Privacy By Design - Interdisciplinary Privacy Course

26-Jun-2012

This interdisciplinary course is part of the thematic training of the Leuven Arenberg Doctoral School Training Programme. The course is mainly aimed at Ph.D. students from all disciplines (either from the K.U.Leuven or from other universities), but also open to undergraduate students, post-docs, people working in industry, or anyone else interested on the topic.

In a series of lectures, the course will provide an overview of various aspects of privacy from the technical, legal, and social science perspectives. This year’s edition of the course will have a special focus
on privacy by design, web search services, and behavioral advertising.

Privacy By Design - an important challenge for the Security Industry at Large

In addition to the lectures, this year’s course will feature interactive exercise sessions in which the participants will work in groups. In these exercise sessions the participants will apply what they learn in the lectures to a practical case study (web search application). The participants will be asked to identify the stakeholders and their requirements, define the functionality of the system, select the technologies that would be implemented in the design, and discuss the legal and societal aspects of the system. The participation in all the sessions is required in order to obtain the certificate of attendance to the course.

=================================================================================

* When

- Wednesday, June 27, from 9:15 to 17:00
- Thursday, June 28, from 9:00 to 17:15
- Friday, June 29, from 9:15 to 16:30

* Where

Lecture room: MTC1 02.07
Interactive exercise sessions rooms: MTC1 00.07 and MTC1 00.16

MTC1 Maria-Theresiacollege
Sint-Michielsstraat 6
3000 Leuven (Belgium)

* Speakers

- Claudia Diaz (KU Leuven ESAT/COSIC)
- Seda Gürses (KU Leuven ESAT/COSIC)
- Eleni Kosta (KU Leuven Law/ICRI)
- Bettina Berendt (KU Leuven CS/DTAI)
- Jo Pierson (VUB IBBT-SMIT)
- Invited speaker(s) - TBA

* Registration

- The course is free of charge, but attendees are required to register by sending an email to claudia.diaz@esat.kuleuven.be
- The course will provide coffee breaks for the participants. Lunches are not provided. A number of restaurants are in the vicinity of the course venue.
- The registration deadline is: Tuesday, June 20, 2012

* Web page

http://people.cs.kuleuven.be/~bettina.berendt/teaching/Privacy12

=================================================================================

*** Programme

Wed June 27

09:15 - 09:30 Welcome coffee
09:30 - 10:15 Lecture 1: Introduction (Claudia Diaz)
10:15 - 11:15 Lecture 2: Addressing Surveillance and Privacy during Requirements Engineering:
The challenge of search and behavioral advertising (Seda Gürses)
11:15 - 11:40 Coffee break
11:40 - 12:30 Explanation of the practical exercise (Seda Gürses)
12:30 - 14:00 Lunch break
14:00 - 15:15 Exercise session 1
15:15 - 15:40 Coffee break
15:40 - 17:00 Exercise session 2

Thu June 28

09:00 - 09:15 Welcome coffee
09:15 - 10:15 Lecture 3: Web mining and privacy: threats, opportunities, and design issues (Bettina Berendt)
10:15 - 11:15 Lecture 4: Social perspective on (dis)empowerment of users in an internet environment (Jo Pierson)
11:15 - 11:35 Coffee break
11:35 - 12:35 Lecture 5: Technologies for private search (Claudia Diaz)
12:35 - 14:00 Lunch break
14:00 - 15:00 Lecture 6: (Re)introducing privacy by design: the realm of search engines (Eleni Kosta)
15:15 - 15:35 Coffee break
15:35 - 17:15 Exercise session 3

Fri June 29

09:15 - 09:30 Welcome coffee
09:30 - 11:00 Invited talk (tba)
11:00 - 11:20 Coffee break
11:20 - 12:30 Exercise session 4
12:30 - 14:00 Lunch break
14:00 - 15:00 Exercise session 5: preparation of presentations
15:00- 15:20 Coffee break
15:20 - 16:30 Presentations of results of the exercise and discussion

=================================================================================

*** Abstracts

Lecture 1: Introduction (by Claudia Diaz)

This lecture will motivate the need for privacy protection, introduce the arguments in the privacy debate, and review the main approaches to privacy. Some of the questions that we will address in this talk include: Why is privacy important? Why is it so complex? What are the different meanings of “privacy”? How does “privacy” translate to technical properties and how do these relate to classical security properties?

