<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:burst="http://xmlns.com/burst/0.1/" xmlns:xsd="http://www.w3.org/2001/XMLSchema#" xmlns="http://purl.org/rss/1.0/" xmlns:admin="http://webns.net/mvcb/" xmlns:rdfs="http://www.w3.org/2000/01/rdf-schema#" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:owl="http://www.w3.org/2002/07/owl#" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:swrc="http://swrc.ontoware.org/ontology#" xmlns:cc="http://web.resource.org/cc/"><channel rdf:about="http://puma.uni-kassel.de/user/jaeschke/security"><title>PUMA publications for /user/jaeschke/security</title><link>http://puma.uni-kassel.de/user/jaeschke/security</link><description>PUMA RSS feed for /user/jaeschke/security</description><dc:date>2013-05-20T10:20:14+02:00</dc:date><items><rdf:Seq><rdf:li rdf:resource="http://puma.uni-kassel.de/bibtex/27be2b4bf0987c4d18adf7243eae690c0/jaeschke"/><rdf:li rdf:resource="http://puma.uni-kassel.de/bibtex/2283f8a780ac47746cc3031ad47bfdf9c/jaeschke"/><rdf:li rdf:resource="http://puma.uni-kassel.de/bibtex/2a20d5aa858b63fcf5d2daf908fec874f/jaeschke"/><rdf:li rdf:resource="http://puma.uni-kassel.de/bibtex/23c8aa0e647903603ddce90c1642b89b2/jaeschke"/><rdf:li rdf:resource="http://puma.uni-kassel.de/bibtex/20efc5c0ef9a17c35402c654ff76247b0/jaeschke"/></rdf:Seq></items></channel><item rdf:about="http://puma.uni-kassel.de/bibtex/27be2b4bf0987c4d18adf7243eae690c0/jaeschke"><title>Building access control models with attribute exploration</title><link>http://puma.uni-kassel.de/bibtex/27be2b4bf0987c4d18adf7243eae690c0/jaeschke</link><dc:creator>jaeschke</dc:creator><dc:date>2012-12-21T10:15:28+01:00</dc:date><dc:subject>access analysis attribute concept control exploration fca formal security </dc:subject><content:encoded>&lt;span class=&#034;authorEditorList&#034;&gt;&lt;a href=&#034;/author/Obiedkov&#034;&gt;Sergei
 				 
 				Obiedkov&lt;/a&gt;, &lt;a href=&#034;/author/Kourie&#034;&gt;Derrick G.
 				 
 				Kourie&lt;/a&gt;,  und &lt;a href=&#034;/author/Eloff&#034;&gt;J.H.P.
 				 
