C. Hernandez Ganan
Please Note
25 records found
1
Security by Expectation
Establishing an Empirical Understanding of Reasonable User Expectations in the Internet of Things
Growing security challenges of the IoT reflect a structural imbalance in the market. Consumers typically lack the information or technical capacity to evaluate or influence a product’s security, while manufacturers face little incentive to prioritize it over features or cost efficiency. To address this, governments, particularly within the European Union, are increasingly introducing legislation that codifies how security should be built, maintained, and enforced across the IoT ecosystem. Key among these initiatives are the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD), which place explicit emphasis on the expectations of users as a benchmark for determining compliance and responsibility.
The concept of reasonable user expectations has therefore become central to the regulation of IoT products. It provides a flexible legal standard to assess what users can justifiably anticipate regarding the safety and security of their devices. However, despite its prominence in emerging laws, there is no agreed-upon method for determining what these expectations actually are. Courts may consider factors such as prevailing industry practices or product marketing, but empirical evidence of what users themselves expect in practice has been scarce. This creates uncertainty for regulators and manufacturers alike, who must interpret and act on these expectations long before any case law emerges. Against this backdrop, the overarching research question guiding the work is: What are users’ expectations regarding preventive and reactive security measures of IoT devices?
To answer this research question, this dissertation investigates user expectations at different stages of the IoT device lifecycle: when security or privacy incidents occur, how they are prevented over the device's lifespan, and when devices are used in organizational environments. The studies link these expectations to the broader regulatory concepts of product liability and product conformity, providing evidence that can inform both policy and industry practice.
...
Growing security challenges of the IoT reflect a structural imbalance in the market. Consumers typically lack the information or technical capacity to evaluate or influence a product’s security, while manufacturers face little incentive to prioritize it over features or cost efficiency. To address this, governments, particularly within the European Union, are increasingly introducing legislation that codifies how security should be built, maintained, and enforced across the IoT ecosystem. Key among these initiatives are the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD), which place explicit emphasis on the expectations of users as a benchmark for determining compliance and responsibility.
The concept of reasonable user expectations has therefore become central to the regulation of IoT products. It provides a flexible legal standard to assess what users can justifiably anticipate regarding the safety and security of their devices. However, despite its prominence in emerging laws, there is no agreed-upon method for determining what these expectations actually are. Courts may consider factors such as prevailing industry practices or product marketing, but empirical evidence of what users themselves expect in practice has been scarce. This creates uncertainty for regulators and manufacturers alike, who must interpret and act on these expectations long before any case law emerges. Against this backdrop, the overarching research question guiding the work is: What are users’ expectations regarding preventive and reactive security measures of IoT devices?
To answer this research question, this dissertation investigates user expectations at different stages of the IoT device lifecycle: when security or privacy incidents occur, how they are prevented over the device's lifespan, and when devices are used in organizational environments. The studies link these expectations to the broader regulatory concepts of product liability and product conformity, providing evidence that can inform both policy and industry practice.
Evaluation of Anti-Abuse Strategies Among Hosting Providers
A data-driven analysis of malicious IPs and compliance practices
This study evaluates the effectiveness of anti-abuse measures employed by Dutch hosting providers, with a focus on the role of the DSA in helping with compliance and reducing malicious activity. Specifically, it examines whether adherence to the DSA improves the ability of hosting providers to mitigate cyber threats, particularly in reducing the prevalence of malicious IP addresses. Using passive DNS data, the research examines changes in the prevalence of malicious IP addresses before and after the implementation of the DSA. Compliance levels were also analyzed to understand their correlation with malware percentages. The study employed statistical methods, including Interrupted Time Series (ITS) analysis and regression models, to evaluate trends and relationships between compliance and malicious activity.
The findings indicate no statistically significant reduction in malicious IP activity following the implementation of the DSA, suggesting that compliance alone does not automatically translate into improved security outcomes. While the DSA strengthens transparency and procedural accountability, hosting providers continue to face operational challenges in implementing effective anti-abuse measures. Factors such as cybercriminal adaptation, enforcement inconsistencies, and resource constraints likely influence the weak correlation between compliance and actual abuse reduction. These results shows the need for a more holistic approach to cybersecurity regulation, combining technical advancements, industry collaboration, and proactive security enforcement alongside regulatory compliance. Evaluating the effectiveness of frameworks like the DSA is essential to ensuring that they not only establish compliance standards but also provide hosting providers with practical tools to enhance online security and mitigate digital threats effectively.