Lecture 2: Addressing Surveillance and Privacy during Requirements Engineering: The challenge of search and behavioral advertising (by Seda Gürses)

Privacy is a debated notion with various definitions that are also often vague. While this increases the resilience of the privacy concept in social and legal context, it poses a considerable challenge to defining the privacy problem and the appropriate solutions to address those problems in a system-to-be.  Surveillance can be summed up as “any collection and processing of personal data, whether identifiable or not, for the purposes of influencing or managing those whose data have been garnered” (Lyon, 2001). One of the main concerns with any type of surveillance is social sorting, a form of classifying people based on surveillance data that may lead to real effects on the life-chances of people. In the context of web-based search, given its current integration with targeted and behavioral advertisement, different parties raise concerns with respect to privacy and surveillance. From an engineering perspective this raises questions about whether and how these matters can be addressed when engineering information systems? Ideally, when engineering systems, the stakeholders of the system step through a process of reconciling the relevant privacy and surveillance definitions and the (technical) privacy solutions in the given social context. We will explore methods to define and elicit concerns based on different privacy and surveillance notions; summarize the desired steps of a multilateral requirements analysis approach; and discuss how these methods can be applied in the context of web based search and behavioral advertising.

Lyon, D. (2001). Surveillance society: Monitoring everyday life. Buckingham, UK: Open University Press.

Lecture 3: Web mining and privacy: threats, opportunities, and design issues (by Bettina Berendt)

Web mining is the application of data mining techniques on Web data such as queries and other records of usage, social-network profiles and friend links, or news, blogs and tweets. Data mining means finding new knowledge that was previously only implicit in data. Web mining thus operates on many personal data that keep growing in volume and interrelatedness, and it0leads to inferences on inferences and groups that may be beneficial for some but unwanted-to-pernicious for others.

In this lecture, I will first give an overview of mining techniques and typical uses such as profiling. I will then describe methods that have been proposed for protecting personal data from unwanted inferences (privacy-preserving data mining) or for reducing the risks of releasing these data (privacy-preserving data publishing). I will investigate the roles in the mining process (who is doing the mining on whose data of what sorts) and identify threats and opportunities in different settings that range from business intelligence to feedback and awareness tools for user empowerment. I will conclude with thoughts on what “privacy by design” may mean in the context of Web mining.

Lecture 4: Social perspective on (dis)empowerment of users in an internet environment (by Jo Pierson)

In a society where people increasing rely on search engines and social media for communication and information sharing, it is vital to investigate these new forms of mediated communication from the social perspective of users/citizens/consumers. However in this transitional digital media ecosystem we observe how people can become simultaneously empowered as well as disempowered, in particularly on the levels of identity, privacy and surveillance. How this works out depends on the interrelationship between how internet systems are being designed (i.e. what they enable) and what people within their social context do with these systems (i.e. are able to do). In this way we notice for example that users of search engines and social media are foremost framed as consumers, and where ‘relevance’ is foremost posited as ‘commercial relevance’. Questions are therefore: How can governance and power manifest itself through the algorithm? To what extent and how are the social practices by citizens and communities following, opposing and/or negotiating the ‘governance’ of internet systems? In what ways is the social self increasingly being commodified, with personal data becoming the new currency? In what way can a socio-technological perspective offer solutions?

Lecture 5: Technologies for private search (by Claudia Diaz)

Search queries are closely related to the issues on which we are interested. This raises privacy concerns, as potentially sensitive information can be inferred from these queries, such as income level, health issues, or political beliefs. In this talk we will review different technologies for implementing private search services. This includes cryptographic techniques such as private information retrieval, as well as obfuscation-based private web search based on automatically generating fake queries.