 				Eloff&lt;/a&gt;. &lt;/span&gt;&lt;em&gt;Computers and Security&lt;/em&gt; &lt;em&gt;28(1–2):2--7&lt;/em&gt; (&lt;em&gt;2009&lt;/em&gt;)</content:encoded><taxo:topics><rdf:Bag><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/access"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/analysis"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/attribute"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/concept"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/control"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/exploration"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/fca"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/formal"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/security"/></rdf:Bag></taxo:topics><burst:publication><rdf:Description rdf:about="http://puma.uni-kassel.de/bibtex/27be2b4bf0987c4d18adf7243eae690c0/jaeschke"><owl:sameAs rdf:resource="http://puma.uni-kassel.de/uri/bibtex/27be2b4bf0987c4d18adf7243eae690c0/jaeschke"/><rdf:type rdf:resource="http://swrc.ontoware.org/ontology#Article"/><owl:sameAs rdf:resource="http://www.sciencedirect.com/science/article/pii/S0167404808000497"/><swrc:date>Fri Dec 21 10:15:28 CET 2012</swrc:date><swrc:journal>Computers and Security</swrc:journal><swrc:number>1–2</swrc:number><swrc:pages>2--7</swrc:pages><swrc:title>Building access control models with attribute exploration</swrc:title><swrc:volume>28</swrc:volume><swrc:year>2009</swrc:year><swrc:keywords>access analysis attribute concept control exploration fca formal security </swrc:keywords><swrc:abstract>The use of lattice-based access control models has been somewhat restricted by their complexity. We argue that attribute exploration from formal concept analysis can help create lattice models of manageable size, while making it possible for the system designer to better understand dependencies between different security categories in the domain and, thus, providing certain guarantees for the relevance of the constructed model to a particular application. In this paper, we introduce the method through an example.</swrc:abstract><swrc:hasExtraField><swrc:Field swrc:value="0167-4048" swrc:key="issn"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="10.1016/j.cose.2008.07.011" swrc:key="doi"/></swrc:hasExtraField><swrc:author><rdf:Seq><rdf:_1><swrc:Person swrc:name="Sergei Obiedkov"/></rdf:_1><rdf:_2><swrc:Person swrc:name="Derrick G. Kourie"/></rdf:_2><rdf:_3><swrc:Person swrc:name="J.H.P. Eloff"/></rdf:_3></rdf:Seq></swrc:author></rdf:Description></burst:publication></item><item rdf:about="http://puma.uni-kassel.de/bibtex/2283f8a780ac47746cc3031ad47bfdf9c/jaeschke"><title>Conceptual Information Systems Discussed through an IT-Security Tool</title><link>http://puma.uni-kassel.de/bibtex/2283f8a780ac47746cc3031ad47bfdf9c/jaeschke</link><dc:creator>jaeschke</dc:creator><dc:date>2012-10-22T14:46:13+02:00</dc:date><dc:subject>analysis concept example fca formal grundschutz gshb security </dc:subject><content:encoded>&lt;span class=&#034;authorEditorList&#034;&gt;&lt;a href=&#034;/author/Becker&#034;&gt;Klaus
 				 
