We analyze the risks associated with teenagers ’ online activities and the potential migration of cyber threats originating from teenagers to their parents ’ wor k-from-home (WFH) devices, even when defensive measures such as VPN are employed. Furthermore, we examine the serious implications these risks have on corporate security. Of particular concern, parents who work with confid ential corporate information, such as financial projections or product roadmaps, might find that their kids are targeted by hackers who seek an easier entry-point to home networks and eventually WFH devices. This paper is timely since there is a rising trend of hybrid work in white - collar professions, mixing traditional in-office work with WFH. The latter is increasingly done in split shifts, including work performed before breakfast or after dinner. While this shift offers numerous workforce advantages and helps teen-parent bonding, it also introduces a plethora of cybersecurity risks, especially when these devices and networks are shared with teenagers on home networks. We did a structured survey of 62 teens which confirms that risky online activity abounds, so the threat of risk migration onto corporate networks should not be ignored. We perform a migration risk assessment and identify which teen-origin risks are most likely to contaminate parent s ’ WFH devices. We evaluate 20 attack vectors and generate 60 risk ratings. We classify 29 as high risk, 8 as medium risk, 13 as low risk, and 10 as not relevant. We offer recommendations to mitigate this new set of cyber risks.
De Smidt, G. And Botzen, W. (2018) Perceptions of Corporate Cyber Risks and Insurance Decision-Making. The Geneva Papers on Risk and Insurance-Issues and Practice, 43, 239-274. https://doi.org/10.1057/s41288-018-0082-7
Popovici, V. And Popovici, A.L. (2020) Remote Work Revolution: Current Opportunities and Challenges for Organizations. Ovidius University Annals, Economic Sciences Series, XX, 468-472.
Adeyinka, O (2008) Analysis of Problems Associated with IPSec VPN Technology. 2008 Canadian Conference on Electrical and Computer Engineering, Niagara Falls, 4-7 May 2008, 001903-001908. https://doi.org/10.1109/CCECE.2008.4564875
Brynjolfsson, E., Horton, J.J., Ozimek, A., Rock, D., Sharma, G. and TuYe, H.Y. (2020) COVID-19 and Remote Work: An Early Look at US Data (No. w27344). National Bureau of Economic Research. https://doi.org/10.3386/w27344
Selwyn, N. (2010) Schools and Schooling in the Digital Age: A Critical Analysis. Routledge, London. https://doi.org/10.4324/9780203840795
Adorjan, M. and Ricciardelli, R. (2018) Cyber-Risk and Youth: Digital Citizenship, Privacy and Surveillance. Routledge, London. https://doi.org/10.4324/9781315158686
Xiong, J. and Jamieson, K. (2013) SecureArray: Improving Wifi Security with Fine-Grained Physical-Layer Information. Proceedings of the 19th Annual International Conference on Mobile Computing & Networking, Florida, 30 September-4 October 2013, 441-452. https://doi.org/10.1145/2500423.2500444
Mahmood, T. and Afzal, U. (2013) Security Analytics: Big Data Analytics for Cybersecurity: A Review of Trends, Techniques and Tools. 2013 2nd National Conference on Information Assurance, Rawalpindi, 11-12 December 2013, 129-134. https://doi.org/10.1109/NCIA.2013.6725337
Berger, T. (2006) Analysis of Current VPN Technologies. First International Conference on Availability, Reliability and Security, Vienna, 20-22 April 2006, 8-115. https://doi.org/10.1109/ARES.2006.30
Willard, N.E. (2007) Cyber-Safe Kids, Cyber-Savvy Teens: Helping Young People Learn to Use the Internet Safely and Responsibly. John Wiley & Sons, New York.