Lecture 6: (Re)introducing privacy by design: the realm of search engines (by Eleni Kosta)

Building legally compliant systems that process personal information is turning into a nightmare for online business. The quest for finding the balance between the privacy of the users on the one hand, and the maximization of the profit of online business, usually deriving from the processing of user information, on the other, proves to be a difficult task. This lecture will present the initiatives of the European Commission in the frame of the reform of the European Data Protection Directive to achieve such a balance. The case of search engines, who collect and process vast amounts of use information is going to be used as an example.

=================================================================================

*** Interactive exercise sessions

Exercise session 1

In this session the students will identify the stakeholders and describe their interests and stakes in the system. This will include: their incentives, their interests, and the identification of potential conflicts between their interests.

Exercise session 2

In this session the students will specify the functionality, domain, and trust assumptions of the system. They also construct an initial model of the information that is necessary to fulfill the functionality of the system.

Exercise session 3

In this session the participants will identify the legal frameworks that apply, describe the legal roles and responsibilities of the stakeholders and their data protection requirements, and discuss the societal implications of the system linked to power relations between different stakeholders. They will also conduct an analysis of the privacy concerns of the stakeholders and the service integrity guarantees (i.e., threat and security analysis).

Exercise session 4

In this session the participants will further refine the definition of privacy goals and provide suggestions for privacy technologies that could be used in the system. The participants are asked to apply some of the things they learned in the lectures to the system they are developing. The specific choices of technical solutions to be used in the system will require re-thinking of the applicability of legal frameworks, the concrete functionality and the information model.

Exercise session 5

In this session the participants will consolidate their conclusions and prepare the presentation for the rest of the course participants that will take place in the last session of the course.

Are you a leader in Security ? Do you want to share your expertise and join the Leaders in Security as a Core Expert Member ?
Contact us via email! Or call +32.16.32.85.41 for a direct contact and more information.
An information set and your Membership Welcome Pack awaits you.

 

Copyright LSEC vzw 2007-2008 with the support of the IWT.

LSEC vzw Kasteelpark 10 - 3001 Heverlee - VAT BE BE 478 045 395 - fax. +32.16.32.19.69 - info @ lsec.be

<< June 2012 >>

S M T W T F S
27 28 29 30 31 1 2
3 4 5 6 7 8 9
10 11 12 13 14 15 16
17 18 19 20 21 22 23
24 25 26 27 28 29 30

Expert: IBM Security Services Belgum

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: Symantec

Symantec helps consumers and organizations secure and manage their information-driven world.

Expert: Symantec

Symantec helps consumers and organizations secure and manage their information-driven world.

Expert: Cognitive Security

Providing detailed intelligence against highly sophisticated network attacks.

Expert: Courion

Leader in IAM Solutions

Expert: Oracle

Oracle Belgium & Luxemburg

Expert: Option

Wireless data security enablers

Expert: TNO

TNO Research and Innovation

Expert: Control & Protection

Automatisering SCADA, PLC; Meettoestellen en brandbeveiliging

Expert: Thales Group

Thales Group

Expert: On2It

Smart IT Security We Are On To It

Expert: Mobco

Mobile Fleet Management

Expert: TITANS

TITANS ICT Consulting

Expert: G Data

G Data Anti Virus Solutions

Expert: Outpost 24 - Vulnerability Management Made Easy

Outpost 24 - Vulnerability Management Made Easy

Expert: Regify - Trusted and Binding Secure eMail

Regify - Trusted and Binding Secure eMail

Expert: Mobila - Mobile Enterprise Applications

Mobile Enterprise & Applicatinos

Expert: Lancelot Institute

Lancelot Institute - Training in Information Security, IT- Risk & IT - Auditing

Expert: CSI Tools

CSI tools is an expert software solution provider specialized in powerful tools for IT architects and auditors who are focused on maximizing GRC project development efficiency in SAP environments.

Expert: Intrinsic-ID

Content Protection, Unique Device Identification, Key Storage, PUF Physical Unclonable Functions

Expert: Belgacom ICT

Belgacom ICT Security Solutions for Large, Medium and Small Enterprises

Expert: Qualys

On Demand Vulnerability Management and Policy Compliance

Expert: Trend Micro

Securing your web world

Expert: Egemin

Egemin provides process and handling automation engineering and Secures Industry Automation

Expert: AEP Networks

More than 60 countries ... protected by AEP Networks

Expert: Palo Alto Networks

Next Generation Firewalls

Expert: Atos Origin Belgium & Luxemburg

A leading IT services provider. Ranks 1 in telecom outsourcing. Via Atos Worldline specialized in financial transactions.

