Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Thursday, February 25, 2010

#5 State of Your Research Prospectus (freewrite, 10 minutes)


My thinking has come very far just from the start of the topic. In the beginning I knew I wanted to do something related to Biometrics, as that has always interested me since the day that Professor Heishman introduced it to the class. From this fairly vague topic I had to then research into some of the more narrow topics within this field. I had previous knowledge of security and privacy being problems with this system, and thought that that would be a very manageable topic considering these methods are closing in on the general population fast, and they will more than likely be implemented in most place within the nextseveral years. Knowing that security and privacy are problems, I started hypothesizing different questions regarding that subject, making sure to keep on that single narrow subject. With this I found that the question should involve some sort of new "method" for guarding the general public against the security and privacy concerns of biometrics, after all, almost all Computer Science journals that I have read propose some sort of alternative method that gets the job done in a much more efficient way. From this question it was fairly easy to devise the problem since the question was initially derived from a problem that the population was having. Using the question the problem was very straightforward and concerned how people felt towards the security and privacy problems and how those people can be put at risk by using biometrics.


Although I haven't really started the review of the literature, I feel this won't be a very hard part. Most of the general information concerning biometrics is widely available, and in fact I have already found many sources using the keywords "Biometrics & Privacy" which will help me in my methodological literature review. In developing my literature review, I have learned to make the subject as broad as possible so that the audience will be able to tell that I have "done my homework" concerning the topic at hand. With this in mind I plan to take a thematic approach of the methods used in biometrics, jumping around to the most prominent topics in biometrics by explaining how some of the more famous theories have been derived and are used in everyday biometrics.

#3 Reading the Literature Review (freewrite, 10 minutes)

I recently read a Literature Review of biometrics, which also happens to be the topic of my research prospectus. Its structure was much less straightforward and narrow compared to the article that I used for the Anatomy of a Journal Article assignment. Instead of following through with a single research question or problem, this author decided to take the literature review on a broad journey of a single topic, creating a very nice overview of Biometrics. This literature review seemed to mostly be organized thematically. To begin, the author first started talking about the historical aspect of Biometrics and about how it has advanced. Then the author moved on to share the differences among the many different types of biometric methods that have evolved. There were many models and pictures in this point, which almost seemed to take my focus away from extracting knowledge from the writing. From this point, the author decided to include a wide variety of some of the present day companies or entities that use biometrics. He noted that people are increasingly using this in their homes in order to increase security. He also noted how there are many companies all over the world that have started to implement various biometric systems. There seemed to be three main themes throughout this review, the history, the methods, and the use. Although they seemed to mesh together rather well when reading it, now that I stepped back to look at the overall themes of the paper I don't think that they work that well together at all. I think there should have been more interlinking between the advantages and disadvantages of the various methods with the various methods that are available for use today.

It is different from papers that I have written in the past in that it is a very broad overview of a single topic. Most papers that I have written require that you focus on a single issue and then discuss ways to solve it. This literature review would be useful as support for a project proposal just based upon the sheer amount of data contained on a single subject in just one place. Literature Reviews are really helpful for most researchers as they don't necessarily have to look all over the place to find sources when they could just look in one place to find everything that they needed. Although the review may not be as dense as the researcher wanted, you can also trace back through the sources of the literature review, seemingly opening up your available sources exponentially. Usually the sources that are used in a literature review are some of the best sources on that topic, so by using those sources you can almost guarantee a solid paper.

Sunday, February 7, 2010

Refined Research Problem Statement

(*) Introduce the issue to be studied.


As issues of security are starting to get greater and greater, the general public is really starting to see a gradual shift in the methods of security.  One of the main methods that we are shifting our paradigm to is Biometrics, the way we uniquely identify humans based on physical or behavioral traits.  It seems like this issue would be just as foolproof as the normal password and PIN security method, but in reality it has just as many vulnerabilities and pitfalls.

