Sampsa Rauti

dblp:119/8628 · DBLP profile ↗
← Back
32ranked-venue papers
8as first author
17since 2021 · last 2026
0000-0002-1891-2353ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Applied, interdisciplinary, general and emerging computing · 13 · 2 first-author · 7 since 2021Security and privacy · 7 · 2 first-author · 4 since 2021Human-computer interaction and ubiquitous computing · 5 · 3 since 2021Artificial intelligence and machine learning · 4 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 3Graphics, computer vision, multimedia, augmented reality and games · 2 · 2 since 2021
YearPublicationVenuePosition
2026 Challenges in Automatic Analysis of Privacy Policy Documents with LLMs
Riia Laakso, Shashika Harshani, Sini Salmi, Sammani Rajapaksha, Sampsa Rauti
WorldCIST (2)5
2025 Assessing Privacy Practices on Ontario Municipal Websites
abstract
The sharing of personal data on government websites is a major concern of daily users. The existing regulations do not allow for the collection and sharing of personal data. This study investigates the privacy practices of 444 municipal websites across Ontario, Canada, focusing on compliance with relevant data protection regulations and the extent of third-party data sharing. In particular, we examine the issues in line with Canadian standards, the Personal Information Protection and Electronic Documents Act (PIPEDA), the Canadian Privacy Act (CPA), and the Municipal Freedom of Information and Protection of Privacy Act (MFIPPA). We perform network traffic analysis, and apply a combination of privacy policies. Our findings uncover substantial gaps in privacy practices, including insufficient transparency, inadequate user-consent mechanisms, and pervasive third-party data sharing. The results of our study highlight an urgent need for the enhancement of privacy measures on government municipal websites to protect the personal data of users and for the implementation of practices that comply with local and international privacy laws, such as PIPEDA, CPA, MFIPPA, and the General Data Protection Regulation (GDPR). The study provides actionable recommendations aimed at strengthening data protection and restoring public trust in digital municipal services.
Adegboola David Adelabu, Sampsa Rauti, Ville Leppänen, Zuhaibuddin Bhutto
PST4
2025 Securing QR Codes for Data Transfer Between Applications
Onnimanni Hannonen, Sampsa Rauti
WorldCIST (1)2
2025 Third-Party Data Leaks on the Web: Notes on Personally Identifiable Information
Panu Puhtila, Sampsa Rauti
WorldCIST (1)2
2025 Third-Party Data Leaks and Privacy Compliance on Finnish Government Websites
Sammani Rajapaksha, Timi Heino, Sampsa Rauti, Panu Puhtila, Ville Leppänen
WorldCIST (1)3
2024 Sacred Spaces in the Digital Age: Perceptions of Lutheran Christian Priests on Augmented Reality at Holy Sites
abstract
The concepts of sacred places and spaces appear throughout religions globally. Places such as churches, cathedrals, temples, mosques, synagogues and graveyards are given special meanings, both functionally and spiritually, and separated from the ordinary. Recently location-based augmented reality (AR) technologies and applications have become widespread, and this raises questions regarding how AR content relates to sacred places. In this study, we approached this complex topic by asking clergy of the Lutheran Christian Church (N=47) to reflect on associated phenomena. We approached the data via reflexive thematic analysis and uncovered tensions related to (1) connected vs detached from sacredness; (2) supporting the spiritual purpose of the space vs conflicting with it; and (3) maintaining tradition vs embracing innovation. Overall, our findings suggest that AR technologies and products impact sacred spaces on multiple levels, but currently there is no consensus among the clergy on the impact of these changes.
Samuli Laato, Sampsa Rauti, Anni Maria Laato, Samaan Al-Msallam, Sangwon Jung, Erkki Sutinen, Juho Hamari
IMX2
2024 Third-Party Data Leaks in the Websites of Finnish Social and Healthcare Districts
Panu Puhtila, Esko Vuorinen, Sampsa Rauti
WorldCIST (1)3
2024 Gamification of walking in nature: A field experiment with Pokémon GO Routes
abstract
There are numerous benefits from regularly walking in nature, and today's mobile technologies have the potential to encourage people to do so. Past research has showed that gamified map-based apps and location-based games (LBGs) have the capability to incentivize people to go to nature areas in cities and beyond. In this study, we explored LBGs' potential to bring people to nature by conducting a field experiment with a new mechanic called Routes in the popular LBG Pokémon GO. Prior to the Route feature's launch, we created altogether 13 Routes of various lengths in both city and nature landscapes. We collected numerical in-game data of how many times each Route was walked and deployed a survey (n=67) for Pokémon GO players in the area where the Routes were made. The findings suggest that proximity to population concentrations and in-game rewards are key drivers of Route popularity. Players' motivators to choose nature Routes over urban Routes were limited to outside-the-game factors such as scenery, and overall in our experiment the urban Routes turned out to be more popular.
