events contact us
Search the complete PARC site
 

Security & Privacy
Developing technologies that intelligently support usable security and privacy for ubiquitous computing environments

The proliferation of networked devices has long posed a security challenge in protecting sensitive content, along with a usability challenge for people trying to access it.

Similarly, as people increase their virtual presence – personally and professionally – users are unaware of the many real threats to privacy.

PARC Approach

PARC’s pioneering work in ubiquitous computing highlighted the need for a world-class research capability in security. With expertise in applied cryptography, human factors, and network security, PARC researchers are developing new technologies that intelligently support usable security and privacy for ubiquitous computing environments.

While our security researchers' work is often a key component of client-sponsored engagements, the team has also developed turnkey security and privacy solutions.

Focus Areas

  • Usable Security — enabling easy management of large networks of devices, as well as usable access control for distributed content
     
  • Fraud and Crimeware Defense — using a socio-technical approach to anticipate trends and develop robust protection mechanisms
     
  • Data Privacy — using semi-automated methods for protecting content, based on deep content analysis and inference control

Team & Activities

Contributors

Recent Selected Publications

Breaking out of the Browser to Defend Against Phishing Attacks, CEAS 2008

Love and Authentication, ACM CHI 2008

Delegating Capabilities in Predicate Encryption Systems, ICALP 2008

Why and How to Perform Fraud Experiments, IEEE Security & Privacy March/April 2008

Machine Learning Attacks Against the Asirra CAPTCHA, ACM CCS 2008

Detecting Privacy Leaks Using Corpus-based Association Rules, KDD 2008

Ad hoc guesting: when exceptions are the rule, Usability, Psychology and Security (UPSEC) 2008

Making CAPTCHAs Clickable, HotMobile 2008

A content-driven access control system, IDTrust '08

Private Social Network Analysis: How to Assemble Pieces of a Graph Privately, Workshop on Privacy in the Electronic Society
[2007 Runner-Up Award for Outstanding Research in Privacy Enhancing Technologies, PET Workshop]

Vault: Practical Uses of Virtual Machines for Protection of Sensitive User Data, Proceedings of The 3rd Information Security Practice and Experience Conference

Web-based inference detection, USENIX Security 2007

Cryptanalysis of a cognitive authentication scheme, IEEE Security and Privacy 2007

Conferences

Journals

 

 

BUSINESS CONTACT
Mark Grandcolas
Director of Business Development, Computing Science Laboratory
650-812-4429
LEARN MORE/ DOWNLOADS

one-page brochure with research team information [low-res .pdf]

video: "Love and Authentication: Addressing the problem of password reset" (August 2008)

RELATED WEBPAGES

Usable Security

Network-in-a-Box Solution

Privacy Appliance Solution

NEWS

Palin case exposes uneasy truth: E-mail accounts easy to break into, Mercury News

'Forgot Your Password?' May Be Weakest Link, MSNBC

What is worse than reusing passwords?, ITWorld [post by PARC Scientist Markus Jakobbson]

Countermeasures against targeted attacks in the enterprise, SearchSecurity.com [feature by PARC Scientist Markus Jakobbson]

...Technology That Blocks Access to Sensitive Data in Documents to Prevent Security Leaks [includes animated demo]

Xerox developing new document encryption technology, SearchSecurity.com

...'Intelligent Redaction', eWeek

The New Security Solutions, Information Week

Smart Pages: Xerox Technology Protects Sensitive Information, MIT Technology Review

Security Counterattack, NetworkWorld

PARC Wants to Make Networks Smarter, Easier, Computerworld

Instant Networks, CIO Magazine

   

  (Logo/Homepage) PARC - Palo Alto Research Center

Copyright © 2002-2007 Palo Alto Research Center Incorporated. All Rights Reserved.
PARC, the PARC Logo, AspectJ, DataGlyph, Obje, Silx, StressedMetal, and ClawConnect
are trademarks or registered trademarks of Palo Alto Research Center Incorporated.