首页> 外文会议>IEEE Security and Privacy Workshops >Privacy Risk Assessment for Data Subject-Aware Threat Modeling
【24h】

Privacy Risk Assessment for Data Subject-Aware Threat Modeling

机译:数据主体感知威胁建模的隐私风险评估

获取原文

摘要

Regulatory efforts such as the General Data Protection Regulation (GDPR) embody a notion of privacy risk that is centered around the fundamental rights of data subjects. This is, however, a fundamentally different notion of privacy risk than the one commonly used in threat modeling which is largely agnostic of involved data subjects. This mismatch hampers the applicability of privacy threat modeling approaches such as LINDDUN in a Data Protection by Design (DPbD) context. In this paper, we present a data subject-aware privacy risk assessment model in specific support of privacy threat modeling activities. This model allows the threat modeler to draw upon a more holistic understanding of privacy risk while assessing the relevance of specific privacy threats to the system under design. Additionally, we propose a number of improvements to privacy threat modeling, such as enriching Data Flow Diagram (DFD) system models with appropriate risk inputs (e.g., information on data types and involved data subjects). Incorporation of these risk inputs in DFDs, in combination with a risk estimation approach using Monte Carlo simulations, leads to a more comprehensive assessment of privacy risk. The proposed risk model has been integrated in threat modeling tool prototype and validated in the context of a realistic eHealth application.
机译:诸如通用数据保护条例(GDPR)之类的监管工作体现了隐私风险的概念,该概念围绕数据主体的基本权利。但是,这是与威胁建模中常用的隐私风险根本不同的概念,后者在很大程度上不涉及所涉及的数据主体。这种不匹配阻碍了隐私威胁建模方法(如LINDDUN)在数据保护设计(DPbD)上下文中的适用性。在本文中,我们在隐私威胁建模活动的特定支持下提出了一种数据主体感知的隐私风险评估模型。该模型使威胁建模者可以更全面地了解隐私风险,同时评估特定隐私威胁与正在设计的系统的相关性。此外,我们建议对隐私威胁建模进行许多改进,例如使用适当的风险输入(例如,有关数据类型和涉及的数据主体的信息)来丰富数据流图(DFD)系统模型。将这些风险输入并入DFD中,再结合使用蒙特卡洛模拟的风险估计方法,可以对隐私风险进行更全面的评估。拟议的风险模型已集成到威胁建模工具原型中,并在实际的eHealth应用程序中进行了验证。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号