Presentation 2020-03-02
An Evaluation of Contact Points for Security Notifications
Miori Saito, Rui Tanabe, Akira Fujita, Katsunari Yoshioka, Tsutomu Matsumoto,
PDF Download Page PDF download Page Link
Abstract(in Japanese) (See Japanese page)
Abstract(in English) With the evolving threat of cyber attacks, the importance of security notifications is increasing. In general, information provided by services such as WHOIS are used as contact points for notification. However, in some services, contact points may be kept hidden to the public to protect user privacy or contact information may not be updated frequently. In this study, we conduct notification experiment to contact points collected via various sources besides WHOIS, and evaluate their effectiveness. As a result, out of the 733 contact points obtained by the collection method, the notifications were successfully sent to 476 contact points. By considering what type of organization each contact point belong to as well as the 98 responses we obtained from these notifications, we subjectively evaluate and conclude that 386 of the 476 contact points are appropriate for security notification. On the other hand, from the feedbacks of notified entities, we could only confirm the effectiveness of notification for 6 cases, which indicate that we need further improvement of notification process and reliability as a notifier.
Keyword(in Japanese) (See Japanese page)
Keyword(in English) security notification / WHOIS / SNS
Paper # ICSS2019-94
Date of Issue 2020-02-24 (ICSS)

Conference Information
Committee ICSS / IPSJ-SPT
Conference Date 2020/3/2(2days)
Place (in Japanese) (See Japanese page)
Place (in English) Okinawa-Ken-Seinen-Kaikan
Topics (in Japanese) (See Japanese page)
Topics (in English) Security, Trust, etc.
Chair Hiroki Takakura(NII)
Vice Chair Katsunari Yoshioka(Yokohama National Univ.) / Kazunori Kamiya(NTT)
Secretary Katsunari Yoshioka(NICT) / Kazunori Kamiya(KDDI labs.)
Assistant Keisuke Kito(Mitsubishi Electric) / Toshihiro Yamauchi(Okayama Univ.)

Paper Information
Registration To Technical Committee on Information and Communication System Security / Special Interest Group on Security Psychology and Trust
Language JPN
Title (in Japanese) (See Japanese page)
Sub Title (in Japanese) (See Japanese page)
Title (in English) An Evaluation of Contact Points for Security Notifications
Sub Title (in English)
Keyword(1) security notification
Keyword(2) WHOIS
Keyword(3) SNS
1st Author's Name Miori Saito
1st Author's Affiliation Yokohama National University(Yokohama National Univ.)
2nd Author's Name Rui Tanabe
2nd Author's Affiliation Yokohama National University(Yokohama National Univ.)
3rd Author's Name Akira Fujita
3rd Author's Affiliation Yokohama National University(Yokohama National Univ.)
4th Author's Name Katsunari Yoshioka
4th Author's Affiliation Yokohama National University(Yokohama National Univ.)
5th Author's Name Tsutomu Matsumoto
5th Author's Affiliation Yokohama National University(Yokohama National Univ.)
Date 2020-03-02
Paper # ICSS2019-94
Volume (vol) vol.119
Number (no) ICSS-437
Page pp.pp.195-200(ICSS),
#Pages 6
Date of Issue 2020-02-24 (ICSS)