Samuli Laato, Sampsa Rauti, Bastian Kordyaka, Konstantinos Papangelis, Sangwon Jung, Timo Nummenmaa, Juho Hamari
Proc. ACM Hum. Comput. Interact.2
2023 Resemblance of religion and pervasive games: A study among church employees and gamers
abstract
Previous research suggests that the experience and practices related to gaming and extended realities, and religion and spiritualism, share similarities. In this study, we explore how both the employees of the Evangelical Lutheran Church (n=156) and pervasive game players (n=98) perceive and make sense of these connections. We approach the qualitative data from the perspective of Durkheim, who, similarly to how game theorists view games, views religion as a multi-faceted system that incorporates the rules, practices and communities that comprise the religion. From the data emerges the following prominent connection as perceived by both groups of informants: systems of (1) shared premise, (2) resilience and restoration, (3) symbolism, (4) extended reality and (5) day-to-day structuring. A numerical view of the data shows that 42,5% of the participants did not perceive similarities, and examination of these responses suggested that while religion and pervasive games share functional similarities, they are further apart from a substantive perspective.
Samuli Laato, Sampsa Rauti, Juho Hamari
CHI2
2023 Composing Music Through Tile-based Games
abstract
In the realm of music we have multiple examples of successful rock stars, composers and producers who describe themselves as self-taught. This suggests there might be a demand in formal music education for learning technologies that support students’ self-propelled discovery. In this theoretical work, we explore the design space of educational music composing games that would allow students to explore and learn music theory concepts at their leisure. We designed four unique tile-based music creation games based on popular contemporary video game genres, and evaluated them from the perspectives of learning and musical expression. This study opens up new avenues in music composing game design, and offers examples of some ways in which games can be harnessed as vehicles to learn music theory and composition.
Samuli Laato, Sampsa Rauti, Alexander Espeseth, Heinrich Söbke, Juho Hamari, Oguz Turan Buruk
ISM2
2023 Privacy Risks of Third-Party Services on Women's Shelter Websites
abstract
Women's shelters usually operate with a commitment to confidentiality to protect the privacy and safety of the help-seeking individuals. In today's digital age, this principle also extends to their websites, highlighting the importance of online visitors' privacy. This study discusses the potential negative outcomes of using third-party analytics services on websites of the women's shelters, conducted by analyzing the contents of web requests made to third parties and how they jeopardize the user privacy. The results show that 95.5% of the studied websites leak visitors' personal data, such as IP addresses, and device identifiers. Along with these identifying details, the current website URL is also leaked, potentially revealing the user's intent to seek help. Consequently, detailed profiles of violence victims could be created by third parties. The study also offers recommendations to protect the confidential personal data of vulnerable individuals seeking support.
Panu Puhtila, Robin Carlsson, Sampsa Rauti
SIN3
2023 Data Leaks to Third-Party Services on Medical Websites
abstract
Several web-based healthcare services such as medi-cal center websites, online pharmacies and mental health websites process sensitive medical data that should not end up in the wrong hands. Today's trend of incorporating several third-party services on websites poses a threat to online privacy, and this is also a considerable risk when it comes to medical websites. In this study, we conduct a network traffic analysis on 20 Finnish healthcare websites to investigate the types of personal data that these websites inadvertently share with third parties and to identify these third-party entities. Our results indicate that even without consent, 12 of these websites leak sensitive data to third parties. We also discuss the implications of health data leaks and offer recommendations for web developers to prevent such privacy issues in the future.
Sampsa Rauti, Esko Vuorinen, Robin Carlsson, Panu Puhtila
SIN1
2022 Assessing discrepancies between network traffic and privacy policies of public sector web services
abstract
Online services are increasingly being used to complete everyday tasks, and ordinary users with very little technical knowledge have learned to use web services and applications. At the same time, many user applications are gradually moving from the traditional desktop environment to the web. Because of these developments, it is not surprising that user privacy has become a very important consideration when developing web services. In the current study, we assess the privacy of 34 web services provided and maintained by Finnish public sector bodies. We perform a network traffic analysis in order to find out what kind of personal data the studied services deliver to third party analytics services. We then take a look at the privacy policy documents of these web services and gauge their transparency and clarity by comparing their contents to the actual network data sent out by the web services. Our findings reveal numerous inconsistencies between what is said about handling personal data in the analyzed privacy policies and the actual traffic of the studied web services. Another prominent finding is the sheer amount of analytics services employed by the studied websites. We conclude that there is still an obvious need for web developers and public sector bodies to improve their awareness of existing privacy regulations and personal information their online services deliver to third parties. A lot of work also remains to be done in clearly and transparently communicating privacy-related matters to users.
