Security and privacy in emerging information technologies
Xiaodong Sheldon Lin, Jianwei Liu, Stefanos Gritzalis · Security and Communication Networks · 2011
Advances in communication and information technologies including pervasive computer applications, rapid deployments of new wireless networks like 3G, Wifi, WiMAX and their tight coupling to the Internet, have revolutionised our society and really changed every aspect of our lives through a variety of new applications. The rapidly evolving technologies have become ubiquitous, for example, allowing people to stay connected anywhere, anytime via social media services accessed by smartphones, such as Facebook and Twitter. While we experience tremendous benefits from adopting the new technologies, we also continue to face challenges and the biggest challenge is always: how to address security and privacy issues, which may be caused by new technology adoption. This special issue consists of seven papers addressing the security and privacy issues in emerging information technologies such as delay tolerant networking, vehicular communication systems and smartphones and mobile devices. In the first paper, D. Damopoulos, S.A. Menesidou, G. Kambourakis, M. Papadaki, N. Clarke and S. Gritzalis present an evaluation study of anomaly-based IDS for mobile devices using machine learning classifiers. A dataset consisting of iPhone users data log files has been created and various classification and validation methods have been evaluated to assess their effectiveness in detecting misuses. The experimental procedure includes and cross-evaluates four machine learning algorithms (i.e. Bayesian Networks, Radial Basis Function, K-Nearest Neighbours and Random Forest), which classify the behaviour of the end-user in terms of Telephone calls, SMS and Web browsing history. The results acquired are very promising, showing the ability of at least one classifier to detect intrusions with a high True Positive Rate of 99.8%. The second paper, “User Identification and Anonymization in 802.11 Wireless LANs” by D. Xu, Y. Wang, X. Shi, and X. Yin, deals with privacy issues for 802.11 Wireless LAN users. It first proposes a new 802.11 user identification approach through enhanced feature selection and generation. Then, it further studies how to provide user anonymity by introducing a set of 802.11 user anonymisation approaches based on bogus traffic injection. Accountability is a very important topic for computer and networking systems, and a key to achieve accountability is a better logging system, which can capture not only the activities but also their relationships. The third paper, “Accountability using Flow-net: Design, Implementation, and Performance Evaluation” by Y. Xiao, K. Meng and D. Takahashi extends the flow-net methodology, which is a logging mechanism for accountability previously proposed by the authors, and presents its design and implementation in wireless networks. They also evaluate the performance of flow-net and compare it to that of audit log files. The fourth paper, “Modelling Security Message Propagation in Delay Tolerant Networks ” by Z. Jia, S. Li, H. Peng, Y. Yang and S. Guo, proposes a security message propagation model for delay tolerant networks formed by vehicles on the road. The goal of the paper is to evaluate how many public keys should be maintained by each node in order to achieve fast message propagation while single hop authentication scheme is used. Network coding provides an excellent solution to maximise throughput in various networks. Because of its simplicity and high efficiency, the idea of network coding can also be used for designing lightweight key distribution schemes for wireless ad hoc network. The fifth paper, “A key distribution scheme using network coding for mobile ad hoc network” by J. Liu, R. Du, J. Chen and K. He, presents a key distribution scheme that exploits the inherent security properties of network coding. The new scheme relies on simple XOR network coding operations to provide data confidentiality and as well use message authentication codes to guarantee the integrity of the distributed keys. Recently, vehicular ad-hoc network (VANET) has emerged as a promising approach to increasing road safety and efficiency. However, the attractive features of VANET inevitably incur higher risks for abuse if we do not take into account security and privacy considerations before the wide deployment of such network. It would jeopardise the public safety and become the main barrier to the acceptance of such a new technology. The last two papers focus on the security and privacy issues in VANETs. In the sixth paper, “LPA: A New Location-based Privacy-preserving Authentication Protocol in VANET” by X. Xue and J. Ding, a novel location-based authentication protocol for conditional privacy preservation in VANETs is proposed. By utilising location information and layered security scheme, the large storage overhead problem in anonymous certificates-based protocols and the long verification time problem in group signature-based protocols are solved. The seventh paper, “An Efficient Distributed Key Management Scheme for Group Signature based Anonymous Authentication in VANET” by Y. Sun, Z. Feng, Q. Hu and J. Su, proposes a distributed key management (DKM) scheme based on Group Signature for anonymous authentication in VANETs. The goal of the paper is to prevent vehicles from leaking the value of the updated group secret key to the regional group manager during the group key updating process. Subsequently, it can avoid the buck-passing between vehicles and regional group managers when the malicious messages are detected. In closing, we would like to thank all the authors who have submitted their research work to this special issue. We would also like to acknowledge the contribution of many experts in the field who have participated in the review process and provided helpful suggestions to the authors on improving the content and presentation of the papers. We would also like to express our gratitude to the Editor-in-Chief, Dr. Hsiao-Hwa Chen for his support and help in bringing forward this special issue. We hope you will enjoy the papers in this collection. Prof. Xiaodong Lin received the Ph.D. degree in information engineering from Beijing University of Posts and Telecommunications, Beijing, China, in 1998 and the Ph.D. degree (with Outstanding Achievement in Graduate Studies Award) in electrical and computer engineering from the University of Waterloo, Waterloo, ON, Canada, in 2008. He is currently an assistant professor of information security with the Faculty of Business and Information Technology, University of Ontario Institute of Technology, Oshawa, ON, Canada. His research interests include wireless network security, computer forensics, software security, and applied cryptography. Dr. Lin was the recipient of a Natural Sciences and Engineering Research Council of Canada (NSERC) Canada Graduate Scholarships (CGS) Doctoral and the Best Paper Awards of the 18th International Conference on Computer Communications and Networks (ICCCN 2009), the 5th International Conference on Body Area Networks (BodyNets 2010), the 3rd International Conference on Forensic Applications and Techniques in Telecommunications, Information and Multimedia (e-Forensics 2010), and IEEE International Conference on communications (ICC 2007). He is a member of IEEE. Prof. Jianwei Liu received his Ph.D. in communication engineering from Xidian University, China in 1998, and his B.S. and M.S. degrees in electronic engineering from Shandong University, China in 1985 and 1988. He is currently a professor and vice dean of School of Electronic and Information Engineering of Beihang University. His current research interests include the security of wireless and mobile communication network and computer network. He is a senior member of the Chinese Institute of Electronics and director of the Chinese Association for Cryptologic Research. Prof. Stefanos Gritzalis is a Professor at the Dept. of Information and Communication Systems Engineering, University of the Aegean, Greece and the Director of the Lab. of Information and Communication Systems Security. He also serves as the Special Secretary at the Greek Ministry of Administrative Reform and Electronic Governance. He holds a BSc in Physics, an MSc in Electronic Automation, and a PhD in Information and Communications Security from the Dept. of Informatics and Telecommunications, University of Athens, Greece. He has been involved in several national and EU funded R&D projects. His published scientific work includes 30 books or book chapters, 90 journals and more than 120 international refereed conference and workshop papers. The focus of these publications is on Information and Communications Security and Privacy. His most highly cited papers have more than 1,000 citations. He has been involved in more than 30 international conferences and workshops as General Chair or Program Committee Chair. He has served on more than 230 Program Committees of international conferences and workshops. He is an Editor-in-Chief or Editor or Editorial Board member for 15 journals. He has supervised 10 PhD dissertations. He was an elected Member of the Board (Secretary General, Treasurer) of the Greek Computer Society. His professional experience includes senior consulting and researcher positions in a number of private and public institutions. He is a Member of the ACM, and the IEEE.