Krombholz, K., Hobel, H., Huber, M. and Weippl, E. (2015) Advanced Social Engineering Attacks. Journal of Information Security and Applications, 22, 113-122. https://doi.org/10.1016/j.jisa.2014.09.005
AlDaajeh, S., Saleous, H., Alrabaee, S., Barka, E., Breitinger, F. and Choo, K.K.R. (2022) The Role of National Cybersecurity Strategies on the Improvement of Cybersecurity Education. Computers & Security, 119, Article ID: 102754. https://doi.org/10.1016/j.cose.2022.102754
Haan, K. (2023) Remote Work Statistics & Trends. Forbes Advisor. https://www.forbes.com/
Dhamija, R., Tygar, J.D. and Hearst, M. (2006) Why Phishing Works. Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, Montréal, 22-27 April 2006, 581-590. https://doi.org/10.1145/1124772.1124861
Florencio, D. and Herley, C. (2007) A Large-Scale Study of Web Password Habits. Proceedings of the 16th International Conference on World Wide Web, Banff, 8-12 May 2007, 657-666. https://doi.org/10.1145/1242572.1242661
Sukwong, O., Kim, H. and Hoe, J. (2011) Commercial Antivirus Software Effectiveness: An Empirical Study. Computer, 44, 63-70. https://doi.org/10.1109/MC.2010.187
Herath, T.B., Khanna, P. and Ahmed, M. (2022) Cybersecurity Practices for Social Media Users: A Systematic Literature Review. Journal of Cybersecurity and Privacy, 2, 1-18. https://doi.org/10.3390/jcp2010001
Ter Louw, M., Lim, J.S. and Venkatakrishnan, V.N. (2008) Enhancing Web Browser Security against Malware Extensions. Journal in Computer Virology, 4, 179-195. https://doi.org/10.1007/s11416-007-0078-5
Singh, A.K., Samaddar, S.G. and Misra, A.K. (2012) Enhancing VPN Security through Security Policy Management. 2012 1st International Conference on Recent Advances in Information Technology (RAIT), Dhanbad, 15-17 March 2012, 137-142. https://doi.org/10.1109/RAIT.2012.6194494
Khan, M.T., DeBlasio, J., Voelker, G.M., Snoeren, A.C., Kanich, C. and Vallina-Rodriguez, N. (2018) An Empirical Analysis of the Commercial VPN Ecosystem. Proceedings of the Internet Measurement Conference 2018, Boston, 31 October-2 November 2018, 443-456. https://doi.org/10.1145/3278532.3278570
Szabo, N. (1997) Formalizing and Securing Relationships on Public Networks. First Monday, 2, page. https://doi.org/10.5210/fm.v2i9.548
Rieck, K., Holz, T., Willems, C., Düssel, P. and Laskov, P. (2008) Learning and Classification of Malware Behavior. In: Zamboni, D., Ed., DIMVA 2008: Detection of Intrusions and Malware, and Vulnerability Assessment, Springer, Berlin, 108-125. https://doi.org/10.1007/978-3-540-70542-0_6
Geers, K. (2010) The Challenge of Cyber Attack Deterrence. Computer Law & Security Review, 26, 298-303. https://doi.org/10.1016/j.clsr.2010.03.003
Li, S.M. and Liang, H.Y. (2011) A Model of Path Fault Recovery of MPLS VPN and Simulation. 2011 International Conference on Electric Information and Control Engineering, Wuhan, 15-17 April 2011, 1925-1928. https://doi.org/10.1109/ICEICE.2011.5777806
Siddiqi, M.A., Pak, W. and Siddiqi, M.A. (2022) A Study on the Psychology of Social Engineering-Based Cyberattacks and Existing Countermeasures. Applied Sciences, 12, Article 6042. https://doi.org/10.3390/app12126042
Sun, Y., Wang, B., Wang, C. and Wei, Y. (2021) On Man-in-the-Middle Attack Risks of the VPN Gate Relay System. Security and Communication Networks, 2021, Article ID: 9091675. https://doi.org/10.1155/2021/9091675
Radanliev, P., De Roure, D.C., Maple, C., Nurse, J.R., Nicolescu, R. and Ani, U. (2019) Cyber Risk in IoT Systems. https://doi.org/10.20944/preprints201903.0104.v1
Zhang, Z., Zhang, Y.Q., Chu, X. and Li, B. (2004) An Overview of Virtual Private Network (VPN): IP VPN and Optical VPN. Photonic Network Communications, 7, 213-225. https://doi.org/10.1023/B:PNET.0000026887.35638.ce
Miller, J.F. (2013) Supply Chain Attack Framework and Attack Patterns. The MITRE Corporation, MacLean VA. https://doi.org/10.21236/ADA610495
Chen, W., He, Y., Tian, X. and He, W. (2021) Exploring Cybersecurity Education at the k-12 Level. In: Langran, E. and Rutledge, D., Eds., Proceedings of SITE Interactive Conference, Association for the Advancement of Computing in Education, Chesapeake, 108-114.