AK

A.J. Klievink

info

Please Note

42 records found

Intelligence services must balance values such as national security and privacy when collecting data, with each scenario involving specific contextual trade-offs. While citizens benefit from effective intelligence operations, they also risk having their rights infringed upon. This makes citizen perspectives on acceptable data collection for intelligence and national security salient, as their legitimacy is also contingent upon public support. Yet, important aspects of citizen perspectives are understudied, such as the influence of contextual factors related to the use of intelligence collection methods. This study, inspired by Nissenbaum's contextual integrity framework, uses a factorial survey experiment with vignettes among a representative sample of 1423 Dutch citizens to examine the influence of threat type, duration, data subject, collection method, data type, and data retention on public acceptance of surveillance. Additionally, the study considers the impact of respondents' trust and privacy attitudes. The findings reveal significant influence of both contextual variables – particularly threat type, data subject, and data retention – and respondent predispositions – particularly trust in institutions, trust in intelligence services' competence, and privacy concerns for others. The findings imply that more in-depth contextual knowledge among the public may foster support for intelligence activities. ...
Many cybercriminal entrepreneurs lack the skills and techniques to provision certain parts of their business model, leading them to outsource these parts to specialized criminal vendors. Online anonymous markets, from Silk Road to AlphaBay, have been used to search for these products and contract with their criminal vendors. While one listing of a product generates high sales numbers, another identical listing fails to sell. In this paper, we investigate which factors determine the performance of cybercrime products.
To answer this question, we analyze scraped data on the business-to-business cybercrime segments of AlphaBay (2015-2017), consist- ing of 7,543 listings from 1,339 vendors, sold at least 126,934 times. We construct new variables to capture product differentiators and price. We capture the influence of vendor characteristics by identifying five distinct vendor profiles based on latent profile analysis of six properties. We leverage these product and vendor characteristics to empirically predict the performance of cybercrime products, whilst controlling for the lifespan and type of solution. Consistent with earlier insights into carding forums, we identify prevalent product differentiators to be influencing the relative success of a product. While all these product differentiators do correlate significantly with product performance, their explanatory power is lower than that of vendor profiles. When outsourcing, the vendor seems to be of more importance to the buyers than product differentiators. ...

