Circular Image

M.J.G. van Eeten

info

Please Note

40 records found

Establishing an Empirical Understanding of Reasonable User Expectations in the Internet of Things

The rapid expansion of the Internet of Things (IoT) has increasingly computerized physical objects and tools. Products such as household appliances, cars, industrial machinery, and medical devices are now equipped with sensors, software, and network connections that enable new forms of automation and data exchange. While these developments promise convenience and efficiency, they also introduce new risks. Weak security controls, insufficient privacy safeguards, and inadequate post-market support have repeatedly led to breaches, surveillance incidents, and large-scale cyberattacks. As IoT systems proliferate, the consequences of these vulnerabilities extend beyond individual users or companies to critical infrastructures and society as a whole.

Growing security challenges of the IoT reflect a structural imbalance in the market. Consumers typically lack the information or technical capacity to evaluate or influence a product’s security, while manufacturers face little incentive to prioritize it over features or cost efficiency. To address this, governments, particularly within the European Union, are increasingly introducing legislation that codifies how security should be built, maintained, and enforced across the IoT ecosystem. Key among these initiatives are the Cyber Resilience Act (CRA) and the revised Product Liability Directive (PLD), which place explicit emphasis on the expectations of users as a benchmark for determining compliance and responsibility.

The concept of reasonable user expectations has therefore become central to the regulation of IoT products. It provides a flexible legal standard to assess what users can justifiably anticipate regarding the safety and security of their devices. However, despite its prominence in emerging laws, there is no agreed-upon method for determining what these expectations actually are. Courts may consider factors such as prevailing industry practices or product marketing, but empirical evidence of what users themselves expect in practice has been scarce. This creates uncertainty for regulators and manufacturers alike, who must interpret and act on these expectations long before any case law emerges. Against this backdrop, the overarching research question guiding the work is: What are users’ expectations regarding preventive and reactive security measures of IoT devices?

To answer this research question, this dissertation investigates user expectations at different stages of the IoT device lifecycle: when security or privacy incidents occur, how they are prevented over the device's lifespan, and when devices are used in organizational environments. The studies link these expectations to the broader regulatory concepts of product liability and product conformity, providing evidence that can inform both policy and industry practice.
...

Municipal Cybersecurity Measures in Practice

Municipalities play a central role in delivering essential public services, including civil registration, social services, taxation, communication, and local democratic processes. In doing so, they increasingly rely on digital systems. Cyber incidents affecting these systems can disrupt service delivery, expose sensitive personal data, and impose significant recovery costs. Because municipalities are often the most visible and accessible layer of government for citizens, such incidents may also affect public trust. In addition, municipalities operate and oversee systems that support local critical infrastructure, such as water management, traffic control, and energy distribution, placing them within the scope of both financially motivated cybercriminals and state-sponsored advanced persistent threats (APTs).

In response to this threat landscape, municipalities are expected to implement a range of cybersecurity measures. These include complying with security frameworks and standards, managing vulnerabilities through patching and configuration, participating in information sharing and coordination structures, and preparing for incident response and recovery. At the same time, municipalities typically operate under constraints that distinguish them from many other organizations, including limited internal cybersecurity capacity, extensive reliance on outsourcing and shared service providers, and complex internal structures in which responsibility for systems and data is distributed across departments and external parties.

As a result, municipal cybersecurity is rarely a matter of isolated technical controls. Instead, it is shaped by interactions between municipalities and a broader ecosystem of actors, including vendors, managed service providers, sectoral and national CSIRTs, and commercial security firms. Information about threats and vulnerabilities often reaches municipalities through intermediaries, and the ability to act on that information depends on institutional arrangements, contractual relationships, and organizational processes. Understanding municipal cybersecurity, therefore, requires examining not only which security measures are in place but also how those measures function in practice within this institutional context.

This dissertation examines the security measures municipalities use to address cyber threats and how they function in practice under these conditions. It investigates vulnerability remediation, institutional support for incident prevention and response, and the use of commercial threat intelligence, and asks how these security measures can be improved in practice, addressing the central research question: How can municipalities improve security measures to address cyber threats? To answer this question, the dissertation presents three empirical studies that combine technical measurements with practitioner perspectives, adopting a socio-technical approach that connects technical observations to organizational and institutional contexts.
...

