DIGITAL SECURITY AND INFORMATION ASSURANCE


This blog is created to stimulate academic discussion in partial fulfillment of the degree of Doctorate of Computer Science in DIGITAL SECURITY AND INFORMATION ASSURANCE for the Colorado Technical University, Colorado Springs, Colorado.

Courses includes - EM835 Information Accountability and Web Privacy Strategies; SC862 Digital Security; Quantitative Analysis; Software Architecture and Design - CS854;















Saturday, October 19, 2013

The intricacies of Research processes


The intricacies of Research Processes


Arguably, the four most important research elements that the article reminded me are design, measurement, analysis and high ethical standard in whatever research methodology or approach used in my doctorate dissertation. The authors emphasized how a solid research planning or strategy often produces an excellent research result that can contribute to the body of knowledge. This observation and experience according to the authors cut across both qualitative and quantitative research methodologies.

I was initially showing an interest to use qualitative research strategy for my research during and after the qualitative class last semester. But the dynamic has changed.
The reason is that quantitative method would enable me to use various statistical analysis procedures that may help to explain why the incidences of malware shows no abate on the web. I should be able to either use experimental or survey research design to focus on my research. My research committee under the direction of Dr. Stout has the final say on this one. Although the IRB process will be an integral part of the research to ensure that high ethical standards are followed.

The authors advised to do enough literature searches as part of research plan is no doubt important. This can help to narrow down the research focus and provide a mean to craft a well defined research proposal.
In addition, research reports according to the article must be presented in a format that is acceptable both to the school and the academic community. Peer review of papers to be published was also recommended for credibility.

Reference:


Burian, P., Rogerson, L., & Maffei III, F. (2010). The Research Roadmap: A Primer To The Approach And Process. Contemporary Issues In Education Research (CIER), 3(8), 43-58. Retrieved from http://journals.cluteonline.com/index.php/CIER/article/view/226/217

Monday, September 3, 2012

RBAC Approach and implementation

Access control is the heart of security and also the first line of defense in asset protection. Arguable so because it has the ability to allow only authorized users, programs or processes system or resource access to a particular object on a network or stand alone system.
In discretionary access control (DAC), the custodial of the data or information determines or specifies which persons or subjects can access the data or information resource. The access control to the information asset is at the discretion of the owner (Harris, 2010). 

Most DAC systems grant or deny access based on the identity of the information or data requester. Often DAC uses ACLs (access control lists) to grant or deny access to network resources. However, in mandatory access control (MAC) access to information resource is based solely on security labeling system. In which case users have security clearances and resources themselves have security labels with data classifications. MAC implementation is found in certain environments where information classification and high confidentiality are of paramount important. A good example is in the military. In MAC implementations, the system makes access decisions by comparing the subject’s clearance and need-to-know level to that of the security label (Harris, 2010). An essential feature of MAC is that the underlying operating systems enforce the system’s security policy through the use of security labels on information assets and the level of security clearance a user possesses. 

In contrast to the above two models is the role based access control (RBAC) sometimes called non –discretionary model. With RBAC, access to information resources is based on the role users are assigned in the organization and nothing more. Kayem, Akl, & Martin (2010) observed that role-based access control (RBAC) is a combination of mandatory and discretionary access control; and also RBAC models are more flexible than their discretionary and mandatory counterparts because users can be assigned several roles and a role can be associated with several users. 

Although the access control implementation will depend on the environment. But in a distributed environment where I have been privilege to implement RBAC, the RBAC model is the best out of the three because users’ role can be mapped to job function and authorization level. By using the authorization level, user privileges can be easily designed without having to resort to ACLs commonly used in DAC. In addition, RSAC according to Kayem et al. (2010) assigns permissions to specific operations with a specific meaning within an organization, rather than to low level files as in other models. The incident of Trojan horse infection on the network can be reduced by implementing RSAC. DAC is silent on the ways files are to be modified in network operations and this open more ground for security vulnerabilities.

I will use a centralized access control administration as a way to increase security because all access requests will go through a central authority. Visibility on access operations will be enhanced as administration is more simplify. As an administrator, I will only have to cope with a single point of failure and access performance bottlenecks on the network will be easily controlled (Smith, J.)