Expert: Websense

Leading provider of unified content security

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: CA Technologies

Protect your critical IT assets, achieve sustainable regulatory compliance, reduce IT administration costs and enable new business opportunities with our security management products.

Expert: Axl-Trax

axl & trax are highly qualified experts in providing leading edge GRC services for SAP

Expert: VintiQ

VintiQ - Security Management Services

Expert: T-Systems Belgium

T-Systems is Deutsche Telekom's corporate customer arm.

Expert: LIN.K nv - LINKID

LIN.K is a provider of online user authentication, identification with the system LINKID

Expert: Devoteam Belgium

Devoteam Belgium, one of the major European ICT consultancy specialists with offices in 23 countries

Expert: CHB Technologies - Celadon Hailstone Biometrics

Celadon Bailstone Biometrics

Expert: Barracuda Networks

Worldwide supplier of email and internet security

Expert: Sophos

Sophos is the Utimaco is a leading global provider of data security solutions, enabling mid- to large-size organizations to safeguard their data assets against intentional or unintentional data loss, and to comply with privacy laws.

Expert: Dimension Data

Dimension Data

Expert: Bull

Bull

Expert: Check Point Software Technologies

Check Point Software Technologies

Expert: MMS-Secure

MMS-Secure nv, a distributor with a specific focus on network and systems security

Expert: F-Secure Corporation

F-Secure - Fastest Focused Anti-Virus Protection

Expert: C-Cure

C-Cure are Information Security architects already since 1998

Expert: IS4U

IS4U - Cronos specializes in Identity and Access Management

Expert: UCL Crypto Group

The Crypto Group of UCL, the UC of Louvain-la-Neuve is a research group specialized in cryptography and information security.

Expert: eID Company

eID company provides a flexible easy to integrate eID in any web application. Access to eID as a webservice.

Expert: ACA IT-Solutions

ACA IT-Solutions, end to end IT solutions and IDM Expert. Probably the largest and most successful independent J2EE solution provider.

Expert: RSA - Security Division of EMC

RSA - The Security Division of RSA. One of the leading companies in the world in IT Security. Enterprise wide Data Security solutions, suites and Services.

Expert: Unisys

Security Unleashed – At Unisys, we’re looking at security in an entirely new way.Security is no longer a defensive measure. It’s an enabling catalyst for achievement.Unisys Secure Business Operations help to unleash your full potential.

Expert: Zion Security

ZION SECURITY is the leading European application security company. Our mission is to secure your business value by securing your business applications.

Expert: Zetes

For those who want to see the difference!

Expert: Vasco

VASCO designs, develops, markets and supports patented User Authentication products for e-business and e-commerce.

Expert: SUN Microsystems

Everyone and everywhere connected to the network.

Expert: Security4Biz

Security4Biz offers ICT security consultancy services.

Expert: SecurIT

The value proposition to our customers is the competence and experience of highly qualified people, combined with best-in-class solutions from leading suppliers, and our entire focus on Identity and Access Management.

Expert: Sealed

Expert in implementation of e-Security, e-Proofs and e-ID within the management of business & document flows & processes, or within the management of your enterprise content in the broad sense.

Expert: McAfee

McAfee is the world largest dedicated security companY;

Expert: NXP (founded by Philips)

Sense & simplicity. Help customers to transform initial ideas into competitive products and cost-efficient manufacturing solutions within healthcare, lifestyle and technology.

Expert: KPMG

PMG Information Risk Management (IRM) focuses on inherent risks in technology systems used to support your business objectives and grow your business.

Expert: EMC2

EMC Corporation is the world's leading developer and provider of information infrastructure technology and solutions.

Expert: Deloitte

In addition to the qualities of a leading Belgian audit and consulting firm, Deloitte is different through the values it shares daily with clients and employees.