 				Becker&lt;/a&gt;, &lt;a href=&#034;/author/Stumme&#034;&gt;Gerd
 				 
 				Stumme&lt;/a&gt;, &lt;a href=&#034;/author/Wille&#034;&gt;Rudolf
 				 
 				Wille&lt;/a&gt;, &lt;a href=&#034;/author/Wille&#034;&gt;Uta
 				 
 				Wille&lt;/a&gt;,  und &lt;a href=&#034;/author/Zickwolff&#034;&gt;Monika
 				 
 				Zickwolff&lt;/a&gt;. &lt;/span&gt;&lt;em&gt;Knowledge Engineering and Knowledge Management Methods, Models, and Tools, &lt;/em&gt;&lt;em&gt;Volume 1937 von Lecture Notes in Computer Science, &lt;/em&gt;&lt;em&gt;Springer, &lt;/em&gt;&lt;em&gt;Berlin/Heidelberg, &lt;/em&gt;(&lt;em&gt;2000&lt;/em&gt;)</content:encoded><taxo:topics><rdf:Bag><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/analysis"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/concept"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/example"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/fca"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/formal"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/grundschutz"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/gshb"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/security"/></rdf:Bag></taxo:topics><burst:publication><rdf:Description rdf:about="http://puma.uni-kassel.de/bibtex/2283f8a780ac47746cc3031ad47bfdf9c/jaeschke"><owl:sameAs rdf:resource="http://puma.uni-kassel.de/uri/bibtex/2283f8a780ac47746cc3031ad47bfdf9c/jaeschke"/><rdf:type rdf:resource="http://swrc.ontoware.org/ontology#InCollection"/><owl:sameAs rdf:resource="http://dx.doi.org/10.1007/3-540-39967-4_27"/><swrc:date>Mon Oct 22 14:46:13 CEST 2012</swrc:date><swrc:address>Berlin/Heidelberg</swrc:address><swrc:booktitle>Knowledge Engineering and Knowledge Management Methods, Models, and Tools</swrc:booktitle><swrc:pages>352--365</swrc:pages><swrc:publisher><swrc:Organization swrc:name="Springer"/></swrc:publisher><swrc:series>Lecture Notes in Computer Science</swrc:series><swrc:title>Conceptual Information Systems Discussed through an IT-Security Tool</swrc:title><swrc:volume>1937</swrc:volume><swrc:year>2000</swrc:year><swrc:keywords>analysis concept example fca formal grundschutz gshb security </swrc:keywords><swrc:abstract>Conceptual Information Systems are based on a formalization of the concept of ‘concept’ as it is discussed in traditional philosophical logic. This formalization supports a human-centered approach to the development of Information Systems. We discuss this approach by means of an implemented Conceptual Information System for supporting IT security management in companies and organizations.</swrc:abstract><swrc:hasExtraField><swrc:Field swrc:value="978-3-540-41119-2" swrc:key="isbn"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="Computer Science" swrc:key="keyword"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="Entrust Technologies (Switzerland) Ltd liab. Co Glatt Tower CH-8301 Glattzentrum Switzerland" swrc:key="affiliation"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="10.1007/3-540-39967-4_27" swrc:key="doi"/></swrc:hasExtraField><swrc:author><rdf:Seq><rdf:_1><swrc:Person swrc:name="Klaus Becker"/></rdf:_1><rdf:_2><swrc:Person swrc:name="Gerd Stumme"/></rdf:_2><rdf:_3><swrc:Person swrc:name="Rudolf Wille"/></rdf:_3><rdf:_4><swrc:Person swrc:name="Uta Wille"/></rdf:_4><rdf:_5><swrc:Person swrc:name="Monika Zickwolff"/></rdf:_5></rdf:Seq></swrc:author><swrc:editor><rdf:Seq><rdf:_1><swrc:Person swrc:name="Rose Dieng"/></rdf:_1><rdf:_2><swrc:Person swrc:name="Olivier Corby"/></rdf:_2></rdf:Seq></swrc:editor></rdf:Description></burst:publication></item><item rdf:about="http://puma.uni-kassel.de/bibtex/2a20d5aa858b63fcf5d2daf908fec874f/jaeschke"><title>reCAPTCHA: Human-Based Character Recognition via Web Security Measures</title><link>http://puma.uni-kassel.de/bibtex/2a20d5aa858b63fcf5d2daf908fec874f/jaeschke</link><dc:creator>jaeschke</dc:creator><dc:date>2012-04-16T14:44:05+02:00</dc:date><dc:subject>captcha cirg collective computing intelligence ocr recaptcha security social </dc:subject><content:encoded>&lt;span class=&#034;authorEditorList&#034;&gt;&lt;a href=&#034;/author/von Ahn&#034;&gt;Luis
 				 