Reference:

Harris, S. (2010, 5th Edition). CISSP all in one exam guide. Columbus, Ohio: McGraw Hill.

Kayem, A., Akl, S., & Martin, P. (2010). Adaptive cryptographic access control. Advances in Information security, DOI 10.1007/978-1-4419-6655-1_2.

Smith, J. Access Control Systems & Methodology. Retrieved April 29, 2012, from 
www.purdue.edu/securepurdue/docs/training/AccessControls.ppt

Risk Management a must for Security

Risk management in information security program is one of the yardsticks of due diligence and care that formed the cornerstone of information security governance. One of the ways to incorporate risk management and assessment in the security program is to establish a security policy and procedure in the organization. The security policy will form the basis of risk management policy that will be tailored to address the following 

* Uncovering potential dangers in the environment

* Researching and understanding the vulnerabilities, threats and risks that is
peculiar to the environment

* Performing periodic security assessments

* It is absolutely essential to perform analysis of assessment data. This can be used to establish a security baseline with necessary security controls to adequately safeguard information assets.

We need to know where we are going and where we are coming from in term of security for the security program to succeed in any organization. The benefits of risk analysis are immeasurable because it helps to us to understand what exactly is at risk in the environment; to conform to due care and comply with legal and regulatory requirements (Harris, 2010). 

By performing risk analysis, we are in better position to know what security controls, countermeasures and safeguards to implement in order to re-enforce the environment security posture in view of known vulnerabilities and risks. For instance, the risk assessment could mean the patch management and anti-malware deployments should be more visible. According to Harris (2010), a risk analysis helps integrate the security program objectives with the company’s business objectives and requirements.

I will confront emerging threats by making sure that adequate security controls both technical and administrative are in place and also by fine tuning continuous education of users of the importance of information security as they perform their daily tasks. Security monitoring and awareness training will also be heightened to address all forms of social engineering and non- compliance with security policy and procedures. Without implementing adequate protection measures, enterprises are at risk of having their operations critically disrupted (Murphy & Zwieback, 2005). No amount of IDS, IPS and firewalls can offer the necessary protection if the users who are in the first line of defense fails to imbibe simple security rules.
The risk assessment will include a detail threat and vulnerability analysis, a thorough examination of countermeasure mechanisms as well as assets identification. Without these components the purpose of the risk assessment is defeated and the whole risk management program might be in jeopardy. 

References:

Harris, S. (2010, 5th Edition). CISSP all in one exam guide. Columbus, Ohio: McGraw Hill.

Murphy, J. & Zwieback, D. (2005). Managing emerging security threats. Retrieved April 24, 2012, from http://www.greetsomeone.com/pdf/inkcom_managing_security_threats.pdf

Cyber attack or terrorism is real

President Bill Clinton in 1998 put it rather direct “Our foes have extended the fields of battle – from physical space to cyberspace” (O’Hara, 2004). If our former president acknowledged this fact, I strongly believe that cyber terrorism or attack is a real and an ever expanding threat against our well being and a security challenge. O’Hara (2004) pointed out that cyber warfare is now a primary tool in the information warfare arsenal to achieve non-kinetic attacks which is the type of attack not aimed at physical destruction but is designed to impact the adversary’s will to fight and decision making process.

The US federal government has acknowledged that we are susceptible to cyber terrorism because digital security controls has not been built into most of our critical systems from the design phase and in the entire system life cycle. It is now that we are catching up and the resilient of our cyber protecting mechanisms are still questionable. Cyber attacks can easily be launched provided you have a computer; internet connection and a variety of hacking and cyber warfare tools which are available on a multitude of internet sites worldwide. The price of perpetrating a cyber attack is just a fraction of the cost of the economic or physical damage such an attack can produce: cyber attack is also characterized by aggressive enemy efforts to collect intelligence on the country’s weapons, electrical grid, traffic-control systems, and even its financial markets (Lipman Report, 2010). 

The damage to our critical infrastructures will be unprecedented if we are attacked by cyber criminals either sponsored by rogue states or organized criminals. Our transportation hubs, air-control systems, water treatment plants and telecommunication facilities are targets of such attacks and the impact on our lives will be so catastrophic and the economic loss will be immeasurable and may be worst than 911. Cyber warfare can negatively affect our economic prosperity in this century and beyond. Just of recent a cyber attack due to the Stuxnet worm caused international havoc and systematically shutdown the Iranian nuclear program.