(*) Introduce to background of the research area. 



Now that the massive shift to biometrics is taking place, many people are finding that the biometric data given to these security machines can be compromised against peoples liking.  Not only are there ways for attackers to gain access and to duplicate some of your biometric data, the companies or agencies that actually choose to implement the security methods can use your own biometric data against you.  Some biometric methods are capable of telling your sex, skin color, race, and even sometimes your thoughts.  This opens up the capabilities for the company, or even someone else with the capabilities, to use that data against your will.

(*) State the key issue, the overall research problem, specific research question/s.  There may be 1-3 separate questions connected to research problem area. Should be formulated in a very clear language in a form of a question.  



Although Biometrics seems fine to most people outside of the Computer Science field, many people are finding plenty of issues with the new methods which biometrics entails.  The largest issue with the biometric method would be the privacy concerns found with the use of gathered biometric data.


I am studying the advancement of biometrics with respect to the privacy of the individuals who use the system because I want to find out how the entities that implement these systems can use the biometric data against the user in order to help the user understand how their privacy is being violated and what new things can be done to fix the problem.


(*) Statement of relevance to the field. Define your audience of experts.


Since the advancement of biometrics is continuing, the key issues found within this topic will only grow worse.  By acknowledging the issues, the Computer Science field will be able to better serve the general public instead of merely pleasing everyone in the technology field.  By solving this problems now instead of later, we will be able to truly find a better method of security, be it in biometrics or not, and in the end solving this problem of privacy within the biometrics field will revolution both security and technology.  


The audience of experts for this topic would be biometric, security, and human-computer interaction experts.  Almost every topic in Computer Science correlates to biometrics in some form or fashion, so almost any scholarly being in the Computer Science field would find this problem and solution interesting.

(*) Introduce your proposed methods of study, in brief, if you can at this time.



A general proposal of my study methods would be primarily based on others research since I am unable to design my own biometric systems.  It would be best to decipher scholarly articles to search for methods that would be relevant to the privacy and advancement of biometrics.  If methods of this type can be merged into a singular method, the effect may be strong enough to fix the problem.

(*) Introduce limitations of the study, if you can at this time.



Although it will be easy to find sources regarding the topics that are already designed and being implemented, the limitation begins at the design of new systems.  I have had a wealth of experience in my college career, but it isn't at the point that I can go out and design a new biometric system to solve this problem.

(*) Note scholarly publications (1-3 publications, by title) where you might be able to publish the resulting paper you would write.



Security & Privacy Magazine, IEEE 
Journal of the ACM
Computer Law and Security Review


Bibliography


[1] A. Squicciarini and E. Bertino, "Privacy Preserving Multi-Factor Authentication with Biometrics,"Identity, 2006, pp. 63-71.


[2] A.M. Froomkin, "The Death of Privacy?," Stanford Law Review, vol. 52, 2000, pp. 1461-1543.


[3] D. Bala, "Biometrics and information security," Kennesaw, Georgia: ACM, 2008, pp. 64-66.


[4] J. Woodward, "Biometrics: privacy's foe or privacy's friend?," Proceedings of the IEEE, vol. 85, 1997, pp. 1480-1492.


[5] S. Prabhakar, S. Pankanti, and A. Jain, "Biometric recognition: security and privacy concerns,"Security & Privacy, IEEE, vol. 1, 2003, pp. 33-42.


[6] S. Cimato, M. Gamassi, V. Piuri, R. Sassi, and F. Scotti, "Privacy-Aware Biometrics: Design and Implementation of a Multimodal Verification System," 2008, pp. 130-139.

Saturday, February 6, 2010

#4 Refine Your Research Topic/Question/Problem (freewrite, 10 minutes)

1. How can we utilise and advance biometrics while still insuring personal privacy of citizens?

First I would like to start with refining my research problem.  I really wanted to stick with something that deals with the privacy part of biometrics.  For example, I am fairly curious as to what companies or other agencies actually do with the biometric data. One refined question could be:

I am studying the advancement of biometrics with respect to the privacy of the individuals who use the system because I want to find out how the entities that implement these systems can use the biometric data against the user in order to help the user understand how their privacy is being violated and what new things can be done to fix the problem.

