The IT Security Research Group at the Department of Information Systems takes an interdisciplinary approach on a range of research questions in information security and privacy. We focus our efforts on the following topics:

Economics of Information Security and Privacy

Security breaches are in the news almost daily, each bigger and more costly than the last. But rarely are they caused by technical failures. Bad security often is a result of wrong decisions on the deployment of security technology. The economic perspective on information security starts with looking at these decisions and analyzes underlying processes and incentive systems. Technology merely defines the action space. Yet with insights into economic and behavioral mechanisms, technology can be designed and deployed in such a way that bad security decisions become less likely.

Relevant research questions include: How can security be measured? How much shall individuals, firms, and governments spend on (cyber-)security? How exactly shall they invest? What incentives really drive privacy decisions? What distinguishes cyber-risks from conventional risks and what consequences emerge for cyber-risk management? How does all this affect the IT security industry?

Our methods in this field range from economic modeling of isolated aspects, via quantitative empirical studies, to broader strategy/policy analyses targeted to corporate decision makers and governments.

Multimedia Security

Multimedia security aims to enforce protection goals (in particular confidentiality and integrity) for or with the help of digital signals, which represent parts of reality.

Our particular interest is in steganography and steganalysis as well as digital image forensics. Steganography means "covert writing". It is a hiding technique which can be used to embed secret messages into inconspicuous cover media. Steganalysis is the counter-technology to steganography. Its goal is to detect steganographic communication. Digital image forensics, a young and rapidly growing research field, encompasses the development of methods to test the authenticity of digital images.

Privacy-Enhancing Technologies (PET)

Over the past decades, advances in information technology have tremendously facilitated collection, storage, retrieval, and processing of large amounts of data. This enables ever more individuals and institutions to monitor other people without consent by observing the data traces they leave in computer systems. Privacy-enhancing technologies serve as building blocks for systems that reduce such privacy problems without constraining the desired functionality unnecessarily. PETs thus contribute to finding a balance between privacy protection and information sharing in the information society.