...
This study evaluates the effectiveness of anti-abuse measures employed by Dutch hosting providers, with a focus on the role of the DSA in helping with compliance and reducing malicious activity. Specifically, it examines whether adherence to the DSA improves the ability of hosting providers to mitigate cyber threats, particularly in reducing the prevalence of malicious IP addresses. Using passive DNS data, the research examines changes in the prevalence of malicious IP addresses before and after the implementation of the DSA. Compliance levels were also analyzed to understand their correlation with malware percentages. The study employed statistical methods, including Interrupted Time Series (ITS) analysis and regression models, to evaluate trends and relationships between compliance and malicious activity.
The findings indicate no statistically significant reduction in malicious IP activity following the implementation of the DSA, suggesting that compliance alone does not automatically translate into improved security outcomes. While the DSA strengthens transparency and procedural accountability, hosting providers continue to face operational challenges in implementing effective anti-abuse measures. Factors such as cybercriminal adaptation, enforcement inconsistencies, and resource constraints likely influence the weak correlation between compliance and actual abuse reduction. These results shows the need for a more holistic approach to cybersecurity regulation, combining technical advancements, industry collaboration, and proactive security enforcement alongside regulatory compliance. Evaluating the effectiveness of frameworks like the DSA is essential to ensuring that they not only establish compliance standards but also provide hosting providers with practical tools to enhance online security and mitigate digital threats effectively.
From Disclosure to Exploitation
A Comprehensive Analysis of IoT Vulnerability Targeting and Attacker Decision-Making
This dissertation investigates how IoT vulnerabilities are selected for exploitation in practice, with a particular focus on attacker behavior, exploit development, and vulnerability characteristics. It systematically examines the interplay between these factors to understand how they collectively shape exploitation trends in IoT ecosystems. To answer the central research question on What factors shape the exploitation in IoT vulnerabilities, from target selection to exploit development and prediction?, this dissertation presents four peer-reviewed studies.... ...
This dissertation investigates how IoT vulnerabilities are selected for exploitation in practice, with a particular focus on attacker behavior, exploit development, and vulnerability characteristics. It systematically examines the interplay between these factors to understand how they collectively shape exploitation trends in IoT ecosystems. To answer the central research question on What factors shape the exploitation in IoT vulnerabilities, from target selection to exploit development and prediction?, this dissertation presents four peer-reviewed studies....
The Signals We Send
Analysing the Market Signals for IoT Security and Privacy
The underlying reasons for the S&P issues in IoT devices are not merely technical, there are socio-technical and economic dimensions associated with them. For instance, large scale DDoS attacks from insecure IoT devices are a classic example of negative externalities where the consequences of the attack are experienced by a party that is neither the manufacturer nor the consumer. In such a context, manufacturers often face a lack of incentives to improve on the underlying S&P issues since doing so would increase their development costs and delay their time to market. Although consumers as device owners may not be directly targeted by DDoS attacks, they do face indirect consequences from DDoS attacks on governments, banks and other websites. Moreover, they bear the brunt of individual losses to S&P, for example, when their IoT devices are hacked or their personal video feeds are exposed. Therefore, consumers have incentives to buy IoT devices with strong S&P features. Recent studies affirm this, and show that consumers not only care about IoT S&P, they are also willing to pay a premium for it – if they are informed about the S&P at the time of purchase.
However, the problem still remains that consumers do not have sufficient information – at the time of purchase – to discern IoT devices that have good S&P features from those that do not. While regulations like the Cyber Resilience Act (CRA) in the EU, and the US Cyber TrustMark aim to decrease this information asymmetry, they are not yet in effect. In the absence of official information about an IoT device’s S&P at the time of purchase, consumers might use other signals that directly or indirectly indicate the S&P posture of IoT devices like mention of security concerns in consumer reviews on e-commerce platforms. Since consumers currently depend on such indirect sources to assess S&P, insights into these signals can help design more effective interventions that fit into their current decision-making flow. However, there is currently no empirical analysis on these market signals which limits our understanding of how much the consumer base already recognises and signals a need for S&P.
