Refine
Document Type
- Article (4)
- Conference Paper (3)
Is part of the Bibliography
- no (7)
Keywords
- Computer security (1)
- Computers (1)
- Conferences (1)
- HbbTV (1)
- IT security (1)
- Printing (1)
- Privacy (1)
- Publishing (1)
- Ranking (statistics) (1)
- Reviews (1)
Institute
Four decades of security and privacy research: evolution of topics, impact, and the community
(2026)
As digital technologies become increasingly embedded in societal infrastructure, IT security and privacy (S&P) have become critical for protecting sensitive information and preserving trust. These domains have evolved from foundational security measures to address complex challenges introduced by artificial intelligence, regulatory frameworks, and decentralized technologies. This paper presents a longitudinal analysis of the evolution of IT S&P research from 1980 to 2023, analyzing over 13k papers from the most relevant venues. Employing the frameworks of established theories from social sciences, i.e. Latour’s actor–network theory, and Bourdieu’s forms of capital, along with Leydesdorff’s key dimensions in scientometrics, we discuss the evolution of research topics and highlight research priorities in the past and today. We apply modern natural language processing techniques to build a taxonomy of research topics within the S&P community. Using this taxonomy, we analyze the community’s thematic development, tracing its growth from 5 topics in the 1980s to 100 distinct research topics, reflecting the field’s expanding scope and complexity. Analyzing 0.5M authors, we demonstrate strong collaboration networks in the IT S&P community. We also demonstrate that the proportion of female authors in this community has remained relatively constant over the decades, despite an increase in their research activity in recent years. Finally, we assess factors impacting paper citations, author networks, and the linguistic evolution of the community. This study enhances the understanding of the S&P research community, providing valuable insights into future directions. The data underlying this article, including the analysis code and data processing pipeline, are available in the repository at: https://pulse-of-cybersecurity.com/, which also provides an interactive webpage for exploring our results.
Hybrid broadcast broadband television (HbbTV) is an evolving technology that connects linear TV with modern HTML5 applications, delivering extras like games, videos, and online shopping. However, its bidirectional transmission functionality raises privacy concerns, as it introduces new tracking methods for TV channels. While previous studies focused on security issues or user awareness of HbbTV privacy challenges, a detailed examination of the tracking and transparency mechanisms of the HbbTV ecosystem is still missing. This study fills this gap by extensively analyzing these features within the European HbbTV ecosystem, and in particular within German-language TV channels. We monitored more than 350 TV channels for over 400 hours, evaluating 1) prevalent HbbTV tracking methods, 2) consent notice prevalence and user interactions, and 3) privacy policy disclosures. Our findings indicate that the HbbTV tracking system operates independently of the Web, consent notices exploit system constraints to influence users, and privacy policies often do not align with actual data practices.
Metascience examines the practices, evaluation mechanisms, and incentive structures that shape the production and validation of scientific knowledge. While metascientific research is increasingly institutionalized across disciplines, including parts of computer science, its presence in the Security and Privacy (S&P) community remains limited, particularly in flagship venues. This paper analyzes the current state of metascience in S&P and identifies structural factors, notably evaluation criteria that equate novelty with technical innovation, that constrain its integration into the field’s core publication ecosystem. We (i) review existing S&P metascientific work and map its publication landscape, (ii) report on our experience submitting metascience studies to major S&P conferences, and (iii) examine the methodological and institutional barriers that arise when a predominantly technical research culture engages in self-reflective research using social-science methods. We argue that prevailing evaluative norms create a structural mismatch with metascientific contributions and propose pathways for integrating metascience into the S&P community.
Filter lists are used by various users, tools, and researchers to identify tracking technologies on the Web. These lists are created and maintained by dedicated communities. Aside from popular blocking lists (e.g., EasyList), the communities create region-specific blocklists that account for trackers and ads that are only common in these regions. The lists aim to keep the size of a general blocklist minimal while protecting users against region-specific trackers. In this paper, we perform a large-scale Web measurement study to understand how different region-specific filter lists (e.g., a blocklist specifically designed for French users) protect users when visiting websites. We define three privacy scenarios to understand when and how users benefit from these regional lists and what effect they have in practice. The results show that although the lists differ significantly, the number of rules they contain is unrelated to the number of blocked requests. We find that the lists’ overall efficacy varies notably. Filter lists also do not meet the expectation that they increase user protection in the regions for which they were designed. Finally, we show that the majority of the rules on the lists were not used in our experiment and that only a fraction of the rules would provide comparable protection for users.
Das Internet hat sich als globale Kommunikations-, Informations-, Commerce- und Businessinfrastruktur fest in der Gesellschaft etabliert. Mit jedem Grad Zuwachs bei der Digitalisierung wird das Leben einfacher und schneller - aber auch gefährlicher. Die konkrete Gefährlichkeit bleibt dabei bislang oft ein Mysterium - Strategien für die IT-Sicherheit müssen auf Basis von Annahmen und Erfahrungen entwickelt werden. Internet-Kennzahlen und deren systematische Auswertung sollen nun dabei helfen, Probleme, Risiken und Schwachstellen als Trend zu erkennen, um Sicherheitsstrategien proaktiv fokussierter zu gestalten. Auch der Stand der IT-Sicherheit lässt sich durch Messung der Kennzahlen ermitteln und bewerten. Internet-Kennzahlen werden von lokalen und globalen Anbietern bereitgestellt.
Sicheres und vertauenswürdiges Arbeiten im Homeoffice : aktuelle Situation der Cybersicherheitslage
(2021)
Durch die fortschreitende Digitalisierung bekommt die IT einen immer größeren Stellenwert in allen Bereichen. Dadurch steigt die Abhängigkeit von der IT und damit auch das Schadenspotenzial durch Cyberangriffe. Besonders durch die Zunahme des Arbeitsform Homeoffice sowie de Ad-hoc-Verlagerung von Beschäftigten und Geschäftsprozessen in das Homeoffice entstehen durch bisher unzureichende infrastrukturelle Sicherheitsvorkehrungen höhere Risiken. Anbieter von Video-Konferenz- und anderen Kollaborationstools haben durch den enormen Digitalisierungsschub nicht genug Zeit gehabt, ihre Systeme angemessen zu schützen. Dazu kommt, dass die Nutzung von unsicheren oder nicht ausreichend datenschutzkonformen Lösungen, wie Messenger oder sozialen Netzwerken, weitere Risiken für Unternehmen darstellen können. Welche technischen, personellen und organisatorischen Maßnahmen sind also erforderlich, um in der angespannten Lage ein sicheres Homeoffice einzurichten?
Mit den Reisebeschränkungen in der Corona-Krise ist der Bedarf an einfach zu handhabenden Videokonferenzsystemen sprunghaft gestiegen. Krisengewinner war dabei ohne Zweifel der amerikanische Hersteller Zoom Video Communications.
Mit seinem „Zoom Meeting“-Dienst preschte das junge Unternehmen an bisherigen Branchenlieblingen vorbei. Derzeit gilt Zoom als populärstes Konferenzsystem auf dem Markt. Mitten im Aufstieg ist Zoom jedoch auch heftig in Kritik geraten: Schlechte Umsetzung des Datenschutzes, hohe Angreifbarkeit durch klaffende Schwachstellen und unzureichende Verschlüsselung lauteten die Vorwürfe. Der Hersteller zeigte sich bei der Behebung der Schwachstellen kooperativ. Doch ist jetzt alles sicher und vertrauenswürdig?