A Cross-Regional Empirical Analysis of Gender, Race, and Sexual Orientation Bias

Autocomplete feature may appear trivial, but on platforms like TikTok, where millions of users turn to search as a gateway to information, it plays a significant role in shaping what people ask and how they think. As the platform becomes increasingly central to digital culture and identity formation, the predictive suggestions it offers can reflect, reinforce, or challenge social biases. This thesis examines TikTok’s autocomplete system through the lens of toxic language, analysing over 225,000 suggestions generated from more than 3,000 identity-related prompts across ten countries. The aim is to understand whether the system amplifies toxic stereotypes around gender, race, and sexual orientation, and whether these patterns vary by geography or ranking.
To approach this, the study conceptualises algorithmic bias as a form of representational distortion, when identities are disproportionately linked to hostile, stereotypical, or derogatory language. Toxicity is used as a measurable proxy for this phenomenon, with scores derived from Google’s Perspective API and validated against a human-annotated subset. This framework allows the study to scale while maintaining conceptual clarity, offering a bridge between statistical insight and social meaning. The use of a cross-national dataset further adds depth, enabling the analysis to explore both universal and context-specific patterns of bias.
The findings show clear evidence that identity matters. Prompts referencing homosexual identities and Black identity terms consistently produced higher toxicity scores than their heterosexual and White counterparts. Gender-based disparities were also observed, though they were less pronounced. Interestingly, these patterns held steady across all ten countries studied. Despite cultural, regulatory, and linguistic differences, the toxicity distributions remained largely similar, suggesting that TikTok’s autocomplete system likely runs on a globally standardised model that does not meaningfully adapt to regional contexts. In contrast, the ranking of suggestions, where a toxic output appears within the top eight, had only a marginal impact on overall exposure. While some toxic completions did surface in mid-list positions, their distribution lacked a clear or consistent pattern.
Taken together, the research offers an empirical audit of TikTok’s search interface from a bias and fairness perspective. It shows that autocomplete, though often overlooked, can act as a subtle mechanism through which social hierarchies are reproduced. This insight carries implications for platform accountability and algorithmic design, especially in the context of ongoing policy efforts such as the EU AI Act, an emerging regulatory landscape that is likely to include systems like TikTok's autocomplete. By demonstrating that toxic associations are not isolated glitches but predictable patterns, the study highlights the limitations of moderation strategies that focus solely on removals or post hoc filtering. Ultimately, the thesis argues that mitigating algorithmic bias requires more than adjusting output rankings, it demands deeper attention to how predictive models are trained, evaluated, and governed. As TikTok continues to shape how a new generation accesses information, improving the social impact of features like autocomplete is not only a technical challenge but a public responsibility. ...
This dissertation investigates the measurement of profit-driven cybercrime, defined as crimes facilitated or committed using computers, networks, or hardware devices with financial motivations. While cybercrime has been extensively studied, its true scale remains difficult to determine due to underreporting and the challenges of distinguishing malicious from benign online activity. Existing research often remains divided between large-scale Internet measurements, which provide breadth but lack depth, and criminological studies, which offer detailed insights but rely on smaller datasets. This work argues that socio-technical measurements, combining both perspectives, can improve understanding and governance of cybercrime.

The research is structured around five studies. The first two chapters focus on cryptojacking, a cybercrime involving the unauthorized use of computing resources for cryptocurrency mining. The first study assesses the prevalence of cryptojacking on websites, identifying attack vectors, targeted website categories, and large-scale campaigns. The second extends this inquiry to compromised infrastructure, particularly MikroTik routers, revealing a broader and more organized set of cryptojacking operations. Using Internet traffic analysis and campaign mapping, this chapter uncovers the operational lifecycles of infected infrastructure and the varying sophistication of attackers.

The third study addresses phishing, particularly targeting Dutch citizens. By examining the development and trade of phishing kits, the research uncovers the full life cycle of phishing campaigns against the Dutch financial sector. Insights into attackers’ techniques, including their use of TLS certificates and phishing kit usage, inform policy recommendations for anti-phishing initiatives.

The fourth study examines the anti-abuse ecosystem, focusing on how intermediaries such as hosting providers handle abuse reports. Through access to the internal data of a Dutch hosting provider, the study shows that responses depend largely on the source and type of abuse notification. Governance instruments like blocklisting or law enforcement pressure prove more effective in eliciting responses than individual reports, highlighting gaps in current mitigation practices.

The fifth study reviews 38 academic works on phishing, booter services, and remote access trojans, structuring them through the concept of value chains. By comparing methods and data sources, and incorporating reflections from law enforcement professionals, the study identifies which scientific measurements are considered most valuable. This highlights the need for measurement approaches that align more closely with law enforcement priorities, especially regarding the development and monetization components of cybercrime.

The dissertation concludes by emphasizing that Internet measurements of cybercrime must reflect the intent and decision-making processes of criminals, as well as incorporate geographical demarcation to match the jurisdictional constraints of law enforcement agencies. Value chain analysis, lifecycle mapping, and campaign analysis emerge as tools for structuring meaningful measurements. Ultimately, the research demonstrates that bridging technical and criminological approaches produces insights that better serve governance needs and provide actionable intelligence for law enforcement. ...

Analysing the Market Signals for IoT Security and Privacy

The rapid rise in Internet-of-Things (IoT) devices, from smart thermostats and fitness trackers to connected cameras, while providing unprecedented convenience to consumers and profitable subscription based business models to manufacturers, has also raised critical security and privacy (S&P) concerns. From hacked video feeds and exploitation of sensitive data to revenue loss from service outages due to Distributed Denial of Service (DDoS) attacks, the consequences of poor S&P of IoT devices are experienced both at the individual level and at the collective societal level.