This dissertation addresses this gap by analyzing S&P of consumer IoT devices through a market-based empirical lens that examines how economic incentives, S&P signals, and purchase decisions interact across different stakeholders in real-world e-commerce settings. Specifically, five mature and popular IoT device types are considered: IP cameras, smart printers, smart speakers, smart TVs and smart watches. By examining the interactions between manufacturers, consumers, sellers, and the e-commerce platforms that sell these devices, using actual market data (sales figures, prices, reviews, and product listings), this dissertation provides a unique vantage point on the market signals for IoT S&P and information asymmetry experienced by consumers. Overall, this dissertation aims to answer the following overarching research question through five research studies. What signals for security and privacy are present in the e-commerce platforms that sell IoT devices?
...
The underlying reasons for the S&P issues in IoT devices are not merely technical, there are socio-technical and economic dimensions associated with them. For instance, large scale DDoS attacks from insecure IoT devices are a classic example of negative externalities where the consequences of the attack are experienced by a party that is neither the manufacturer nor the consumer. In such a context, manufacturers often face a lack of incentives to improve on the underlying S&P issues since doing so would increase their development costs and delay their time to market. Although consumers as device owners may not be directly targeted by DDoS attacks, they do face indirect consequences from DDoS attacks on governments, banks and other websites. Moreover, they bear the brunt of individual losses to S&P, for example, when their IoT devices are hacked or their personal video feeds are exposed. Therefore, consumers have incentives to buy IoT devices with strong S&P features. Recent studies affirm this, and show that consumers not only care about IoT S&P, they are also willing to pay a premium for it – if they are informed about the S&P at the time of purchase.
However, the problem still remains that consumers do not have sufficient information – at the time of purchase – to discern IoT devices that have good S&P features from those that do not. While regulations like the Cyber Resilience Act (CRA) in the EU, and the US Cyber TrustMark aim to decrease this information asymmetry, they are not yet in effect. In the absence of official information about an IoT device’s S&P at the time of purchase, consumers might use other signals that directly or indirectly indicate the S&P posture of IoT devices like mention of security concerns in consumer reviews on e-commerce platforms. Since consumers currently depend on such indirect sources to assess S&P, insights into these signals can help design more effective interventions that fit into their current decision-making flow. However, there is currently no empirical analysis on these market signals which limits our understanding of how much the consumer base already recognises and signals a need for S&P.
This dissertation addresses this gap by analyzing S&P of consumer IoT devices through a market-based empirical lens that examines how economic incentives, S&P signals, and purchase decisions interact across different stakeholders in real-world e-commerce settings. Specifically, five mature and popular IoT device types are considered: IP cameras, smart printers, smart speakers, smart TVs and smart watches. By examining the interactions between manufacturers, consumers, sellers, and the e-commerce platforms that sell these devices, using actual market data (sales figures, prices, reviews, and product listings), this dissertation provides a unique vantage point on the market signals for IoT S&P and information asymmetry experienced by consumers. Overall, this dissertation aims to answer the following overarching research question through five research studies. What signals for security and privacy are present in the e-commerce platforms that sell IoT devices?
From the Outside In
Predicting internal security incidents with external network data
Uncovering the vulnerable
Exploring the issue of TCP reflective amplification in the network of an ISP
The thesis primarily focuses on exploring vulnerable devices and their end-users within the consumer network of a Dutch ISP, KPN. The ultimate goal is to gather more information on the types of vulnerable devices and actors involved to eventually assist an ISP in making informed decisions to remediate the vulnerability in their network.
The study found that the problem can be described in two different issues: vulnerable middleboxes and vulnerable consumer IoT devices with broken TCP protocols. The problem of vulnerable middleboxes has been solved in the network of the Dutch ISP as manufacturers have released updates remediating the vulnerability. This is not the case for vulnerable consumer IoT, as updating consumer IoT devices does not necessarily address the vulnerability present in the devices that have been identified. However, vulnerability notifications can potentially be useful for end-users to encourage them to update their vulnerable devices.