An interdisciplinary research agenda

Journal article (2019) - Eefje Cuppen, Bram Klievink, Neelke Doorn
The crowd increasingly plays a key role in facilitating innovations in a variety of sectors, spurred on by IT-developments and the concomitant increase in connectivity. Initiatives in this direction, captured under the umbrella-term ‘crowd-based innovations’ (CBI), offer novel opportunities in all domains of society by increasing the access, reach and speed of services and goods. At the same time, they signify important challenges because these innovations occur in a context of traditional, well-established institutional arrangements. CBI create an ‘institutional void’: existing rules, standards and practices are challenged and renegotiated. This raises questions about the safeguarding of public values such as quality, legitimacy, efficiency and governance of crowd-based innovations. The objective of this perspective piece is to present an interdisciplinary research agenda to address normative challenges for governing CBI. We will argue that such an agenda needs an integrated empirical-normative approach. We will detail three lines of empirical-normative research that together build up towards an interdisciplinary agenda. ...
Journal article (2019) - H. G.(Haiko) van der Voort, A. J.(Bram) Klievink, M. (Michela) Arnaboldi, A. J.(Albert) Meijer
Big data promises to transform public decision-making for the better by making it more responsive to actual needs and policy effects. However, much recent work on big data in public decision-making assumes a rational view of decision-making, which has been much criticized in the public administration debate. In this paper, we apply this view, and a more political one, to the context of big data and offer a qualitative study. We question the impact of big data on decision-making, realizing that big data – including its new methods and functions – must inevitably encounter existing political and managerial institutions. By studying two illustrative cases of big data use processes, we explore how these two worlds meet. Specifically, we look at the interaction between data analysts and decision makers. In this we distinguish between a rational view and a political view, and between an information logic and a decision logic. We find that big data provides ample opportunities for both analysts and decision makers to do a better job, but this doesn't necessarily imply better decision-making, because big data also provides opportunities for actors to pursue their own interests. Big data enables both data analysts and decision makers to act as autonomous agents rather than as links in a functional chain. Therefore, big data's impact cannot be interpreted only in terms of its functional promise; it must also be acknowledged as a phenomenon set to impact our policymaking institutions, including their legitimacy. ...
Journal article (2019) - Simon Vydra, Bram Klievink
Despite great potential, high hopes and big promises, the actual impact of big data on the public sector is not always as transformative as the literature would suggest. In this paper, we ascribe this predicament to an overly strong emphasis the current literature places on technical-rational factors at the expense of political decision-making factors. We express these two different emphases as two archetypical narratives and use those to illustrate that some political decision-making factors should be taken seriously by critiquing some of the core ‘techno-optimist’ tenets from a more ‘policy-pessimist’ angle. In the conclusion we have these two narratives meet ‘eye-to-eye’, facilitating a more systematized interrogation of big data promises and shortcomings in further research, paying appropriate attention to both technical-rational and political decision-making factors. We finish by offering a realist rejoinder of these two narratives, allowing for more context-specific scrutiny and balancing both technical-rational and political decision-making concerns, resulting in more realistic expectations about using big data for policymaking in practice. ...
Book chapter (2019) - Sergei Zhilin, Bram Klievink, Martin De Jong
The concept of the smart city increasingly being used but is in fact an umbrella topic covering several disciplines and domains. In the current literature is no agreement on a comprehensive vision of the smart city; perspectives on it vary from purely technological urban development to initiatives addressing societal challenges. We argue that in these perspectives, self-governance is often ignored, yet plays an important role in the smart city idea, bringing together people, technologies, and policies. The objective of this chapter is to provide a framework for the classification of self-governance initiatives on a community level. The framework unites heterogeneous urban initiatives giving a broader understanding of existing self-governance practices that could be used within the smart city. ...
Business-to-government information exchange has over the past decades greatly benefited from data exchange standards and inter-organisational systems. The data era enables a new shift in the type of information sharing; from formal reporting to opening up full (and big) data sets. This enables new analytics and insights by government, more effective and efficient compliance assessment, and other uses. The emphasis here shifts from establishing formats to deciding what information can be shared, under what conditions, and how to create added value. There are numerous initiatives that explore how to put data to better use for businesses, for government and for their interactions. However, there is limited attention to exactly how these new forms of extensive data sharing affects the supervision relationships. In this paper, we exploratively look across three research projects to identify the implications of information sharing beyond the regulatory requirements (‘over-compliant’). We find that the lack of attention to those implications lead to solutions that are hard to scale up and present unexpected consequences down the line, which may negatively impact the future willingness to explore new potential added value of data sharing. ...
Conference paper (2018) - Sergei Zhilin, Bram Klievink, Martin De Jong
Citizens interested in the democratization of urban development processes experiment with the co-creation of public spaces. Some of them collect, improve, and share design blueprints and manuals of their projects on the internet with help of free and open source tools. As a result, they produce open source design manuals that can be used freely, modified, and developed further. However, such attempts at opening urban design are still uncoordinated, atomized, and dispersed, and therefore fail to create the value that a more concerted effort might. We argue that open source urbanism practices would benefit from open design platforms that are purposefully designed for the complex domain of urbanism. As a first step, this paper identifies the requirements that such platform should meet. As there are currently no examples of such a platform, we analyze the platforms that are there and partially satisfy the demand to extract the shared underlying requirements ...
Researchers have observed the increasing commoditization of cybercrime, that is, the offering of capabilities, services, and resources as commodities by specialized suppliers in the underground economy. Commoditization enables outsourcing, thus lowering entry barriers for aspiring criminals, and potentially driving further growth in cybercrime. While there is evidence in the literature of specific examples of cybercrime commoditization, the overall phenomenon is much less understood. Which parts of cybercrime value chains are successfully commoditized, and which are not? What kind of revenue do criminal business-to-business (B2B) services generate and how fast are they growing? We use longitudinal data from eight online anonymous marketplaces over six years, from the original Silk Road to AlphaBay, and track the evolution of commoditization on these markets. We develop a conceptual model of the value chain components for dominant criminal business models. We then identify the market supply for these components over time. We find evidence of commoditization in most components, but the outsourcing options are highly restricted and transaction volume is often modest. Cash-out services feature the most listings and generate the largest revenue. Consistent with behavior observed in the context of narcotic sales, we also find a significant amount of revenue in retail cybercrime, i.e., business-to-consumer (B2C) rather than business to-business. We conservatively estimate the overall revenue for cybercrime commodities on online anonymous markets to be at least US $15M between 2011-2017. While there is growth, commoditization is a spottier phenomenon than previously assumed. ...