The underlying reasons for the S&P issues in IoT devices are not merely technical, there are socio-technical and economic dimensions associated with them. For instance, large scale DDoS attacks from insecure IoT devices are a classic example of negative externalities where the consequences of the attack are experienced by a party that is neither the manufacturer nor the consumer. In such a context, manufacturers often face a lack of incentives to improve on the underlying S&P issues since doing so would increase their development costs and delay their time to market. Although consumers as device owners may not be directly targeted by DDoS attacks, they do face indirect consequences from DDoS attacks on governments, banks and other websites. Moreover, they bear the brunt of individual losses to S&P, for example, when their IoT devices are hacked or their personal video feeds are exposed. Therefore, consumers have incentives to buy IoT devices with strong S&P features. Recent studies affirm this, and show that consumers not only care about IoT S&P, they are also willing to pay a premium for it – if they are informed about the S&P at the time of purchase.

However, the problem still remains that consumers do not have sufficient information – at the time of purchase – to discern IoT devices that have good S&P features from those that do not. While regulations like the Cyber Resilience Act (CRA) in the EU, and the US Cyber TrustMark aim to decrease this information asymmetry, they are not yet in effect. In the absence of official information about an IoT device’s S&P at the time of purchase, consumers might use other signals that directly or indirectly indicate the S&P posture of IoT devices like mention of security concerns in consumer reviews on e-commerce platforms. Since consumers currently depend on such indirect sources to assess S&P, insights into these signals can help design more effective interventions that fit into their current decision-making flow. However, there is currently no empirical analysis on these market signals which limits our understanding of how much the consumer base already recognises and signals a need for S&P.

This dissertation addresses this gap by analyzing S&P of consumer IoT devices through a market-based empirical lens that examines how economic incentives, S&P signals, and purchase decisions interact across different stakeholders in real-world e-commerce settings. Specifically, five mature and popular IoT device types are considered: IP cameras, smart printers, smart speakers, smart TVs and smart watches. By examining the interactions between manufacturers, consumers, sellers, and the e-commerce platforms that sell these devices, using actual market data (sales figures, prices, reviews, and product listings), this dissertation provides a unique vantage point on the market signals for IoT S&P and information asymmetry experienced by consumers. Overall, this dissertation aims to answer the following overarching research question through five research studies. What signals for security and privacy are present in the e-commerce platforms that sell IoT devices?
...

A Comprehensive Analysis of IoT Vulnerability Targeting and Attacker Decision-Making

The rapid growth of Internet-of-Things (IoT) devices, such as smart cameras, home routers, and smart thermostats, has transformed the digital landscape while also introducing new cybersecurity risks. IoT systems are often targeted by attackers due to outdated software, long device lifespans, and fragmented security practices. Although many IoT vulnerabilities are discovered and disclosed, only a small fraction are actually exploited in the wild. This raises important questions about which vulnerabilities are targeted, why attackers choose them, and how long they remain in use.

This dissertation investigates how IoT vulnerabilities are selected for exploitation in practice, with a particular focus on attacker behavior, exploit development, and vulnerability characteristics. It systematically examines the interplay between these factors to understand how they collectively shape exploitation trends in IoT ecosystems. To answer the central research question on What factors shape the exploitation in IoT vulnerabilities, from target selection to exploit development and prediction?, this dissertation presents four peer-reviewed studies.... ...

An Analysis of Untracked Software Vulnerabilities Disclosed in Public Issue Trackers

In the modern digital age, software vulnerabilities pose significant threats to security and privacy. These vulnerabilities are weaknesses in software products that can be exploited for malicious purposes. To manage and coordinate information about these vulnerabilities, the Common Vulnerabilities and Exposures (CVE) system is widely used. Although a lot of research has been done on coordinated CVEs, there is less focus on vulnerabilities that did not receive a CVE number. This research aims to estimate the number of vulnerabilities in open-source projects that do not receive CVE identification numbers and are consequently overlooked by the community. The focus of the research is on quantifying the prevalence of security issues in the issue tracker of GitHub projects, examining these security issues to find hidden CVEs and determining their severity based on the CVSS 3.1 scoring methodology. The methods used for the research are data extraction and analysis, transformer-based models for the classification of security issues, and expert validation for CVE identification and severity scoring. The findings of the research reveal crucial insights into the scale and nature of security threats in open-source software. The DeBERTaV3 model fine-tuned on the Chromium dataset demonstrated good performance metrics for the task of classifying security issues, achieving an f1 score of 0.9 with threshold modification. The case-study application of the model on the gRPC project demonstrated that in the issue tracker, 2.4\% of issues have been predicted as being security issues, out of which 52 were validated as CVEs with an average severity score CVSS 3.1 score of 5.3, compared to 11 CVEs attributed to the gRPC project on NVD. These findings suggest a need for revising current practices in vulnerability reporting and management in open-source projects, potentially influencing future security protocols and policies. The results of the study serve as information for the decision-making process of improving the coordinated vulnerability disclosure process in open-source software. An initial intervention suggestion is provided to induce behavior change and incentivize discoverers to disclose sensitive vulnerability information in private communication channels. Future work on understanding the motivations of discoverers to post such sensitive information in public trackers is required to create well-informed and effective policies for coordinated vulnerability disclosure. ...