 				von Ahn&lt;/a&gt;, &lt;a href=&#034;/author/Maurer&#034;&gt;Benjamin
 				 
 				Maurer&lt;/a&gt;, &lt;a href=&#034;/author/McMillen&#034;&gt;Colin
 				 
 				McMillen&lt;/a&gt;, &lt;a href=&#034;/author/Abraham&#034;&gt;David
 				 
 				Abraham&lt;/a&gt;,  und &lt;a href=&#034;/author/Blum&#034;&gt;Manuel
 				 
 				Blum&lt;/a&gt;. &lt;/span&gt;&lt;em&gt;Science&lt;/em&gt; &lt;em&gt;321(5895):1465--1468&lt;/em&gt; (&lt;em&gt;2008&lt;/em&gt;)</content:encoded><taxo:topics><rdf:Bag><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/captcha"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/cirg"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/collective"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/computing"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/intelligence"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/ocr"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/recaptcha"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/security"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/social"/></rdf:Bag></taxo:topics><burst:publication><rdf:Description rdf:about="http://puma.uni-kassel.de/bibtex/2a20d5aa858b63fcf5d2daf908fec874f/jaeschke"><owl:sameAs rdf:resource="http://puma.uni-kassel.de/uri/bibtex/2a20d5aa858b63fcf5d2daf908fec874f/jaeschke"/><rdf:type rdf:resource="http://swrc.ontoware.org/ontology#Article"/><owl:sameAs rdf:resource="http://www.sciencemag.org/content/321/5895/1465.abstract"/><swrc:date>Mon Apr 16 14:44:05 CEST 2012</swrc:date><swrc:journal>Science</swrc:journal><swrc:number>5895</swrc:number><swrc:pages>1465--1468</swrc:pages><swrc:title>reCAPTCHA: Human-Based Character Recognition via Web Security Measures</swrc:title><swrc:volume>321</swrc:volume><swrc:year>2008</swrc:year><swrc:keywords>captcha cirg collective computing intelligence ocr recaptcha security social </swrc:keywords><swrc:abstract>CAPTCHAs (Completely Automated Public Turing test to tell Computers and Humans Apart) are widespread security measures on the World Wide Web that prevent automated programs from abusing online services. They do so by asking humans to perform a task that computers cannot yet perform, such as deciphering distorted characters. Our research explored whether such human effort can be channeled into a useful purpose: helping to digitize old printed material by asking users to decipher scanned words from books that computerized optical character recognition failed to recognize. We showed that this method can transcribe text with a word accuracy exceeding 99%, matching the guarantee of professional human transcribers. Our apparatus is deployed in more than 40,000 Web sites and has transcribed over 440 million words.</swrc:abstract><swrc:hasExtraField><swrc:Field swrc:value="10.1126/science.1160379" swrc:key="doi"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="http://www.sciencemag.org/content/321/5895/1465.full.pdf" swrc:key="eprint"/></swrc:hasExtraField><swrc:author><rdf:Seq><rdf:_1><swrc:Person swrc:name="Luis von Ahn"/></rdf:_1><rdf:_2><swrc:Person swrc:name="Benjamin Maurer"/></rdf:_2><rdf:_3><swrc:Person swrc:name="Colin McMillen"/></rdf:_3><rdf:_4><swrc:Person swrc:name="David Abraham"/></rdf:_4><rdf:_5><swrc:Person swrc:name="Manuel Blum"/></rdf:_5></rdf:Seq></swrc:author></rdf:Description></burst:publication></item><item rdf:about="http://puma.uni-kassel.de/bibtex/23c8aa0e647903603ddce90c1642b89b2/jaeschke"><title>Attacks and design of image recognition CAPTCHAs</title><link>http://puma.uni-kassel.de/bibtex/23c8aa0e647903603ddce90c1642b89b2/jaeschke</link><dc:creator>jaeschke</dc:creator><dc:date>2010-10-11T15:39:09+02:00</dc:date><dc:subject>captcha image recognition security web </dc:subject><content:encoded>&lt;span class=&#034;authorEditorList&#034;&gt;&lt;a href=&#034;/author/Zhu&#034;&gt;Bin B.
 				 
