Critical.
Authoritative.
Strategic.
Subscribe to CIO Magazine »

European information security agency warns about data-profiling risks to minors

ENISA makes recommendations to mitigate online threats that can affect the lives of children

The European Network and Information Security Agency (ENISA) has issued recommendations to law enforcement agencies, European Union member states, civil society groups, as well as parents and educators on how to mitigate risks faced by children online.

The agency has identified cyberbullying and online grooming, which refers to gaining the confidence of minors with the intent of sexual abuse, as some of the top online risks to underage children and warned that data mining and profiling can facilitate these forms of abuse.

To provide context for its recommendations ENISA created a fictitious scenario centered around a 13-year-old girl named Kristie who has a very active social presence online and maintains a secondary profile where she presents herself as an adult by lying about her age and occupation.

This is increasingly common behavior for tech-savvy children. According to a recent study performed in the U.S., a large number of parents actually help their children evade age restriction controls on social media websites because they believe that such online services can further their educations, enable family communication and enhance their social interactions.

In ENISA's scenario, an attacker uses data mining and profiling techniques to build an online identity for himself that matches Kristie's interests so he can earn her trust. The young girl ends up starting an online relationship with a boy who she believes to be 16, but is actually a 35-year-old sexual predator.

Unfortunately, there are many cases where data profiling is used by online attackers for the selection of victims. Back in September, 32-year-old Luis Mijangos of Santa Ana, California, was sentenced to six years in prison for charges related to sextortion -- extortion involving sexually explicit photos and videos.

According to the U.S. Federal Bureau of Investigation, which investigated the case for two years, Mijangos had over 200 female victims, many of them underage girls, which he targeted through social networking websites. He impersonated their friends and family members to trick them into installing malware on their computers. This allowed him to intercept their private communications and hijack their webcams.

A 23-year-old man from Citrus Heights, California, named George Samuel Bronk pleaded guilty in January to hacking into the email accounts of dozens of women by using information they posted online. He searched the compromised accounts for intimate photos and used them to harass his victims.

ENISA said that its report is intended to complement existent national and international child protection initiatives with non-technical recommendations. The agency's suggestions range from E.U. member states strengthening law enforcement agencies and statistical data collection efforts regarding cases of information misuse, to launching more frequent online campaigns regarding the prevention of cyberabuse, and trying to close the knowledge gap between adults and teenagers when it comes to computer use and online issues.

ENISA recommended that teenagers use specialized security settings online and that applications that handle teenager data be assessed for their impact on privacy. It also wants mechanisms that allow the deactivation of online components to be made available in mobile apps and current age-oriented access controls to be enhanced.

Join the CIO Australia group on LinkedIn. The group is open to CIOs, IT Directors, COOs, CTOs and senior IT managers.

More about: etwork, Facebook, Federal Bureau of Investigation
References show all

Comments

Post new comment

The content of this field is kept private and will not be shown publicly.
Users posting comments agree to the CIO comments policy.
Login or register to link comments to your user profile, or you may also post a comment without being logged in.
Related Coverage
Related Whitepapers
Latest Stories
Community Comments
Tags: European Network and Information Security Agency, online safety, security
Latest Blog Posts
Whitepapers
  • IDC Insight: V-Ray Gives Symantec NetBackup a Competitive Advantage Today and into the Future
    Over a decade ago, Veritas software announced NetBackup FlashBackup to address the millions of small files problem, which had been and often remains the nemesis to fast and efficient backup of large file servers. Today, the FlashBackup technology is used to provide a logical understanding of what is stored with a VMDK- or VHD-image-level backup, without the necessity to install an agent inside each virtual machine. Read more.
    Learn more »
  • Oracle Exadata Database Machine Warehouse Architectural Comparisons
    Exadata is Oracle’s fastest growing new product. Much of the growth of Exadata has come at the expense of specialized data warehouse appliance vendors. These vendors have published competitive comparisons to Exadata, claiming: Architecture is what really matters for performance, Purpose-built data warehousing architectures perform best, They see architecture as an end in itself rather than as a means to an end. Read on.
    Learn more »
  • IDC Forecast: Worldwide Purpose - Built Backup Appliance 2011 – 2015, Forecast Update: Explosive Growth in 2011
    This IDC Forecast Update provides share positions for revenue and raw capacity for nine named PBBA vendors for the first half of 2011. In addition, this study provides the market size and a five-year forecast for the worldwide PBBA market as part of IDC's Storage Solutions coverage. The five-year forecast includes total factory revenue and raw capacity in terabytes through 2012. The worldwide PBBA market covers both open system-and mainframe-attached products.
    Learn more »
All whitepapers
rhs_login_lockGet exclusive access to Invitation only events CIO, reports & analysis.