A case study of how Amazon uses privacy protection to expand its power over IoT manufacturers

Privacy-enhancing technologies (PETs) have historically been used for safeguarding individual privacy from both public and private interference. But lately, tech companies have started using PETs as one instrument for the expansion of their power over different actors, as appears to be unfolding in the case of Amazon’s Sidewalk service: a United States-only privacy-preserving crowdsourced service that promises connectivity to Internet of Things (IoT) devices manufactured by third parties in smart-home, logistics, and utilities use-cases. Compatible IoT devices (‘endpoints’) are granted connectivity by ‘gateways’, namely smart-home devices from Amazon’s Echo (smart speakers) and Ring (smart cameras and doorbells) series that donate a portion of their bandwidth to endpoints that might be owned by others. Amazon pushed a software update to these Echo and Ring devices, that turned them from smart-home devices to contributors to the Sidewalk network, unless users actively opted out, yielding a coverage of at least 90% of the US population. With Sidewalk, Amazon leverages PETs (namely end-to-end encryption and device identifier obfuscation) to mitigate privacy concerns that the crowdsourced architecture yields. However, this necessitates significant investments from third-party manufacturers to make their devices Sidewalk-compatible, suggesting a power emergence shaped by PETs.

I answered the research question “How does Amazon’s use of privacy-enhancing technologies in Sidewalk affect its power over IoT manufacturers?” by reviewing grey literature, analysing the Sidewalk technology, and elite interviewing with high-ranking employees of Sidewalk-adopting manufacturers. I have shown that Amazon leveraged PETs to mitigate public security concerns, but in the meantime reshapes how manufacturers produce their devices. Part of this ploy is cementing AWS in their production processes. Amazon also uses this leverage to mobilise manufacturers’ and silicon providers’ resources to improve Sidewalk’s public reception, technology, and governance.

These reconfigurations are expensive and complicated to realise, but manufacturers stressed the importance of Sidewalk adoption to leverage Amazon’s reputation vis-à-vis suppliers and customers, and “befriend the giant” for they rely on Amazon’s Marketplace, cloud, and logistics.

Meanwhile, Amazon’s reductionist framing of privacy and security as protecting user identity and data confidentiality, means that confidentiality of manufacturers’ business-sensitive information is not discussed. With this vantage point, Amazon can learn which endpoint types are popular and how they work; but Sidewalk might also be a vehicle for Amazon to attract more IoT developers to AWS.

In sum, I have demonstrated that strictly pursuing user privacy (or confidentiality) in digital services may have unforeseen effects on production. Therefore, I call upon privacy and competition scholars, advocates, and regulators to question how privacy protection actually augments companies’ power, and stepping away from their narrow “consumer harm” lenses. These actors should debate a right to personal control over devices. A mere consumer focus in studying these developments is insufficient: I established that business-to-business relations and businesses’ production processes are more significantly affected than consumers. The production focus of this work lays bare the novel power dynamics between Amazon and manufacturers, shaped by PETs. ...

Predicting internal security incidents with external network data

Doctoral thesis (2024) - M. Vermeer, C. Hernandez Ganan, M.J.G. van Eeten
It goes without saying that the Internet is far from secure. As the number of Internet-connected devices increases, so do the number of cyberattacks we have to deal with. Numerous industry reports reveal significant upswings in software vulnerabilities year after year. These are issues plaguing enterprises of all sizes, within the public and private sector. In light of these findings, it becomes imperative for businesses, regardless of size, to prioritize cybersecurity and re-evaluate their current defense mechanisms against this evolving threat landscape. The evolving cyber threat landscape has emphasized the importance of adopting proactive approaches to manage and mitigate cybersecurity risks. Organizations can take a great many steps to achieve this, but mainly choose security measures that revolve around compliance requirements and standardized methodologies and frameworks to improve overall security posture. However, it remains unclear to which extent such investments have their desired effect. This is mainly because security is a latent property that cannot be measured directly. Alternative approaches have recently emerged that aim to measure security in a more direct manner. Instead of relying on self-reported data, internal or otherwise, firms gather externally accessible data and subsequently train a classifier using this data, enabling it to predict, with a certain level of accuracy, which organizations are likely to experience (large-scale) breaches. Still, it is not clear how metrics derived from purely external measurements compare to the security level derived from internal measurements of an organization's network. This reveals the necessity of taking into account the internal state of networks when observing external security signals, instead of exclusively relying on externally observable or publicly reported data breaches. This dissertation studies the feasibility of security incident prediction and risk estimation. It examines how external network scan data can be leveraged to infer information about the internal state of security of an organization's network. Thus, we aim to answer the following research question: How can internal security incidents be predicted through the leverage of external network signals? ...
This paper explores the potential of smart contracts in the reinsurance industry to address escalating non-productive costs driven by market dynamics. Reinsurers, aiming to enhance stability amid increasing inflation, claim severity, and frequency, have adopted stricter underwriting criteria and raised premiums. This has led to a more detailed drafting of reinsurance contracts, reminiscent of the formalization trend that began in the 1970s. However, this formalization has inadvertently inflated administrative and dispute resolution costs, counter to the industry's core objective of efficient risk and capital allocation.