A Definition, a Criterion and a Method for Deciding on What Context-Aware Systems Should Sense and Adapt to

Context-awareness refers to the ability to sense and adapt to context. With the rise of context-aware systems, designers are struggling with what variables should be sensed from the context. According to the definitions found in the literature, whether something belongs to context, has to do with whether it is relevant. However, what it means to be relevant is left implicit in these definitions. Most work on context-aware systems is based on assumptions of the context that should be taken into account. Hence, it is unclear how to decide whether something belongs to context or should be left out. In this paper, first we analyse what is meant with context and provide a definition. In this definition we introduce the notion of a context variable, defined as an attribute of an object that is relevant. Context is then defined as the set of context variables. We establish explicit criteria for deciding whether an attribute of an object is a context variable based on the proposed definition and the designer’s goal. We also provide a straightforward method to help designers to determine whether the criterion is met and a variable should be included in the context. This method is based on filling out a scheme to describe context variables. ...

Balancing innovation and control

Driven by the technological capabilities that ICTs offer, data enable new ways to generate value for both society and the parties that own or offer the data. This article looks at the idea of data collaboratives as a form of cross-sector partnership to exchange and integrate data and data use to generate public value. The concept thereby bridges data-driven value creation and collaboration, both current themes in the field. To understand how data collaboratives can add value in a public governance context, we exploratively studied the qualitative longitudinal case of an infomobility platform. We investigated the ability of a data collaborative to produce results while facing significant challenges and tensions between the goals of parties, each having the conflicting objectives of simultaneously retaining control whilst allowing for generativity. Taken together, the literature and case study findings help us to understand the emergence and viability of data collaboratives. Although limited by this study’s explorative nature, we find that conditions such as prior history of collaboration and supportive rules of the game are key to the emergence of collaboration. Positive feedback between trust and the collaboration process can institutionalise the collaborative, which helps it survive if conditions change for the worse. ...