The study highlights the presence of vulnerable devices in the ISP network that cannot be remediated by updating the device due to the unavailability of a fix. This calls for the exploration of alternative notification methods like walled garden notifications for ISP's to address the issue as mail notifications seem not feasible at the moment of writing. While updating devices is a suggested solution, it may not be feasible for end-users with vulnerable consumer IoT devices, making it crucial for manufacturers to ensure their products have secure TCP protocols. While end-users are motivated and capable to keep their vulnerable devices up to date, whether or not they receive a vulnerability notification from their ISP, this action alone will not fully address the vulnerability as long as manufacturers remain unaware of the issue or fail to provide updates to remedy it.
...
The thesis primarily focuses on exploring vulnerable devices and their end-users within the consumer network of a Dutch ISP, KPN. The ultimate goal is to gather more information on the types of vulnerable devices and actors involved to eventually assist an ISP in making informed decisions to remediate the vulnerability in their network.
The study found that the problem can be described in two different issues: vulnerable middleboxes and vulnerable consumer IoT devices with broken TCP protocols. The problem of vulnerable middleboxes has been solved in the network of the Dutch ISP as manufacturers have released updates remediating the vulnerability. This is not the case for vulnerable consumer IoT, as updating consumer IoT devices does not necessarily address the vulnerability present in the devices that have been identified. However, vulnerability notifications can potentially be useful for end-users to encourage them to update their vulnerable devices.
The study highlights the presence of vulnerable devices in the ISP network that cannot be remediated by updating the device due to the unavailability of a fix. This calls for the exploration of alternative notification methods like walled garden notifications for ISP's to address the issue as mail notifications seem not feasible at the moment of writing. While updating devices is a suggested solution, it may not be feasible for end-users with vulnerable consumer IoT devices, making it crucial for manufacturers to ensure their products have secure TCP protocols. While end-users are motivated and capable to keep their vulnerable devices up to date, whether or not they receive a vulnerability notification from their ISP, this action alone will not fully address the vulnerability as long as manufacturers remain unaware of the issue or fail to provide updates to remedy it.
This research is focused on a better understanding of how the remediation has influenced the impact Flubot has had on victims and smartphone users in general. A quantitative research approach, based on a survey of victims within a large Dutch telecom provider’s client database, is used to gain this understanding. This is aided by desk research, an interview with an active case of Flubot and expert input (employed by telecom providers and governmental bodies). The results from these research methods are put into context by making use of the Fogg Behavior Model, to better understand what might trigger certain target groups to or not to remediate the infection. The larger environment Flubot functioned in, is analysed too, as it was developed over time and by June of 2022 it had been taken down.
This research has found that the detection methods used against Flubot, before it was taken down, were ineffective in detecting and stopping the spread of the malware. This is a result of a misunderstanding of the more recent workings of Flubot and a larger incorrect presumption that there was no urgency to do much about the malware. Furthermore, in the remediation process some important issues are unclear or unaddressed for victims, leading to a situation where it is often not clear what might have caused the infection or what can be done to prevent a future infection. It is important to prevent further infections, as similar malware does exist, functioning on similar principles, and there is a chance that Flubot might reappear.
The research is based on victims and there was no target group reached that had not been victimised. This makes for a possibly skewed understanding of the situation which should be researched. The data has been gathered through one of the largest telecom providers of the Netherlands, which is not necessarily representative for the whole Dutch industry. Researching other telecom providers in and outside the Netherlands could provide a more comprehensive understanding. The research has led recommending an adaptive notification systems and improvements to the notifications currently used. ...
This research is focused on a better understanding of how the remediation has influenced the impact Flubot has had on victims and smartphone users in general. A quantitative research approach, based on a survey of victims within a large Dutch telecom provider’s client database, is used to gain this understanding. This is aided by desk research, an interview with an active case of Flubot and expert input (employed by telecom providers and governmental bodies). The results from these research methods are put into context by making use of the Fogg Behavior Model, to better understand what might trigger certain target groups to or not to remediate the infection. The larger environment Flubot functioned in, is analysed too, as it was developed over time and by June of 2022 it had been taken down.