Timi Heino, Robin Carlsson, Sampsa Rauti, Ville Leppänen
ARES3
2022 Study of Third-Party Analytics Services on University Websites
Timi Heino, Sampsa Rauti, Robin Carlsson, Ville Leppänen
HIS2
2022 A Study on Written Communication About Client-Side Web Security
Sampsa Rauti, Samuli Laato, Ali Farooq 0001
HIS1
2022 Where Does Your Data Go? Comparing Network Traffic and Privacy Policies of Public Sector Mobile Applications
Robin Carlsson, Timi Heino, Lauri Koivunen, Sampsa Rauti, Ville Leppänen
WorldCIST (1)4
2021 Filters that Fight Back Revisited: Conceptualization and Future Agenda
Sampsa Rauti, Samuli Laato
WorldCIST (1)1
2020 The Role of Music in 21st Century Education-Comparing Programming and Music Composing
abstract
21st century skills are being added onto K-12 educational curricula globally, often via integrating them into existing subjects such as math. Simultaneously music teaching in K-12 education is losing relevance and popularity. Yet, music theory contains logical structures which are in many regards similar to program code. Additionally the digitization of music production requires composers to effectively use digital music production tools and associated technology. We investigate the opportunities technology-assisted music composing offers for teaching 21st skills and programming in K-12 education through expert interviews with professional music composers (n=4) and programmers (n=5). Analysis of the similarities and differences in the thought processes between creating software and composing music revealed the latter to have potential for teaching the following thinking skills present in K-12 educational curricula: modularity, loops and conditionals, data structures, input/output and software design. Additionally implicit learning benefits on increasing technical know-how, cooperative skills and design thinking were discovered.
Samuli Laato, Sampsa Rauti, Erkki Sutinen
ICALT2
2020 Building a Virtualized Environment for Programming Courses
Tuisku Polvinen, Timo Ylikännö, Ari Mäkeläinen, Sampsa Rauti, Jari-Matti Mäkelä, Jani Tammi
WorldCIST (2)4
2020 Location-Based Games as Interfaces for Collecting User Data
Sampsa Rauti, Samuli Laato
WorldCIST (2)1
2019 A Review of Location-based Games: Do They All Support Exercise, Social Interaction and Cartographical Training?
abstract
Studies on location-based games ubiquitously report positive learning outcomes for the players. Particularly these games are shown to promote exercise, encourage to social interaction and increase geographical and cartographical knowledge. To find out whether these positive effects are game-specific or characteristic to all location-based games, we conduct a software search for available location-based games on iOS and Android platforms and evaluate if and how exercise, cartographical training and social interaction are supported. Based on our results we were able to identify six sub-genres of location-based games, and the positive effects associated with each genre. The most popular category in terms of number of games was scavenger hunts and the most popular category in terms of active installs on Android and iOS was location-based MMORPG’s. Presence of factors associated with immersion and mixed reality were paired with the popularity and positive outcomes of the games. Cartographi cal practise, social interaction and exercise were supported the most in the location-based MMORPG sub-genre, to which, for example, Pokémon GO belongs to
Samuli Laato, Tarja Pietarinen, Sampsa Rauti, Mauri Paloheimo, Nobufumi Inaba, Erkki Sutinen
CSEDU (1)3
2019 A Survey on Countermeasures Against Man-in-the-Browser Attacks
Sampsa Rauti
HIS1
2019 Towards Cyber Attribution by Deception
Sampsa Rauti
HIS1
2018 Towards Profiling Program Instances in Host-Based Intrusion Detection Systems by Recognizing Software Update Patterns
abstract
Host intrusion detection systems are used to analyze internal events on host machines and detect behavioral patterns that differ from normal operation of the system and its processes. One important aspect in observing the behavior of processes are the application updates that may change the behavior of an application but also potentially help to build a profile for the application when observing its update patterns. In this study, we observe update frequencies and patterns of a set of applications on 100 machines during an analysis period of 100 days. Our preliminary results indicate that it is possible to detect clear software update patterns that can be used for profiling processes.