The treat of cyber attacks is real if the likes of Google and Cisco networks can be hacked and attacked by the bad guys. Exploitable vulnerabilities are making our critical infrastructures unsecured to the point that hackers are just a step away of using malicious codes to take full control of even the highly classified systems. This is frightened but is the truth. It is only recently that the US federal government through the various agencies under the auspices of NIST sanctioned them to perform periodic the risk assessment of their systems and network infrastructures. The agencies are to develop remedial and mitigation plans to curtail security risks and other associated problems within a timeframe. However, if we anticipate and know of any imminent threats from cyber criminals or rouge states, we have absolute right to defend ourselves using all information security arsenals and even convectional weapons. Pre-emptive strikes should be part of our cyber security defense vocabularies and we must be capable of developing cyber offensive capabilities. Good defensive operations will point in the direction of the attacker, which then allows offensive operations to target them for retaliation (O’Hara, 2004). 

Urgent proactive actions such continuous monitoring , patch management and development of multiple layers of defense as well as perimeter securities are needed to guide against cyber warfare and other malicious intents. In addition, we need to train more security professionals who can design secure systems, write safe computer codes and create the ever more sophisticated tools needed to prevent, detect and mitigate and reconstitute systems after an attack (Lipman Report, 2010). We must not be complacent with our security and develop false sense of security when are still vulnerable to incessant cyber attacks.



References


O’Hara T. (2004). Cyber warfare and cyber terrorism. Retrieved April 12, 2012, from http://www.dtic.mil/cgi-bin/GetTRDoc?Location=U2&doc=GetTRDoc.pdf&AD=ADA424310

The Lipman Report (2010). Threats to the information highway: Cyber warfare, cyber terrorism and cyber Crime. Retrieved April 12, 2012, from http://www.guardsmark.com/files/computer_security/TLR_Oct_10.pdf


Godwin Omolola

Saturday, October 1, 2011

Common Quantatative Analysis Questions and Answers.

Below are common Quantitative Analysis related Questions and solutions

What is the nature of causation and what are the criteria for assessing causation?
The nature of causation is often to show that causes differ in significance and thus warrant further investigation and examination in details. This investigation often falls in three distinct categories to determine the necessary cause, sufficient cause and contributory cause. To show causation it must be obvious that the variables are statistically related. Causation cannot be prove with complete certainty.
Causation also differs in the timing of their influence.

The major criteria for assessing causation are whether the conditions for the cause do exist in the first place. Causation always makes it possible to conduct further investigation on correlation between variables.
It is important to know whether the causation is linear in nature or reciprocal in order to assess it. The linear causality assumes causal influence is in one direction. While reciprocal depict the causal influence is bidirectional or sometimes circular.
In quantitative research analysis, correlation can never in its entirety show causation because it does not imply causation.


Discuss the difference between experimental and correlation research?
Experimental researches involve processes that clearly define the design approach used in conducting the research in question. In a way, it emphasized how data is collected for final analysis. In experimental research, the researcher can manipulate his or her experiment and check the effect or results of the initial manipulation.
While correlation research involves analysis tools used in conducting the research. Variables are not influenced but only the relationship between them is measured and show by the researcher. In addition, sometimes there is correlations in experimental research but typically one of the variables is manipulated.

Finally, experimental research is only about experiment while correlation research is common in archival research, naturalistic observation, survey research, and even in case study.
 
How can surveys be designed to elicit the most valuable responses?

Surveys generally accomplish two main purposes to know new thing about the research and to be able to generalize from the survey data. Therefore in order to elicit adequate and most valuable responses from respondents, it is essential to use a design approach that is consistent with the following:
-The quality of survey questions must be well tailored to the focus group.
-The questions should be well designed, meaningful and sample size manageable.
- Appropriate survey techniques such as mailing, email, telephone must be employed and used in the circumstance under consideration.
- Appropriate language of communication that is comfortable with the audience especially during face to face encounter must be used.
- Survey questions must be devoid of ambiguity. It is important to test the questions.
- A face to face encounter with survey respondents often provides more tenable answers.
- The researchers must provide enough clarification being asked by survey respondents.
- There is no basis for being bias because a biased sample will produce biased results.