 				Zhu&lt;/a&gt;, &lt;a href=&#034;/author/Yan&#034;&gt;Jeff
 				 
 				Yan&lt;/a&gt;, &lt;a href=&#034;/author/Li&#034;&gt;Qiujie
 				 
 				Li&lt;/a&gt;, &lt;a href=&#034;/author/Yang&#034;&gt;Chao
 				 
 				Yang&lt;/a&gt;, &lt;a href=&#034;/author/Liu&#034;&gt;Jia
 				 
 				Liu&lt;/a&gt;, &lt;a href=&#034;/author/Xu&#034;&gt;Ning
 				 
 				Xu&lt;/a&gt;, &lt;a href=&#034;/author/Yi&#034;&gt;Meng
 				 
 				Yi&lt;/a&gt;,  und &lt;a href=&#034;/author/Cai&#034;&gt;Kaiwei
 				 
 				Cai&lt;/a&gt;. &lt;/span&gt;&lt;em&gt;CCS &amp;#039;10: Proceedings of the 17th ACM conference on Computer and communications security, &lt;/em&gt;&lt;em&gt;Seite 187--200. &lt;/em&gt;&lt;em&gt;New York, NY, USA, &lt;/em&gt;&lt;em&gt;ACM, &lt;/em&gt;(&lt;em&gt;Oktober 2010&lt;/em&gt;)</content:encoded><taxo:topics><rdf:Bag><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/captcha"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/image"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/recognition"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/security"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/web"/></rdf:Bag></taxo:topics><burst:publication><rdf:Description rdf:about="http://puma.uni-kassel.de/bibtex/23c8aa0e647903603ddce90c1642b89b2/jaeschke"><owl:sameAs rdf:resource="http://puma.uni-kassel.de/uri/bibtex/23c8aa0e647903603ddce90c1642b89b2/jaeschke"/><rdf:type rdf:resource="http://swrc.ontoware.org/ontology#InProceedings"/><owl:sameAs rdf:resource="http://portal.acm.org/citation.cfm?id=1866307.1866329"/><swrc:date>Mon Oct 11 15:39:09 CEST 2010</swrc:date><swrc:address>New York, NY, USA</swrc:address><swrc:booktitle>CCS &#039;10: Proceedings of the 17th ACM conference on Computer and communications security</swrc:booktitle><swrc:month>oct</swrc:month><swrc:pages>187--200</swrc:pages><swrc:publisher><swrc:Organization swrc:name="ACM"/></swrc:publisher><swrc:title>Attacks and design of image recognition CAPTCHAs</swrc:title><swrc:year>2010</swrc:year><swrc:keywords>captcha image recognition security web </swrc:keywords><swrc:abstract>We systematically study the design of image recognition CAPTCHAs (IRCs) in this paper. We first review and examine all existing IRCs schemes and evaluate each scheme against the practical requirements in CAPTCHA applications, particularly in large-scale real-life applications such as Gmail and Hotmail. Then we present a security analysis of the representative schemes we have identified. For the schemes that remain unbroken, we present our novel attacks. For the schemes for which known attacks are available, we propose a theoretical explanation why those schemes have failed. Next, we provide a simple but novel framework for guiding the design of robust IRCs. Then we propose an innovative IRC called Cortcha that is scalable to meet the requirements of large-scale applications. It relies on recognizing objects by exploiting the surrounding context, a task that humans can perform well but computers cannot. An infinite number of types of objects can be used to generate challenges, which can effectively disable the learning process in machine learning attacks. Cortcha does not require the images in its image database to be labeled. Image collection and CAPTCHA generation can be fully automated. Our usability studies indicate that, compared with Google&#039;s text CAPTCHA, Cortcha allows a slightly higher human accuracy rate but on average takes more time to solve a challenge.</swrc:abstract><swrc:hasExtraField><swrc:Field swrc:value="http://homepages.cs.ncl.ac.uk/jeff.yan/ccs10.pdf" swrc:key="ee"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="Chicago, Illinois, USA" swrc:key="location"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="978-1-4503-0245-6" swrc:key="isbn"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="10.1145/1866307.1866329" swrc:key="doi"/></swrc:hasExtraField><swrc:author><rdf:Seq><rdf:_1><swrc:Person swrc:name="Bin B. Zhu"/></rdf:_1><rdf:_2><swrc:Person swrc:name="Jeff Yan"/></rdf:_2><rdf:_3><swrc:Person swrc:name="Qiujie Li"/></rdf:_3><rdf:_4><swrc:Person swrc:name="Chao Yang"/></rdf:_4><rdf:_5><swrc:Person swrc:name="Jia Liu"/></rdf:_5><rdf:_6><swrc:Person swrc:name="Ning Xu"/></rdf:_6><rdf:_7><swrc:Person swrc:name="Meng Yi"/></rdf:_7><rdf:_8><swrc:Person swrc:name="Kaiwei Cai"/></rdf:_8></rdf:Seq></swrc:author></rdf:Description></burst:publication></item><item rdf:about="http://puma.uni-kassel.de/bibtex/20efc5c0ef9a17c35402c654ff76247b0/jaeschke"><title>Protecting your daily in-home activity information from a wireless snooping attack</title><link>http://puma.uni-kassel.de/bibtex/20efc5c0ef9a17c35402c654ff76247b0/jaeschke</link><dc:creator>jaeschke</dc:creator><dc:date>2010-10-11T15:30:59+02:00</dc:date><dc:subject>attack automation home rfid security sensor </dc:subject><content:encoded>&lt;span class=&#034;authorEditorList&#034;&gt;&lt;a href=&#034;/author/Srinivasan&#034;&gt;Vijay
 				 