Lauri Koivunen, Sampsa Rauti, Ville Leppänen
SIN2
2018 Recognizing Dynamic Fields in Network Traffic with a Manually Assisted Solution
Jarko Papalitsas, Jani Tammi, Sampsa Rauti, Ville Leppänen
WorldCIST (2)3
2018 Diversification and obfuscation techniques for software security: A systematic literature review
abstract
Context: Diversification and obfuscation are promising techniques for securing software and protecting computers from harmful malware. The goal of these techniques is not removing the security holes, but making it difficult for the attacker to exploit security vulnerabilities and perform successful attacks. Objective: There is an increasing body of research on the use of diversification and obfuscation techniques for improving software security; however, the overall view is scattered and the terminology is unstructured. Therefore, a coherent review gives a clear statement of state-of-the-art, normalizes the ongoing discussion and provides baselines for future research. Method: In this paper, systematic literature review is used as the method of the study to select the studies that discuss diversification/obfuscation techniques for improving software security. We present the process of data collection, analysis of data, and report the results. Results: As the result of the systematic search, we collected 357 articles relevant to the topic of our interest, published between the years 1993 and 2017. We studied the collected articles, analyzed the extracted data from them, presented classification of the data, and enlightened the research gaps. Conclusion: The two techniques have been extensively used for various security purposes and impeding various types of security attacks. There exist many different techniques to obfuscate/diversify programs, each of which targets different parts of the programs and is applied at different phases of software development life-cycle. Moreover, we pinpoint the research gaps in this field, for instance that there are still various execution environments that could benefit from these two techniques, including cloud computing, Internet of Things (IoT), and trusted computing. We also present some potential ideas on applying the techniques on the discussed environments.
Shohreh Hosseinzadeh, Sampsa Rauti, Samuel Laurén, Jari-Matti Mäkelä, Johannes Holvitie, Sami Hyrynsalmi, Ville Leppänen
Inf. Softw. Technol.2
2018 A case study on software vulnerability coordination
Jukka Ruohonen, Sampsa Rauti, Sami Hyrynsalmi, Ville Leppänen
Inf. Softw. Technol.2
2017 Mining social networks of open source CVE coordination
abstract
Coordination is one central tenet of software engineering practices and processes. In terms of software vulnerabilities, coordination is particularly evident in the processes used for obtaining Common Vulnerabilities and Exposures (CVEs) identifiers for discovered and disclosed vulnerabilities. As the central CVE tracking infrastructure maintained by the non-profit MITRE Corporation has recently been criticized for time delays in CVE assignment, almost an ideal case is available for studying software and security engineering coordination practices with practical relevance. Given this pragmatic motivation, this paper examines open source CVE coordination that occurs on the public oss-security mailing list. By combining social network analysis with a data-driven, exploratory research approach, the paper asks six data mining questions with practical relevance. By contemplating about answers to the questions asked by means of descriptive statistics, the paper consequently contributes not only to the contemporary industry debates, but also to the tradition of empirical vulnerability research. The perspective and the case are both novel in this tradition, thus opening new avenues for further empirical inquiries and practical improvements for the contemporary CVE coordination.
Jukka Ruohonen, Sami Hyrynsalmi, Sampsa Rauti, Ville Leppänen
IWSM-Mensura3
2017 A Survey on Fake Entities as a Method to Detect and Monitor Malicious Activity
abstract
This paper surveys research concentrating on fake entities as a method to detect and monitor malware. A fake entity is a digital entity (such as a file) no one except a malicious attacker should access. When the entity is accessed, the defender immediately knows there is unwanted activity in the system and can start to monitor it. We discuss both faking different entities on one machine and in a network using virtual groups of fake hosts.
Sampsa Rauti, Ville Leppänen
PDP1
2017 Internal interface diversification with multiple fake interfaces
abstract
Malware uses knowledge of well-known interfaces to achieve its goals. However, if we uniquely diversify these interfaces in each system, the malware no longer knows the "language" of a specific system and it becomes much more difficult for malicious programs to operate. This paper extends the idea of interface diversification by presenting a scheme where a fake original interface and multiple other fake interfaces are provided along with the valid interface in order to log the suspicious activity in the system and possibly deceive malware by initiating fallacious interaction with it. We also present a proof-of-concept implementation of this scheme in Linux environment and conduct experiments with it.
Sampsa Rauti, Ville Leppänen
SIN1
2017 Practical challenges in building fake services with the record and play approach
abstract
One way to learn more about how a malicious program functions and what its objectives are is to deceive it with fake services that provide responses containing fabricated data. This goal can be achieved with so called record and play -honeypot that learns what the normal communication between clients and a server looks like and then tries to mimic it, but fabricates the contents of the responses so that they contain fake data. This paper outlines and presents the challenges faced in practical development of such honeypot. Some solutions and recommendations that mitigate the identified problems are also considered.
Jani Tammi, Sampsa Rauti, Ville Leppänen
SIN2
2017 A Survey on Anti-honeypot and Anti-introspection Methods
Joni Uitto, Sampsa Rauti, Samuel Laurén, Ville Leppänen
WorldCIST (2)2