- Research Article
- 10.47620/tgee1982
A Growing Security Threat: Iranian Intelligence Operations in Scandinavia (Part Two: Sweden)
- Sep 02, 2025
- Middle East Quarterly
- Ardavan M Khoshnood + 2 more +2
Publications from 2021 to 2026
Showing 10 of 67 papers
A Growing Security Threat: Iranian Intelligence Operations in Scandinavia (Part Two: Sweden)
Revisiting the Folklore Algorithm for Random Access to Grammar-Compressed Strings
“I Have No Idea What a Social Bot Is”: On Users’ Perceptions of Social Bots and Ability to Detect Them
Social bots—software agents controlling accounts on online social networks (OSNs)—have been employed for various malicious purposes, including spreading disinformation and scams. Understanding user perceptions of bots and ability to distinguish them from other accounts can inform mitigations. To this end, we conducted an online study with 297 users of seven OSNs to explore their mental models of bots and evaluate their ability to classify bots and non-bots correctly. We found that while some participants were aware of bots’ primary characteristics, others provided abstract descriptions or confused bots with other phenomena. Participants also struggled to classify accounts correctly (e.g., misclassifying > 50% of accounts) and were more likely to misclassify bots than non-bots. Furthermore, we observed that perceptions of bots had a significant effect on participants’ classification accuracy. For example, participants with abstract perceptions of bots were more likely to misclassify. Informed by our findings, we discuss directions for developing user-centered interventions against bots.
Read moreResilience risk controls and the Netflix Unified Resilience Framework
This paper argues that programmes built around existing enterprise resilience/business continuity management (ER/BCM) metrics provide a low return on investment, which ultimately can damage the perceived value of the industry. It goes on to introduce a new approach to creating and measuring ER/BCM programmes that provides a much greater level of return for a smaller investment. Finally, it describes how this new approach can be used to satisfy traditional programme requirements, and provides a shared framework for emerging uses, such as cyber resilience.
Read moreWho Knows I Like Jelly Beans? An Investigation Into Search Privacy
Abstract Internal site search is an integral part of how users navigate modern sites, from restaurant reservations to house hunting to searching for medical solutions. Search terms on these sites may contain sensitive information such as location, medical information, or sexual preferences; when further coupled with a user’s IP address or a browser’s user agent string, this information can become very specific, and in some cases possibly identifying. In this paper, we measure the various ways by which search terms are sent to third parties when a user submits a search query. We developed a methodology for identifying and interacting with search components, which we implemented on top of an instrumented headless browser. We used this crawler to visit the Tranco top one million websites and analyzed search term leakage across three vectors: URL query parameters, payloads, and the Referer HTTP header. Our crawler found that 512,701 of the top 1 million sites had internal site search. We found that 81.3% of websites containing internal site search sent (or leaked from a user’s perspective) our search terms to third parties in some form. We then compared our results to the expected results based on a natural language analysis of the privacy policies of those leaking websites (where available) and found that about 87% of those privacy policies do not mention search terms explicitly. However, about 75% of these privacy policies seem to mention the sharing of some information with third-parties in a generic manner. We then present a few countermeasures, including a browser extension to warn users about imminent search term leakage to third parties. We conclude this paper by making recommendations on clarifying the privacy implications of internal site search to end users.
Read moreTowards Stalkerware Detection with Precise Warnings
International audience
Understanding Worldwide Private Information Collection on Android
Mobile phones enable the collection of a wealth of private information, from unique identifiers (e.g., email addresses), to a user's location, to their text messages.This information can be harvested by apps and sent to third parties, which can use it for a variety of purposes.In this paper we perform the largest study of private information collection (PIC) on Android to date.Leveraging an anonymized dataset collected from the customers of a popular mobile security product, we analyze the flows of sensitive information generated by 2.1M unique apps installed by 17.3M users over a period of 21 months between 2018 and 2019.We find that 87.2% of all devices send private information to at least five different domains, and that actors active in different regions (e.g., Asia compared to Europe) are interested in collecting different types of information.The United States (62% of the total) and China (7% of total flows) are the countries that collect most private information.Our findings raise issues regarding data regulation, and would encourage policymakers to further regulate how private information is used by and shared among the companies and how accountability can be truly guaranteed.
Read moreChapter 40 - Medical device cybersecurity—At the convergence of CE and IT
Business continuity management as an operational risk service provider: An approach to organisational resilience
In today’s 24/7 business world, any disruption of operations is often disastrous — from both a reputational as well as a financial perspective. This paper discusses why this reality has diminished the perceived value of traditional ‘recovery capability’ business continuity management programmes among many organisations and executives. The paper proposes three steps to resiliency to show how resiliency programmes can reposition themselves to reverse this perception and provide increased value to the organisations they protect. The paper describes innovative, concrete steps to develop a programme that spans from a simple compliance, or recovery, programme, to becoming a resiliency risk service provider that can become the backbone of an organisation’s ability to maintain 24/7 availability.
Read moreDesign Modifications to an Existing High-Density Mid-Board Optical Engine For Liquid Immersion Cooling
Modern optical transceivers are not hermetically sealed due to cost, with the assumption that the optical train is surrounded by air to ensure optimum optical coupling. Without sealing, submersion in liquid cooling systems will severely compromise the coupling efficiency resulting in high losses with a corresponding degradation in link performance. As a result, changes to these optical transceivers maintain overall system performance. We describe the processing changes to an existing mid-board optical engine that can then be submerged in a cooling liquid. In addition, we compare the thermal and high-speed performance of the resulting engine in both air and a commercially available high-performance single-phase cooling liquid.
Read more