Have a personal or library account? Click to login
End User Licence to Open Government Data? A Simulated Penetration Attack on Two Social Survey Datasets Cover

End User Licence to Open Government Data? A Simulated Penetration Attack on Two Social Survey Datasets

Open Access
|May 2016

Abstract

In the UK, the transparency agenda is forcing data stewardship organisations to review their dissemination policies and to consider whether to release data that is currently only available to a restricted community of researchers under licence as open data. Here we describe the results of a study providing evidence about the risks of such an approach via a simulated attack on two social survey datasets. This is also the first systematic attempt to simulate a jigsaw identification attack (one using a mashup of multiple data sources) on an anonymised dataset. The information that we draw on is collected from multiple online data sources and purchasable commercial data. The results indicate that such an attack against anonymised end user licence (EUL) datasets, if converted into open datasets, is possible and therefore we would recommend that penetration tests should be factored into any decision to make datasets (that are about people) open.

Language: English
Page range: 329 - 348
Submitted on: Dec 1, 2014
|
Accepted on: Nov 1, 2015
|
Published on: May 28, 2016
Published by: Sciendo
In partnership with: Paradigm Publishing Services
Publication frequency: 4 issues per year

© 2016 Mark Elliot, Elaine Mackey, Susan O’Shea, Caroline Tudor, Keith Spicer, published by Sciendo
This work is licensed under the Creative Commons Attribution-NonCommercial-NoDerivatives 3.0 License.