<p>A privacy threat represents any possible limitation of the system design that can lead to harming the (explicit or implicit) privacy needs of the system stakeholders. Privacy threat modeling involves the systematic elicitation and analysis of potential privacy threats at the level of a system model representation. One of the most notable approaches—<span>linddun</span>—provides support in terms of both methodology and knowledge on how to identify relevant privacy threats. In terms of approach, threat modelers either engage in more open-ended brainstorms, or conduct more systematic and rigorous assessment using a system model encoded as a data flow diagram (<span>dfd</span>). In both cases, the threat modeler still extensively falls back upon implicit information and assumptions about the system under analysis, and this ties the threat analysis outcomes to such intangible and tacit factors. This is problematic as (i)&#xa0;it makes the knowledge, experience, and expertise of the threat analyst a dominant factor in the outcome, and (ii)&#xa0;when systems evolve, these implicit knowledge factors may change as well, yet their implicit nature hinders re-assessment of relevant threats. In this article, we present <span>linddun</span>&#xa0;<span>maestro</span>, an architecture framework which extends the traditional flow data diagram with six complementary architectural viewpoints, respectively, named the ‘application’, ‘communication’, ‘data’, ‘data subject’, ‘data lifecycle’, and ‘data access’ viewpoint. Each viewpoint supports capturing specific system model enrichments, which in turn supply relevant system information for focused <span>linddun</span> threat analysis. By selectively enriching the overall system model in function of privacy threat analysis, a more proactive approach can be taken to make threat analysis outcomes more clearly tied to the information expressed in the system model itself. In consequence, the overall threat analysis effort becomes more guided, focused, reproducible, and less prone to assumptions and uncertainty. We illustrate and validate <span>maestro</span> in an industrial application case, an IoT-based home automation system. Furthermore, we specifically evaluate the extent to which the proposed architectural views capture information otherwise stipulated or posited in threat model assumptions, and demonstrate that the proposed approach reduces reliance on implicit, informal or vaguely specified system assumptions.</p>

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

linddun maestro: an architecture framework for privacy threat modeling

  • Dimitri Van Landuyt,
  • Laurens Sion,
  • Wouter Joosen

摘要

A privacy threat represents any possible limitation of the system design that can lead to harming the (explicit or implicit) privacy needs of the system stakeholders. Privacy threat modeling involves the systematic elicitation and analysis of potential privacy threats at the level of a system model representation. One of the most notable approaches—linddun—provides support in terms of both methodology and knowledge on how to identify relevant privacy threats. In terms of approach, threat modelers either engage in more open-ended brainstorms, or conduct more systematic and rigorous assessment using a system model encoded as a data flow diagram (dfd). In both cases, the threat modeler still extensively falls back upon implicit information and assumptions about the system under analysis, and this ties the threat analysis outcomes to such intangible and tacit factors. This is problematic as (i) it makes the knowledge, experience, and expertise of the threat analyst a dominant factor in the outcome, and (ii) when systems evolve, these implicit knowledge factors may change as well, yet their implicit nature hinders re-assessment of relevant threats. In this article, we present linddun maestro, an architecture framework which extends the traditional flow data diagram with six complementary architectural viewpoints, respectively, named the ‘application’, ‘communication’, ‘data’, ‘data subject’, ‘data lifecycle’, and ‘data access’ viewpoint. Each viewpoint supports capturing specific system model enrichments, which in turn supply relevant system information for focused linddun threat analysis. By selectively enriching the overall system model in function of privacy threat analysis, a more proactive approach can be taken to make threat analysis outcomes more clearly tied to the information expressed in the system model itself. In consequence, the overall threat analysis effort becomes more guided, focused, reproducible, and less prone to assumptions and uncertainty. We illustrate and validate maestro in an industrial application case, an IoT-based home automation system. Furthermore, we specifically evaluate the extent to which the proposed architectural views capture information otherwise stipulated or posited in threat model assumptions, and demonstrate that the proposed approach reduces reliance on implicit, informal or vaguely specified system assumptions.