Daniel W. Woods

dblp:228/4088 · DBLP profile ↗
← Back
13ranked-venue papers
4as first author
11since 2021 · last 2025
0000-0002-8569-1917ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 11 · 4 first-author · 10 since 2021Computer networks · 1Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
YearPublicationVenuePosition
2025 SoK: Measuring Blockchain Decentralization
Christina Ovezik, Dimitris Karakostas, Mary Milad, Daniel W. Woods, Aggelos Kiayias
ACNS (1)4
2025 "Why Would Money Protect me from Cyber Bullying?": A Mixed-Methods Study of Personal Cyber Insurance
abstract
Individuals can become victims of security incidents, privacy violations, online scams, and social media abuse. In addition to prevention, users should create response strategies in case misfortune strikes. To better understand response to digital harm, we conducted the first study of personal cyber insurance in the US and the UK. We explored the supply-side via a content analysis of 24 cyber insurance policies. The results show personal cyber insurance compensates security, privacy and fraud incidents, with a slim majority also covering cyberbullying. Comparing these results to prior work, we find that coverage in the US and UK has significant differences to coverage in Germany. We study the demand-side via a survey distributed to 584 participants with an even US/UK split. Just 1.6% of respondents have cyber coverage and 8.5% are aware of the product. We introduce the concepts of risk uncertainty and coverage uncertainty, finding both are prevalent for personal cyber insurance. Studying coverage uncertainty, we discover a gap between insurers and participants, which is broadest for online fraud and narrowest for identity theft and cyber-bullying. Turning to risk uncertainty, we discovered that in the aggregate users are relatively well calibrated regarding the frequency of different incidents. Individuals estimate that fraud incidents have the greatest impact, followed by security and privacy incidents. Cyberbullying has very low estimated impact. Regarding purchasing a policy, participants raised uncertainties about contractual details, reporting requirements, victimization statistics, and access to security solutions.
Rachiyta Jain, Temima Hrle, Margherita Marinetti, Adam D. G. Jenkins, Rainer Böhme, Daniel W. Woods
SP6
2025 Study Club, Labor Union or Start-Up? Characterizing Teams and Collaboration in the Bug Bounty Ecosystem
abstract
A unique bug bounty ecosystem has evolved in China. Platforms allow groups of hackers to register together to receive team-level awards. However, little is known about the prevalence and productivity of these teams, or how team members collaborate. To address this gap, we conducted a mixed-methods study. The first stage characterized teams from a top-down ecosystem perspective. We collected bug bounty rankings from 85 platforms, using fuzzy-matching to identify 2.1k unique teams and 5.9k hunters. We show that 46% of users are registered as part of a team, and hunters with teams are more than twice as productive as hunters without teams. The typical team has less than 10 members and only operates on a handful of platforms, but we also identified mega teams participating in more than 50 platforms with hundreds of team members. The second phase provided bottom-up insights into why hackers join teams and how they collaborate within teams. Our semi-structured interviews (n = 18) reveal bug hunting teams are multi-faceted–part study club, part labor union, and part start-up. Teams act like study clubs in enabling knowledge exchange and skills development, and act like labor unions in negotiating with bug bounty platforms and vendors. Hunter teams also displayed company-like aspects when earning and sharing revenue, and also creating rules that members should follow. In doing so, hunter teams help to address three of the main challenges that bug hunters face, namely skills development, negotiating with large technology companies, and income uncertainty.
Yangheran Piao, Temima Hrle, Daniel W. Woods
SP3
2024 Formalizing Attack Trees To Support Economic Analysis
abstract
Abstract Attack trees and attack graphs are both examples of what one might term attack modelling techniques. The primary purpose of such techniques is to help establish and enumerate the ways in which a system could be compromised; as such, they play a key role in the (security) risk analysis process. Given their role and the consequent need to ensure that they are correct, there are good reasons for capturing such artefacts in a formal manner. We describe such a formal approach, which has been motivated by a desire to model attacks from the perspectives of attackers, to support economic analysis. As an illustration, we consider exploitation cost.