When do ethical issues become important in experimental research?
The ultimate aim of any experimental research work is to advance and contribute to the body of knowledge. Thus serious ethical issues become concerns when for instance there is glaring abuse in selection process of research participants. A good selection process must be undertaking and encouraged. It must be deemed fair and balance and not tainted to favor a group or set of people.
Informed consent must be afforded to all research participants partly to address any of their concerns as well as afford them the opportunity to know what the research is all about. If otherwise, the experimental research could be said to fail one of the ethical standards recognized worldwide in research projects.
The risks and benefits of the research must be well spell out and clarified to  subjects or research participants in order to alleviate issues that bother on ethical concern. Which I believe can later jeopardize the whole research efforts.
Discuss threats to validity.
Bias will increasingly be recognized as one of the most important threats to validity that must be addressed in the design, conduct and interpretation of research. Not removing bias can in the long run compromised the final interpretation of research result hence its validity.
Also, the low reliability of measures which can be attributed to factors such as poor question wording, bad instrument design or layout, illegibility of field notes are great threat to research validity.
Passing communication among research subjects who are not suppose to know it until the research exercise is over can affect the validity of the research in a negative way. This will greatly reduce the measurable effects of the research program because the information so obtain indirectly cast doubt on the true validity of the research results.

How can computer output for t-tests and confidence intervals be interpreted?
The t-tests output can be interpreted in the context of regression analysis whether a regression coefficient (b) is significantly different from zero. However, in the context of experimental work, it is used to test whether the differences between the two observed means are significant different from zero. For instance, SPSS provides the exact probability that the observed value of “t” would occur if the value of “b” in the population were zero. In this regard, if the observed significance is less than .05 (p <0.05), we may conclude it reflect a genuine effect from the population.
Confidence intervals can be interpreted from means by looking at the range of values that contain with some probability (95%) of the true value from the population. In a computer output, it represents the 95% of the difference between the lower and upper limits by estimate. This mean that the true value of the difference in population is somewhere between the limits and we can be 95% confidence of this value.

Are regression and ANOVA antagonistic methods.
The answer is affirmative no and undoubtedly, Regression and ANOVA are both based on the general Linear model (GLM). The techniques are recognized as two most useful statistical analysis tools be it in business, psychology or sociology circles. In fact, they are complementary tools and are not antagonistic as some school of thoughts argued. For instance and in most researches, when it is desirable to test a multiple regression equation for the statistical significant factors or measureable variables, it is imperative to start with ANOVA.
In the same token, when using ANCOVA for analysis the degree of covariance and in order to improve on an ANOVA technique it is usually incumbent on the researcher to use regression methods. The regression method applied in this way enable on the spot adjustment for a control variable before embarking on ANOVA. Reliability of statistical analysis and results in such research undertaking are further reinforced. So I submit to this forum that it depends on what the statistical research want to achieve and the information the researcher wants to convey to the public.
It is important to stress that for any statistical output to be considered validated when using ANOVA or regression techniques; certain assumptions must be fulfilled and tested. For example in ANOVA, measurable independent variables must be categorical.

Reference:
Field P.A. (2009). Discovering Statistics Using SPSS, 3rd edition.  Thousand Oaks, CA: Sage.
Vogt, W. P. (2007). Quantitative research methods for professionals. Boston: Pearson Education, Inc.

Thursday, September 29, 2011

Type 1 error and Type 11 error in Quantitative analysis

Type 1 error and Type 11 error
A type 1 error occurs when it is infer that a hypothesis is true when in actual sense is false. In other word, an experimental research is considered falsely successful to support a hypothesis. Example is when a patient is wrongly told that he or she has a highly infectious disease when in actual fact is not.  Also a driver is punished for no fault according to eye witness reports. In both cases, this in statistical parlance is a false rejection of the null.
Whilst the type 11 error is committed when it is deduced that a hypothesis is false when in actual sense is true. For example, a group of white Caucasians are wrongly classified as Orientals in an ethnic study. Also a negative pregnancy test when in reality the woman is says two months pregnant. This is a false acceptance of the null hypothesis

