospective I offered in 2006, it has become chillingly clear to me that neither sufficient political will nor sufficient corporate accountablility exist to address these problems in any meaningful way.

What I do have sustained confidence in, of course, is academic research, particularly that done here at CyLab, such work is one of our greatest hopes, and that is why I am so happy to a part of such a program.

The only other element of contemporary cyber security that I have sustained confidence in is the work of those few in business and government who have made the existential choice to see and respond to what actually is, and do so in some way that can make a real difference in and of itself.

That's why my CSO articles this year (see them listed on the sidebar) are all interviews with c-level security and privacy executives who are also thought leaders (surely, you have noticed that these two descriptors are not synonyms). It is also why I take the time, annually, to report to you on the release of the latest BSIMM.

Am I inferring that BSIMM is THE solution? Of course not. There is no ONE solution. But it is an exemplary effort to mitigate and to collective coalesce around mitigating efforts, and as such it is worthy of both your attention and possibly your involvement.

BSIMM4 encompasses ten times the measurement data of the original 2009 study (95 distinct measurements), it includes updated activity descriptions, and reports on two new activities (bringing the activity count going forward to 111); and (like BSIMM3), it also includes a longitudinal study. 

The project continues to grow is a steady and meaningful way.

The first release of BSIMM, in 2009, included data from nine organizations. By the next release, BSIMM2, in 2010, participation had tripled to thirty organizations.

In 2011, the number of organizations contributing data continued to grow, forty-five organizations were involved in BSIMM3.

This year's iteration, BSIMM4, is built on data from fifty-one firms; and these participants represent a range of twelve overlapping verticals including: financial services (19) independent software vendors (19), technology firms (13), cloud (13), media (4), security (3), telecommunications (3), insurance (2), energy (2), retail (2) and healthcare (1).

The list of organizations contributing data is impressive, e.g., Adobe, Aon, Bank of America, Box, Capital One, The Depository Trust & Clearing Corporation (DTCC), EMC, F‐Secure, Fannie Mae,  Fidelity, Google, Intel, Intuit, JPMorgan Chase & Co., Mashery, McKesson, Microsoft, Nokia, Nokia Siemens Networks, QUALCOMM, Rackspace, Salesforce, Sallie Mae, SAP, Scripps Network, Sony Mobile, Standard Life, SWIFT, Symantec, Telecom Italia, Thomson Reuters, Vanguard, Visa, VMware, Wells Fargo and Zynga.

"A Huge Difference"

To provide some insight on this year's BSIMM release, I caught up with with its architect, Cigital CTO Gary McGraw, and asked him some questions.

What strikes you in this year's data? Or in the cumulative data so far? What stands out as surprising or deserving of added emphasis?

"The BSIMM continues to grow and evolve as we gather more data. We now have 10 times as many measurements as we started with in 2009. Basically, the data show that if you are not doing software security today you are rapidly falling behind. As an example of what this means, consider that two brand new activities were identified in the BSIMM4 model. The field is growing and progressing."

How would you characterize the impact of BSIMM so far? How would you gauge it? What difference is it making? What difference could it potentially make?

"The BSIMM is making a huge difference in software security as practiced in the commercial marketplace. With 51 firms actively participating, the BSIMM has become a large community of like minded professionals. The power of the community is evident during the (private) conferences that we hold once a year. The professionals who run software security initiatives are eager to share what they know and learn from each other."

Download BSIMM4. Review it with your team, bring it to your Board of Directors. Participant in the next iteration. Become part of the solution, or at least an example of what one dimension of the solution would look like.

For more information and to access the BSIMM4 study, which is distributed free of charge under a Creative Commons license, please visit: http://bsimm.com/

Related Posts

BSIMM3 Released: "An Excellent Tool for Devising a Software Security Strategy"

Evolving Rapidly, BSIMM2 Offers Key Elements of Successful Software Security Initiatives Shared by 30 Major Corporations

From Biometrics to BSIMM , & "50 Hurricanes Hitting At Once!" -- A Report on the Sixth Annual Partners Conference

CyLab Business Risks Forum: Gary McGraw on Online Games, Electronic Voting and Software Security

Fortify & Cigital Release BSIMM -- Integrating Best Practices from Nine Software Security Initiatives