Governance as a key success factor for big data solutions in mobility

The promise of big data in the field of mobility is great, for example for mobility-as-a-service solutions. Having a better sense of the existing flows over the network would allow for much improved modelling of future flows and nudging users into behaviours targeting collectively better outcomes. Because of this promise the interest that cities have in big data for mobility is high. They are looking for ways in which a mobility data platform gathers the relevant data, allow for advanced modelling of current and future network states, and ways to drive travel behaviour. We participated in the EU funded PETRA project that built such a platform for the cities of Haifa, Rome and Venice. In this paper, we are looking for key governance mechanisms that affect the success of mobility data platforms, and how they are related to technical features. The project and an additional study into 10 cases revealed that the more ambitious a platform is on a technical level, the more governance challenges they will encounter, thus the more advanced governance arrangements are necessary. However, many governance arrangements are a given rather than a subject to design. This implies that for success, the technical ambition of the platform should be aligned with the institutions of the city in which the platforms will be implemented. ...
Business-to-government (B2G) information sharing can benefit government organisations, as well as businesses. Yet, businesses are often reluctant to share, as data sharing might not just provide benefits but also entails risks. Therefore, a system supporting B2G information sharing should provide the appropriate level of openness, such that the advantages of openness and possibilities to control risks for businesses are balanced. At the same time, the information obtained by the government should be useful. We identified three architectural layers at which B2G information sharing architectures can have different levels of openness, viz. the Software Layer, the Access Control Layer and the Data Layer. In this work, we compare three archetypical configurations of architectures for B2G information sharing with different levels of openness. Our aim is to provide insight into their impact on the possibilities for obtaining advantages from information sharing and managing risks of opening up data. We found that the relationship between the different levels of openness and the advantages and risks of information sharing is highly complex. We discuss this complexity and find that different levels of openness are appropriate in different situations. ...
Supply chain management is hampered by a lack of information sharing among partners. Information is not shared as organizations in the supply chain do not have direct contact and/or do not want to share competitive and privacy sensitive information. In addition, companies are often part of multiple supply chains and trading partners vary over time. Blockchains are distributed ledgers in which all parties in a network can have access to data under certain conditions. Private blockchains can be used to support parties in making their demand data directly available to all other parties in their supply chain. These parties can use this data to improve their planning and reduce the bullwhip effect. However, the transparency that blockchain technology offers makes it more difficult to protect sensitive data. The dynamics between these properties are not well understood. In this paper, we design and evaluate a blockchain architecture to explore its feasibility for reducing information asymmetry, while at the same time protecting sensitive data. We found that blockchain technology can allow parties to balance their need for inventory management with their need for flexibility for changing partners. However, measures to protect sensitive data lead either to reduced information, or to reduced speed by which the information can be accessed. ...
Context-aware systems are systems that have the ability to sense and adapt to the environment. To operate in large-scale multi-stakeholder environments, systems often require context awareness. The context elements that systems in such environments should take into account are becoming ever more complex and go beyond elements like geographic location. In addition, these environments are themselves so complex that it is hard to determine what parts of them belong to the relevant context of a context-aware system. However, insight into what belongs to this context is needed to establish what the design of a context-aware system should be to meet its goal. The ambiguity of what belongs to context in these complex organizational environments causes the design process to become either inefficient or less effective. In this paper, we provide a method to identify what elements of the environment are relevant context and to then base the design on this insight. The proposed method consists of three steps: 1) getting insight into context, 2) determining what components are needed to sense and adapt to context, and 3) determining the rules for how the system should adapt in different situations. To reduce ambiguity by organizations, the method requires a more specified definition of context than the ones in current literature, which we also provide in this paper. In addition to reducing ambiguity, the highly structured way in which the components and rules are derived from insight into context provides a way to further deal with the high complexity of the context. The method was applied for the development of a context-aware system for business-to-government (B2G) information sharing in the container shipping domain. Information sharing in this domain is highly complex, as legislation, many stakeholders, and a mix of cooperation and competition result in a highly complex environment. The development of this B2G information sharing system thus provides an example of how the method can be used to develop a context-aware system in a highly complex environment. ...

Over digitale innovatie en samenwerking in een institutional void

Journal article (2017) - Bram Klievink, Rolf van Wegberg, Michel van Eeten
The speed and disruptive character of digital innovations affect social structures and practices faster than institutions can keep up with them. This results in an ‘institutional void’, i.e. a gap between the rules and institutions and their ability and the effectiveness of their measures. It also affects the institutional stability that is the basis for the paradigm of collaboration-based types of governance. In this paper, we explore how parties are able to set up collaboration for digital security, which is inherently a topic that transcends organisational boundaries. Yet digital innovations constantly enable new challengers that might not share the same incentives for collaboration. Life in an institutional void is convenient for them and enables new business models. Hence, a key question is whether (institutionalised) collaboration is a sustainable model for addressing shared problems like digital security. We explore this question in the domain of financial cyber fraud. The new (regulatory) space currently being created for innovators suggests that the answer is ‘no’. It is too early to say how this will play out specifically and we argue for further research into the antecedents for collaboration in institutional voids. ...