Expert: Certipost

Specialist in secured electronic document exchange for companies, the state, and for residential customers.

Expert: Ascure

World class information risk management services!

Expert: Verizon Business

Verizon Business is now the leading provider of managed security services worldwide with acquisition of Cybertrust.

Expert: IBM

A world leader in Information Technology with a large professional organization in Belgium and a series of security experts.

Expert: K.U. Leuven

Computer Security and Industrial Cryptography (COSIC): Cryptography to protect data against passive and active fraud.

Expert: ATOS Worldline nv

Specialist in end-to-end secure payment systems.

Expertise: UTM

UTM - Unified Threat Management

Expertise: End Point Security

End Point Security

Expertise: DLP - Data Leakage, Data Loss Prevention and Protection

DLP - Data Leakage, Data Loss Prevention and Protection

Expertise: SOA - Service Oriented Architectures

Expertise: Identity Management

Identity Management (IdM) enables organizations to facilitate and control their users' access to critical online applications and resources — while protecting confidential personal and business information from unauthorized access

Expertise: Crypto

Cryptography - Cryptografie - Cryptographie

Expertise: Secure Application Development

Secure Application Development. Security does not only start at user name and password login, from the first entry of a software security needs to be integrated.

Expertise: RFID

passive and active low-cost wireless tags

Expertise: Application Security

encompasses measures taken to prevent exceptions in the security policy of an application or the underlying system

Expertise: Wireless Security

Expertise: Appliances

protect computer networks from unwanted data traffic, intruders, email spam, enforce policies, and may also be used to create and manage VPNs.

Expertise: Access Control

the ability to permit or deny the use of something by someone.

Expertise: Risk and Vulnerability Assessment

process of identifying and quantifying vulnerabilities in a system..Cataloging assets and capabilities (resources) in a system

Expertise: Penetration Testing

A method of evaluating the security of a computer system or network by simulating an attack by a malicious user, commonly known as a hacker.

Expertise: Physical Security

describes measures that prevent or deter attackers from accessing a facility, resource, or information stored on physical media. It can be as simple as a locked door or as elaborate as multiple layers of armed guardposts.

Expertise: Remote Access

computer program that lets you access your PC from another PC via the Internet, LAN, or phone connection and work on your computer ...

Expertise: Security Policy

security policy is a definition of what it means to be secure for a system, organization or other entity. For systems, the security policy addresses constraints on functions and flow among them, constraints on access by external systems and adversaries

Expertise: Anti-Virus

Software that detects, repairs, cleans, or removes virus-infected files from a computer.

Expertise: Spyware

Software that covertly gathers user information through the user's Internet connection without his or her knowledge, usually for advertising purposes.

Expertise: Authorization

The process of enforcing policies: determining what types or qualities of activities, resources, or services a user is permitted. Usually, authorization occurs within the context of authentication.

Expertise: Authentication

Provides a way of identifying a user, typically by having the user enter a valid user name and valid password before access is granted. The process of authentication is based on each user having a unique set of criteria for gaining access.

Expertise: Computer Virus

Program or programming code that replicates by being copied or initiating its copying to another program, computer boot sector or document.

Expertise: Smart Cards

smart card or chip card, is defined as any pocket-sized card with embedded integrated circuits which can process information such as a SIM for a mobile phone or an eID card

Expertise: UTM and Appliances

Unified threat management (UTM) is a term which is used to describe network firewalls that have many features in one box, for example junk e-mail filtering,or anti-virus capability, along with the traditional activities of a firewall.

Expertise: NAC

Network access control (NAC) is a method by which hardware and software grant access to enterprise network resources after first authorizing the user and device and verifying the device's compliance with the enterprise's security policy.

Expertise: Biometrics

Biometrics (ancient Greek: bios ="life", metron ="measure") is the study of methods for uniquely recognizing humans based upon one or more intrinsic physical or behavioral traits.

Expertise: DRM

Expertise: eID - Electronic Identity Cards

The electronic identity card (eID) is an official electronic proof of one's identity. It also enables the possibility to sign electronic documents with a legal signature.