Tuesday, March 29, 2011

Privacy and Security Issues in Social Networking

                            
Project Paper: Privacy and Security Issues in Social Networking
Dr. Brian Pankau
                   Submitted in Partial Fulfillment of the Requirements for EM835
Information Accountability and Web Privacy Strategies
(Winter 2011)

Abstract

Most online social networking sites share a core of features that are completely absent in their offline counterpart. The relation between privacy and a person’s social network is multi-faceted. In certain occasions we want information about ourselves to be known only by a small circle of close friends, and not by strangers. In other instances, we are willing to reveal personal information to anonymous strangers, but not to those who know us better. In this paper, I highlight the privacy issues as well as digital security problems the rapid growing online social networking sites are facing. I also put forward a set of recommendations that makes social networking safer and promote healthy web interactions.

Introduction

The online social networking goes like this, an interested individual with an internet connection visit the social site. The individual creates a profile of themselves which includes names, sex, age, and geographical location to others to peruse, with the intention of contacting or being contacted by others or to meet new friends or dates.
Gross R. et al (2005) observed that “While social networking sites share the basic purpose of online interaction and communication, specific goals and patterns of usage vary significantly across different services.
The most common model is based on the presentation of the participant’s profile and the visualization of her network of relations to others - such is the case of Friendster”. The model varies and is completely different in some social network sites like match.com, salon and others while it is absolutely compulsory to have a profile for you to interact with other members. In some, the creation of a profile is secondary for instance on Livejournal.com. Therefore the patterns of online personal information revelation are quite variable as you transverse one social networking site to another. For instance, the use of a person real name to represent an account profile is encouraged on some sites like facebook.com but is the opposite in some sites.
Social networking sites like facebook tend to connect participants’ profiles to their public identities. This has its own demerits as well as privacy problems. A site like Friendster doesn’t encourage the use of real names in fact there are filters that shield the public identity of a person and his or her online persona by making only the first name visible to others and not the last name. “Notwithstanding the different approaches to personal identity, most sites encourage the publication of personal and identifiable personal photos (such as clear shots of a person’s face” (Gross R. et al (2005). It has been reported that online social networks are vaster and have weaker ties, on the average, than the offline social networks.
Trust in and within online social networks may thus be assigned differently and could therefore have different meaning than their offline counterparts. Consequently, the degree of privacy evasion is more in online networks because of the loose relationship within such communities. In essence, trust decrease within online social network.



1. 0 Privacy implications

The privacy implications associated with online social networking in this technology age are manifolds and depends to large extent on the level of identification of the information provided, its possible recipients and uses. In a study conducted by Gross R. (2005), it was discovered that “Even social networking websites that do not openly expose their users’ identities may provide enough information to identify the profile’s owner. This may happen, for example, through face re-identification”. Identifiable information is often available to the hosting sites of some of the notable social networks. These sites may on their own use the information knowingly or sometimes revealed the information to third party thereby contradicting their own privacy or user agreements.
            The easiness of joining and at the same time of extending one’s network on most of these social networking sites makes it easy for hackers to access online the community users’ data. 
Newitz A. (2003) reported that “LiveJournal used to receive at least five reports if identification hijacking per day”. Some unscrupulous persons and con artists often navigate online social web sites and have been using stolen identities to commit frauds and other crimes. With stolen identities, hackers sometimes entice unsuspecting social network members in chat rooms into parting with money, peddle traditional business opportunity scams. It was reported by the Federal Trade Commission the con artists are contacting social networking site community members through email with false promises about earnings through day trading. Also hijacking unsuspecting members' modems and cramming hefty long-distance charges onto their phone bills.
Some online social networking community members do not care about the amount of information they reveal online. This is because the type of information they revealed often include such things as
Hobbies and interests,
Information about current and previous schools
Employment history or information and name of employers
Private information such as drinking, smoking and drug habits
Sexual preferences and orientation
Age
Marriage status
Geographical location.