This research has found that the detection methods used against Flubot, before it was taken down, were ineffective in detecting and stopping the spread of the malware. This is a result of a misunderstanding of the more recent workings of Flubot and a larger incorrect presumption that there was no urgency to do much about the malware. Furthermore, in the remediation process some important issues are unclear or unaddressed for victims, leading to a situation where it is often not clear what might have caused the infection or what can be done to prevent a future infection. It is important to prevent further infections, as similar malware does exist, functioning on similar principles, and there is a chance that Flubot might reappear.
The research is based on victims and there was no target group reached that had not been victimised. This makes for a possibly skewed understanding of the situation which should be researched. The data has been gathered through one of the largest telecom providers of the Netherlands, which is not necessarily representative for the whole Dutch industry. Researching other telecom providers in and outside the Netherlands could provide a more comprehensive understanding. The research has led recommending an adaptive notification systems and improvements to the notifications currently used.
SAVing the Internet
Measuring the adoption of Source Address Validation (SAV) by network providers
Dear customer, critters are crawling through your precious files
Understanding real-world evidence of QSnatch clean-up results and user experiences after warnings from the ISP
Centralised DNS-based Malware Mitigation
Examining the adoption and efficacy of centralised DNS-based malware mitigation services
Privacy issues of mobile phone companies’ usage of Ultra-Wideband (UWB) technology
Analysing the use of UWB in mobile phones from a multi-actor perspective, magnifying privacy concerns and formulating guidelines
range in mobile phones. This allows for fast data rate, low power secure
communication, multipath facilities and accurate localization. While the integration of UWB is mostly advantageous to users and innovators, its ability of accurate localisation may lead to severe privacy concerns
The aim of the thesis is to understand the privacy concerns of UWB’s integration into mobile phones by answering the main research question: how do experts and users perceive privacy concerns of UWB usage in mobile phones; and how can they be mitigated? It was subsequently broken down into three sub-research
questions: 1. What are the possible applications of UWB in mobile phones? Phones have other incumbent radio technology embedded such as Bluetooth (BLE) and Wi-Fi, however it seems like UWB is being integrated to serve additional purposes. The answer to this question seeks to understand from gray and research literature how UWB can be used in mobile phones and what advantage it gives over incumbent technology. Research shows UWB gives phones the ability for indoor navigation, gesture-based control, foot traffic analysis for smart retail, teleconference systems, proximity-based localization, key-less entry among others.
This leads to research question 2. What are the potential privacy concerns associated with UWB? The incorporation of new technology capable of accurate localization leads to privacy concerns. All privacy issues were categorised on the basis of three paradigms: social, surveillance and institutional mentioned in Gurses and Diaz, 2013. This was initially done by interviewing experts from the three groups of privacy experts, policy regulators and technology experts. Analysis of their answers showed that UWB privacy concerns seem relatively similar to BLE and Wi-Fi localization, albeit with higher granularity. UWB allows mobile phones companies, third parties and governments track people accurately indoors, push advertisements depending on location, obtain relative relationships between people based on distance leaving people with no place to hide. Subsequently, user interviews were carried out to see if they could identify the same concerns of UWB. Results showed that that from the data of users interviewed, all of them believed that accurate data
localization of people is crossing a line that users cannot push back on. A majority of them saw most of the same privacy issues as the experts showing that, as people get more adept with technology they understand
how it can affect their privacy. A common question that was asked across all the interviews was how can we protect our privacy in the face of such penetrating innovation as time lapses.
Which is the final sub-research question: 3. What are technical and societal approaches to address privacy concerns? Experts provided solutions that were more industry oriented which included decoupling UWBfrom other location-based services, provision of opt-out settings on a more prominent basis, reworking license agreements, industry wide discussion and self-regulation in terms of privacy. However, users gave answers that were more user-centric and gave more control to the common public. This included users neggotiating their own privacy agreements, compensation models for loss of privacy, a more holistic regulation process and finally, trying to break the control of big tech companies. This shows that users and experts have very similar understanding of privacy issues but very different views on how privacy should be protected. Perhaps, it may be time for regulators to pay heed to user suggestions. These suggestions were then compared with privacy mitigation strategies mentioned in literature. Notably, the most overarching concept that needs to be incorporated is the concept of Privacy-by-design which can then be broken down into technical and societal strategies. Technical approaches included concepts such as obfuscation, k-anonymiser, differential privacy, dummy localization and access control mechanisms. All the technical strategies seemingly had the same issue of requiring third-party applications to function. Sophisticated security measures and privacy statements would then be needed to ensure these companies do not choose monetary gain over user privacy. Societal approaches included concepts of data-for-all, technical regulatory bodies and finally, breaking up of big tech companies. As time passes and innovations become more pervasive, it may be too late to incorporate privacy protection actively. The time to protect privacy is now. ...
