From Privacy Policies to Privacy Threats: A Case Study in Policy-Based Threat Modeling

被引:0
作者
Dimova, Yana [1 ]
Kode, Mrunmayee [1 ]
Kalantari, Shirin [1 ]
Wuyts, Kim [1 ]
Joosen, Wouter [1 ]
Muhlberg, Jan Tobias [2 ]
机构
[1] Katholieke Univ Leuven, DistriNet, Leuven, Belgium
[2] Univ Libre Bruxelles, Brussels, Belgium
来源
PROCEEDINGS OF THE 22ND WORKSHOP ON PRIVACY IN THE ELECTRONIC SOCIETY, WPES 2023 | 2023年
关键词
privacy; privacy policy; threat modeling; case study; LINDDUN;
D O I
10.1145/3603216.3624962
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Privacy threat modeling is a systematic approach to assess potential privacy risks which are a consequence of a given system design. Eliciting privacy threats requires a detailed understanding of system components and the ways in which these components interact. This makes it hard to impossible for any user, e.g., parties who interact with the system but do not possess knowledge about the inner workings of that system, to meaningfully engage in threat modeling and risk assessment. We explore an approach to address this problem by relying on information from a system's publicly available privacy policies to derive system models and apply threat modeling analyses. We chose the WhatsApp instant messaging system as a case study for privacy threat modeling from the perspective of a "regular" user. We apply the LINDDUN GO methodology and evaluate how threats evolved with time in two significant territorial areas, the European Union and India. Our study illustrates the impact of regulations and court cases and our approach may aid practitioners without inside knowledge to make informed choices regarding privacy risks when adopting third-party services.
引用
收藏
页码:17 / 29
页数:13
相关论文
共 56 条
  • [1] Abby, 2020, WhatsApp Pay: what is happening with WhatsApp not-so-new payment feature?
  • [2] Amoroso EG., 1994, Fundamentals of computer security technology
  • [3] Privacy Policies over Time: Curation and Analysis of a Million-Document Dataset
    Amos, Ryan
    Acar, Gunes
    Lucherini, Elena
    Kshirsagar, Mihir
    Narayanan, Arvind
    Mayer, Jonathan
    [J]. PROCEEDINGS OF THE WORLD WIDE WEB CONFERENCE 2021 (WWW 2021), 2021, : 2165 - 2176
  • [4] Andow B, 2020, PROCEEDINGS OF THE 29TH USENIX SECURITY SYMPOSIUM, P985
  • [5] Andow B, 2019, PROCEEDINGS OF THE 28TH USENIX SECURITY SYMPOSIUM, P585
  • [6] [Anonymous], 2018, Introducing the WhatsApp Business App
  • [7] Banaji S., 2019, WHATSAPP VIGILANTES
  • [8] Bateman Tom, 2021, WhatsApp rewrites its Europe privacy policy after a record _225 million GDPR fine
  • [9] Braiterman Zoe, 2023, Threat Modeling Manifesto
  • [10] Cavoukian A., 2009, PRIVACY DESIGN 7 FDN