            The information stolen from social networking sites and communities can be used for various purposes depending on the type of information or data retrieved. Some of the information can be somehow intimate or extensive. The risks include online and physical stalking, personal embarrassment, price discrimination and more so blackmailing. Privacy is virulently at risk but who is to blame if you realize that most information on social networking sites is freely given by member themselves. Hence privacy expectations may not be matched by privacy reality. Facebook for instance, is straightforward about the usage of personal information it collects from members even on the one unknowingly provided for example the IP address of login members.  Facebook detailed its privacy policy as follows:


1. Introduction
2. Information We Receive
3. Sharing information on Facebook
4. Information You Share With Third Parties
5. How We Use Your Information
6. How We Share Information
7. How You Can Change or Remove Information
8. How We Protect Information (adapted from facebook.com/policy.php)

 1.1 Embarrassing Digital Dossier  

Social networking sites build a digital dossier of the information they received from participants judging from the low and decreasing costs of storing digital information nowadays. So it is possible to continuously monitor user’s profiles on these social networking sites which currently are consider insignificant but may become public information as time goes on. Views that are considered privately expressed may become an embarrassing nightmare in the future when the data currently mined are freely available. Only time will tell as technology of online networking is unbelievable dynamic.

1.2 Stalking and Cyber-Stalking

            A rather dangerous side effect of privacy evasion from online social networking sites is the tendency of being stalked by online acquaintances. It is very common to socialite with online friends within same geographical areas. For example, Facebook have recently introduced a new relationship based on user location. In fact profiles on the site contain information about residence location, sometimes class schedule and location of last login. A completely derail person who has previously obtained or have a knowledge of someone location due to an online association can stalk that person.  In the same token, a potential stalker can take advantage of its prey because the resident location information is available to him or her with easy.
            Privacy evasion is becoming more apparent on social networking sites with instant messenger services and those that offer chat room for participants. For example, AOL instant messenger has a feature called buddies list. But unlike other messaging services, AIM allows members to add buddies to buddies list without their knowledge or confirmation. Once the attacker is a buddies list, the victim can be tracked as soon as he or her logon to the social networking site. The notoriety is called cyber-stalking.

1.3 Fake Email address for Account creation
            The process of verifying a user registration on most social networking sites takes minutes, therefore a hacker can quickly join an online social site also within a couple of minutes.
The social networking site will verify the hacker as a legitimate user by sending a confirmation email to the fake email address he or she quickly created to login to the site. So the process of account creation and verification on social networking sites is an added incentive to hacker’s detective mission to steal and retrieve genuine user information.


1.4 Manipulation of Users
            It has been reported that obtaining confidential information from social networking sites has taken a new dimension. Social engineering antics are now being employed to retrieve personal information from unsuspecting online socialite. According to Jump K. (2005), “thirty percent of Facebook users are willing to make all of their profile information available to a stranger and his network of friends”.

1.5 Cyber Bully
The privacy concerns have also resulted in a number of reported cases of online bully especially among young teenagers in our education systems mostly in primary and high schools. Many factors have since been identified as contributory factors to online bully on social networking sites and in order to reduce such incidents the following have been recommended.
○ Raise awareness of safety education messages and acceptable use policies on all social          
   networking sites frequent by kids for instance Facebook.
Ensure that services are age-appropriate for the intended audience.
Empower users through tools and technology to be able to block any one that bullies from                            
  many direct contact with them.
Provide easy-to-use mechanisms to report illicit conduct or improper content.
Promptly respond to notifications of illegal content or conduct.
○ Enable and encourage users to employ a safe approach to personal information and privacy,
Assess the means for reviewing illegal or prohibited content and bullying conduct.

1.6 Single sign on promotes dynamic privacy
            Just recently, Facebook launched its “Facebook connect” service to try to solve a major ache of online computing especially among social networkers. According to Harris S. (2009),
“it saves visitors from having to fill out yet another tedious registration form, upload another profile picture and memorize another username and password. Instead, visitors can now sign into other sites using their existing identity on Facebook”. The Facebook connect service is helping to promote dynamic privacy by aiding profile sharing amongst various online destinations.


2.0 Security Implications
        It is reasonable to expect that security issues of online social networking sites far outweigh its offline social forum.
The social network sites most likely to suffer from privacy and security issues are the popular ones. Privacy issues most often involve the unwarranted access of private information and may not be directly due to security breaches. A crafty and determined individual may through shoulder peeking watch you type your password and consequently use it to obtain confidential information from your computer at a later time.
According to Brendan Collins (2008), “a security issue occurs when a hacker gains unauthorized access to a site’s protected coding or written language” There is a clear distinction between privacy and security issues that most social networks faces due to rapid popularity and its profitable financial importance. There is a tremendous amount of information and data that most social network sites processes every day.  Thus there could be lapses in security on those sites making it possible for would -be-hacker to exploit flaws in the systems.
The following features on network social sites which involve mass participation of people are targeted by hackers or site attackers:
Chat rooms
Messages
Invitations
Photos
• Open platform applications.

