Data Protection

The Data Protection group studies foundational and practical challenges in protecting individuals' privacy and data.

Studying foundational and practical challenges in protecting individuals' privacy and data

Privacy and security of electronic data (e.g., electronic health records, financial data, demographic data) has become a hugely important issue. Access control is often employed as the first line of defense for data protection. Existing access control models and mechanisms, however, are often not suited for the challenges introduced by modern IT systems. Moreover, access control can be circumvented, for instance, by insiders exploiting policy misconfiguration or by attackers gaining unauthorized access through social engineering attacks against legitimate users. The Data Protection group aims to realize novel theories, methods, and technology that enable the realization of an adaptive authorization infrastructure capable of responding to security threats. To achieve this goal, we focus on three orthogonal and complementary research lines: Access Control, Data analytics for security, and Social Engineering.