Presentation | 2020-03-02 An Evaluation of Contact Points for Security Notifications Miori Saito, Rui Tanabe, Akira Fujita, Katsunari Yoshioka, Tsutomu Matsumoto, |
---|---|
PDF Download Page | PDF download Page Link |
Abstract(in Japanese) | (See Japanese page) |
Abstract(in English) | With the evolving threat of cyber attacks, the importance of security notifications is increasing. In general, information provided by services such as WHOIS are used as contact points for notification. However, in some services, contact points may be kept hidden to the public to protect user privacy or contact information may not be updated frequently. In this study, we conduct notification experiment to contact points collected via various sources besides WHOIS, and evaluate their effectiveness. As a result, out of the 733 contact points obtained by the collection method, the notifications were successfully sent to 476 contact points. By considering what type of organization each contact point belong to as well as the 98 responses we obtained from these notifications, we subjectively evaluate and conclude that 386 of the 476 contact points are appropriate for security notification. On the other hand, from the feedbacks of notified entities, we could only confirm the effectiveness of notification for 6 cases, which indicate that we need further improvement of notification process and reliability as a notifier. |
Keyword(in Japanese) | (See Japanese page) |
Keyword(in English) | security notification / WHOIS / SNS |
Paper # | ICSS2019-94 |
Date of Issue | 2020-02-24 (ICSS) |
Conference Information | |
Committee | ICSS / IPSJ-SPT |
---|---|
Conference Date | 2020/3/2(2days) |
Place (in Japanese) | (See Japanese page) |
Place (in English) | Okinawa-Ken-Seinen-Kaikan |
Topics (in Japanese) | (See Japanese page) |
Topics (in English) | Security, Trust, etc. |
Chair | Hiroki Takakura(NII) |
Vice Chair | Katsunari Yoshioka(Yokohama National Univ.) / Kazunori Kamiya(NTT) |
Secretary | Katsunari Yoshioka(NICT) / Kazunori Kamiya(KDDI labs.) |
Assistant | Keisuke Kito(Mitsubishi Electric) / Toshihiro Yamauchi(Okayama Univ.) |
Paper Information | |
Registration To | Technical Committee on Information and Communication System Security / Special Interest Group on Security Psychology and Trust |
---|---|
Language | JPN |
Title (in Japanese) | (See Japanese page) |
Sub Title (in Japanese) | (See Japanese page) |
Title (in English) | An Evaluation of Contact Points for Security Notifications |
Sub Title (in English) | |
Keyword(1) | security notification |
Keyword(2) | WHOIS |
Keyword(3) | SNS |
1st Author's Name | Miori Saito |
1st Author's Affiliation | Yokohama National University(Yokohama National Univ.) |
2nd Author's Name | Rui Tanabe |
2nd Author's Affiliation | Yokohama National University(Yokohama National Univ.) |
3rd Author's Name | Akira Fujita |
3rd Author's Affiliation | Yokohama National University(Yokohama National Univ.) |
4th Author's Name | Katsunari Yoshioka |
4th Author's Affiliation | Yokohama National University(Yokohama National Univ.) |
5th Author's Name | Tsutomu Matsumoto |
5th Author's Affiliation | Yokohama National University(Yokohama National Univ.) |
Date | 2020-03-02 |
Paper # | ICSS2019-94 |
Volume (vol) | vol.119 |
Number (no) | ICSS-437 |
Page | pp.pp.195-200(ICSS), |
#Pages | 6 |
Date of Issue | 2020-02-24 (ICSS) |