Possible answers would be the subject that I have heard of in class (but not researched) which is called cancelable biometrics.  We all know that our own biometric data cannot be changed because we cannot just change our fingerprints, but with this new method the security system would implement some sort of hashing or manipulation algorithm which would safeguard the user from even having to lose their biometric data in the first place.  As for the issues of their privacy being used against them, the companies that create these security systems should also do algorithms which hide important data from the company.  This would then safeguard the user from racism or other privacy-eluding acts that would allow the company to figure out the users color, race, gender, and in some highly technological security systems, their thoughts.

Another issue that I would like to get into would be the issue regarding the national DNA database for newborns.  Although this doesn't seem like biometrics, under the shell it is being used as an uniquely identifiable source, which categorizes it as biometrics.

Sunday, January 31, 2010

#7 List of Research Questions/Problems (freewrite, 5-5-5 minutes)

Biometrics

Identify the parts and how they interrelate

What are the parts of your topic, and how do they relate to each other?

How do they scan for facial recognition?
What kind of computer architeture and systems are needed for biometrics security?
Can different types of biometric devices be used concurrently?

How is your topic part of a larger system?

Is biometrics better than normal types of security?
How is biometric security better than password security?

Trace is own history and its role in a larger history

How and why has your topic changed through time, as something with its own history?

Why is biometrics just becoming big now?
How will biometrics change in the future as technology grows more complex

How and why is your topic an episode in a larger history?

How will biometrics shape the future of security around the world?
Could biometrics fail at being secure in the future, making us revert back to other security measures?

Identify its characteristics and the categories that include it

What kind of thing is your topic?  What is its range of variation?  How are instances of it similar to and different from another?

How will biometric security better secure the systems that need securing?
Why are the security measures of today outdated and needing to be replaced by biometric devices?

To what larger categories can your topic be assigned?  How does that help us understand it?

How will computer security benefit from the advancement of biometrics?
We all know about fingerprints, but what other methods of biometric security measures are there?

Determine its value

What values does your topic reflect?  What values does it support?  Contradict?

Are the uses of biometric data again privacy laws or the privacy of individuals?
Should the authorities have access to your biological data such as hand and face patters?

How good or bad is your topic?  Is it useful?

Could biometrics be used for bad purposes?
What are the consequences and methods for fighting compromised biometric data?


Audio Compression


Identify the parts and how they interrelate

What are the parts of your topic, and how do they relate to each other?

How does audio compresssion relate to the actually devices that make the sounds?
Why is there a need for audio compression even when storage is so affordable?
What are the different methods of audio compression and how do they differ?
Among hte different methods of audio compression, which sound better to the human ear?

How is your topic part of a larger system?

How can the different audio compressions be used to trick your mind?


Trace is own history and its role in a larger history

How and why has your topic changed through time, as something with its own history?

How has audio compression changed with the invention of CD's, MP3's and DVD's?
Have differnt audio compression methods been designed to fit the new technology advances in sound storage?
How has audio compression advanced with the invention of newer and better audio technologies?

Determine its value

How good or bad is your topic?  Is it useful?

Does audio compression take the sound quality away form the listener?
What are the best methods of audio compression?


Network Security


Identify the parts and how they interrelate

What are the parts of your topic, and how do they relate to each other?

How are wireless and wired security similar?
Which is less secure, wireless or wired networks?

How is your topic part of a larger system?

How is cryptography used in the process of network security?
How is the method of data transfer across wireless networks vulnerable to attacks?


Trace is own history and its role in a larger history

How and why has your topic changed through time, as something with its own history?

With the invention of newer wireless technologies, has the advancement of security in the wireless field been less needed?

