数据收集技术的计算机安全

Q1 Economics, Econometrics and Finance
Camille Cobb , Samuel Sudar , Nicholas Reiter, Richard Anderson, Franziska Roesner, Tadayoshi Kohno
{"title":"数据收集技术的计算机安全","authors":"Camille Cobb ,&nbsp;Samuel Sudar ,&nbsp;Nicholas Reiter,&nbsp;Richard Anderson,&nbsp;Franziska Roesner,&nbsp;Tadayoshi Kohno","doi":"10.1016/j.deveng.2017.12.002","DOIUrl":null,"url":null,"abstract":"<div><p>Many organizations in the developing world (e.g., NGOs), include digital data collection in their workflow. Data collected can include information that may be considered sensitive, such as medical or socioeconomic data, and which could be affected by computer security attacks or unintentional mishandling. The attitudes and practices of organizations collecting data have implications for <em>confidentiality</em>, <em>availability</em>, and <em>integrity</em> of data. This work, a collaboration between computer security and ICTD researchers, explores security and privacy attitudes, practices, and needs within organizations that use Open Data Kit (ODK), a prominent digital data collection platform. We conduct a detailed <em>threat modeling</em> exercise to inform our view on potential security threats, and then conduct and analyze a survey and interviews with technology experts in these organizations to ground this analysis in real deployment experiences. We then reflect upon our results, drawing lessons for both organizations collecting data and for tool developers.</p></div>","PeriodicalId":37901,"journal":{"name":"Development Engineering","volume":"3 ","pages":"Pages 1-11"},"PeriodicalIF":0.0000,"publicationDate":"2018-01-01","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"https://sci-hub-pdf.com/10.1016/j.deveng.2017.12.002","citationCount":"0","resultStr":"{\"title\":\"Computer security for data collection technologies\",\"authors\":\"Camille Cobb ,&nbsp;Samuel Sudar ,&nbsp;Nicholas Reiter,&nbsp;Richard Anderson,&nbsp;Franziska Roesner,&nbsp;Tadayoshi Kohno\",\"doi\":\"10.1016/j.deveng.2017.12.002\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"<div><p>Many organizations in the developing world (e.g., NGOs), include digital data collection in their workflow. Data collected can include information that may be considered sensitive, such as medical or socioeconomic data, and which could be affected by computer security attacks or unintentional mishandling. The attitudes and practices of organizations collecting data have implications for <em>confidentiality</em>, <em>availability</em>, and <em>integrity</em> of data. This work, a collaboration between computer security and ICTD researchers, explores security and privacy attitudes, practices, and needs within organizations that use Open Data Kit (ODK), a prominent digital data collection platform. We conduct a detailed <em>threat modeling</em> exercise to inform our view on potential security threats, and then conduct and analyze a survey and interviews with technology experts in these organizations to ground this analysis in real deployment experiences. We then reflect upon our results, drawing lessons for both organizations collecting data and for tool developers.</p></div>\",\"PeriodicalId\":37901,\"journal\":{\"name\":\"Development Engineering\",\"volume\":\"3 \",\"pages\":\"Pages 1-11\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2018-01-01\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"https://sci-hub-pdf.com/10.1016/j.deveng.2017.12.002\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"Development Engineering\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://www.sciencedirect.com/science/article/pii/S2352728516300677\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"Q1\",\"JCRName\":\"Economics, Econometrics and Finance\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"Development Engineering","FirstCategoryId":"1085","ListUrlMain":"https://www.sciencedirect.com/science/article/pii/S2352728516300677","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"Q1","JCRName":"Economics, Econometrics and Finance","Score":null,"Total":0}
引用次数: 0

摘要

发展中国家的许多组织(例如非政府组织)在其工作流程中包括数字数据收集。收集的数据可能包括可能被视为敏感的信息,如医疗或社会经济数据,这些信息可能受到计算机安全攻击或无意的不当处理的影响。组织收集数据的态度和做法对数据的机密性、可用性和完整性都有影响。这项工作是计算机安全和ICTD研究人员之间的合作,探讨了使用开放数据工具包(ODK)的组织对安全和隐私的态度、做法和需求。开放数据工具包是一个著名的数字数据收集平台。我们进行详细的威胁建模练习,以告知我们对潜在安全威胁的看法,然后对这些组织中的技术专家进行调查和分析,以实际部署经验为基础进行分析。然后我们反思我们的结果,为收集数据的组织和工具开发人员吸取教训。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Computer security for data collection technologies

Many organizations in the developing world (e.g., NGOs), include digital data collection in their workflow. Data collected can include information that may be considered sensitive, such as medical or socioeconomic data, and which could be affected by computer security attacks or unintentional mishandling. The attitudes and practices of organizations collecting data have implications for confidentiality, availability, and integrity of data. This work, a collaboration between computer security and ICTD researchers, explores security and privacy attitudes, practices, and needs within organizations that use Open Data Kit (ODK), a prominent digital data collection platform. We conduct a detailed threat modeling exercise to inform our view on potential security threats, and then conduct and analyze a survey and interviews with technology experts in these organizations to ground this analysis in real deployment experiences. We then reflect upon our results, drawing lessons for both organizations collecting data and for tool developers.

求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
Development Engineering
Development Engineering Economics, Econometrics and Finance-Economics, Econometrics and Finance (all)
CiteScore
4.90
自引率
0.00%
发文量
11
审稿时长
31 weeks
期刊介绍: Development Engineering: The Journal of Engineering in Economic Development (Dev Eng) is an open access, interdisciplinary journal applying engineering and economic research to the problems of poverty. Published studies must present novel research motivated by a specific global development problem. The journal serves as a bridge between engineers, economists, and other scientists involved in research on human, social, and economic development. Specific topics include: • Engineering research in response to unique constraints imposed by poverty. • Assessment of pro-poor technology solutions, including field performance, consumer adoption, and end-user impacts. • Novel technologies or tools for measuring behavioral, economic, and social outcomes in low-resource settings. • Hypothesis-generating research that explores technology markets and the role of innovation in economic development. • Lessons from the field, especially null results from field trials and technical failure analyses. • Rigorous analysis of existing development "solutions" through an engineering or economic lens. Although the journal focuses on quantitative, scientific approaches, it is intended to be suitable for a wider audience of development practitioners and policy makers, with evidence that can be used to improve decision-making. It also will be useful for engineering and applied economics faculty who conduct research or teach in "technology for development."
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信