Por motivos de mantenimiento se ha deshabilitado el inicio de sesión temporalmente. Rogamos disculpen las molestias.
Artículo
Digital persona portrayal: Identifying pluridentity vulnerabilities in digital life
Autor/es | Olivero González, Miguel Ángel
Bertolino, Antonia Domínguez Mayo, Francisco José Escalona Cuaresma, María José Matteuci, Ilaria |
Departamento | Universidad de Sevilla. Departamento de Lenguajes y Sistemas Informáticos |
Fecha de publicación | 2020 |
Fecha de depósito | 2022-05-11 |
Publicado en |
|
Resumen | The increasing use of the Internet for social purposes enriches the data available online about all of us and promotes the concept of the Digital Persona. Actually, most of us are represented online by more than one identity, ... The increasing use of the Internet for social purposes enriches the data available online about all of us and promotes the concept of the Digital Persona. Actually, most of us are represented online by more than one identity, what we define here as a Pluridentity . This trend brings increased risks: it is well known that the security of a Digital Persona can be exploited if its data and security are not effectively managed. In this paper, we focus specifically on a new type of digital attack that can be perpetrated by combining pieces of data belonging to one same Pluridentity in order to profile their target. Some victims can be so accurately depicted when looking at their Pluridentity that by using the gathered information attackers can execute very personalized social engineering attacks, or even bypass otherwise safe security mecha- nisms. We characterize these Pluridentity attacks as a security issue of a virtual System of Systems, whose constituent systems are the individual identities and the humans themselves. We present a strategy to identify vulnerabilities caused by overexposure due to the combination of data from the constituent iden- tities of a Pluridentity. To this end we introduce the Digital Persona Portrayal Metamodel, and the related Digital Pluridentity Persona Portrayal Analysis process that supports the architecting of data from differ- ent identities: such model and process can be used to identify the vulnerabilities of a Pluridentity due to its exploitation as a System of Systems. The approach has been validated on the Pluridentities of seven- teen candidates selected from a data leak, by retrieving the data of their Digital Personae, and matching them against the security mechanisms of their Pluridentities. After analyzing the results for some of the analyzed subjects we could detect several vulnerabilities. |
Agencias financiadoras | Ministerio dell'Universitá e della Ricerca (Italia) Ministerio de Economía y Competitividad (MINECO). España |
Identificador del proyecto | GAUSS 2015KWREMX
TIN 2016-76956-C3-2-R (POLOLAS) |
Cita | Olivero González, M.Á., Bertolino, A., Domínguez Mayo, F.J., Escalona Cuaresma, M.J. y Matteuci, I. (2020). Digital persona portrayal: Identifying pluridentity vulnerabilities in digital life. Journal of Information Security and Applications, 52 (June 2020, art. nº102492) |
Ficheros | Tamaño | Formato | Ver | Descripción |
---|---|---|---|---|
Digital persona portrayal ... | 3.391Mb | [PDF] | Ver/ | |