In-Depth Analysis of College Students' Data Privacy Awareness
Total Page:16
File Type:pdf, Size:1020Kb
Columbus State University CSU ePress Theses and Dissertations Student Publications 12-2020 In-Depth Analysis of College Students’ Data Privacy Awareness Vernon D. Andrews Follow this and additional works at: https://csuepress.columbusstate.edu/theses_dissertations Part of the Computer Sciences Commons Recommended Citation Andrews, Vernon D., "In-Depth Analysis of College Students’ Data Privacy Awareness" (2020). Theses and Dissertations. 437. https://csuepress.columbusstate.edu/theses_dissertations/437 This Thesis is brought to you for free and open access by the Student Publications at CSU ePress. It has been accepted for inclusion in Theses and Dissertations by an authorized administrator of CSU ePress. COLUMBUS STATE UNIVERSITY IN-DEPTH ANALYSIS OF COLLEGE STUDENTS’ DATA PRIVACY AWARENESS A THESIS SUBMITTED TO THE TURNER COLLEGE OF BUSINESS IN PARTIAL FULFILLMENT OF THE REQUIREMENTS FOR THE DEGREE OF MASTER OF CYBERSECURITY MANAGEMENT TSYS SCHOOL OF COMPUTER SCIENCE BY VERNON D. ANDREWS COLUMBUS, GEORGIA 2020 Copyright © 2020 Vernon D. Andrews All Rights Reserved. IN-DEPTH ANALYSIS OF COLLEGE STUDENTS’ DATA PRIVACY AWARENESS By Vernon D. Andrews Committee Chair: Dr. Lydia Ray Committee Members Dr. Radhouane Chouchane Dr. Lixin Wang Columbus State University December 2020 ABSTRACT: While attending university, college students need to be aware of issues related to data privacy. Regardless of the age, gender, race, or education level of college students, every student can relate to the advancement of the internet within the last decades. The internet has completely transformed the way the world receives and stores messages. Positively, the internet allows messages to be sent across the globe within the fraction of a second and provides students with access to potentially unlimited information on a variety of subjects. On the downside, there are issues on the internet that can cause more harm than good. Most college students automatically think the internet is secure; however, the internet is full of loopholes that allow hackers to expose them on the internet and utilize them to exploit individuals for monetary gains. Within the last decade, there has been an enormous number of data breaches that have pinpointed the lack of awareness regarding data privacy. Do college students, who utilize the Internet for entertainment and education, know about the issue of data privacy on the Internet? In this thesis, I have proposed a modern method that carefully analyzes the data privacy level amongst college students. To ensure ultimate data privacy, we must initially create the awareness then analyze the awareness of data privacy. To adequately address the fundamental issues of data privacy, students will be respectfully asked to satisfactorily complete a structured questionnaire. The questionnaire will measure students' competence level regarding data privacy. The observational data will be utilized to uniquely determine if students are aware of the issues of data privacy or not. After further analysis, the data will be used to determine if there are unique characteristics that separates those who are aware from those who are not aware. The characteristics will be age, education, race, and exposure to computer related classes. INDEX WORDS: Data Privacy, Data Awareness, Data Privacy Competence, Encryption, Cryptography iv ACKNOWLEDGMENTS First and foremost, praise and humbly thanks to God, the Almighty for divine wisdom, divine guidance, and his showering of blessing throughout my research work to satisfactorily complete the academic research successfully. I would genuinely like to admirably express my deep and sincere gratitude to my research supervisor, Dr. Lydia Ray, for providing me the opportunity to do research and providing me with invaluable guidance throughout this research. Her heartfelt sincerity, unique vision, and academic motivation have deeply inspired me. It was genuinely a pleasure and an incredible honor to work and study under her guidance. Besides my research supervisor, I would like to sincerely thank the rest of my thesis committee: Dr. Radhouane Chouchane and Dr. Lixin Wang for their insightful and encouraging comments. Last but not least, I would like to graciously thank the Association for Computing Machinery (ACM) for selecting me to present at their scholarly conferences and for publishing my scholarly research. v TABLE OF CONTENTS 1. INTRODUCTION 1 1.1 Cyber Attacks 1 1.2 Data Privacy 3 1.3 Risks Associated with Data Privacy 4 1.4 Data Privacy Concerns for College Students 4 1.5 Social Engineering (Phishing Attack) 5 1.6 Cyber Attacks’ Weakest link 6 2. LITERATURE REVIEW 7 3. RESEARCH STUDY 10 3.1 Goals 11 3.2 Motivation 11 3.3 Methodology 12 3.4 Research Questionnaire 13 3.5 Questions Design 14 3.6 Students Tested 15 3.7 Steps to Recruitment 15 3.8 Questionnaire Summary 16 4 RESULTS 16 4.1 Results and Score Grid 16 4.2 T-Test Distribution 17 4.3 Hypothesis 18 4.4 Further Analysis based on Question #5 22 5 CONCLUSIONS 27 6 LIMITATIONS 28 REFRENCES 29 APPENDICES 