The study delves into how smart contracts can offer a solution. Smart contracts are computerized protocols that can automate contract clauses, potentially aligning better with industry goals. The examination focuses on their impact on transaction costs, involving expenses incurred by insurers and reinsurers to execute transactions.

Findings reveal that smart contracts can effectively reduce administrative costs by automating tasks, particularly in high-volume and standardized scenarios. However, their effect on dispute resolution costs is more nuanced, as the reinsurance sector still benefits from human interpretation.

In conclusion, while smart contracts hold promise for reducing transaction costs in reinsurance, the industry's unique complexities and high financial stakes may pose challenges and necessitate post-implementation adjustments. The paper recommends exploring smart contract applications in industries with smaller disputed amounts and lower trust levels than reinsurance. ...
The EU Artificial Intelligence Act (AI Act) proposed by the European Commission is a significant legislative effort to regulate AI systems. It is the first legal framework that specifically addresses the risks associated with AI systems, aiming to ensure their trustworthiness and alignment with the values enshrined in the Charter of the Fundamental Rights of the EU and the Union values. Thus, the draft of the AI Act emphasizes the importance of fundamental rights in Europe's AI approach.

The AI Act covers various AI applications, including machine learning, logical, statistical, and knowledge-based approaches. It provides a classification framework based on the purpose and risks posed by AI applications: Prohibited/Unacceptable risk, High-Risk, Limited-Risk, and Minimal/No risk. However, there are concerns about the clarity of the classification criteria mentioned in the AI Act. Some AI systems may fall into multiple classifications, leading to ambiguity. For example, a social robot used in patient treatment could be classified as High-Risk or Limited-Risk. This ambiguity is also observed in classifying AI systems in enterprise functions, where 40{\%} of the classifications remain unclear.

Therefore, these challenges provide an opportunity to improve the classification process of AI systems under the AI Act, facilitating the classification process and accommodating emerging AI technologies. The main research question addressed in this thesis is: \textbf{"To what extent can the process of AI systems classification under the AI Act be improved?"}

The research focuses specifically on AI systems classification. It explores specific provisions of the AI Act, including Prohibited Risk, Classification Rules for High-Risk AI systems, Transparency Obligations, and Annexes II and III.

To achieve the objective of improving the classification accuracy of AI systems based on the AI Act, the study adopts the Design Science Methodology. This methodology involves systematically studying existing AI systems classifications and challenges, extracting themes to develop a framework, and evaluating the framework through feedback from AI experts.

A decision tree is designed as the proposed framework. It is evaluated on 16 respondents from two different backgrounds: legal and non-legal. In order to obtain comprehensive insights, the evaluation is designed to incorporate an experiment where respondents are tasked to classify AI systems to the risk level with the AI Act only. Then in the second experiment, they have to classify AI systems using the proposed decision tree framework. It is important to note that the study acknowledges the possibility of overestimating or underestimating respondents' ability to classify AI systems due to their diverse backgrounds and levels of understanding of the AI Act. Furthermore, a semi-structured interview is conducted to strengthen the analysis.

Based on the evaluation, the decision tree's performance revealed higher accuracy than the classification approach without the decision tree. However, the overall accuracy remained low, indicating room for improvement. Challenges identified include the need for additional context and understanding of terms, definitions, and examples in the decision tree and the potential for misclassification due to vague definitions and assumptions. Respondents also expressed the need for more detailed information about AI system use cases to improve classification accuracy.

The decision tree's performance varied between obvious and non-obvious use cases, with non-obvious cases presenting challenges in accurate classification. The accuracy for obvious cases was higher, highlighting the difficulty of distinguishing between High-Risk and Unacceptable Risk categories. Lack of clarity in terms and definitions and limited contextual information contributed to the challenges faced in classifying non-obvious cases.

Legal experts demonstrated higher accuracy than non-legal respondents, indicating familiarity with legal terminology and the AI Act. However, legal and non-legal respondents encountered difficulties classifying non-obvious cases, emphasizing the need for clearer frameworks and tools to enhance clarity and streamline the classification process. Greater clarity in the AI Act and an interdisciplinary approach were recommended to address these challenges and facilitate understanding of the risks associated with AI systems.