Andrew C. Simpson, Matthias Dellago, Daniel W. Woods
Comput. J.3
2024 Economics of incident response panels in cyber insurance
abstract
Cyber insurance is becoming a popular cyber risk management tool. Beyond pure financial risk transfer, prior theoretical works anticipated that cyber insurance would influence the mitigation measures employed by policyholders, such as by excluding losses caused by security mismanagement or by offering premium discounts for security controls. Empirical literature has shown cyber insurance is ineffective at influencing pre-breach security levels; however, it has also identified how insurers indemnify the cost of a team of post-breach providers with expertise spanning legal, technical, and communications. Our work models the peculiarities of the institution, the panel, that triages incidents and assigns firms. In particular, we model the incomplete aspect of this contract in which policyholders may be assigned a less efficient firm, which can be interpreted as a bait and switch. At the same time, our context for the bait and switch is business-to-business (B2B) and differs from the usual understanding of the phenomenon as an upsell. Consequently, new managerial implications arise on the insurer-side of the market. We characterise the conditions under which policyholders accept their insurer's hotline recommendation for incident response under the incomplete contract. We additionally show how panels can mitigate the adverse selection problem with respect to policyholders' losses by including providers of differentiated efficiency.
Daniel G. Arce, Daniel W. Woods, Rainer Böhme
Comput. Secur.2
2023 DarkDialogs: Automated detection of 10 dark patterns on cookie dialogs
abstract
In theory, consent dialogs allow users to express privacy preferences regarding how a website and its partners process the user’s personal data. In reality, dialogs often employ subtle design techniques known as dark patterns that nudge users towards accepting more data processing than the user would otherwise accept. Dark patterns undermine user autonomy and can violate privacy laws. We build a system, DarkDialogs, that automatically extracts arbitrary consent dialogs from a website and detects the presence of 10 dark patterns. Evaluating DarkDialogs against a hand-labelled dataset reveals it extracts dialogs with an accuracy of 98.7% and correctly classifies 99% of the studied dark patterns. We deployed DarkDialogs on a sample of 10,992 websites, where it successfully collected 2,417 consent dialogs and found 3,744 different dark patterns automatically present on the consent dialogs. We then test whether dark pattern prevalence is associated with each of: the website’s popularity, the presence of a third-party consent management provider, and the number of ID-like cookies.
Daniel Kirkman, Kami Vaniea, Daniel W. Woods
EuroS&P3
2023 Lessons Lost: Incident Response in the Age of Cyber Insurance and Breach Attorneys
Daniel W. Woods, Rainer Böhme, Josephine Wolff, Daniel Schwarcz
USENIX Security Symposium1
2022 The commodification of consent
abstract
In the commodification of consent, a legal concept designed to empower users has been transformed into an asset that can be traded across firms. Users interact with a consent dialog offered by one coalition member. The default setting allows any other coalition member, including both publishers and third-party vendors, to use this consent as a legal basis for processing personal data. In doing so, the commodification of consent creates interdependent privacy considerations within the notice and consent paradigm. This paper considers how this legal innovation could change the distribution of revenues among firms. Our model shows coalitions create the most value for firms with large consent deficits, which describes the proportion of users who the firm does not directly obtain consent from. The market leader in consent can capture all of the coalition fees by forming a series of 2-firm coalitions. Finally, a model extension shows how consent coalitions shift users towards providing consent to the coalition against the users’ wishes even though the probability of erroneously providing consent in a given dialog remains unchanged.
Daniel W. Woods, Rainer Böhme
Comput. Secur.1
2021 Blessed Are The Lawyers, For They Shall Inherit Cybersecurity
abstract
This paper considers which types of evidence guide cybersecurity decisions. We argue that the “InfoSec belongs to the quants” paradigm will not be realised despite its normative appeal. In terms of progress to date, we find few empirical results that can guide risk mitigation decisions. We suggest the knowledge base about quantitative cybersecurity is continually eroded by increasing complexity, technological flux, and strategic adversaries. Given these secular forces will not abate any time soon, we argue that legal reasoning will increasingly influence cybersecurity decisions relative to technical and quantitative reasoning. The law as a system of social control bristles with ambiguity and so legal mechanisms exist to resolve uncertainties over time. Actors with greater claims to authority over this knowledge base, predominantly lawyers, will accrue decision making power within organisations. We speculate about the downstream impacts of lawyers inheriting cybersecurity, and also sketch the limits of the paradigm’s explanatory power.