31 APPENDIX A - Old Questionnaire 31 APPENDIX B - New Questionnaire 34 vi LIST OF TABLES Table 1 Notable Cyber Attacks 01-02 vii LIST OF FIGURES Figure 1. Hidden Message 22 Figure 2. Males and Females Percentages 23 Figure 3. Race Percentages 24 Figure 4. Computer Science and Non-Computer Science Percentages 25 Figure 5. Education Level Percentages 26 Figure 6. Age Percentages 27 viii IN-DEPTH ANALYSIS OF COLLEGE STUDENTS’ DATA PRIVACY AWARENESS A thesis submitted to Turner School of Business in partial fulfillment of the requirements for the degree of MASTER OF CYBERSECURITY MANAGEMENT TSYS OF COMPUTER SCIENCE By Vernon D. Andrews 2020 ___________________________________________ ______________________________2/16/2021 Dr. Lydia Ray, Chair Date ___________________________________________ _______________________________4/15/2021 Dr. Radhouane Chouchane, Member Date ___________________________________________ _______________________________4/15/2021 Dr. Lixin Wang, Member Date 1 1. INTRODUCTION 1.1 Cyber Attacks Within the last decade, the number of cyberattacks has increased dramatically. According to researchers from the Pew Research Center, cyberattacks will continue to increase at an exponential rate within the next few years (Rainie, Anderson, & Connolly, 2020). Some of the attacks that instantly became notable in the world are listed in the Table 1 (Notable Cyber Attacks) below: Table 1(Notable Cyber Attacks): Name of Company Company’s Hacking Date # of users account Information exposed Abode Computer software October 2013 153 million Adult Friend Finder Dating Service October 2016 412.2 million Canva Graphic design May 2019 137 million Dubsmash Video messaging December 162 million service 2018 eBay Online auction May 2014 145 million Equifax Credit bureau July 2017 147.9 million Heartland Payment Card transaction March 2008 134 million Systems LinkedIn Social network June 2012 & 165 million May 2016 Marriott Int. Hotel 2014-18 500 million 2 My Fitness Pal Fitness app February 2018 150 million Myspace Social Media June 2013 360 million NetEase Mailbox services October 2015 235 million Sina Weibo Social Media March 2020 538 million Yahoo Web services 2013-14 3 billion Zynga Gaming September 218 million 2019 Not only did the attacks become notable but they also exposed the hundreds of vulnerabilities in the cybersecurity infrastructure of these organizations (Swinhoe, 2020). One of the major known vulnerabilities that always becomes exploited is human error. Human error, in cybersecurity context, is defined as unintentional actions - or lack of action - by employees and users that cause, spread or allow a security breach to take place (Aloha, 2020). Among all attacks that exploit human error and human vulnerability, social engineering is the most common and most frequent. And among all social engineering attacks, phishing emails are the most popular because these are easy to launch, and chances of successful attack are high. Now that we are in the middle of the coronavirus pandemic, cyberattack experts have seen a 600 percent spike in malicious emails (Miller, 2020). One significant harm caused by cyberattacks and data breaches is that they can expose and collect people’s private information. Most individuals might not agree with promoting data privacy awareness but there are at least two reasons why promoting data privacy awareness is important. One is that data breaches can expose a lot of private data. In 2016, Adult Friend Finder was hacked and exposed to over 412 millions of their users’ private lives which resulted in some suicides. The other reason is that attackers can use private information for constructing sophisticated spear-phishing emails. Phishing emails can manipulate users onto a fake domain site 3 that can monitor their users’ logins and passwords. For example, a phishing email can be strategically designed for a particular person that seems legit but in reality, is an attempt made to lure that person into entering their user’s login information. Checking emails is a task that many college students perform daily. With checking emails, students have to become aware of the enticing tools that hackers use to get students to perform human errors when checking for soliciting emails such as coupon codes, honor committee, flash sales, etc. The importance of becoming aware of data privacy is extremely high. Most college students don’t seem to think checking and clicking emails can expose them to becoming a potential victim or comprising their computer network. The approach here is to analyze whether college students are or are not aware of the issues related to data privacy. After researching this topic, it is safe to say that there is no such article that analyzes data privacy amongst college students. 1.2 Data Privacy What is data privacy, and how do we measure data privacy? As technology evolves, we clearly realize more and more issues related to data privacy. Data privacy has officially become an essential tool that all or almost every college student needs to explore the internet. One of the main issues related to data privacy is the awareness of data privacy.