Based on the analysis, several areas for improving AI systems classification under the AI Act have been identified. The current classification process faces challenges related to ambiguities in definitions, lack of contextual information, and difficulties in distinguishing between different risk levels.

To address these challenges and enhance the classification process, it is recommended to introduce clearer guidelines and refine the decision tree used for classification. The decision tree should incorporate additional criteria and features that provide more clarity and context. It is important to consider biases, subjective interpretations, clarity, and the dynamic nature of AI technologies in these improvements.

The study has certain limitations. The small sample size of respondents may impact the generalizability of the findings. The number of participants might not be representative of the entire population. Additionally, the limited number of use cases utilized in the research may limit the comprehensiveness of the classification framework. The study is based on the latest amendment of a policy proposal, and there is a potential for changes in the regulation's details, which may affect the effectiveness of the results. Finally, potential biases may exist in the development of the research, such as in making the decision tree and selecting the use cases.

Future research should explore the continuity of the decision tree's performance over time and its evaluation. There should be more research on non-obvious cases in specific domains or industries. It is crucial to focus on potential issues in classifying certain risk levels in the AI Act that hinder classification accuracy. Understanding the differences between legal and non-legal perspectives on the AI Act is also important to establish standardized understanding among stakeholders. Additionally, conducting quantitative research with larger and more diverse respondents from industrial backgrounds can further evaluate the proposed framework. ...
Master thesis (2023) - R. Bahl, S.E. Parkin, J. Lieu, M.J.G. van Eeten
Addressing the growing problem of phishing attacks requires nurturing a reporting culture within organizations. This research examines the factors influencing reporting behavior and the role of infrastructure & support in enhancing reporting rates. By adopting a mixed methods approach and analyzing phishing simulation logs and user perspectives, the study utilizes the COMB model to identify key factors that affect reporting behavior. The research emphasizes the importance of reassessing the desired level of reporting to ensure the benefits of reporting do not overshadow the associated costs. To foster a reporting culture, organizations should ensure a user-friendly reporting process and offer regular reminders and training programs. Emphasizing communication, transparency, and trust-building are vital in encouraging reporting and providing timely feedback. Leveraging technology to optimize the reporting process and appreciating users' efforts further enhance reporting rates. Overall, embracing a paradigm shift that recognizes users as part of the solution is crucial in nurturing a reporting culture and ensuring a secure digital environment. ...

Obtaining novel insights into how a current misalignment of (dis)incentives among business stakeholders in the software supply chain can explain the limited adoption of SBOM

Master thesis (2023) - B.J.P. Kloeg, M.J.G. van Eeten, Y. Zhauniarovich, Aaron Ding, Sjoerd Pellegrom
In today's business landscape, software has become an integral part of operations for all companies, with a growing reliance on third-party components. This increasing complexity in software supply chains has led to a significant reduction in transparency and visibility, posing challenges for effective management and security. Software Bill of Materials (SBOMs) emerges as a promising concept to address this issue by providing detailed information about software components and their supply chain relationships, ultimately enhancing transparency within these supply chains. However, despite its potential benefits, SBOM adoption remains limited in practice.

This research examines the perspectives of four key business stakeholders involved in the software supply chain to understand their incentives and disincentives surrounding SBOM adoption. Through a series of in-depth interviews with representatives from each stakeholder group, we aimed to identify stakeholder-specific risks, benefits, concerns, and incentives related to SBOM adoption. The analysis reveals that SBOM adoption potential is notably higher among system integrators and software vendors. These stakeholders perceive the benefits of enhanced transparency and supply chain risk mitigation, which align with their strategic objectives. On the contrary, B2B customers and Individual Developers exhibit the least motivation for SBOM adoption. Their limited interest stems from a perception that SBOMs may impose additional complexities without commensurate benefits. Given that B2B customers and individual developers are the primary consumers and suppliers of SBOMs, respectively, the findings suggest that the overall adoption potential of this technology remains restricted.
...
This study investigates organizations’ approaches to managing cybersecurity challenges that are associated with high levels of teleworking. Over the last two and a half years the pandemic forced organizations to implement teleworking models that resulted in a large share of the workforce working from home. The increasing use of teleworking resulted in organizations being worried about their ability to handle cyberthreats, while at the same time they sidestepped on their cybersecurity to implement a proper teleworking model. There is a large body of literature showing what the security risks and practices are related to these high levels of teleworking, while it is not clear what the related security challenges are and how organizations are approaching these. So, there is a gap in the literature regarding the understanding of the current cybersecurity challenges and approaches that are associated with these high levels of teleworking. Semi-structured interviews were conducted with both cybersecurity consultants and individuals that fulfill a role in an organization that makes them responsible for the cybersecurity management of the organization. Thematic analysis was used that led to the identification of four main security challenges and four approaches used to manage these challenges. The following four challenges were identified: ‘Security vs. privacy’ which shows how it is challenging for organizations to secure the private environments of their organizations without invading their privacy. Secondly, the ‘Control & awareness which addresses the balance between control and awareness. More restrictions can lead to less security if there is a lack of awareness and knowledge among employees. Thirdly, the ’Lack of resources’ challenge, not all organizations have the monetary resources to achieve the desired level of security. Finally, the ’Priorities’ challenge shows how according to the consultants, cybersecurity is still seen as a burden and is being neglected by organizations, regardless of the increase in cybersecurity attention and the increased risks related to high levels of teleworking.
The identified approaches start with ‘Technology & Processes’ as this is most often the first choice for organizations. Using device management systems with corporate devices or BYOD devices with an enclave to ensure security without invading privacy. Education of the workforce is deemed one of the most successful approaches, since the security of the organizations is now more dependent on the workforce, raising awareness through education is of great importance. An approach that at first glance seems more counter-intuitive is the establishment of a security culture that takes years to achieve. Cybersecurity is involved into the daily tasks of the complete workforce. Without forcing and too many controls, but nudging employees by discussion and giving them responsibilities. The last approach shows that despite the priority challenge that is only mentioned by consultants, organizations want to become more mature, and organizations are currently giving cybersecurity a higher priority.