It has been reported that the aforementioned features are avenues to gain unprecedented access to some privacy information of unsuspecting individuals. A recent case in mind is the one that shows a devastating hole in the framework of a third party application programming interface on Facebook. This programming flaw allows hackers to gain unrestricted access to private information. The developers of those applications failed to follow sound programming techniques thereby exposing more information than necessary to run the application in the first place. This glaring consequence of over-sharing of user data is not new because security of social network sites has not been taking seriously until just recently. To mitigate against such security problems, some sites introduce users privacy controls at all levels within profiles. But such increase privacy settings does not in all ramifications guaranteed adequate privacy and security issues. Most social network sites do not have a streamline way to test third party applications where users’ data and information can be retrieved without consent. Such application flaws can allow criminal minded developers to sell users data to advertising companies for financial gains.
The online social security issues incorporated its entire offline counterpart and include risks that are growing daily. Some of these include:

Identity Theft
● Email spamming to propagate malware
● Use of false profiles
● Social Engineering tactics to retrieve information
● Targeted attacks through botnets
● Vulnerability to Cross-site scripting e.g. MySpace.                                                                                  ● Source of releasing confidential or proprietary information
● Phishing Attacks



Data and Information

Gross R. et al (2005) found that “across different sites, anecdotal evidence suggests that participants are happy to disclose as much information as possible to as many people as possible. It is not unusual to find profiles on sites like Friendster or Salon Personals that list their owners’ personal email addresses (or link to their personal websites), in violation of the recommendation or requirements of the hosting service itself”.
Most internet based companies hold large volume of personal data which are unregulated and includes:
1. Processing of the data
2. Analyzing data
3. Transmitting data
4. Collection of data.
In the light of mass database in various data centers around the world, one can categorically agree with the assertion that “data processing technology and the creation of mass databases inevitably erode privacy” (Landy K., 2008).
We all know that there’s need for well-conceived privacy policies to take care of the unprecedented digital privacy issues, but leadership is lacking both in government and in private settings.
Due to the explosive use of online social networks, various notable businesses have been building applications to target such users. There are increased efforts for communicating with people using those sites and is been intensified. Most companies are using targeting marketing strategy to:
Monitor their habits and views
For influencing their opinions and
Direct their spending powers

Among the menace of the social networking sites are:
Data safety – frequent visitors are continuously hit by identity theft and frauds.
Minors are expose to improper content or faces indecent exposure online
People entering into dangerous relationships
Elderly are lured in risky financial dealings.

The exponential growth in the number of users using social networking sites is not a surprise.  In 2008, the total number was put at 200 Million, now the number as reported by various online Watchers put the figure roughly at 700 million users with facebook only having a total of 500 million registered users and is still growing by the hour.  Hofer F. (2010) observed “Given these figures it’s definitely no surprise that companies from various industry sectors are keen on trying to develop potential business applications with a specific focus on social network
users”. The notion is online social networking users are potential customers in all indications.
In fact, social networking sites are regarded as the new business environment and a lot of
companies are building application to specifically target social-networkers using various
marketing tactics available in their arsenals.

Lack of Social network Policies:

It was observed during the international conference on data protection and improper use of private information posted by users on social networks that some golden rules be observed.
These are categorized in term of users and online service providers. Users were advised to:
• Carefully select which personal data (if any) to be posted on a social network.
• Bear in mind other individuals’ expectation to privacy when publishing information
  about them.
• Always be cognizant that security of their information online is not 100 percent guaranteed.
• Users’ information can be mined and use for various marketing purpose by online marketers.

The online social networking service providers were reminded among others to (adapted from Harris S. (2009):
■ Comply with privacy standards in place and as per regulatory authorities.
■ Inform users adequately about use of posted data, possible consequences of their
    publishing and security risks.
■ Favor to a maximum extent users’ control on their data and profiles.
■ Offer users privacy-friendly default settings.
■ constantly improve systems’ security in order to prevent fraudulent access.
■ Granting users’ right to access control and correct their personal data.
■ Offer suitable means for deleting personal profiles and information once membership
     is terminated.
■ Enable the creation and encourage the use of pseudonyms.
■ Prevent uncontrolled third party access and practices such as spidering and bulk
    harvesting.
■ Allow external crawling only on users’ informed, specific and in-advance consent.




