Next Generation Society. Technological and Legal Issues. Third International Conference, e-Democracy 2009, Athens, Greece, September 23-25, 2009, Revised Selected Papers

Research Article

Evaluating Common Privacy Vulnerabilities in Internet Service Providers

Download
438 downloads
  • @INPROCEEDINGS{10.1007/978-3-642-11631-5_15,
        author={Panayiotis Kotzanikolaou and Sotirios Maniatis and Eugenia Nikolouzou and Vassilios Stathopoulos},
        title={Evaluating Common Privacy Vulnerabilities in Internet Service Providers},
        proceedings={Next Generation Society. Technological and Legal Issues. Third International Conference, e-Democracy 2009, Athens, Greece, September 23-25, 2009, Revised Selected Papers},
        proceedings_a={E-DEMOCRACY},
        year={2012},
        month={5},
        keywords={Internet Service Provider Privacy Vulnerabilities Security Measures},
        doi={10.1007/978-3-642-11631-5_15}
    }
    
  • Panayiotis Kotzanikolaou
    Sotirios Maniatis
    Eugenia Nikolouzou
    Vassilios Stathopoulos
    Year: 2012
    Evaluating Common Privacy Vulnerabilities in Internet Service Providers
    E-DEMOCRACY
    Springer
    DOI: 10.1007/978-3-642-11631-5_15
Panayiotis Kotzanikolaou1,*, Sotirios Maniatis1,*, Eugenia Nikolouzou1,*, Vassilios Stathopoulos1,*
  • 1: Hellenic Authority for Communications Privacy (ADAE)
*Contact email: p.kotzanikolaou@adae.gr, s.maniatis@adae.gr, e.nikolouzou@adae.gr, v.stathopoulos@adae.gr

Abstract

Privacy in electronic communications receives increased attention in both research and industry forums, stemming from both the users’ needs and from legal and regulatory requirements in national or international context. Privacy in internet-based communications heavily relies on the level of security of the Internet Service Providers (ISPs), as well as on the security awareness of the end users. This paper discusses the role of the ISP in the privacy of the communications. Based on real security audits performed in national-wide ISPs, we illustrate privacy-specific threats and vulnerabilities that many providers fail to address when implementing their security policies. We subsequently provide and discuss specific security measures that the ISPs can implement, in order to fine-tune their security policies in the context of privacy protection.