Daniel W. Woods, Aaron Ceross
NSPW1
2021 SoK: Quantifying Cyber Risk
abstract
This paper introduces a causal model inspired by structural equation modeling that explains cyber risk outcomes in terms of latent factors measured using reflexive indicators. First, we use the model to classify empirical cyber harm studies. We discover cyber harms are not exceptional in terms of typical or extreme losses. The increasing frequency of data breaches is contested and stock market reactions to cyber incidents are becoming less damaging over time. Focusing on harms alone breeds fatalism; the causal model is most useful in evaluating the effectiveness of security interventions. We show how simple statistical relationships lead to spurious results in which more security spending or applying updates are associated with greater rates of compromise. When accounting for threat and exposure, indicators of security are shown to be important factors in explaining the variance in rates of compromise, especially when the studies use multiple indicators of the security level.
Daniel W. Woods, Rainer Böhme
SP1
2021 Privacy Preference Signals: Past, Present and Future
abstract
Abstract Privacy preference signals are digital representations of how users want their personal data to be processed. Such signals must be adopted by both the sender (users) and intended recipients (data processors). Adoption represents a coordination problem that remains unsolved despite efforts dating back to the 1990s. Browsers implemented standards like the Platform for Privacy Preferences (P3P) and Do Not Track (DNT), but vendors profiting from personal data faced few incentives to receive and respect the expressed wishes of data subjects. In the wake of recent privacy laws, a coalition of AdTech firms published the Transparency and Consent Framework (TCF), which defines an optin consent signal. This paper integrates post-GDPR developments into the wider history of privacy preference signals. Our main contribution is a high-frequency longitudinal study describing how TCF signal gained dominance as of February 2021. We explore which factors correlate with adoption at the website level. Both the number of third parties on a website and the presence of Google Ads are associated with higher adoption of TCF. Further, we show that vendors acted as early adopters of TCF 2.0 and provide two case-studies describing how Consent Management Providers shifted existing customers to TCF 2.0. We sketch ways forward for a pro-privacy signal.
Maximilian Hils, Daniel W. Woods, Rainer Böhme
Proc. Priv. Enhancing Technol.2
2020 Measuring the Emergence of Consent Management on the Web
abstract
Privacy laws like the General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA) have pushed internet firms processing personal data to obtain user consent. Uncertainty around sanctions for non-compliance led many websites to embed a Consent Management Provider (CMP), which collects users' consent and shares it with third-party vendors and other websites. Our paper maps the formation of this ecosystem using longitudinal measurements. Primary and secondary data sources are used to measure each actor within the ecosystem. Using 161 million browser crawls, we estimate that CMP adoption doubled from June 2018 to June 2019 and then doubled again until June 2020. Sampling 4.2 million unique domains, we observe that CMP adoption is most prevalent among moderately popular websites (Tranco top 50-10k) but a long tail exists. Using APIs from the ad-tech industry, we quantify the purposes and lawful bases used to justify processing personal data. A controlled experiment on a public website provides novel insights into how the time-to-complete of two leading CMPs' consent dialogues varies with the preferences expressed, showing how privacy aware users incur a significant time cost.
Maximilian Hils, Daniel W. Woods, Rainer Böhme
Internet Measurement Conference2
2019 Post-incident audits on cyber insurance discounts
abstract
We introduce a game-theoretic model to investigate the strategic interaction between a cyber insurance policyholder whose premium depends on her self-reported security level and an insurer with the power to audit the security level upon receiving an indemnity claim. Audits can reveal fraudulent (or simply careless) policyholders not following reported security procedures, in which case the insurer can refuse to indemnify the policyholder. However, the insurer has to bear an audit cost even when the policyholders have followed the prescribed security procedures. As audits can be expensive, a key problem insurers face is to devise an auditing strategy to deter policyholders from misrepresenting their security levels to gain a premium discount. This decision-making problem was motivated by conducting interviews with underwriters and reviewing regulatory filings in the U.S.; we discovered that premiums are determined by security posture, yet this is often self-reported and insurers are concerned by whether security procedures are practised as reported by the policyholders. To address this problem, we model this interaction as a Bayesian game of incomplete information and devise optimal auditing strategies for the insurers considering the possibility that the policyholder may misrepresent her security level. To the best of our knowledge, this work is the first theoretical consideration of post-incident claims management in cyber security. Our model captures the trade-off between the incentive to exaggerate security posture during the application process and the possibility of punishment for non-compliance with reported security policies. Simulations demonstrate that common sense techniques are not as efficient at providing effective cyber insurance audit decisions as the ones computed using game theory.
Sakshyam Panda, Daniel W. Woods, Aron Laszka, Andrew Fielder, Emmanouil A. Panaousis
Comput. Secur.2