range in mobile phones. This allows for fast data rate, low power secure
communication, multipath facilities and accurate localization. While the integration of UWB is mostly advantageous to users and innovators, its ability of accurate localisation may lead to severe privacy concerns
The aim of the thesis is to understand the privacy concerns of UWB’s integration into mobile phones by answering the main research question: how do experts and users perceive privacy concerns of UWB usage in mobile phones; and how can they be mitigated? It was subsequently broken down into three sub-research
questions: 1. What are the possible applications of UWB in mobile phones? Phones have other incumbent radio technology embedded such as Bluetooth (BLE) and Wi-Fi, however it seems like UWB is being integrated to serve additional purposes. The answer to this question seeks to understand from gray and research literature how UWB can be used in mobile phones and what advantage it gives over incumbent technology. Research shows UWB gives phones the ability for indoor navigation, gesture-based control, foot traffic analysis for smart retail, teleconference systems, proximity-based localization, key-less entry among others.
This leads to research question 2. What are the potential privacy concerns associated with UWB? The incorporation of new technology capable of accurate localization leads to privacy concerns. All privacy issues were categorised on the basis of three paradigms: social, surveillance and institutional mentioned in Gurses and Diaz, 2013. This was initially done by interviewing experts from the three groups of privacy experts, policy regulators and technology experts. Analysis of their answers showed that UWB privacy concerns seem relatively similar to BLE and Wi-Fi localization, albeit with higher granularity. UWB allows mobile phones companies, third parties and governments track people accurately indoors, push advertisements depending on location, obtain relative relationships between people based on distance leaving people with no place to hide. Subsequently, user interviews were carried out to see if they could identify the same concerns of UWB. Results showed that that from the data of users interviewed, all of them believed that accurate data
localization of people is crossing a line that users cannot push back on. A majority of them saw most of the same privacy issues as the experts showing that, as people get more adept with technology they understand
how it can affect their privacy. A common question that was asked across all the interviews was how can we protect our privacy in the face of such penetrating innovation as time lapses.
Which is the final sub-research question: 3. What are technical and societal approaches to address privacy concerns? Experts provided solutions that were more industry oriented which included decoupling UWBfrom other location-based services, provision of opt-out settings on a more prominent basis, reworking license agreements, industry wide discussion and self-regulation in terms of privacy. However, users gave answers that were more user-centric and gave more control to the common public. This included users neggotiating their own privacy agreements, compensation models for loss of privacy, a more holistic regulation process and finally, trying to break the control of big tech companies. This shows that users and experts have very similar understanding of privacy issues but very different views on how privacy should be protected. Perhaps, it may be time for regulators to pay heed to user suggestions. These suggestions were then compared with privacy mitigation strategies mentioned in literature. Notably, the most overarching concept that needs to be incorporated is the concept of Privacy-by-design which can then be broken down into technical and societal strategies. Technical approaches included concepts such as obfuscation, k-anonymiser, differential privacy, dummy localization and access control mechanisms. All the technical strategies seemingly had the same issue of requiring third-party applications to function. Sophisticated security measures and privacy statements would then be needed to ensure these companies do not choose monetary gain over user privacy. Societal approaches included concepts of data-for-all, technical regulatory bodies and finally, breaking up of big tech companies. As time passes and innovations become more pervasive, it may be too late to incorporate privacy protection actively. The time to protect privacy is now.
The Root Cause of Data Breaches
Investigating security misconfigurations as the root cause of data breaches
Where do all the idIoTs come from?
Identification of Insecurely Developed IoT devices and a corresponding analysis of Dutch digital markets that sell them
Investigating Target Selection and Financial Impact of Service Fraud
An empirical research into criminal activities on underground markets and their implications for businesses
Creating a Configuration Security Layer for Embedded Devices
A research-based on the case study of a widely used Embedded Device