Recommendations and Solutions to social network privacy/security issues

◊Don't share your password with anyone.
◊After you type your login credentials into the login page, make sure you uncheck box
  “remember me”.
◊Always log out when you're finished using any social networking site.
◊ Try to avoid to put sensitive information on social web sites, choose what kind of information you share with the site and how much.
 ◊ Choose to put just the essential things, for example if you deal with hobbies (music etc.) don't add non-essential work information.
◊.Customize your privacy settings
◊ Blocking accesses and eventually report privacy violations.
◊. Limit your online social activity and online presence
◊. Don’t post anything that you are ready to divulge to a complete stranger
◊. Be sure of the identity of who you add as an acquaintance online
◊ Read the privacy disclosure of the site before you join
◊. If possible, verify that adequate privacy settings are allowed on the site



CONCLUSION:
            Humans by their nature are social animals thus online social networks are genuine avenues to exercise more interactions. Social networks are not threats but they are created to offer more opportunity for social interactions universally. A common sense approach is needed to guide against unsolicited friendship and information dissemination in online social networking forum.  The false of security makes people on social sites to divulge so much information about themselves. Geolocation services being offered on some sites keeps a record of where online participants visit and go. The security implication is grave and alarming because the information that is leaked online can undoubtedly used against the person divulging the information. What hitherto is considered private is no longer private. Also, constantly update profile information with your whereabouts could open a flood gate for criminals to target your house and burgled it.
            To avoid identity theft, the use of secure credentials is recommended on social networking sites.  A weaker password for example could compromise a participant’s account and hackers can use it to spam all your contacts. There is also need for industry regulation and policy on the social networking sites

Reference

Acquisti, A., Gritzalis, Stefanos, Lambrinoudakis, Costas, De Capitani Di Vimercati, Sabrina (2008). “Digital Privacy, Theory, Technologies, and Practices”. Auerback  Publications. Taylor & Francis Group, LLC

Gross R. (2005). Re-identifying facial images. Technical report, Carnegie Mellon University, Institute for Software Research International, 2005. In preparation.

Gross R., Acquisti A. and John Heinz H. III. Information Revelation and Privacy in Online Social Networks. Retrieved 03/12/2011 from,
http://dataprivacylab.org/dataprivacy/projects/facebook/facebook1.pdf

Collins B. Privacy and Security Issues in Social Networking. Retrieved 03/12/2011 from,
http://www.fastcompany.com/articles/2008/10/social-networking-security.html

Harris S. (2009). Security Issues of Social Network Sites. Retrieved 03/12/2011 from,
http://www.informit.com/blogs/blog.aspx?uk=Security-Issues-of-Social-Network-Sites

Hofer A. F. Privacy issues in social networking: the European perspective1. Retrieved 03/15/2011 from, http://www.gala-marketlaw.com/pdfs/Privacyissuesinsocialnetworking.pdf

Jump K. (2005). A new kind of fame. Retrieved 03/15/2011 from,
http://www.columbiamissourian.com/stories/2005/09/01/a-new-kind-of-fame/

Newitz. A. (2003). Defenses lacking at social network sites. Security Focus, December 31, 2003.
Oram A. & Viega J. (Eds.). (2009) Beautiful security: Leading security experts explain how they think (pp 33-61). Beijing: O’Reilly Media
Zorz M. (2009). Social networking privacy issues. Retrieved 03/13/2011 from,
http://www.net-security.org/article.php?id=1331

Facts for Consumers.  Retrieved 03/16/2011 from
http://www.ftc.gov/bcp/edu/pubs/consumer/tech/tec09.shtm

Social Networking Sites: A Parent’s Guide. Retrieved 03/16/2011
http://www.ftc.gov/bcp/edu/pubs/consumer/tech/tec13.shtm

The Facebook. Privacy policy. Retrieved 03/16/2011 from,
http://facebook.com/policy.php, August 2005.