Understanding the social side of cyber-security issues

When Engin Kirda started focusing on cyber-security research 10 years ago, those primarily responsible for launching Internet attacks were teenagers out for kicks, he said. But the scope of threats existing through the Web has dramatically changed since then.
Now security breaches are often financially motivated and highly organized 鈥 which presents intriguing challenges for the new associate professor with joint appointments in Northeastern鈥檚 College of Computer and Information Science and Department of Electrical and Computer Engineering.
鈥淲e鈥檝e seen a shift from attacks for fun to attacks for profit,鈥 said Kirda, who joined the faculty in January. 鈥淭hat鈥檚 why it鈥檚 fascinating for me to see how these bad guys are operating, and to try to come up with solutions to combat them.鈥
Kirda studies Internet security issues and how to discover vulnerabilities in websites and Internet applications to create more secure applications. He is also working on creating better virus-detection techniques. He previously taught at research institutions in Vienna and Sophia Antipolis, France, and he is the cofounder and codirector of the International Secure Systems Lab 鈥 a collaborative effort of European and U.S. researchers focused on analyzing and designing tools for computer security.
Kirda plans to take a closer look at why some users鈥 computers get infected with malware, a software designed to harm or secretly access a computer system, and how well those people are able to identify cyber attacks. As part of this project, users would be given online tests to determine the scope of their understanding of cyber threats.
鈥淥ne thing I have learned over the years is that security problems are not only technical problems. There is a very social aspect to all these issues,鈥 he says. 鈥淔or example, someone can come up with technical solutions, but they might still fail because we don鈥檛 exactly understand how well users are actually able to accept these technical solutions.鈥
Kirda was drawn to Northeastern in part because of the new Information Assurance doctoral program, and he hopes to explore interdisciplinary collaborations here to develop more robust systems and better solutions.
He says one small virus released in a network or system, for a bank or nuclear reactor, can cause major damage. Given the number of people and companies depending on Internet reliability and security on a daily basis, he is excited to work in an ever-evolving field of significant societal importance.
鈥淭he problems are very real,鈥 Kirda says, 鈥渟o there is an opportunity to make quite a large impact.鈥
Provided by Northeastern University