How and why is your topic an episode in a larger history?

What new technologies are on the horizon of breaking through, and will they be able to secure networks better?

Identify its characteristics and the categories that include it


What kind of thing is your topic?  What is its range of variation?  How are instances of it similar to and different from another?

How are the instances of a wired network and wireless network similar?
Of the wired and wireless networks, which are the more secure and why?
What are some different, unseen methods of securing networks?

Determine its value

What values does your topic reflect?  What values does it support?  Contradict?

Speaking of Google, Should their views on network security allow them to collect random information from their users?
What are the criminal charges placed against someone who infiltrates a computer network?

How good or bad is your topic?  Is it useful?

How could an attacker take advantage of a vulnerable wired or wireless network?




Reblog this post [with Zemanta]

Saturday, January 30, 2010

#6 Refined List of Research Topics (freewrite, 5-5-5 minutes)

Biometrics
This topic covers some very easily implemented programming concepts and some very intricate, complex ones.  The most basic, which I have done in a CS class, was to implement a very easy and basic eye scanner, something which could have been more complex and maybe fashioned into something usable.  Most of the biometrics stuff I have learned about deals with security issues on computers and many other places.  With a single eye scanner security can be made much more impermiable.  Just like your fingerprint, your eyes are also extremely unique, and now that I'm thinking about it, I think i've read that it is the most distinguishable thing about us humans.  Other uses of biometrics would be to test your gait.  I remember hearing about this in a lecture with Professor Heishman some time ago.  Apparently this can be used to detect people that should or should not be in the room at the time, almost like a under-floor security detection system.  Biometrics can also help with the disabled.  Just like scanners can use your eyes to secure certain places or things, they can also use them for people missing limbs so that they will be able to work in a better fashion in order to ease their lives.

Audio Compression
Although I havn't had any formal classes on this topic, I have seen enough of it to be interested.  No matter what you're listening to, each file has a certain file type extension.  These correlate to the compressions that the audio has undergone.  I am really interested in figuring out what these compressions actually mean for us humans, and to what extent the sound quality drops in our minds.  I am also interested in learning about DRM.  I know that many music companies sell their music with this type of security integrated so that the buyer won't be able to do anything illegal with that piece of music.  While on the topic of audio compression, I would also like to know how the compression is done.  I know most of it can be done on a computer with various software, but in what manner does the program actually compress the file to make it smaller?  It would be interesting to learn about the function and algorithms put in place to actually compress the files.  Does the software just pick out pieces of the music in different increments so that the song sounds the same, or is there just another algorithm for piecing the music apart while still allowing the original sounds to come through?

Network Security
I haven't had a formal class on this topic either, but while messing around with the topic on Linux I have opened my interests for this topic.  I've heard many instances of network security being very easy to break, allowing intruders into your home network where a lot of delicate information can be stored.  I know that WEP is the source of the problems, but I would think that after a while of being used it would either be honed down to be perfect, or another passwording system with better integrity would be implemented and take over.  In this topic I also know that there is cryptography.  I did a short project on this within the first year of joining George Mason University, and I know that the very basic level is completely overwhelming for a beginner in Computer Science.  During that project we learned that there are many various ways to crypt data and other information that you don't want to be found, and I know that various network traffic can be made secure, both via your browser (for example Google https) and in a terminal via secure file transfer, both of which are still widely used today.  I would be interested in learning some of the more secure ways of crypting data, and learning the uses of each one and how exactly they crypt and secure your data.

#5 List of Research Topics (freewrite, 5 minutes)

Biometrics
Biometric security uses
Global Warming
Clean fuels
Audio Compression
Robotics
Software Engineering models
Computer hardware
Linux/Opensource(free) software
Operating Systems
Database integrity
Computer Ethics
Computer architectures
Unsolveable problems (Formal Methods and Models)
Social Networks
Programming languages
Network Security
Cryptography