From Privacy Policies to Privacy Threats: A Case Study in Policy-Based Threat Modeling

被引:0
|
作者
Dimova, Yana [1 ]
Kode, Mrunmayee [1 ]
Kalantari, Shirin [1 ]
Wuyts, Kim [1 ]
Joosen, Wouter [1 ]
Muhlberg, Jan Tobias [2 ]
机构
[1] Katholieke Univ Leuven, DistriNet, Leuven, Belgium
[2] Univ Libre Bruxelles, Brussels, Belgium
关键词
privacy; privacy policy; threat modeling; case study; LINDDUN;
D O I
10.1145/3603216.3624962
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Privacy threat modeling is a systematic approach to assess potential privacy risks which are a consequence of a given system design. Eliciting privacy threats requires a detailed understanding of system components and the ways in which these components interact. This makes it hard to impossible for any user, e.g., parties who interact with the system but do not possess knowledge about the inner workings of that system, to meaningfully engage in threat modeling and risk assessment. We explore an approach to address this problem by relying on information from a system's publicly available privacy policies to derive system models and apply threat modeling analyses. We chose the WhatsApp instant messaging system as a case study for privacy threat modeling from the perspective of a "regular" user. We apply the LINDDUN GO methodology and evaluate how threats evolved with time in two significant territorial areas, the European Union and India. Our study illustrates the impact of regulations and court cases and our approach may aid practitioners without inside knowledge to make informed choices regarding privacy risks when adopting third-party services.
引用
收藏
页码:17 / 29
页数:13
相关论文
共 50 条
  • [41] Knowledge-enriched Security and Privacy Threat Modeling
    Sion, Laurens
    Yskout, Koen
    Van Landuyt, Dimitri
    Joosen, Wouter
    PROCEEDINGS 2018 IEEE/ACM 40TH INTERNATIONAL CONFERENCE ON SOFTWARE ENGINEERING - COMPANION (ICSE-COMPANION, 2018, : 290 - 291
  • [42] Surprising Privacy Threats from Innocuous Sensors
    Singh, Shirish
    MAISP 2021 - Proceedings of the 2021 1st Workshop on Security and Privacy for Mobile AI, 2021, : 19 - 24
  • [43] LINDDUN GO: A Lightweight Approach to Privacy Threat Modeling
    Wuyts, Kim
    Sion, Laurens
    Joosen, Wouter
    2020 IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2020), 2020, : 302 - 309
  • [44] Policy-based Coordination in PAGODA: A Case Study
    Talcott, Carolyn L.
    ELECTRONIC NOTES IN THEORETICAL COMPUTER SCIENCE, 2007, 181 (01) : 97 - 112
  • [45] Privacy Threat Modeling Framework for Online Social Networks
    Wang, Yong
    Nepali, Raj Kumar
    PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON COLLABORATION TECHNOLOGIES AND SYSTEMS, 2015, : 358 - 363
  • [46] On the Applicability of Security and Privacy Threat Modeling for Blockchain Applications
    Van Landuyt, Dimitri
    Sion, Laurens
    Vandeloo, Emiel
    Joosen, Wouter
    COMPUTER SECURITY, ESORICS 2019, 2020, 11980 : 195 - 203
  • [47] An Exploratory Study on the Measuring of Privacy Policies
    Yang, Lianfeng
    Chen, Qiuying
    Hu, Yonhong
    SIXTEENTH WUHAN INTERNATIONAL CONFERENCE ON E-BUSINESS, 2017, : 338 - 348
  • [48] Is Your Policy Compliant? A Deep Learning-based Empirical Study of Privacy Policies' Compliance with GDPR
    Al Rahat, Tamjid
    Long, Minjun
    Tian, Yuan
    PROCEEDINGS OF THE 21ST WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2022, 2022, : 89 - 102
  • [49] Interaction-based Privacy Threat Elicitation
    Sion, Laurens
    Wuyts, Kim
    Yskout, Koen
    Van Landuyt, Dimitri
    Joosen, Wouter
    2018 3RD IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY WORKSHOPS (EUROS&PW 2018), 2018, : 79 - 86
  • [50] Privacy: History, Statistics, Policy, Laws, Preservation and Threat Analysis
    Nair, Meghna Manoj
    Tyagi, Amit Kumar
    JOURNAL OF INFORMATION ASSURANCE AND SECURITY, 2021, 16 (01): : 24 - 34