On the Economic Incentives and Criminal Business Models in Financial Malware Schemes

Fraud with online payment services is an ongoing problem, with significant financial-economic and societal impact. One of the main modus operandi is financial malware that compromises consumer and corporate devices, thereby potentially undermining the security of critical financial systems. Recent research into the underground economy has shown that cybercriminals are organised around highly specialised tasks, such as pay-per-install markets for infected machines, malware-as-a-service and money mule recruitment. Setting up a successful financial malware scheme requires the aligning of many moving parts. Analysing how cybercrime groups acquire, combine and align these parts into value chains can greatly benefit from existing insights into the economics of online crime. Using transaction cost economics, this paper illustrates the business model behind financial malware and presents three novel value chains therein. For this purpose, we use a conceptual synthesis of the state-of-the-art of the literature on financial malware, underground markets and (cyber)crime economics, as well as today’s banking practice. ...
This document represents the governance handbook on mobility data platforms for the PETRA project. The governance handbook provides metropolitan authorities contemplating the implementation of a mobility data platform in line with the PETRA project about governance issues and design.
The analysis has shown mobility data platforms with the reach of PETRA are not available, however a variety of solutions of both the platform and the app exist in various situations. Of those, 13 were analyses to understand how governance shapes the solutions implemented and what the solutions implemented need from governance. The results do not provide a single best solution of governance for three reasons. First, mobility data platforms will land in a variety of (governance) contexts. Assuming that authorities would be willing to fully adjust their governance for the implementation of a mobility data platform is naïve. Second, mobility data platforms can come in a variety of forms. The governance has to align with the particular implementation. Third, governance solutions consist of a great deal of element that not necessarily always act uniformly, and as such, not always act predictably in various contexts. Because of that variability the handbook highlights key mechanisms that authorities working on the governance of a mobility data platform should take in to account, rather than provide a theoretical and unrealistic single optimal governance design. The report adapts a column structure to align with this focus on specific mechanisms to take into account. It also provides specific readers with a planned route through the different columns.
The governance handbook was developed based on the analysis of 13 case studies and the three demonstrators. The provided the input to understand the relation between the specific implementation of a mobility data platform and a governance context. Desk research and interviews provided the understanding of those cases, the types of data input, the function of the platform in terms of data linking, capture, retention, storage, aggregation, and modelling, the data output and a possible mobile application. The key question in the cases was to understand organisational links of the stakeholders providing the data and using the data, and the links to the stakeholders with an interest in the various functionalities of the platform in terms of data handling. From these links we could further understand how decision-making on the platform was structured and what outcomes of that decision-making could be expected.
The report starts with an instruction on the overall project, followed by a prologue, that sets the scene. This is followed by a number of theoretical columns, highlighting understood mechanisms from organisational science and public administration that showed to be relevant in the cases and demonstrators. After these, empirical columns highlight mechanisms that were recognised in the cases studied, and that illustrate the complex and varied contexts of mobility data platforms and how to align the governance to specific goals. Finally, five syntheses are given, including a business case, a set of models, and different governance design routes. ...
Conference paper (2017) - Bram Klievink, Alessia Neuroni, Marianne Fraefel, Anneke Zuiderwijk-van Eijk
In recent years, many countries have started to draft strategies and policies related to the data economy. To support new data- driven activities and innovations, the development of a national data infrastructure (NDI) is seen as key. The concept of NDI has entered governmental strategic discussions on data as an asset, the role of data infrastructures in innovation and economic activity, and the role of government therein. However, there is a gap between the ambitions as laid out in the strategies and the actual actions taken towards realizing them. To understand this gap and support NDI development, insight is needed in the components and processes of realizing NDI strategies. In this paper, we study NDI strategies ‘in action’ in the Netherlands and Switzerland using an analytical framework comprising strategies, stakeholders, design, components and governance. Special emphasis is put on the role of government in formulating and implementing strategies. Our cross-case analysis uncovers lessons that seem relevant for NDI development elsewhere, as well as challenges that need to be resolved before NDIs can hope to actually make the impact associated with them. ...