...

An exploratory study on centralized mixing services

Master thesis (2022) - R.F.M. Veelers, R.S. van Wegberg, P.H. Hartel, M.J.G. van Eeten, K J M Lubbertsen
Mixing services try to distort cash flow tracking of cryptocurrencies and obfuscate the origin of customers’ earnings by substituting customers’ cryptocurrency funds with the funds of other customers or the mixers’ private assets. This quality makes mixing services interesting for money laundering, and they are therefore often used by criminals. As such, there is an urgent need to systematically understand how to restore the relationship between deposits and payouts of centralized mixing services. Unfortunately, there is minimal knowledge of how mixing processes of centralized mixing services work, and few attempts exist to create these demixing methods. This research aimed to develop a demixing method for centralized mixers with knowledge gained from ground-truth data. The ground-truth data contains information on orders and the transaction history of mixing service BestMixer. Demixing consists of collecting all addresses that are part of the mixer (attribution) and finding the correct payout to a deposit (reconstruction). Multiple statistical analysis techniques were applied to this data to verify existing attribution heuristics and find new characteristics of mixing services. Also, filtering techniques to reconstruct the relation between deposits and payouts were tested on the order data. This research verifies that BestMixer likely did not reuse addresses in the mixing process. It also showed that the lifespan of most addresses was shorter than 24 hours. In addition, many BestMixer addresses received or sent a transaction to another BestMixer address, which created sequences of BestMixer transactions. The sequences show that the mixer used a peeling chain pattern in combination with multi-input transactions. These characteristics can be used to attribute other centralized mixing services. The results also show that the mixer increased in popularity throughout time.
Overall, the reconstruction attempt with filtering techniques did not perform well on BestMixer orders, as it returned an impracticable amount of possible payout combinations. The mixer showed less activity in the beginning days of the service, and there are signs that the reconstruction works better in this earlier stage of the mixer. This means that when a mixer becomes more popular, it could become more difficult to demix the orders correctly.
From this research can be concluded that the ground-truth data of BestMixer does help in developing attribution heuristics for centralized mixers, but not in developing a general reconstruction method that correctly restores the relation between deposits and payouts, thus not suffice in demixing centralized mixers. ...

A mixed methodology on the interaction of security and privacy related reviews and the customer purchase decision for IoT devices

Due to the increasing use of Internet-of-Things (IoT) devices people have created an entirely new digital world for themselves. However, the security and privacy risk in this world are emerging. People using smart devices for everything in their lives are not realising that every interaction is collected and stored in databases. This study has researched whether people take responsible action when it comes to purchasing an IoT device via displaying security and privacy related reviews.
The research was executed via a mixed methodology, with the quantative method being a discrete choice experimentation in the form of a survey and a website design. The study has found that out of a hundred respondents forty-four people chose a device with positive S\&P related reviews. Furthermore, more than half of the respondents chose the design as the main reason for choosing it. However, the qualitative data has shown that the reviews were often used as a last measure factor to pick between their 'favorite' devices. At that moment most of the respondent picked a device that had positive S\&P related reviews.
This research has contributed to science by showing how S\&P reviews interact with the customer purchase decision. Furthermore, it elaborates on the S\&P awareness process prior to the purchase instead of after. Thereby, it also presents the framing effect in the IoT field, showing that people are sensitive towards positive S\&P related reviews and therefore becoming more risk-averse. In addition, the study gave more insight in the IoT Trust/Value Paradox and the Privacy Paradox in relation the the IoT purchase decision. At last, it has shown the customer-to-customer effect to have an impact on the purchase decision even though is it not always the main reason of purchasing a certain IoT device. ...