 				Srinivasan&lt;/a&gt;, &lt;a href=&#034;/author/Stankovic&#034;&gt;John
 				 
 				Stankovic&lt;/a&gt;,  und &lt;a href=&#034;/author/Whitehouse&#034;&gt;Kamin
 				 
 				Whitehouse&lt;/a&gt;. &lt;/span&gt;&lt;em&gt;UbiComp &amp;#039;08: Proceedings of the 10th international conference on Ubiquitous computing, &lt;/em&gt;&lt;em&gt;Seite 202--211. &lt;/em&gt;&lt;em&gt;New York, NY, USA, &lt;/em&gt;&lt;em&gt;ACM, &lt;/em&gt;(&lt;em&gt;2008&lt;/em&gt;)</content:encoded><taxo:topics><rdf:Bag><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/attack"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/automation"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/home"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/rfid"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/security"/><rdf:li rdf:resource="http://puma.uni-kassel.de/tag/sensor"/></rdf:Bag></taxo:topics><burst:publication><rdf:Description rdf:about="http://puma.uni-kassel.de/bibtex/20efc5c0ef9a17c35402c654ff76247b0/jaeschke"><owl:sameAs rdf:resource="http://puma.uni-kassel.de/uri/bibtex/20efc5c0ef9a17c35402c654ff76247b0/jaeschke"/><rdf:type rdf:resource="http://swrc.ontoware.org/ontology#InProceedings"/><owl:sameAs rdf:resource="http://portal.acm.org/citation.cfm?id=1409663"/><swrc:date>Mon Oct 11 15:30:59 CEST 2010</swrc:date><swrc:address>New York, NY, USA</swrc:address><swrc:booktitle>UbiComp &#039;08: Proceedings of the 10th international conference on Ubiquitous computing</swrc:booktitle><swrc:pages>202--211</swrc:pages><swrc:publisher><swrc:Organization swrc:name="ACM"/></swrc:publisher><swrc:title>Protecting your daily in-home activity information from a wireless snooping attack</swrc:title><swrc:year>2008</swrc:year><swrc:keywords>attack automation home rfid security sensor </swrc:keywords><swrc:abstract>In this paper, we first present a new privacy leak in residential wireless ubiquitous computing systems, and then we propose guidelines for designing future systems to prevent this problem. We show that we can observe private activities in the home such as cooking, showering, toileting, and sleeping by eavesdropping on the wireless transmissions of sensors in a home, even when all of the transmissions are encrypted. We call this the Fingerprint and Timing-based Snooping (FATS) attack. This attack can already be carried out on millions of homes today, and may become more important as ubiquitous computing environments such as smart homes and assisted living facilities become more prevalent. In this paper, we demonstrate and evaluate the FATS attack on eight different homes containing wireless sensors. We also propose and evaluate a set of privacy preserving design guidelines for future wireless ubiquitous systems and show how these guidelines can be used in a hybrid fashion to prevent against the FATS attack with low implementation costs.</swrc:abstract><swrc:hasExtraField><swrc:Field swrc:value="Seoul, Korea" swrc:key="location"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="978-1-60558-136-1" swrc:key="isbn"/></swrc:hasExtraField><swrc:hasExtraField><swrc:Field swrc:value="10.1145/1409635.1409663" swrc:key="doi"/></swrc:hasExtraField><swrc:author><rdf:Seq><rdf:_1><swrc:Person swrc:name="Vijay Srinivasan"/></rdf:_1><rdf:_2><swrc:Person swrc:name="John Stankovic"/></rdf:_2><rdf:_3><swrc:Person swrc:name="Kamin Whitehouse"/></rdf:_3></rdf:Seq></swrc:author></rdf:Description></burst:publication></item></rdf:RDF>