Foreword to the special issue on security, privacy, and social networks

Yang Xiang, Md Zakirul Alam Bhuiyan, Aniello Castiglione, Yu Wang · Concurrency and Computation Practice and Experience · 2019

Social computing and cloud computing are the major trends of technology development in recent years. With the unparalleled popularity, social networks and cloud platforms have become part of our daily lives. Users have produced big data that are beyond the ability of commonly used computer software and hardware tools to capture, manage, and process within a tolerable elapsed time. It has been widely recognized that security and privacy are the key challenges for social network and cloud services due to their scale, complexity, and heterogeneity. The goal of this special issue is to promote research on security, privacy, and social networks. Eleven papers were carefully selected from open submissions and invited from the best original presentations at the 13th International Conference on Information Security Practice and Experience (ISPEC 2017) and the Third International Symposium on Security and Privacy in Social Networks and Big Data (SocialSec 2017). These research papers address the state-of-the-art technologies related to security, privacy, and social networks. The papers are organized under the following topics: security and privacy in social network and web, big data and information security, hardware and software security, and network security. Social media has greater and greater influence on society in recent years. Hu et al1 present an interesting study on the influence of negative opinions spreading in social media during election period. Unlike existing approaches that rely on sentiment analysis and emotional words, the authors take advantage of nouns with emotional context to determine the election preference of each user more accurately. Protecting social networks from security threats and preserving user privacy are the key challenges in social network security. To protect social network users against cross-site scripting worms, Gupta et al2 propose a client-server JavaScript code rewriting-based framework. A Java-based prototype has been developed by the authors, and the authors test its malicious script alleviation capability on several web applications. Yang et al3 propose a novel privacy-preserving authentication protocol for anonymous web browsing, which help users avoid being monitored by the web server on the basis of the identity. In particular, the proposed protocol makes use of a pseudoidentity mechanism and an identity-based elliptic-curve cryptography algorithm. In the area of big data and cloud computing, secure nearest neighbor query over encrypted data is an important issue. Zhu et al4 put forward an efficient attack against the CloudBI-II scheme that is designed for resisting the collusion of cloud server and query users. Accordingly, the authors present an enhanced scheme that can resist the collusion attack. Outsourcing heavy computational tasks to cloud service providers has become popular in the cloud era. As commercial cloud service providers are not trusted, preserving the integrity of computational results becomes an important challenge. Yang et al5 propose a verifiable computation scheme that can protect the output privacy. Ciphertext-policy attribute-based encryption (CP-ABE) is widely used for data access control in cloud storage, which gives data owners direct and flexible control on access policies. Zhang et al6 present a multiauthority attribute-based encryption scheme with constant-size ciphertexts and user revocation for threshold access policy, which addresses the practical challenges in CP-ABE. The security and reliability of information transmission in vehicular ad hoc networks have attracted a lot of research efforts in recent years. Wang et al7 propose a neighborhood trustworthiness-based vehicle-to-vehicle authentication scheme, which uses cloud computing to evaluate the trustworthiness of vehicles for emergent information delivery. The security of ARM embedded devices is important as they are becoming increasingly ubiquitous. Chang et al8 propose a hardware-assisted memory isolation protection mechanism using the B method, and present an implementation of the proposed system on an ARM-based platform. Function-call graph matching is useful in binary code analysis for software security purposes. Huang et al9 propose a function-call graph matching method based on the Hungarian algorithm. The proposed method solves the maximum weight matching problem in polynomial time, which allows matching between graphs of large scale. This special issue would not be complete without covering network security. Yang et al10 use software-defined network techniques to build a moving target defense model that maps physical network elements to a considerably large address space and creates different times of validity randomly to generate mapping addresses. The proposed model helps make it more difficult for attackers to find the targets in a network. Shan et al11 propose a node importance scheme to a community-based caching scheme with network coding for information centric networking. Experimental results indicate that the proposed scheme can improve network performance including average download time, cache hit rate, and instantaneous hop reduction rate. The articles presented in this special issue report recent advances in some areas of security, privacy, and social networks, including security and privacy in social network and web, big data and information security, hardware and software security, and network security. We hope the readers can benefit from the insights of these works and make further contributions to these important and rapidly growing fields. We are grateful to the authors who submitted papers to this special issue. We would also like to thank the reviewers for their hard work and their valuable feedback to the authors. Finally, we would like to express our sincere gratitude to Professor Geoffrey Fox, the Editor in Chief, for providing the opportunity and assistance to edit this special issue in the international journal of Concurrency and Computation: Practice and Experience.

Read the paper · More papers on PaperTik