Measuring the adoption of Source Address Validation (SAV) by network providers

Doctoral thesis (2022) - Q.B. Lone, M.J.G. van Eeten, C. Hernandez Ganan
IP spoofing is the act of forging source IP addresses assigned to a host machine. Spoofing provides users the ability to hide their identity and impersonate another machine. Malicious users use spoofing to invoke a variety of attacks. Examples are Distributed Denial of Service (DDoS) attacks, policy evasion and a range of application-level attacks. Despite source IP address spoofing being a known vulnerability for at least 25 years, and despite many efforts to shed light on the problem, spoofing remains a popular attack method for redirection, amplification and anonymity. Defeating these attacks requires operators to ensure that their networks filter packets with spoofed source IP addresses. This is a Best Current Practice (BCP), known as Source Address Validation (SAV). Yet, widespread SAV adoption is hindered by a misalignment of incentives: networks that adopt SAV incur the cost of deployment, while the security benefits diffuse to all other networks. The challenges posed by SAV adoption exemplify the failure of traditional governance models to provide solutions in the Internet ecosystem. Policy interventions usually require transparency in measurements to quantify and assess the vulnerability landscape. However, measuring SAV requires a vantage point inside the network or in the upstream provider of the network. Once a packet with a spoofed source address leaves the upstream network provider, it is almost impossible to ascertain its origin... ...

Understanding real-world evidence of QSnatch clean-up results and user experiences after warnings from the ISP

As the IoT is widely deployed in people’s homes, adversaries are busy exploiting the vulnerabilities of these devices. One kind of such device is the NAS device made by the company QNAP. Unfortunately, these devices are prone to the QSnatch malware. Unlike previous malware such as Mirai has this nasty habit, it settles deeper into the machine. In this way, the malware gains reboot persistence. Therefore, we consider the malware as persistent IoT malware compared to the non-persistent IoT malware. This affects the clean-up of the virus, as changing the passwords and rebooting the device is not enough to remove the virus. As a result, other steps are needed to get rid of the virus. If we take a look at the NAS device market, we see that the manufacturers of these devices have little incentive to invest a lot in the security of the devices. It is then challenging for the customer to estimate which devices are secure and are mainly tempted by discounts and devices that can be configured quickly. Then, the ISP is the link in the process that, with the help of the non-profit organisation Shadow Server, can determine which of its customers may be infected with certain malware. Shadow Server uses servers to receive the malicious traffic and forwards the corresponding IP addresses to the ISP. The ISP then knows which customer is dealing with possible infection and can inform them. This also happens for the QSnatch malware. The ISP sends the infected customer a notification informing them about the infection and providing steps to clean their device. These steps are a simplified and Dutch-translated version of the steps provided by QNAP. From that moment on, it is up to the infected customer to take action. Previous research has made a tremendous effort in understanding the efforts of infected customers in remediating the issue and showed that various resources could be used by the ISP to improve the results of this process. ...

Implications of the 5th Anti-Money Laundering Directive on virtual currency exchanges in the Netherlands

Master thesis (2021) - C.J. Volten, R.S. van Wegberg, A.M.G. Zuiderwijk-van Eijk, M.J.G. van Eeten
In order to combat financially-economically related crime the government implemented a new directive ensuring that virtual currency exchanges now have to adhere to requirements from legislation countering money laundering. This thesis researches what the extent is of effects that this legislation posed to the daily operations of virtual currency exchanges. ...

A mixed methodology approach to understanding cybercrime

To protect critical services in today's society it is necessary to mitigate and prevent risks threatening the reliability of the internet. Internet-of-Things (IoT) devices are the number one attack target on the internet. The situation will become worse as there will be an expected 40 billion IoT devices in 2025. IoT bot activity represented 78% malware network activity or detection events in carrier networks in 2018. The vulnerability and large volume of IoT devices make them a likely target for cybercriminals in distributed denial-of-service (DDoS) attacks. The rise of IoT is increasing the volume of DDoS attacks. A lot of (critical) infrastructure are therefore susceptible being shut down by DDoS attacks. DDoS attacks are commoditized with booter services, which perform attacks on targets in return for money. This allows a wider audience to utilize DDoS attacks as the only necessary prerequisite is money. These services have increased attack frequencies and attack power of the attacks. The DDoS-as-a-Service landscape has mainly used amplification attacks to take down their victims, however, it is yet unclear if they are also utilizing the growth of IoT for their purposes. This research will look at the impact of IoT-based DDoS attacks on the victims, with the main research question being: What patterns of commoditization and victimization can we observe with IoT­-based DDoS attacks compared to amplification attacks? Conclusively, vulnerable IoT devices are already a serious threat. They are commoditized and they bring significant differences to DDoS attack characteristics and victimization patterns. As DDoS remains an arms race where adaptation is important, this research showcases a concrete example of how emerging technology can change the existing marketplaces and attack patterns. It also showed its value by looking at IoT from a holistic view to gain understanding of the technical as well as the social impacts. However, more research is needed in this field as the quickly changing field needs to be monitored. Questions still remain which factors can explain the country-level effects in more detail. Expansion of the tools and capabilities to investigate underground chat data would be fruitful as well. ...